Privacy Policy
This policy explains what personal data Micali.online collects, why we collect it, who else processes it, and what rights you have.
Effective from 7 September 2026
1. Who we are
Micali.online is an online booking system operated by REALWEB, s.r.o., registered office Vajanského 16/6757, 917 01 Trnava, Slovak Republic, Company ID (IČO) 43899102, Tax ID (DIČ) 2022506332, VAT ID SK2022506332 (registered under §7a of the Slovak VAT Act). In this policy "we", "us" and "the service" mean that company operating Micali.online. You can reach us at support@micali.online.
Account owners are the businesses, organizers and individuals who set up an account to accept bookings. Visitors are the people who book a slot through an account owner's booking page.
For the data created inside an account – customer lists, bookings, form responses, messages – the account owner is the data controller and we act as their processor. For the data we need in order to run the platform itself – accounts, sign-ins, security logs and our own usage analytics – we are the controller.
2. What data we collect
Account data: when you create an account we collect your e-mail address, the account name, language, time zone and every setting you configure (services, events, opening hours, message templates, connector configuration and so on). Managers sign in with a code sent by e-mail. A manager can also set an optional 4-digit PIN for faster sign-in, which works only on a device already verified by an e-mailed code; that PIN is stored only as a bcrypt hash.
Visitor data: when a visitor books a slot, the account owner's form decides what is collected. Typically that is the visitor's name, e-mail address and/or phone number, the chosen service or event, and the answers filled into the booking form. The visitor's bookings, payment status, attendance and memberships are stored as well.
Communication data: every e-mail and SMS the system sends is logged with the recipient, time and delivery status, so the account owner can see what was delivered and so we can diagnose delivery problems. Outgoing e-mails carry a small tracking pixel that records whether the message was opened.
Sign-in and security data: for each sign-in we store the IP address, the browser user agent, the device type and the time of the last activity in that session, in order to secure accounts and detect abuse.
Usage and analytics data: for every page view on our websites and on booking pages, our own analytics stores the page address and title, the referring page, the IP address, the browser user agent, device type, language, traffic source and how long the page stayed open, tied to a two-year "micali_track_id" cookie. Section 7 describes this in detail.
AI assistant data: if you use the Ask AI assistant in the application, your questions and its answers are stored so the conversation keeps its context, and messages older than 7 days are removed the next time you open or use the assistant. Section 9 explains what is sent to the AI provider.
3. How we use your data
We use personal data to operate the booking service: to authenticate users, to create and manage bookings, to send confirmations, reminders and cancellation notices, to let account owners manage their customers, events and statistics, to keep the system reliable and secure, to detect and prevent abuse, and to answer support requests. We do not sell or trade personal data and we do not use it for advertising.
4. Legal basis for processing
Performance of the service you or the account owner asked for – creating a booking, delivering its confirmation, running the account.
Our legitimate interest in keeping the platform working, secure and free of abuse, and in understanding how our pages are used: this covers our own analytics, the visitor statistics we provide to account owners, and the sign-in, security and delivery logs.
Your consent, where consent is what applies – for example the Google Analytics cookies on the marketing website, which load only if you accept them.
Compliance with legal obligations, where they apply to us.
5. How long we keep data, and how it is deleted
Account data – and the bookings, customers, form responses and message logs inside an account – is kept for as long as the account exists. We do not delete accounts for inactivity.
When an account is deleted, the deletion is permanent. The account, its users, events, services, bookings, customer links, form responses, message templates, uploaded files, connector settings and the logs of e-mails and SMS sent from it are removed from the database and cannot be recovered. A root administrator can request deletion in the application; it takes effect after 7 days and can be cancelled during that period (see the Terms of Service). Demo accounts are deleted automatically 7 days after they are created.
Account owners can delete individual records – customers, bookings, form responses, messages – at any time from within the application.
A visitor's identity record, meaning the e-mail address they sign in with, is not removed together with a single account, because the same person may have bookings with other account owners on the platform. Write to support@micali.online if you want that record removed.
Ask AI conversations have a 7-day window: messages older than that are removed the next time that manager opens or uses the assistant. Sign-in, security and usage-analytics records are kept for as long as they are needed to operate and secure the service and to produce the visitor statistics described in section 8; we do not currently apply a fixed deletion period to them.
6. Who else processes the data
We do not sell personal data. It is shared only with the providers technically needed to run the service:
Hosting and infrastructure – the application, the database and uploaded files are hosted with Websupport, s.r.o. (Slovakia), on infrastructure located in the European Union.
E-mail and SMS delivery – when an account connects its own SendGrid, Twilio, SMTP or Gmail account, the content of each message and the recipient's address are transmitted to that provider for delivery under that provider's own terms. Account owners choose and configure those providers. Messages the platform itself sends (sign-in codes, notifications) go through our own SMTP provider.
AI providers – see section 9.
Analytics – Google Analytics (Google LLC) on the marketing website, only with your consent; see section 7.
We may also disclose data where the law requires it, or to protect the rights, safety or property of the service, its users or the public.
7. Cookies and analytics
The application uses the cookies and local storage strictly needed to keep you signed in and to remember basic preferences such as language.
