Privacy Policy

Last Updated: June 2026 ยท Version 1.0

Effective Date: July 1, 2026

1. Who We Are & How to Contact Us

Lookit!!! Lookit!!! is operated by Marius-Mario Haidu, located in Romania.
Website: lookitonline.com

Privacy Officer:

๐Ÿ“งprivacy@lookitonline.com โ€” response within 48 business hours

Data Protection Authority (complaints):

๐Ÿ›๏ธRomanian ANSPDCP โ€” www.anspdcp.ro

2. What Data We Collect & Why

For Customers:

โœ“Name โ€“ to identify you in confirmations
โœ“Email address โ€“ for booking confirmations
โœ“Phone number โ€“ for business communication
โœ“Appointment preferences โ€“ services, dates, times
โœ“Location data โ€“ city/area to find businesses (not GPS)
โœ“Special notes โ€“ requests for appointments

For Business Owners:

โœ“Business name, description, address, hours
โœ“Phone number and email
โœ“Services offered (pricing and duration)
โœ“Customer list (names, contact info)

Collected Automatically:

โœ“Device information โ€“ phone model, OS, app version
โœ“Usage logs โ€“ pages visited, businesses viewed
โœ“Appointment history โ€“ past and scheduled bookings
โœ“IP address โ€“ for security and fraud prevention
โœ“Session cookies โ€“ authentication only
โœ“Analytics data โ€“ aggregated, anonymized stats

What We Do NOT Collect:

โŒCredit card numbers (processed by payment providers)
โŒMedical or health information
โŒContinuous GPS tracking
โŒBiometric data
โŒFinancial account details
โŒChildren's data (we don't serve users under 18)

3. How We Use Your Data

Essential Functions:

โ€ขAppointment booking and scheduling
โ€ขBooking confirmations and reminders
โ€ขAccount management and updates

Service Improvement:

โ€ขAnalytics (which features are used)
โ€ขPerformance monitoring
โ€ขBug identification

What We Do NOT Do:

โŒSell data to third parties
โŒUse data for targeted advertising without consent
โŒShare email/phone with marketers
โŒTrack behavior across other websites
โŒCreate detailed behavioral profiles

4. Data Security & Encryption

How We Protect Your Data:

โœ“Encryption at Rest & In Transit โ€“ All stored data is encrypted and all communications are secured using TLS
โœ“Infrastructure Security โ€“ Automated security patching, firewall management, and DDoS mitigation
โœ“Database Isolation โ€“ Your data is logically isolated from other applications
โœ“Authentication & Row-Level Security (RLS) โ€“ Fine-grained RLS policies ensure users access only authorized records
โœ“Managed Backups โ€“ Automated backups ensure data durability
โœ“Secure API & SDK โ€“ All API endpoints authenticate requests securely

Your Responsibility:

โ€ขKeep passwords confidential
โ€ขLog out on shared devices
โ€ขReport suspicious activity immediately

5. Who We Share Your Data With

Service Providers (Necessary):

โ€ขGoogle Analytics โ€“ anonymized usage stats only
โ€ขAzure/AWS โ€“ encrypted cloud hosting

Legal Obligations:

We may disclose data if required by law (court orders, government requests, emergency safety, enforcement of Terms).

We explicitly do NOT sell data to advertisers, data brokers, or marketing companies.

6. Your Data Rights (GDPR / CCPA / LGPD)

Right to Access

Request a copy of your data (JSON/CSV). Email: privacy@lookitonline.com โ€” 15 days

Right to Correction

Update incorrect information via in-app settings or email โ€” 5 business days

Right to Deletion

Settings > Delete My Account or email. Deleted within 30 days (exceptions: legal/financial records, 7 years)

Right to Data Portability

Settings > Export My Data โ€” 10 days

Right to Opt-Out

Settings > Privacy โ€” immediate effect

Right to Object

Email privacy@lookitonline.com โ€” response within 10 days

7. Data Retention & Deletion

Retention Schedule:

โ€ขAppointment history: 2 years
โ€ขCustomer contact info: Until deletion request
โ€ขPayment records: 7 years (legal requirement)
โ€ขLogin/access logs: 6 months
โ€ขDeleted account data: 30 days backup window
โ€ขDatabase backups: 90 days
โ€ขSupport tickets: 2 years

Automatic Deletion:

โ€ขInactive accounts (2 years): Deleted after warning
โ€ขDisabled accounts: Deleted after 180 days
โ€ขFailed transactions: Deleted after 90 days

8. Data Breach Notification

If a breach occurs, we will notify affected users within 72 hours via email, report to ANSPDCP, and publish a statement at lookitonline.com/security.

We maintain cyber liability insurance for breach response.

