Effective date: 7 September 2026.
This Privacy Policy explains how personal data is processed through the Ylips platform and www.ylips.com. It applies to service providers and their team members, clients, visitors, buyers, gift-card recipients, people who contact us, and business contacts.
1. Who is responsible for the data
Ylips is operated by UAB “Logic4”, company code 302306397, registered office at Lazdynėlių g. 18-6, LT-04126 Vilnius, Lithuania. For privacy matters, email [email protected].
UAB “Logic4” is a controller when it processes data for accounts, billing with Ylips, platform security, support, its own analytics, direct marketing, and business-contact research.
When a service provider uses Ylips for its own client bookings, contacts, orders, gift cards, notes, files, or campaign recipients, that provider is normally the controller and UAB “Logic4” is its processor. Contact the relevant service provider first about that data; we will assist it with a valid request.
2. Data we process
- Account and team data: name, email, password hash, sign-in and verification information, organisation, role, settings, and notification choices.
- Profile and public content: professional name, position, description, photos, gallery, location, contact details, working hours, services, prices, products, policies, FAQs, and reviews.
- Client and transaction data: name, email, phone, appointment time and service, price, discounts, attendance status, notes, files and photos, orders, reviews, referrals, and gift-card buyer and recipient information.
- Payment and subscription data: plan, amount, currency, status, and Stripe customer, payment, or subscription identifiers. Ylips does not store full payment-card details; Stripe processes them directly.
- Communications: contact and support requests, sent and received emails, and delivery, unsubscribe, bounce, or complaint status.
- Technical and usage data: IP address or its hash, session identifier, browser and device information, referrer URL, page and booking-step views, product clicks, login attempts, and browser-push endpoint.
- Public business-contact data: business or professional name, website, publicly listed email, phone, address, location, and detected booking system.
Free-text notes or files may contain sensitive data such as allergies or health information. Ylips does not request such data for general use. The service provider must collect only what is necessary and establish an appropriate GDPR Article 9 condition whenever special-category data is processed.
3. Purposes and legal bases
- Contract: registration, identity verification, accounts, profile publishing, bookings, orders, gift cards, notifications, client-management features, subscriptions, and support (GDPR Article 6(1)(b)).
- Legal obligation: accounting, tax, valid authority requests, and legal compliance (GDPR Article 6(1)(c)).
- Legitimate interests: platform and account security, fraud and abuse prevention, service analytics, fault diagnosis, legal claims, communication with existing customers, and research of public B2B contacts. Our interests are to operate and improve Ylips reliably and introduce it to prospective business users; you may object to this processing (GDPR Article 6(1)(f)).
- Consent: optional analytics and marketing cookies, Ylips newsletters, and other marketing where consent is legally required (GDPR Article 6(1)(a)). You may withdraw consent at any time without affecting earlier lawful processing.
- Service-provider instructions: we process a provider's client data on its behalf to deliver the contracted Ylips functions (GDPR Article 28).
4. Sources and required data
We receive data from you, the service provider or its team, the person booking or buying, Stripe, email and notification infrastructure, the browser, public online sources, and integrations that lawfully reach Ylips. Fields marked as required are necessary for the relevant account, booking, order, or payment; without them, we cannot provide that function. Other fields are optional.
5. Recipients
Data is shared as necessary with: the selected service provider and authorised team members; payment provider Stripe; hosting, database, email, notification, security, support, and other technical service providers; analytics and advertising providers where your consent applies; public-business-data search and verification providers; and professional advisers, auditors, insurers, law-enforcement bodies, or other authorities where a legal basis exists. We give them only the data necessary for the relevant service.
Data published on a public profile is available to internet users and may be indexed by search engines. External product, payment, or social links lead to services operated by separate controllers.
6. Transfers outside the EEA
Some providers or subprocessors may process data outside the European Economic Area. Where this happens, we rely on a European Commission adequacy decision, Standard Contractual Clauses, and additional safeguards where required. You may ask [email protected] for information about the safeguard used for a particular transfer.
7. Retention
- Account and contract data is kept while the account is active and afterwards as needed for legal claims, accounting, fraud prevention, or disputes. Closing an account anonymises the main account identifiers, but lawfully required transaction records may remain.
- A service provider's client records are kept on its instructions and while it uses the service, subject to backups and legally required retention.
- Individual page-view and booking-journey events are kept for 30 days; product-click records are kept for 90 days. Aggregate statistics may remain longer where they can no longer identify a person.
- Email verification, recovery, and sign-in tokens remain valid from 15 minutes to 30 days according to purpose and are deleted after expiry.
- Contact requests are generally kept for up to 2 years after resolution, or longer where needed for a dispute or legal duty.
- Payment and accounting documents are kept for the period required by law.
- Suppression and opt-out records are kept as long as necessary to prove and honour your choice not to receive marketing.
8. Cookies and similar technologies
Necessary technologies support sessions, security, language, interface settings, and remembering your choices. Session data generally lasts until the browser session ends, persistent sign-in data for up to 30 days, and language and consent choices for up to 1 year. Some interface settings may remain in your browser until you delete them or the site data.
Optional analytics and marketing technologies are used only after you select the relevant category in the consent dialog. You can withdraw or change consent by deleting Ylips site data in your browser; the choice dialog will reappear. Blocking necessary technologies may prevent sign-in and core functions from working.
Regardless of optional-technology choices, the server may process limited technical event data for security and first-party service statistics on the basis of legitimate interests. Individual page-view and booking-journey events are deleted after 30 days; product-click records are deleted after 90 days.
9. Your rights
Depending on the circumstances, you may request information and a copy of your data, correction, erasure, restriction, portability, withdraw consent, or object to processing based on legitimate interests. You also have the right not to be subject to a solely automated decision that produces legal or similarly significant effects.
Email [email protected] to exercise a right. We may reasonably verify your identity. We will reply within the GDPR deadline, normally one month. Where a service provider controls the data, we will refer the request to it or explain how to contact it.
You may also complain to the Lithuanian State Data Protection Inspectorate or the EEA supervisory authority where you habitually live or work.
10. Security and changes
We use access controls, encrypted transport, password hashing, time-limited sign-in tokens, auditing, and backups. No internet system is risk-free; we will notify affected people of a personal-data breach when and as the law requires.
We may update this policy when features, providers, or legal requirements change. We will publish the new version here and give an appropriate additional notice if a change is material.