Privacy Policy
Last updated: 25 September 2026
1. Who are we?
De Rechter Software (hereinafter: "we", "us" or "Stippa") is responsible for the processing of personal data as described in this privacy policy.
- De Rechter Software (trading under the name Stippa), sole proprietorship
- Molenwater 20, 4511 BN Breskens, the Netherlands
- Chamber of Commerce (KvK) number: 98466402
- VAT number: NL005332100B80
- Email: support@stippa.nl (or support@derechtersoftware.nl)
We act in two roles. With respect to the account and login data of our account holders (the businesses that use Stippa) and of the users they give access to, we act as the Controller. With respect to the personal data that an account holder manages through Stippa, such as that of its End Clients and the data about its staff (rosters, hours worked, absence and photographs), we act as the Processor: the account holder determines the purpose and is the Controller, and we process that data solely on behalf of and on the instructions of the account holder. The arrangements regarding this are set out in our data processing agreement.
2. What data do we collect?
We process the following categories of personal data:
- Name and email address (upon registration and appointment management)
- Phone number (optional, for reminder messages)
- Appointment data (date, time, service, staff member, notes)
- Transaction data when you pay at the counter (receipt number, the services and products purchased, quantities, amounts, discounts, VAT and the payment method)
- Payment information (processed via Stripe or Mollie; we never store a full card number. For a card payment we record what the card scheme rules require the receipt to show: the card brand, the last four digits and the technical identifier of the card application)
- Gift cards (an encrypted representation of the code, the last four characters, the balance, the validity period and the customer the card was sold to)
- A photograph of a staff member, where the account holder uploads one, with a separate choice per staff member as to whether customers see it
- Technical data (IP address, browser type, usage logs)
- Google Calendar data (only when a staff member connects his or her Google calendar; see section 6 for the full explanation)
3. For what purposes do we use your data, and on what legal basis?
We process each item of data for a specific purpose and on a specific legal basis under Article 6 GDPR:
- Scheduling, managing and confirming appointments, on the legal basis of performance of the contract.
- Sending reminders and notifications, on the legal basis of performance of the contract.
- Processing payments, on the legal basis of performance of the contract and compliance with a legal (tax) obligation.
- Recording and retaining the sales records of a connected business, on the legal basis of compliance with a legal obligation: a business is required to retain its accounting records for seven years (Article 52 of the Dutch General Tax Act).
- Synchronising appointments with external calendars (Google Calendar, iCal), on the legal basis of your explicit consent, which you may withdraw at any time.
- Securing, maintaining and improving the service, including product analytics and fraud prevention, on the legal basis of our legitimate interest in providing a secure and usable service. We weigh this interest against your privacy and limit the processing to what is necessary for that purpose.
- Complying with legal obligations, on the legal basis of a legal obligation.
4. Sharing with third parties
We share your data only with processors that are strictly necessary for the performance of our service:
- Supabase Inc. for database hosting (hosted in the EU)
- Vercel Inc. for hosting of the web application
- Upstash, Inc. for rate limiting and abuse prevention (transient processing of IP addresses)
- Cloudflare, Inc. for bot and abuse protection (Turnstile)
- Sentry (Functional Software, Inc.) for error monitoring and application stability
- Inngest, Inc. for background job execution, such as sending reminders
- Grafana Labs for log management (Loki), only when enabled
- Stripe Payments Europe Ltd. and Mollie B.V. for payment processing (Mollie is hosted in the EU)
- Resend, Inc. for transactional email delivery (confirmations, reminders and notifications)
- Twilio Inc. / WhatsApp Business for optional messaging services
- PostHog for product analytics (on our marketing website after your consent via the cookie banner, and without consent only a cookieless count of page views, and within the application for account holders to improve the service; data is processed on servers within the EU; see section 10)
The following integrations are only enabled when you or a staff member connects them: Google LLC for calendar synchronisation (see section 6) and Moneybird B.V. for an accounting integration.
We never sell your data to third parties. To the extent that personal data is transferred to sub-processors outside the European Economic Area (including the United States, such as with Stripe, Google, Vercel, Resend, Sentry, Cloudflare, Upstash, Inngest, Twilio or Grafana Labs), such transfer relies primarily on the EU-US Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023) for parties certified thereunder. As an additional or fallback safeguard, the European Commission's standard contractual clauses apply (Standard Contractual Clauses, implementing decision (EU) 2021/914).
Webhooks. As the administrator of a business account you can configure webhook endpoints yourself: addresses of a system of your choice to which we send appointment, customer and payment data the moment something happens. That receiving party is not a sub-processor of ours, but a party you choose yourself and for which you are responsible. We only send to the addresses and the events you tick, every message is signed, and you can remove an endpoint at any time. If you would rather no customer data left the platform, choose "the id only" for the endpoint: the message then contains nothing but the type and the id of the changed object.