9. Cookies, Tracking & Analytics

Essential Cookies (Required):

โœ“session_id โ€“ Keeps you logged in
โœ“_csrf_token โ€“ Security protection

Optional Cookies (Can be Disabled):

โ€ขGoogle Analytics โ€“ Usage statistics. Opt-out: Settings > Privacy > Disable Analytics

Important:

โŒNo behavioral profiling
โŒNo cross-site tracking
โŒNo pixel/beacon tracking
โŒNo selling behavior to advertisers
โœ“Respects Do Not Track signals

10. International Data Transfers

โ€ขPrimary Storage: Europe (GDPR-compliant)
โ€ขBackups: Encrypted and distributed
โ€ขServers: Microsoft Azure/AWS (GDPR certified)

EU users are covered under GDPR. California residents have CCPA rights. Brazilian residents have LGPD protection.

11. Children's Privacy

Lookit!!! is not intended for users under 18. If you believe your child's data was collected, contact privacy@lookitonline.com and we will delete it upon notification.

13. Contact & Complaints

๐Ÿ“งQuestions: privacy@lookitonline.com โ€” 48 hour response

Lodge a Complaint:

โ€ขEU: ANSPDCP โ€” www.anspdcp.ro
โ€ขUSA: California Attorney General
โ€ขBrazil: ANPD (Autoridade Nacional de Protecao de Dados)

Or email privacy@lookitonline.com with subject 'Privacy Complaint' โ€” response within 10 business days.

14. Google Calendar Integration

To provide scheduling convenience, Lookit!!! offers optional integration with Google Calendar. This section explains exactly how we access, use, and protect your Google account data in compliance with Google API Services User Data Policy.

Data Accessed:

โœ“Google account email โ€” used solely to identify your account during the OAuth connection flow
โœ“Calendar events (read) โ€” to check your existing availability and prevent double-booking
โœ“Calendar events (write) โ€” to add confirmed Lookit!!! appointments directly to your calendar

Data Usage:

โ€ขCalendar data is used exclusively for appointment scheduling and conflict detection
โ€ขWe do not use calendar data for advertising, profiling, or any purpose unrelated to scheduling
โ€ขWe do not read, modify, or delete any calendar events that were not created by Lookit!!!

Data Sharing:

โŒWe do not share your Google Calendar data with any third parties
โŒAccess is strictly limited to the user who authorized the connection
โŒWe do not sell, rent, or disclose calendar data to advertisers or external entities

Data Protection:

โœ“Access tokens are stored using encrypted, platform-level secure storage
โœ“All data in transit is protected via TLS/SSL encryption
โœ“Row-Level Security (RLS) ensures only you can access your own calendar tokens

Revoking Access & Deletion:

โ€ขYou can revoke Google Calendar access at any time via your Google Account at myaccount.google.com/permissions
โ€ขDisconnecting within Lookit!!! immediately purges all stored tokens and cached calendar data
โ€ขDeleting your Lookit!!! account also permanently removes all Google OAuth tokens from our systems

15. AI-Powered Features & Third-Party AI Services

Lookit!!! uses artificial intelligence to power certain optional features. This section discloses what data is transmitted to AI services, who provides them, and how your information is protected โ€” in compliance with Apple App Store requirements and GDPR.

AI-Powered Features:

โ€ขBooking Assistant (Let us Bookit!) โ€” conversational AI that helps you find businesses, compare services, and book appointments
โ€ขLanguage Translation โ€” translates your messages and generates call scripts for businesses that speak a different language
โ€ขRisk Assessment โ€” analyzes booking patterns to detect fraud and protect businesses (administrator use only)

Data Transmitted to the AI Provider:

โœ“Your first name โ€” for personalized conversation
โœ“Your approximate location (city/area) โ€” to find nearby businesses
โœ“Text messages you type in the AI chat
โœ“Appointment context โ€” service type, date, time, business name
โœ“Business public information โ€” name, services offered, phone number

Data NOT Transmitted:

โŒYour password or authentication credentials
โŒPayment or financial information
โŒPrecise GPS coordinates
โŒYour browsing history outside Lookit!!!
โŒYour email address or phone number (unless you explicitly type them in the chat)

AI Service Provider:

โ€ขProvider: OpenAI, accessed via Base44's platform infrastructure
โ€ขProcessing: Data is sent to OpenAI's API under their enterprise data usage terms
โ€ขTraining: Your data is NOT used to train or improve AI models
โ€ขEncryption: All data in transit is protected via TLS/SSL
โ€ขRetention: AI conversation data is not stored by the provider beyond the session

Your Consent & Control:

โœ“Explicit consent is required before any data is sent to the AI provider
โœ“AI features are entirely optional โ€” you can book appointments without them
โœ“You may withdraw AI consent at any time via Settings
โœ“Withdrawing consent immediately stops all data transmission to the AI provider
โœ“Your existing bookings and account are not affected by withdrawing AI consent
By using Lookit!!!, you acknowledge reading this privacy policy.
Last Updated: June 2026 ยท Next Review: June 2027