hesta
Privacy Policy
Effective date: 7 July 2026
This policy explains how Hesta ("we", "us") collects, uses, and protects personal data when
you use the Hesta apps — the Hesta Business app for salons and beauty
professionals and the Hesta app for customers — and the hesta.app website.
Hesta is operated from Romania and complies with the EU General Data Protection Regulation
(GDPR).
Data we collect
-
Account data — phone number (used to sign in via SMS code), name, email
address, and optional profile photo. If you sign in with Google, Facebook, or Apple, we
receive your basic profile (name, email) from that provider.
-
Business data — for business accounts: business name, description,
address, contact details, services, working hours, staff members, and photos you upload.
-
Booking data — appointments you book or manage, including date, time,
service, and the contact details a business records for its customers.
-
Reviews — ratings and review text you choose to submit.
-
Location — in the customer app, your approximate location (with your
permission) to find salons near you. We do not store a location history.
-
Instagram data — if a business connects its Instagram Professional
account, we store the Instagram account ID and username, an access token (encrypted at
rest), and copies of the business's own Instagram posts that are captioned
#hesta (image, caption, permalink, post date). We never collect data
about other Instagram users, followers, or messages.
-
Device and diagnostics — push-notification tokens, app version, and
crash/error reports (via Sentry) so we can fix problems.
-
Analytics and attribution — only on the website, and only if you accept
the cookie banner: usage analytics via Google Analytics 4, and a first-party attribution
cookie (
hesta_attr) recording which channel brought you to the site — for
example a WhatsApp, Instagram, Facebook, TikTok, Google, or email link — derived from
UTM tags, ad-click identifiers (such as gclid or fbclid), and
the referring website. When you then make a booking, that channel is attached to the
booking so a business can see where its bookings come from. If you decline, none of this
is loaded, set, or collected.
How we use data
- To provide the service: accounts, bookings, calendars, notifications, and reviews.
- To display a business's #hesta Instagram posts on its public Hesta page, when the business has connected Instagram.
- To send service messages such as booking confirmations and reminders (SMS, push, email).
- To keep the service secure, prevent abuse, and diagnose technical issues.
We do not sell personal data, and we do not use it for third-party advertising.
Cookies and analytics
The hesta.app website sets no analytics or marketing cookies until you choose. On your first
visit a consent banner asks whether to enable them:
-
If you accept, we load Google Analytics 4 (operated by
Google Ireland Ltd) to measure how the site is used, and we store a first-party
hesta_attr cookie (up to 90 days) recording the channel that referred you.
When you book, that channel is attached to the booking so the business can see where its
bookings come from. Google Analytics runs in Consent Mode with advertising features
(ad storage and ad personalisation) switched off — we do not use it for advertising.
-
If you decline, Google Analytics is never loaded, no analytics or
attribution cookies are set, and no attribution is recorded — only the strictly necessary
cookies needed to sign in and use the site remain.
-
Your choice is remembered in a
hesta_consent cookie for one year, and you can
change it at any time from the website.
Legal bases
We process data to perform our contract with you (providing the service), with your consent
(e.g. location access, connecting Instagram), and for our legitimate interests (security,
service diagnostics). You can withdraw consent at any time.
Sharing
-
When you book an appointment, the business you book with sees the details needed to serve
you (your name, contact details, and the booking).
-
A business's public page (name, photos, services, reviews, and — if connected — its
#hesta Instagram posts) is visible to app users.
-
We use service providers to run Hesta: hosting and storage, SMS delivery, push
notifications (Firebase Cloud Messaging), email delivery, error reporting (Sentry),
website analytics (Google Analytics 4, operated by Google Ireland — only with your
consent), and — only for connected businesses — the Instagram API operated by Meta
Platforms. These providers process data on our behalf under data-processing agreements.
Retention
We keep data while your account is active. Appointment and audit records are retained only
as long as needed for the service and our legal obligations. Instagram data (token and
mirrored posts) is deleted immediately when a business disconnects Instagram or deletes its
account.
Your rights
Under the GDPR you can access, correct, export, or delete your data, and object to or
restrict processing. In the apps you can edit your profile, export your data, and delete
your account from Settings. See our
data deletion page for details, or contact us at
[email protected]. You also have the right to lodge a
complaint with your data-protection authority (in Romania, ANSPDCP).
Security
Data is encrypted in transit (TLS). Sign-in tokens are stored in your device's secure
storage, and Instagram access tokens are encrypted at rest on our servers. Access to
production systems is restricted.
Children
Hesta is not directed at children under 16, and we do not knowingly collect their data.
Changes
We will post any changes to this policy on this page and update the effective date above.
Contact
Hesta — [email protected]