Privacy Policy
Last updated: June 9, 2026
This Privacy Policy explains how MB Covra. ("Covra.", "we", "us", or "our") collects, uses, stores, and protects personal data when you use the Covra. online booking and business management platform, including our website, public booking pages, client portals, and related services (collectively, the "Service").
Covra. is designed for service businesses - including salons, clinics, studios, and tattoo parlours - to manage appointments, staff, clients, and related workflows. Depending on your relationship with the Service, Covra. may act as a data controller, a data processor, or both, as described in this Policy.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Law on Legal Protection of Personal Data of the Republic of Lithuania, and other applicable data protection legislation.
Who We Are and How to Contact Us
The data controller for personal data relating to business accounts, marketing communications, website visitors, and platform administration is:
- MB Covra.
- Email: hello@covra.lt
- Phone: +370 621 10999
For questions about this Privacy Policy, to exercise your data protection rights, or to contact our data protection representative, please use the contact details above. We will respond within the timeframes required by applicable law.
Scope of This Policy
This Policy applies to:
- Visitors to Covra. marketing pages and documentation
- Business users who register for and operate a Covra. account ("Business Users")
- Staff members invited by Business Users to access a Covra. workspace
- End clients who book appointments, join waitlists, submit reviews, or use token-based portals without creating an account ("End Clients")
- Individuals who interact with tattoo studio features such as project portals, deposit payments, and design review workflows
- Authorised platform administrators who access Covra.'s internal administration system
This Policy does not govern how Business Users process End Client data for their own purposes. Business Users are independent controllers of End Client data and are responsible for providing their own privacy notices and lawful bases for processing.
Data Controller and Processor Roles
Covra.'s role depends on the category of data and the context of processing:
- Controller: Covra. acts as controller for Business User account data, billing and subscription records, marketing and support communications, website analytics where applicable, audit logs relating to platform integrity, and platform administrator access data.
- Processor: When Business Users use Covra. to store and manage End Client data - including booking details, contact information, intake form responses, tattoo project records, reviews, and uploaded files - Covra. processes that data on behalf of the Business User and in accordance with their instructions as set out in the Service configuration.
- Joint arrangements: Where Covra. and a Business User jointly determine purposes and means of processing (for example, certain review or fraud-prevention workflows), responsibilities will be allocated contractually and described in the Business User's terms or data processing terms where required.
Business Users must ensure they have a lawful basis to collect and upload End Client data into Covra. and must not use the Service to process special categories of personal data unless permitted by law and appropriately safeguarded.
Categories of Data Subjects
We process personal data relating to the following categories of individuals:
- Prospective and registered Business Users and account owners
- Staff members with workspace access, including role-based permissions
- End Clients booking services through public pages (/book/[slug]) or managed by Business Users
- Individuals using magic-link or token-based portals to cancel, reschedule, manage, review, or approve designs without an account
- Tattoo studio clients participating in multi-session projects, deposits, and aftercare communications
- Individuals submitting reviews or joining waitlists
- Platform administrators with access to Covra.'s internal administration environment
Personal Data We Collect - Business Users
When you create and use a Business User account, we may collect and process:
- Identity and contact data: name, email address, phone number
- Business profile data: business name, industry, public slug, branding, locale preferences, and onboarding responses
- Account and authentication data: magic link tokens, session identifiers, login timestamps, and device-related metadata
- Operational data: services, schedules, availability blocks, staff records, role assignments, and workspace settings
- Billing data: selected plan (Starter, Pro, or Business), subscription status, Stripe customer and subscription identifiers, invoice references, and payment history metadata (card details are processed directly by Stripe and not stored by Covra.)
- Communications: support requests, feedback, and service-related emails
- Technical and security data: IP address, browser user agent, audit logs of significant account actions, and error diagnostics
We do not charge commission on bookings processed through Covra. Booking payment flows between Business Users and End Clients, where enabled, may involve Stripe or other payment methods configured by the Business User and are subject to separate arrangements.
