← Back to Alara

Privacy Policy

Last updated August 4, 2026

This Privacy Policy explains how Alara collects, uses, and protects personal data when practitioners and their clients use the platform. We aim to collect only what we need to run Alara and to treat your data with the same care your practice deserves. Because Alara is operated from Germany, this policy is written to meet the requirements of the EU General Data Protection Regulation (GDPR / DSGVO).

1. Who is responsible (Controller)

The controller responsible for the data described in this policy (within the meaning of Art. 4(7) GDPR) is:

Alara (sole proprietorship / Einzelunternehmen, small business under § 19 UStG)
Owner: Dominik Gilg
Friedenstr. 58, 10249 Berlin, Germany
Email: hello@alara.space
WhatsApp: +49 1520 7840461

We have not appointed a Data Protection Officer, as we are not legally required to do so.

2. Our dual role: controller and processor

Alara serves two audiences, and our role under data protection law differs depending on the data.

For account and platform data — the data a practitioner provides to create and run their Alara account, and the analytics and security data we generate to operate the service — Alara is the controller.

For a practitioner's own client records — the people a practitioner serves, their bookings, intake answers, and notes — the practitioner determines the purposes of the processing and is the controller. Alara acts as a processor on the practitioner's behalf and processes that data only on their documented instructions, under a data processing agreement (Auftragsverarbeitung, Art. 28 GDPR). If you are a client, please also refer to the privacy practices of the practitioner you booked with.

3. Categories of personal data we process

Account & practice data (practitioners): your email and authentication credentials, name, professional title, bio, avatar, social and website links, your public page slug, brand and page-design settings, currency and timezone, availability and booking rules, your services, and your Stripe and Google connection status.

Client booking data: for each person a practitioner serves, we process first and last name, email address, optional phone number, timezone, any notes the practitioner adds, and the answers a client gives to a service's intake questions. Intake answers may, depending on the practitioner's questions, include sensitive information — practitioners are responsible for keeping their intake questions lawful and proportionate.

Appointment data: booking date and time, location (online or in person), status, meeting links, payment status, and cancellation or refund details.

Payment data: we store transaction references and status (e.g. Stripe payment intent and refund identifiers, amounts, whether a booking is paid, and any dispute records — status, disputed amount, and response deadline). Full card numbers are handled directly by Stripe and are never stored by Alara.

Google integration data: for practitioners who connect Google Meet, we store Google access and refresh tokens and token expiry so we can create and manage calendar events and Meet links on their behalf.

Usage & analytics data: privacy-friendly, aggregated statistics about visits to public booking pages (such as page views, visitor counts, and approximate country/city derived from IP), plus standard server and security logs.

Early-access / waitlist data: if you join our waitlist, we process the name, email, and optional message you submit.

4. Purposes and legal bases (Art. 6 GDPR)

Providing accounts, booking pages, appointments, and payments — to perform our contract with you (Art. 6(1)(b) GDPR). For client booking data, the lawful basis sits with the practitioner as controller (typically contract performance, Art. 6(1)(b)), and Alara processes it on their behalf under Art. 28 GDPR.

Transactional emails (booking confirmations, updates, cancellations, refunds) — necessary to perform the booking, Art. 6(1)(b) GDPR. These are not marketing messages.

Connecting Google Meet — based on the practitioner's explicit consent given when they connect their Google account (Art. 6(1)(a) GDPR), which can be withdrawn at any time by disconnecting.

Google Maps address autocomplete — when entering or selecting an in-person location, Google Maps is loaded to suggest addresses; this serves our and the practitioner's legitimate interest in accurate location entry (Art. 6(1)(f) GDPR).

Map images in booking emails — for in-person sessions, confirmation emails include a static Google Maps image of the session location. When the recipient's email app displays it, that app requests the image from Google, which involves the session address and the recipient's IP address. This serves our and the practitioner's legitimate interest in helping clients find the location (Art. 6(1)(f) GDPR).

