Effective date: March 16, 2026
1. Introduction
SpaMngr is an invite-only mobile application for spa management. It is used by spa owners and their staff to coordinate rooms, sessions, schedules, and employee records. Access requires an invitation from a spa administrator.
In this Privacy Policy, "SpaMngr," "we," "us," and "our" refer to the operator of the SpaMngr application.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, when it may be disclosed, and what rights and choices may be available to you under applicable law.
2. Data We Collect
We collect the personal data reasonably necessary to provide and operate the SpaMngr service:
- Account data — your email address and display name, provided when you register or accept an invitation.
- Device tokens — push notification identifiers (FCM tokens) used to deliver session reminders and alerts to your device.
- Usage data — work check-ins and check-outs, session records (room assignments, start/end times), vacation requests, and calendar appointments within your spa.
We do not collect payment information, health information, or browsing history.
3. How We Use Your Data
Your data is used solely to operate the SpaMngr application:
- Authenticate you and manage your membership in your spa.
- Display real-time room status and session information to your team.
- Send push notifications for session reminders, vacation approvals, and other in-app events.
- Generate work reports and shift summaries for spa managers and owners.
We do not sell your personal data, share it for cross-context behavioral advertising, or use it for advertising purposes.
4. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract performance — processing is necessary to provide the SpaMngr service you have agreed to use.
- Legitimate interests — operating, securing, maintaining, and improving the service, including error monitoring, fraud prevention, and service reliability.
- Consent — for optional features such as push notifications, where your explicit permission is requested.
5. Data Sharing and Disclosure
We do not sell or rent your personal data. We may share data only in the following limited circumstances:
- Within your spa — your display name, role, check-in status, and session activity are visible to other members of your spa team as required for the app to function.
- Service providers — we use third-party service providers, including Google Firebase for infrastructure, Sentry for error reporting, and BetterStack for development and staging log aggregation as described below. These providers process personal data only as reasonably necessary to provide services to us.
- Legal requirements — we may disclose data if required by law, court order, or to protect the rights and safety of users.
6. Data Storage and Security
We use infrastructure provided by our service providers, including Google Firebase, to store and process app data. Personal data may be processed in the United States and other countries where those providers operate.
We implement access controls, Firestore security rules, and Cloud Function authorization to ensure that each user can only access data they are permitted to view within their spa.
7. Third-Party Services
SpaMngr uses the following third-party services:
- Google Firebase — authentication, database storage, and server-side functions. See Google's Privacy Policy.
- Sentry — crash and error reporting used to identify and fix bugs. We configure Sentry to reduce the amount of personal data included in diagnostic reports. See Sentry's Privacy Policy.
- BetterStack — log aggregation used in staging and development environments only. Not active in production builds distributed via the App Store. See BetterStack's Privacy Policy.
- Resend — email delivery used to send account verification and password reset emails. Your email address is transmitted to Resend solely for email delivery purposes. See Resend's Privacy Policy.
8. Data Retention
Your data is retained for as long as you have an active account. Session history is kept for reporting purposes even after a session ends.
If you delete your account, we delete or anonymize personal data associated with your account, including your profile, memberships, vacation requests, and notification-related records, except where limited retention is reasonably necessary for legal compliance, security, fraud prevention, dispute resolution, or internal recordkeeping.
Session service records: Session records (room assignments, service timestamps, and therapist display name snapshots) are retained by the spa operator as historical business records even after a user account is deleted. These records form the basis of monthly work reports and attendance summaries. After account deletion, the record is pseudonymized — the user's account no longer exists, but a snapshot of the display name at the time of the service may remain in the session record. If you have questions about session records retained after account deletion, contact us at contact@spamngr.cloud.
9. Your Rights
Depending on your location and applicable law, you may have rights regarding your personal data, including rights to request access, correction, deletion, or other rights available under applicable law.
- Access — you may request information about the personal data we hold about you.
- Correction — where available, you may update your display name and email address in the app, or contact us to request correction.
- Deletion — you may delete your account in Settings → Account → Delete Account.
- Consent withdrawal — where processing is based on consent, such as device permissions for notifications, you may withdraw consent at any time through your device settings.
To exercise privacy-related rights, contact us at contact@spamngr.cloud. We may need to verify your identity before processing certain requests.
10. California Privacy Notice
If you are a California resident, you may have rights under California law regarding your personal information, including the right to know what personal information we collect and how we use and disclose it, the right to request correction of inaccurate personal information, and the right to request deletion of personal information, subject to applicable exceptions. California law also protects consumers from unlawful discrimination for exercising applicable privacy rights.
In the last 12 months, depending on how the app is configured and used, we may have collected the following categories of personal information:
- identifiers, such as email address, display name, and device notification tokens;
- usage or operational information associated with check-ins, schedules, sessions, vacation requests, and related spa management activity;
- diagnostic information associated with app errors, crashes, and service reliability.
We collect personal information directly from you, automatically from your device and app usage, and from your spa administrator or spa configuration. We collect and use this information to provide and operate the app, manage accounts and spa membership, send notifications, support spa operations, maintain security, and improve service reliability.
We may disclose these categories of personal information to:
- service providers that assist with authentication, hosting, storage, notifications, backend operations, diagnostics, and security; and
- authorized personnel within your spa, where necessary for the service to function.
We do not sell personal information.
We do not share personal information for cross-context behavioral advertising.
We do not use sensitive personal information for purposes other than providing and operating the app's requested features.
California residents may submit privacy-related requests by contacting us at contact@spamngr.cloud.
11. Push Notifications
SpaMngr uses Firebase Cloud Messaging (FCM) to deliver push notifications for session reminders, vacation approvals, and other in-app events. You can disable push notifications at any time through your device's system settings. Disabling notifications will not affect your ability to use the app.
12. Vietnamese Users
SpaMngr respects Vietnamese personal data protection laws applicable to users in Vietnam. Vietnamese users may exercise their rights to access, correct, or request deletion of their personal data by contacting us at contact@spamngr.cloud.
Please note that personal data may be processed through infrastructure operated by our service providers, including in the United States and other countries where they operate. Personal data may be processed outside of Vietnam through infrastructure operated by our service providers, subject to applicable law.
13. Children's Privacy
SpaMngr is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page and post the revised version here. We encourage you to review this policy periodically.
15. Cookies and Tracking
The SpaMngr mobile app does not use cookies. The SpaMngr website (this page) does not use tracking cookies or third-party analytics scripts. We do not track users' activities across third-party websites or online services for behavioral advertising purposes through this website.
16. Contact
If you have questions about this Privacy Policy or your personal data, please contact us:
SpaMngr
contact@spamngr.cloud