← Back to Legal Information
Privacy Policy
Effective date: April 18, 2026
Last updated: April 18, 2026
This Privacy Policy describes how SHPS SHUGARINGI TKBILI EPILATSIA ("Shugaring," "we," "us," or "our") collects, uses, stores, and shares your personal data when you interact with our automated chatbot "SalonAssist" through Facebook Messenger or Instagram Direct, or when you use our appointment booking services.
This policy is provided in English. Translations into other languages may be provided for convenience; in case of any discrepancy, the English version prevails.
1. Who we are (Data Controller)
The entity responsible for processing your personal data is:
- Legal name: SHPS SHUGARINGI TKBILI EPILATSIA (შპს შუგარინგი ტკბილი ეპილაცია)
- Identification number: 418469614
- Registered address: Mshvidobis Ave., №15, apt. 25, Gori, Shida Kartli 1400, Georgia
- Email: tkbiliepilacia@gmail.com
- Phone: +995 599 92 38 56, +995 555 55 97 26
2. What data we collect
When you interact with our SalonAssist chatbot or book an appointment, we collect the following categories of personal data:
2.1. Data from Meta platforms (Facebook / Instagram)
When you send a message to our business page, Meta provides us with:
- Your Page-Scoped ID (PSID) — a unique identifier assigned by Meta for our page
- Your first and last name as listed on your Facebook or Instagram profile
- Your gender, if publicly available on your profile
- Your locale (language preference)
2.2. Data you provide in conversation
- Your phone number (when you provide it during booking)
- Your preferred name (if different from your profile name)
- The content of all messages you exchange with our chatbot and with our human operators
2.3. Booking data
- Selected service, master, date and time of appointment
- Branch location
- Booking status (confirmed, cancelled, completed)
We do not collect: your email address, IP address, device identifiers, location data, financial or payment information, or any data from cookies or analytics tracking (our website does not use analytics tools).
3. How we use your data
We use your personal data solely for the following purposes:
- To respond to your inquiries through our automated chatbot
- To create, modify, and cancel appointments on your behalf
- To send you booking confirmations and reminders via SMS
- To allow a human operator from our salon to take over the conversation when automated responses are insufficient
- To maintain records of services rendered for accounting and tax compliance purposes
- To improve the quality of our chatbot responses through review of conversation logs
4. Legal basis for processing
We process your personal data based on the following legal grounds:
- Performance of a contract: when we process your booking information to provide the services you request
- Consent: by initiating a conversation with our chatbot, you consent to the processing described in this policy. You may withdraw consent at any time (see Section 8)
- Legitimate interest: to maintain conversation history and improve service quality
- Legal obligation: to retain financial and booking records as required by Georgian tax legislation
5. Third parties with whom we share your data
We share your personal data with the following third-party service providers, strictly as necessary to deliver our services:
| Provider |
Purpose |
Data shared |
| Meta Platforms (Facebook, Instagram) |
Messaging platform |
Message content, PSID |
| Altegio |
Appointment booking system |
Name, phone, service, master, date/time |
| ubill.ge |
SMS notifications |
Phone number, SMS message text |
| Google (Gemini API) |
AI-powered message processing |
Conversation content for response generation |
| DeepSeek (if enabled) |
AI-powered message processing (alternative) |
Conversation content for response generation |
| Netcup GmbH |
Server hosting (Germany) |
All data stored in our database |
Each of these providers has their own privacy policy governing their use of your data:
We do not sell your personal data to any third party. We do not share your data with advertising networks.
6. Data retention
We retain your personal data for different periods depending on its nature:
- Conversation history and messages: up to 2 years from the date of last interaction, or until you request deletion, whichever comes first
- Contact information (phone, name): up to 2 years, or until deletion request
- Booking records: financial records may be retained in anonymized form (without phone number or customer name) for up to 6 years as required by Georgian tax legislation
- Meta identifiers (PSID): deleted when you remove our application from your Facebook settings or request deletion
After the retention period expires, data is either deleted or anonymized beyond reasonable identification.
7. Your rights
You have the following rights regarding your personal data:
- Right of access: to request a copy of the personal data we hold about you
- Right to rectification: to request correction of inaccurate data
- Right to erasure: to request deletion of your personal data (subject to legal retention requirements)
- Right to restriction: to request that we limit the processing of your data
- Right to object: to object to processing based on legitimate interest
- Right to withdraw consent: at any time, without affecting the lawfulness of prior processing
8. How to exercise your rights
You can exercise your rights through any of the following methods:
- Through Facebook settings: go to Facebook Settings → Apps and Websites → locate "SalonAssist Bot" → click Remove. Facebook will automatically notify us and we will delete your data within 30 days. You will receive a confirmation code to track the status of your request.
- By email: send a request to tkbiliepilacia@gmail.com from the email address you wish to be identified with, or include your Messenger profile name in the message. We will respond within 30 days.
For detailed instructions, please see our Data Deletion Instructions page.
9. Children's data
Our chatbot is intended for use by adults booking appointments. We do not knowingly collect personal data from children under the age of 13. If you believe a child has provided us with personal data, please contact us at tkbiliepilacia@gmail.com and we will delete the data promptly.
10. Data security
We implement reasonable technical and organizational measures to protect your personal data, including:
- Encryption of sensitive credentials and access tokens at rest
- Transport-layer encryption (HTTPS/TLS) for all data in transit
- Access controls limiting who can view your data to authorized personnel only
- Verification of incoming messages from Meta using cryptographic signatures
While we take these precautions, no method of data transmission or storage is completely secure. We cannot guarantee absolute security.
11. International data transfers
Your data is primarily stored on servers located in Germany (Netcup data center, Nuremberg). Some of our third-party providers (Meta, Google, DeepSeek) may process your data in the United States or other jurisdictions. By using our service, you acknowledge that your data may be transferred outside of Georgia.
12. Changes to this policy
We may update this Privacy Policy from time to time. Changes will be reflected in the "Last updated" date at the top of this page. Material changes will be communicated through our chatbot or other appropriate means. Continued use of our services after changes constitutes acceptance of the updated policy.
13. Governing law and jurisdiction
This Privacy Policy is governed by the laws of Georgia. Any disputes arising from or relating to this policy shall be resolved by the competent courts of Tbilisi, Georgia.
14. Contact us
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us at:
- Email: tkbiliepilacia@gmail.com
- Phone: +995 599 92 38 56, +995 555 55 97 26
- Address: Mshvidobis Ave., №15, apt. 25, Gori, Shida Kartli 1400, Georgia