Privacy-friendly analytics and security — to understand booking-page performance and to keep the platform secure and functioning, based on our legitimate interest in operating and protecting the service and giving practitioners insight into their page (Art. 6(1)(f) GDPR). We do not build cross-site profiles.

Waitlist / early access — based on your consent when you submit the form (Art. 6(1)(a) GDPR).

Legal and tax record-keeping — retaining invoices and payment records to comply with legal obligations (Art. 6(1)(c) GDPR), in particular German retention duties under § 147 AO and § 257 HGB.

5. Recipients and processors

We rely on a small set of trusted providers who process data on our behalf as processors under data processing agreements (AVV / DPA):

Supabase — Postgres database hosting and authentication. Passwords are stored hashed by Supabase; Alara never sees them in plain text. Hosting region: the United States (East US, North Virginia).

Stripe — payment processing via Stripe Connect. Payments are processed directly on the practitioner's own connected Stripe account (direct charges); the practitioner is the merchant of record, and Alara collects only its platform fee where applicable.

Resend — delivery of transactional emails.

Google — only for practitioners who connect Google Meet: the Google Calendar / Meet API is used to create and manage meeting links. Google Maps is additionally used for address autocomplete on booking and service pages.

Umami — cookieless, privacy-friendly web analytics for public booking pages, provided by Umami Software, Inc. (Umami Cloud) as a processor on our behalf, with analytics data hosted in the EU. It does not use cookies, does not track visitors across sites, and does not build personal profiles.

Vercel (Vercel Inc., United States) — hosts and serves the application.

We do not sell personal data and do not share it for third-party advertising.

6. International data transfers

Several of our providers process personal data in the United States — in particular our database provider Supabase (the project is hosted in the East US / North Virginia region), our hosting provider Vercel, Stripe, Resend, and Google. This means your personal data, including data stored in our database, is transferred to and processed in the United States. Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards under Art. 44 ff. GDPR, namely the EU–U.S. Data Privacy Framework (where the provider is certified) and/or the European Commission's Standard Contractual Clauses (SCCs). You can request more information about these safeguards using the contact details in Section 12.

7. Cookies and local storage

Alara uses only what is necessary to operate. Our authentication provider, Supabase, sets necessary cookies to keep you securely signed in to your account; these are strictly necessary and require no consent. When a practitioner opens their Payouts page, Stripe loads its own scripts and may set cookies for fraud prevention and secure payment functionality; these are necessary for that feature. Our analytics (Umami) is cookieless and sets no tracking cookies. We do not use marketing, advertising, or cross-site tracking cookies.

8. Data retention

We keep personal data for as long as your account is active or as needed to provide the service. When a practitioner deletes their account, or a client record or appointment is deleted, we delete or anonymize the associated data within a reasonable period — except where we are legally required to keep it. In particular, invoices and payment-related records are retained for the periods required by German law (generally up to 10 years under § 147 AO and § 257 HGB). Waitlist data is kept until the waitlist purpose is fulfilled or you ask us to remove it.

9. Your rights

Under the GDPR you have the right to: access your personal data (Art. 15), rectify inaccurate data (Art. 16), erase data (Art. 17), restrict processing (Art. 18), data portability (Art. 20), object to processing based on legitimate interests (Art. 21), and — where processing is based on consent — withdraw that consent at any time with effect for the future (Art. 7(3)). Practitioners can manage much of their data directly from the dashboard, or contact us. Clients who wish to exercise rights over their booking data should generally contact the practitioner they booked with, since that practitioner is the controller of that data; we will support practitioners in responding.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information).

10. Security

We use reasonable technical and organizational measures to protect personal data, including encryption in transit (HTTPS/TLS), hashed passwords stored by our authentication provider, and access controls that limit who can reach your data. No system is perfectly secure, but we work to keep your data safe and to respond promptly to any incident.

11. Changes to this policy

We may update this Privacy Policy from time to time, for example to reflect new features or providers, or changes in the law. The current version is always available here with its "last updated" date. If we make material changes, we will take reasonable steps to let you know.

12. Contact

Questions about your privacy or this policy? Reach us at hello@alara.space.