Personal Data We Collect - End Clients
When End Clients interact with a Business User's Covra.-powered booking experience, we may process:
- Identity and contact data: name, phone number, email address
- Booking data: appointment date and time, selected service, staff member, status, cancellation and rescheduling history, and notes added by the client or Business User
- Waitlist data: requested service, preferred times, and contact details
- Review data: star rating, written comment, submission timestamp, IP address, and browser user agent for abuse prevention
- Intake form responses: health, preference, or custom questions configured by the Business User
- Communications metadata: confirmation, reminder, and transactional messages sent via email
- Token portal activity: use of secure links to cancel, manage, reschedule, submit reviews, or participate in design review without creating a password-based account
End Client data is primarily processed on behalf of the relevant Business User. Requests relating to End Client data may be forwarded to that Business User where Covra. acts as processor.
Tattoo Studio and Industry-Specific Data
Business Users in the tattoo industry may use additional features that involve further personal data, including:
- Tattoo client profiles and profileMeta JSON fields storing preferences, medical notes, or custom attributes defined by the Business User
- Project records: design concepts, session plans, deposit amounts, payment status, and progress milestones
- Design references and progress photos uploaded to secure object storage
- Portfolio works and gallery images displayed on public booking pages
- Aftercare instructions and follow-up messages
- Design review and approval workflows using tokenised portal links
Images and files are stored using S3-compatible object storage. Business Users are responsible for obtaining appropriate consent before uploading identifiable images or sensitive information relating to End Clients.
Authentication, Sessions, and Token Portals
Covra. uses passwordless magic link authentication for Business Users and staff. We process email addresses to deliver single-use or time-limited login links and maintain authenticated sessions.
- Session cookies (httpOnly, up to 30 days) maintain authenticated access to Business User workspaces
- Locale cookies store language preferences (Lithuanian, English, or Russian)
- Token portals allow End Clients to perform specific actions via unique URLs without account registration; token validity, scope, and expiry are defined by the Service logic and Business User settings
- Platform administrators access a separate administration system protected by two-factor authentication (2FA), with dedicated session cookies (covra_admin_session) and additional logging of IP address and user agent
You should treat magic links and portal tokens as confidential credentials. Do not share them with unauthorised persons.
Platform Administration and Audit Logs
Covra. maintains an internal platform administration system used by authorised personnel to operate, secure, and support the Service. Related processing includes:
- Administrator identity, credentials, and 2FA enrolment data
- Session records including IP address, user agent, and access timestamps
- Audit logs of administrative actions, configuration changes, and security-relevant events
- System health, billing oversight, and support diagnostics necessary to maintain Service integrity
Access to platform administration functions is restricted on a need-to-know basis and subject to enhanced security controls.
Legal Bases for Processing
We process personal data only where a lawful basis applies under GDPR Article 6 (and Article 9 where relevant). Depending on context, our bases include:
- Contract: to provide the Service, manage subscriptions, deliver booking functionality, and perform obligations under our Terms of Service
- Legitimate interests: to secure the platform, prevent abuse, improve functionality, maintain audit trails, and communicate about service updates, balanced against data subject rights
- Legal obligation: to comply with accounting, tax, or regulatory requirements
- Consent: where required for optional marketing communications or non-essential cookies; End Client consent for certain communications may be obtained by the Business User as controller
Where Covra. processes End Client data as processor, the Business User determines the lawful basis and is responsible for documenting it.
How We Use Personal Data
We use personal data to:
- Provide and operate online booking, calendar management, client records, staff scheduling, and public booking pages
- Enable waitlists, reviews, portfolio displays, intake forms, emergency cancellation workflows, and tattoo studio project features
- Authenticate users, manage sessions, and deliver magic link and portal communications
- Process subscription billing and manage Starter, Pro, and Business plan entitlements
- Send transactional emails such as confirmations, reminders, and account notices via Resend
- Store files including logos, portfolio images, and project photos using S3-compatible storage
- Monitor performance, troubleshoot errors, and protect against fraud or unauthorised access
- Comply with legal obligations and enforce our Terms of Service
We do not sell personal data to third parties.