5. Legal basis for processing
As explained in section 3, we process your data on the basis of performance of a contract, a legitimate interest, a legal obligation, or your explicit consent. Where we rely on consent, you may withdraw it at any time; this does not affect the lawfulness of the processing carried out prior to the withdrawal.
6. Google Calendar integration
Stippa offers staff members the option to connect their Google calendar via Google OAuth 2.0. The provisions below explain which Google user data we access, how we use it, with whom we share it, how we store and secure it, and how you can withdraw your consent.
6.1 Which Google data do we access?
When you or a staff member within your organisation chooses to connect a Google calendar, we request only the following OAuth scope: https://www.googleapis.com/auth/calendar.events.readonly. This is a read-only permission; with this permission Stippa cannot create, modify or delete events in your Google calendar. With that permission we access:
- The email address of the connected Google account (solely for display in the dashboard, so the staff member can see which account is connected);
- Start and end times, status and unique identifiers of events in the primary calendar of the connected Google account within a window of 90 days from the present moment;
- We do not read any titles, descriptions, locations or attendee data from your existing Google calendar, only whether a time slot is occupied.
6.2 How do we use this data?
The data is used solely to display occupied time slots from your Google calendar within Stippa, in order to prevent double bookings. Stippa does not write events to your Google calendar; appointments that you manage in Stippa remain solely within Stippa.
6.3 With whom do we share this data?
We do not share Google user data with any third party. The tokens and calendar data are used solely to communicate with the Google APIs on behalf of the connected user. We never use Google user data for advertising or for any purpose other than those described in this privacy policy.
6.4 How do we store and secure this data?
OAuth access and refresh tokens are encrypted with AES-256-GCM before storage. All communication with Google APIs takes place over TLS 1.2 or higher. The database is hosted within the European Union. Access to tokens is restricted to the automated synchronisation processes; tokens are never viewed by employees of De Rechter Software.
6.5 Retention period and deletion
We retain Google user data for as long as the staff member keeps his or her Google calendar connected to Stippa. When the connection is disconnected via Stippa (Dashboard, Staff tab, "Calendar synchronisation", "Disconnect"):
- the tokens and busy times are immediately deleted from our database;
- the Google push notification channel for that connection is stopped;
- no further data is retrieved from Google.
You can also withdraw access at any time via your Google account at myaccount.google.com/permissions. In addition, you can submit a deletion request via support@stippa.nl; we process such a request within 30 days.
6.6 Limited Use, advertising and AI/ML training
Stippa's use and transfer of data received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use data obtained through Google Workspace APIs to develop, improve or train generalised artificial intelligence (AI) or machine learning (ML) models. Nor do we transfer such data to third parties for that purpose. Google user data is not used to display advertising.
7. Retention periods
Personal data is retained for as long as necessary for the purpose for which it was collected, or for as long as legally required:
- Appointment and customer data: by default 2 years after the last appointment. The account holder sets this period themselves and may shorten or extend it;
- The sales records: 7 years. Where a connected business takes payment through Stippa, the receipt, its lines, the payments and the accompanying journal form that business's statutory accounting records. That data is retained for seven years and cannot be deleted sooner, neither by the account holder nor by shortening the period above: the software refuses to delete it. That remains the case after the business stops using Stippa. Where different retention rules apply in the business's own country, the business itself remains responsible for complying with them;
- Emails sent: the delivery record is retained, while the rendered content of the message is deleted after 30 days;
- Google Calendar tokens and synchronisation data: until the connection is disconnected (see section 6.5);
- Technical log files: a maximum of 90 days;
- Audit logs of changes in the dashboard: 2 years, for security and compliance.
7.1 Employee working-time records
When an account holder switches on the "Time tracking and absence" module, we process the working-time records of their employees as a Processor on behalf of the account holder: hours worked and breaks, the source of each record (clocked, entered by hand, or taken from the roster), absence, and its approval. The account holder, as the employer, is the Controller. The legal basis is compliance with a legal obligation: an employer must keep a proper record of working and rest periods, and the hours worked form part of the payroll records, which must be retained for seven years under the tax retention obligation (Article 52 of the Dutch General Tax Act). We therefore keep these records for 7 years, counted from the day they relate to, after which they are deleted automatically. This term is independent of the customer retention period above: a customer's erasure request does not touch an employee's hours, because those are data about the employee and not about the customer.
8. Your rights
You have the right to:
- Access your personal data
- Rectification or completion of inaccurate data
- Erasure of your data ("right to be forgotten")
- Restriction of processing
- Portability of data (data portability)
- Object to processing based on legitimate interest
- Withdraw consent previously given (such as when connecting an external calendar), without this affecting the lawfulness of earlier processing
You can send requests to support@stippa.nl. We respond within 30 days. To prevent misuse, we may ask you to prove your identity. If you are a customer of a business that uses Stippa, you may also direct your request to that business; we provide the necessary cooperation as a Processor in that regard.
