Privacy policy
Updated 2026-08-12
Here we explain in plain words what data we collect about you, why, who we share it with and how long we keep it.
In short
- We only collect what bookings and payouts need - no marketing, no selling of data.
- Your card details are handled by Stripe alone - we never see them.
- We always use essential cookies; statistics cookies (Google Analytics) only with your consent. We use no advertising cookies.
- You can delete your account at any time - personal data is removed, and only legally required financial records remain, with the data those documents must contain (e.g. the name on an invoice).
1. Who is responsible for your data
SaunaFriday is operated by Nerok Group ltd, company number 12366776, 12 Constance Street, London, E16 2DQ, United Kingdom (the data controller).
For any data protection questions, write to info@saunafriday.lt.
2. What data we collect
We collect only the data the platform needs to work:
- Account - email address, name, country and city, language preference. If you order without an account, we create one automatically so you can manage your order.
- Guest bookings - the name and phone number you enter when booking, the booking time, sauna and amount.
- Sellers (sauna owners and sauna masters) - listing content and photos, the sauna master's address and coordinates (never shown publicly, used only to measure the distance to saunas), a Stripe account identifier for payouts, and tax identity: name or company name, tax identification number (personal code; for UK residents a National Insurance number and UTR) or company number, address, date of birth, VAT code.
- Messages - what you write through the contact form.
- Technical data - IP address for security limits, and server logs.
- Guest invites - when a seller invites their guest by email, we process the recipient address the seller enters: we send a one-time invite with the seller's link and keep a record of the send for abuse prevention and sending limits. Every invite contains an opt-out link - an opted-out address goes on a suppression list and receives no further invites.
- Visit marks - a seller may record how a visit went (e.g. a no-show or a mess left behind). Only the administrator sees the mark; it is never shown publicly and does not block bookings.
We never receive your card details - they are handled solely by the payment provider Stripe.
3. Why, and on what legal basis
- Performance of a contract - your account, bookings, payments and payouts, emails about your bookings.
- Legal obligation - accounting documents and reports to tax authorities.
- Legitimate interest - platform security, fraud prevention, rate limiting, and guest invites sent at a seller's request (recipients can opt out at any time).
We do not use your data for marketing. We do not carry out profiling. There is one automated check: before a booking we compare your email address and name against the sauna owner's or sauna master's login address, the contact address they entered and their name - so that the same person cannot book their own services from a second account and write reviews for themselves. A booking is refused only when it matches the provider's login address; in every other case the booking goes ahead and the review is not shown publicly and not counted in the rating. We store the result of that check with the booking. If you think a check got it wrong, write to us and we will review it.
4. Who we share data with
- The sauna owner and sauna master see the name, phone number and email address from your booking, so they can host you.
- Service providers processing data on our behalf: Stripe (payments and payouts), Vercel (website hosting and photo storage), Supabase (database in the EU, Ireland), Resend (email delivery), Google Maps Platform (address suggestions and coordinates when entering a sauna address, a sauna master address or a seller's tax-details address; the address being typed is sent to fetch suggestions, and a sauna master's address is never shown publicly - it is only used to measure the distance to saunas). For statistics we use Google Analytics (provider - Google Ireland Limited), only with your consent.
- Tax authorities - where the law requires it (see the section for sellers below).
We do not sell your data and never pass it on for advertising.
5. How long we keep data
- Account data - for as long as you use your account.
- After you delete your account - a 30-day grace period, then personal data is removed or irreversibly anonymized.
- Financial records (paid bookings, invoices, statements) - 10 years, as accounting law requires. After account deletion your name and contacts are removed from them, except in already issued documents, which we must keep unchanged.
- Technical logs and security rate-limit entries - up to a few months.
6. Your rights
Under the General Data Protection Regulation (GDPR) you have the right to:
- access your data and get a copy of it,
- correct inaccurate data,
- have your data deleted (except what the law requires us to keep),
- restrict or object to processing,
- receive your data in a portable format.
You can see and manage most of your data in your account. For anything else, write to info@saunafriday.lt - we will reply within 30 days at the latest.
If you believe your data is handled improperly, you can lodge a complaint with the Lithuanian State Data Protection Inspectorate or the supervisory authority of your country.
7. Cookies
We always use essential cookies (for your login session, form protection and remembering your cookie choice). Statistics cookies - Google Analytics - are set only with your consent, which you can withdraw at any time in cookie settings. We use no advertising cookies. Full list: Cookie policy.
Read more in the Cookie policy.
8. For sellers: reports to tax authorities
Under the rules for digital platforms (EU DAC7 and the corresponding UK rules) we must report seller data to tax authorities every year: name or company name, address, tax identification number (personal code, a National Insurance number for UK residents, or company number), the income earned through the platform and the commission paid.
This data may be passed to the tax administrator of your country (e.g. VMI in Lithuania). You will always find a copy of the annual report in your dashboard.
9. Security and transfers outside the EU
The database is kept in the European Union (Ireland). Sign-in is passwordless - one-time links by email - and access to data is strictly limited.
Some of our processors (e.g. Stripe, Vercel, Resend, Google) may process part of the data outside the European Economic Area. In those cases the European Commission's Standard Contractual Clauses apply.
10. Changes to this policy
When we update this policy, we will change the date at the top of the page. We will announce significant changes by email or clearly on the site.