Skip to content

Privacy Policy

Last updated: 8 September 2026

This policy explains how Stella Massage Studio collects, uses, stores and protects personal data when you use stellamassage.rs, send an enquiry or book an appointment.

1. Data controller and contact

Controller: Stella Massage Studio (Salon za masažu Stella)
Address: 3 Vase Pelagića Street, Novi Sad, Serbia
Privacy email: [email protected]
Phone: +381 64 234 4094

2. Data we process

Online booking

When you book an appointment, we process your full name, phone number, email address, selected treatment, appointment date and time, form language, booking reference and status, and any optional note you choose to provide.

Do not include health information or other sensitive data in the optional note. If such information is important for performing a massage safely, provide it directly to the studio.

Contact form and direct communication

When you contact us through the contact form, email, SMS or Viber, we may process your name, email address, phone number, message and the information needed to respond.

Technical data

When you visit the website, the following may be processed: IP address, access date and time, pages visited, device, browser and operating system type, approximate location derived from the IP address, referrer, and technical error and security-event data.

3. Purposes and legal grounds

  • Arranging and providing the service: processing is necessary to organise and provide an appointment at your request.
  • Responding to enquiries: processing is necessary to take steps at your request and for our legitimate interest in communicating with clients.
  • Booking confirmations and notices: data is used only for communication related to the specific appointment.
  • Security and abuse prevention: technical data is used to protect the website, rate-limit automated attempts and diagnose errors.
  • Analytics: aggregated usage data helps us understand visits and improve the website. Where consent is required for analytics cookies under applicable rules, processing is based on the user’s consent.
  • Legal obligations: we may retain or disclose certain data where required by law or a competent authority.

4. Google Calendar and Google API data

Google Calendar is connected only by the studio owner. The system uses the minimum permissions required to check the owner’s calendar availability and manage events created from new website bookings.

  • The FreeBusy check retrieves only occupied time periods, not the titles or content of existing Google events. The result is cached temporarily for no more than 30 seconds.
  • For a new booking, the treatment name, client name, booking reference and duration are sent to the owner’s Google Calendar.
  • The client’s phone number, email address and optional note are not sent to Google Calendar.
  • Existing WordPress bookings are not backfilled into Google Calendar.
  • OAuth tokens are stored separately in encrypted form. Disconnecting the integration removes the token from the website; previously created Calendar events remain until the owner removes them.

Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google data or use it for advertising, profiling or training general AI/ML models, and this integration does not allow people to read the contents of the owner’s calendar.

5. Recipients and service providers

Data may be processed with the assistance of the following providers, only to the extent needed for the purposes described above:

  • Hostinger — website and database hosting;
  • Cloudflare — content delivery, performance and abuse protection;
  • Google — Gmail message delivery, Google Calendar, Google Analytics 4 and Google Maps after the user chooses to load the interactive map.

These providers have their own terms and privacy policies. Data may technically be processed outside Serbia; where required, such processing relies on appropriate contractual or other lawful safeguards.

6. Cookies and similar technologies

The website uses necessary technical mechanisms for security and core functions. Google Analytics 4 and its analytics cookies are not loaded until you explicitly select “Allow analytics” in the cookie banner.

  • Necessary mechanisms provide security, administration, form protection and correct website operation and cannot be disabled through the banner.
  • Google Analytics 4 is used, after consent, to measure visits and website usage. If you select “Necessary only”, the Analytics tag remains blocked and does not send analytics data.
  • Cloudflare technical and security mechanisms may be used where needed to protect traffic.

Your choice is stored in wp_consent_* cookies for 180 days so that the website does not ask on every visit. You can change or withdraw consent at any time through “Cookie settings” in the footer of every page. When consent is withdrawn, available Google Analytics cookies are removed from the browser and Analytics remains blocked on the next page load.

The interactive Google map is not loaded when the Contact page first opens. It loads only after a separate click from you. Google may then receive technical data and set its own cookies. That click does not constitute consent to Google Analytics.

7. Retention

We keep data only for as long as necessary to arrange and record appointments, respond to enquiries, resolve complaints, maintain security and meet legal obligations. When the purpose ends and no obligation or justified reason for further retention exists, the data is deleted or anonymised. Email messages and Calendar events are also subject to the retention settings of the owner’s Google account, while server and security logs follow the retention periods of the hosting and security providers.

8. Your rights

Subject to applicable law, you may request access to, correction or deletion of your data, restriction of processing and data portability where applicable, and object to processing based on legitimate interests. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Send requests to [email protected]. To protect personal data, we may request reasonable proof of identity. You may also lodge a complaint with the Serbian Commissioner for Information of Public Importance and Personal Data Protection.

9. Security

We use reasonable technical and organisational measures, including HTTPS, administrative access controls, form validation, rate limiting, encrypted Google Calendar tokens and backups. No system is entirely risk-free, but these measures are regularly reviewed and adjusted.

10. Changes to this policy

We may update this policy when website features, service providers or legal requirements change. The current version and its last-updated date will always be published on this page.