The data controller is the operator of the Mavify platform. We collect the following categories of data:
We process your data to: provide services (bookings, payments), communicate about platform usage, ensure account security, improve our services, and - with your consent - for marketing purposes. Depending on the purpose, the legal basis is performance of a contract, compliance with a legal obligation, our legitimate interests in security, abuse prevention and aggregate measurement of site effectiveness, or your consent where required.
The Mavify platform consists of two applications: mavify.io (for clients seeking specialists) and pro.mavify.io (panel for specialists). We may share your data with: specialists with whom you make bookings or purchases (applies to clients using mavify.io), clients who make bookings with you (applies to specialists using pro.mavify.io), payment providers (Stripe, Mollie), infrastructure providers (Vercel, Supabase), and — after the relevant consent — Google, Meta and browser-side Sentry features. Limited server/edge error diagnostics through Sentry is described separately below. We also disclose data to public authorities when required by law.
We use cookies necessary for the service to function and - with your consent - analytical and marketing cookies. Independently of cookie consent, we store daily aggregate counters of visits and clicks. To limit duplicates and abuse, the IP address is processed briefly on the server solely to create a one-way HMAC; this metrics system does not store the raw IP address, user agent, referrer, UTM parameters, session ID, or user ID. Detailed information about cookies can be found in our Cookie Policy.
For signed-in accounts, we record events related to feature activation, account lifecycle stages and subscriptions. They are used to analyze and optimize the product, are linked to the account and are retained for no more than 24 months. We delete all of these events earlier when the account is deleted. Accounting documents and payment history are a separate dataset and may be retained longer where required by law. This processing is separate from cookie consent and from consent to receive marketing communications.
If a specialist grants consent for marketing cookies, we store the version and time of that consent with their account. When the account is activated or a paid subscription starts, we may then send an event to the Google Data Manager API and Meta Conversions API. For matching, the account email is normalized and SHA-256 hashed immediately before delivery; neither the raw email nor its hash is stored in the queue. We send a stable event identifier, its timestamp and — for a confirmed payment — the net amount in PLN. A hash is pseudonymous rather than anonymous data. We check consent again immediately before delivery, and withdrawing it cancels events that have not been sent.
When the integration is enabled, we use Sentry for limited server/edge error diagnostics based on our legitimate interest in maintaining service security and reliability. This is not a cookie-based mechanism. We disable default PII transmission and remove IP addresses, cookies and sensitive authentication headers before sending an event. Browser-side Sentry and Session Replay are enabled separately and only after analytics consent.
We implement modern technical and organizational measures to protect your data: SSL/TLS encryption, secure password storage, two-factor authentication for specialists, and regular security audits.
Under the GDPR Regulation, you have the following rights:
California residents have the right to know what data is collected, request deletion, and opt-out of the sale of personal information. Mavify does not sell personal data.
We retain data for the duration of account usage and for the period required by law (e.g., financial data for 5 years). After account deletion, data is anonymized or deleted within 30 days. All account-linked activation, lifecycle and subscription events, together with technical conversion-delivery statuses, are retained for no more than 24 months and are deleted when the account is deleted. Unsent conversions expire earlier according to the provider window (up to 7 days for Meta and up to 63 days for Google matching based on user data). Separately stored accounting documents and payment history remain for the period required by law. Aggregate marketing counters are retained for 2 years. HMACs used for deduplication expire after 5 minutes and are removed by hourly cleanup, while technical anti-spam hashes are removed after 48 hours of inactivity.
We will notify you of significant changes to this privacy policy by email at least 14 days in advance.
For data protection matters and to exercise your rights, please contact: privacy@mavify.io
Last updated: 8/2/2026