We also run our own first-party analytics across the marketing website, the blog, the application and the booking pages. A "micali_track_id" cookie valid for two years identifies the browser, and each page view is stored with its address and title, the referring page, the IP address, the browser user agent, device type, language, traffic source and how long the page stayed open. This runs on our legitimate interest in understanding how our pages are used and in providing account owners with statistics for their own booking pages; it is not tied to the cookie banner. Requests from search-engine crawlers, from our own staff, and from IP addresses we have excluded are not recorded.
The marketing website additionally uses Google Analytics (Google LLC), which is loaded only if you accept analytics in the cookie banner. If you decline, Google Analytics is not loaded at all. Google describes its own processing at https://policies.google.com/privacy
8. Visitor statistics for account owners
Account owners see statistics for their own public booking pages, built from the analytics described in section 7: view counts per page, traffic source, device type and language, and the list of visitors behind those views.
A visitor who is already in that account's customer list is shown by name and e-mail address. Because the browser is recognised by its long-lived cookie, page views made before the visitor signed in or booked can be attributed to them afterwards, once that browser is identified. Everyone else stays anonymous and is described only by device type, traffic source and language.
Account owners never see IP addresses or browser user agents. Page views by the account's own managers, and by search-engine crawlers, are excluded. If you would rather not be recognised this way, you can clear or block cookies in your browser, or ask the account owner to delete your customer record.
9. Artificial intelligence (AI)
The application offers AI features: an "Ask AI" assistant for account managers, generation of booking message texts, and AI Insights – suggestions for the account owner based on their own numbers.
Which provider processes that data depends on the account's AI setup. By default an account uses Micali AI, which runs on our own account with OpenAI (OpenAI, L.L.C., United States). An account can instead connect its own API key for OpenAI or for Google Gemini (Google LLC), in which case the requests go to that provider under the account's own arrangement with them.
What is sent: for the Ask AI assistant, the manager's question together with a snapshot of the account's own data assembled for that conversation – settings, team members, events and dates, services, memberships, and up to 150 of the account's visitor contacts including names, e-mail addresses and phone numbers. For message generation, the manager's prompt and the booking data the message concerns. For AI Insights, aggregated figures about the account (booking and attendance counts, fill rates, message delivery statistics) together with the names of events and services – no visitor contacts.
Data is sent only when someone actually uses an AI feature. AI Insights is switched off for an account unless it is enabled, and its drafts are reviewed by our staff before they are published to the account owner. We do not use the content of these requests to train any model. What an AI provider does with data sent to its API is governed by that provider's own terms, which we do not control: https://openai.com/policies/ and https://policies.google.com/privacy
10. Google user data and Limited Use
Micali.online uses Google APIs only when an account owner connects their own Gmail account so that booking messages are sent from their own address. The connection is made through Google's standard OAuth consent screen and requests only the permission to send email (https://www.googleapis.com/auth/gmail.send) together with the email address of the connected account. Micali.online cannot read, search, download or store the contents of your mailbox – it can only send the booking messages that you or your account's automated reminders trigger. The resulting access and refresh tokens are stored encrypted and are used solely to deliver those messages. You can disconnect Gmail at any time in the application, or revoke access at https://myaccount.google.com/permissions.
Micali's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. That policy is available at https://developers.google.com/terms/api-services-user-data-policy.
Google Workspace user data is not used, transferred, or sold to create, train, or improve generalized or foundational artificial intelligence or machine learning models.
Micali does not provide email content or other Google Workspace user data to AI/ML models. AI-generated content is created independently and is sent through Gmail only after being initiated or approved by the user.
11. Your rights
Subject to applicable law (including the EU GDPR), you have the right to access the personal data we hold about you, to ask for it to be corrected or deleted, to object to or restrict certain processing, and to receive your data in a portable format. You also have the right to withdraw any consent you have given (for example by changing your choice in the cookie banner), and to lodge a complaint with your data protection authority – in Slovakia, the Office for Personal Data Protection of the Slovak Republic.
If you are a visitor who booked through an account, the account owner is the primary point of contact for your data – they decide what they collect and how long they keep it inside their account. You can ask them to update or delete your bookings and form responses. For platform-level requests, write to us at support@micali.online.
12. Security
The measures in place today: the websites, the application and the API are served over HTTPS; managers sign in with a code sent by e-mail, and the optional sign-in PIN is stored only as a bcrypt hash, works only on a device previously verified by an e-mailed code, and is revoked after three wrong guesses; trusted-device tokens are stored only as a SHA-256 hash; access tokens expire and can be revoked; the API is rate-limited and records the IP address and device of every sign-in; connector secrets – SMTP passwords, SendGrid and Twilio API keys, Gmail OAuth tokens, webhook credentials – are encrypted at rest with authenticated encryption (libsodium); every API request is scoped to a single account, so an account can only reach its own data; and platform staff access is separate from account access.
No system can promise absolute security. Should a breach affecting personal data occur, we will deal with it and notify those concerned as the law requires.
Your export and our infrastructure are two different things. We do not offer a per-account restore – there is no feature that rolls one account back to an earlier state – so we recommend that account owners regularly export what matters to them (the application exports event and service bookings to CSV) and keep that copy themselves.
13. Changes and contact
We may update this Privacy Policy from time to time. The current version is always published on this page together with its effective date, and substantial changes will be announced in advance by e-mail or in the application. If you have questions about this policy, or want to exercise your rights, write to us at support@micali.online – REALWEB, s.r.o., Vajanského 16/6757, 917 01 Trnava, Slovak Republic.