Data Sharing, Sub-Processors, and Recipients
We share personal data only as necessary to operate the Service, including with the following categories of recipients:
- Infrastructure and hosting providers operating cloud servers and PostgreSQL database hosting
- Resend - transactional and service email delivery
- Stripe - subscription billing, payment processing, and checkout flows (including Stripe cookies on checkout pages)
- S3-compatible object storage providers - file and image storage
- Professional advisers - lawyers, accountants, or auditors where required
- Public authorities - when required by law or valid legal process
- Business Users - where End Client data is accessed as part of the Service they operate
We maintain appropriate data processing agreements with sub-processors that process personal data on our behalf. A current list of sub-processors may be provided on request to Business Users.
International Data Transfers
Covra. is operated from the European Union. Some sub-processors may process data outside the European Economic Area (EEA). Where such transfers occur, we implement appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission, supplementary technical and organisational measures, and transfer impact assessments where required.
Business Users who export or access data from outside the EEA are responsible for ensuring their own compliance with local data protection requirements.
Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, unless a longer period is required by law:
- Business User account data: for the duration of the subscription and a reasonable period thereafter to resolve disputes, fulfil legal obligations, and allow data export
- End Client booking and profile data: according to Business User settings and instructions while the account remains active; deletion or anonymisation upon account termination subject to backup cycles
- Billing and transaction records: as required by Lithuanian accounting and tax law
- Audit logs and security records: for a defined period appropriate to security and compliance needs
- Marketing and support correspondence: for as long as relevant to the inquiry or relationship
- Token and session data: for the validity period of the token or session, after which it is invalidated or deleted
Backups may retain residual data for a limited period before being overwritten in accordance with our backup schedule.
Security Measures
We implement technical and organisational measures designed to protect personal data, including:
- Encryption in transit using TLS for data transmitted over networks
- Access controls and role-based permissions within Business User workspaces
- HttpOnly session cookies and secure authentication flows
- Two-factor authentication for platform administrators
- Audit logging of significant actions and administrative access
- Segregation between tenant workspaces and the platform administration environment
- Regular monitoring, patching, and infrastructure security practices appropriate to a cloud-hosted SaaS platform
No method of transmission or storage is completely secure. Business Users are responsible for managing staff access, safeguarding magic links, and configuring appropriate privacy settings for their End Clients.
Your Rights Under the GDPR
Depending on your location and our role, you may have the following rights:
- Right of access - to obtain confirmation and a copy of your personal data
- Right to rectification - to correct inaccurate or incomplete data
- Right to erasure - to request deletion where legally applicable
- Right to restriction - to limit processing in certain circumstances
- Right to data portability - to receive data you provided in a structured, machine-readable format where applicable
- Right to object - to processing based on legitimate interests or direct marketing
- Right to withdraw consent - where processing is based on consent, without affecting prior lawful processing
- Right to lodge a complaint - with a supervisory authority
To exercise your rights, contact us at hello@covra.lt. We may need to verify your identity before responding. Where Covra. acts as processor for End Client data, we may direct your request to the relevant Business User.
If you are in Lithuania or the EU, you may lodge a complaint with the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija): www.ada.lt.
Children's Data and Automated Decision-Making
The Service is intended for use by businesses and is not directed at children under 16 years of age. Business Users must not use Covra. to knowingly collect personal data from children without appropriate parental authority and lawful basis.
Covra. does not engage in automated decision-making or profiling that produces legal or similarly significant effects on data subjects within the meaning of GDPR Article 22. Scheduling availability and waitlist ordering are operational features configured by Business Users and do not constitute automated individual decision-making by Covra.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Service, legal requirements, or our processing practices. The "Last updated" date at the top indicates when this Policy was last revised.
Where changes are material, we will provide notice through the Service, by email to Business Users, or by other appropriate means. Continued use of the Service after the effective date of an updated Policy constitutes acknowledgement of the changes, except where further consent is required by law.