8.1 Erasure and the statutory retention obligation
If you have paid at a connected business, an erasure request touches two things that we keep apart.
Your customer data is neutralised: the name, email address, phone number and any notes recorded about you are overwritten, so that the data can no longer be traced back to you.
The receipt itself remains and does not change, because the business is required by law to retain it for seven years. That receipt carries no name: it states what was sold, for what amount and how it was paid. The reference the receipt held to your customer record afterwards points to a neutralised entry, so that the sales figures remain correct without the receipt still saying anything about you.
9. Security
We take appropriate technical and organisational measures to protect your data, including:
- Encryption of data in transit (TLS 1.2 or higher) and at rest;
- Encryption of sensitive tokens (such as OAuth access and refresh tokens) with AES-256-GCM before storage;
- Role-based access control with row-level security in the database;
- Regular security assessments and access logging;
- A procedure for notifying data breaches to data subjects and the Dutch Data Protection Authority in accordance with the GDPR.
10. Cookies and analytics
We use functional cookies and local storage that are strictly necessary for the operation of the service (session management, login status and preferences). These are always set and cannot be disabled, because the service does not function without them.
On our public marketing website we additionally use PostHog for product analytics, to understand how visitors use the website and to improve it. Apart from the limited count described below, this analysis is carried out only after you have given your consent via the cookie banner that appears on your first visit. If you refuse, or have not yet made a choice, we only count which pages are viewed and which website or link brought you here (for example a search engine or an AI assistant). No cookies are placed and nothing is stored on your device for this: PostHog links the page views of a single visit using a code it calculates on its servers from, among other things, your IP address, your browser type and a key that changes daily, so you cannot be recognised from one day to the next. Clicks, heatmaps and session recordings are not recorded in that case. This limited count is based on our legitimate interest in knowing how visitors find our website. We ask for consent per purpose: statistics (which pages are read and what gets clicked, aggregated across all visitors) and session recordings (a recording of your own visit that we can play back to track down problems, kept for 30 days). You can change or withdraw your choice at any time via 'Cookie preferences' at the bottom of every page.
Within the logged-in application we use PostHog for product analytics at the account level (such as which features are used), on the legal basis of our legitimate interest in improving the service. In this environment there is no session recording, no heatmap registration and no automatic click tracking. During administrative sessions (impersonation by support), analytics is fully disabled.
That account-level analysis includes the search box inside the application. We measure how often people search, how many results a search returns and which result is chosen. We do not store the text that was typed, with one exception: when a search returned no results at all, we keep the word so that we can add missing search terms. Even then we remove the text before it is transmitted as soon as it has the shape of a person (more than one word, a leading capital, an @ sign, four or more consecutive digits, or simply long), so that your customers’ names, email addresses and phone numbers never reach our analytics.
In the public booking widget, the page on which you make an appointment as a customer of a connected business (including when that page is embedded in that business's own website), we measure only, and in anonymised form, how many visitors complete a booking and at which step the others stop. No cookies are placed and nothing is stored on your device: the temporary identifier that links the steps together exists only in your browser's working memory and disappears as soon as you close the page. Your IP address is not stored, and names, email addresses and telephone numbers are never included in this measurement data. The data cannot be traced back to an individual visitor and serves to improve the booking service. No consent is required for this; the processing takes place on the legal basis of our legitimate interest.
In addition, via Vercel Speed Insights we collect anonymised performance data (such as load times, browser type, device type and country at country level) to monitor and improve the speed and reliability of the application. No cookies are placed and no personal data or IP addresses are stored; the data cannot be traced back to an individual visitor. No consent is therefore required for this; the processing takes place on the legal basis of our legitimate interest.
In the same way, Vercel Web Analytics counts which pages are viewed and which website visitors arrive from. No cookies are placed for this either; a visitor is recognised only within a single day, through a hash that is renewed daily, and IP addresses are not stored.
All analytics data is processed on servers within the European Union. We do not use advertising cookies and we do not share data with advertising networks.
11. Children
A Stippa account is not intended for persons under the age of 16, and we do not knowingly collect personal data from children under the age of 16 as an account holder or user of the dashboard. If someone under the age of 16 books an appointment with a business that uses Stippa, we process that data as a Processor on behalf of that business. If you suspect that we have collected such data outside that case, please contact us so that we can delete it.
12. Automated decision-making
We do not use automated decision-making or profiling that produces legal effects concerning you or that significantly affects you.
13. Complaints
Do you have a complaint about how we handle your data? Please contact us via support@stippa.nl. You also have the right to lodge a complaint with the Dutch Data Protection Authority via autoriteitpersoonsgegevens.nl. If you are located in another EU Member State, you may also turn to the supervisory authority of your own country.
14. Changes
We may update this privacy policy from time to time. The most recent version is always available on this page. In the event of significant changes, we will inform you by email or through a notification in the application.