Platform privacy notice
Last updated: 11 October 2026
This privacy notice describes how Klarte.no (“Klarte”, “we”, “us”) processes personal data when you create and use a business account on our booking platform.
1. Two kinds of information — do not mix them
| Information | Klarte’s role |
|---|---|
| Your account (sign-in email, profile, security logs) | Klarte is the controller |
| Booker data entered through the booking service | Your business is the controller; Klarte is only the processor |
Bookers must contact your business about their booking data. Klarte does not decide how you use that information.
2. Information we collect about business users
- Account email, name, and password hash (for email-and-password accounts)
- Business details you provide (business name, email, and address for the privacy notice)
- A record that you have accepted the terms, the data processing agreement, and the controller confirmations
- Logs for security and abuse prevention (sign-in activity; visitor identifiers stored as salted hashes with a short retention period — not for marketing)
- Support correspondence
- If you use Google sign-in: the stable Google account ID we store to recognise the account, plus the verified email and name Google returns at sign-in (see section 2a)
2a. Optional Google sign-in
You can create or open the Klarte business account with Sign up with Google or Sign in with Google, instead of (or in addition to linking) email and password. This is optional.
When you choose Google sign-in:
- You are sent to Google LLC (accounts.google.com / Google OAuth) to authenticate with your Google account
- Google handles the authentication under Google’s own terms and privacy rules
- After you consent, Klarte receives a limited OpenID Connect profile: a stable Google user ID (
sub), a verified email address, email-verification status, and first/last name if Google provides them - Klarte uses the information only to create, link, or sign you in to the Klarte business account, and for related security logging
Klarte does not receive your Google password, does not access Google Drive or Gmail content for this feature, and does not use Google sign-in for appointment data. Fonts on Klarte are self-hosted — Google sign-in has nothing to do with Google Fonts.
2b. Two-factor authentication (TOTP)
Optional two-factor uses a standard time-based one-time code (TOTP) stored encrypted on Klarte’s servers. Codes are verified by Klarte — we do not send your two-factor secret to Google or other third parties. The QR code shown during setup is generated in your browser by a Klarte script. You can use any compatible authenticator app (including apps named “Google Authenticator”). The app is chosen and controlled by you, not by Klarte as a sub-processor.
3. Lawful basis
- Contract — to provide the SaaS service you signed up for (including authenticating you with the method you choose)
- Legal obligation — accounting and compliance where it applies
- Legitimate interest — security, fraud prevention, and improving the product
4. Retention
Account information is kept while the account is active, and for a limited period afterwards for legal and security reasons. You can request account deletion under Settings → Security. If the account is linked to Google sign-in, we keep the Google ID only as long as needed to recognise the link. Deleting the Klarte account removes it together with the other account information.
5. Sub-processors and third parties
We use Hetzner (hosting), Bird (transactional email and SMS reminders), ImprovMX (forwarding of inbound email), Stripe (SaaS subscription and, if you turn on cards for appointments, processing on your connected Stripe account — you remain the seller), Google (optional Google sign-in only), and limited CDN providers. The current public list (including location and transfer basis) is published at /legal/sub_processors. Questions: hjelp@klarte.no.
5a. Briefly, what we collect
- Name — on the business account, and the name the booker types into the form (then your business is the controller and Klarte is the processor)
- Email — sign-in and account notices, and the email the booker provides to complete an appointment
- Phone — when you or the booker provide a number, for example for an SMS reminder. Klarte does not use the number for its own marketing
- Cookies — necessary cookies for sign-in and security, and optional analytics and marketing cookies only after consent. Details: cookies
5b. How the information is protected
- Production traffic uses HTTPS/TLS. Plain HTTP is redirected to HTTPS (local development is excluded)
- Passwords are stored as hashes, not as readable text
- Two-factor secrets are stored encrypted
- Database backups are encrypted with AES-256 before they are stored, and copies older than 30 days are deleted. The job does not write an unencrypted dump
- Access to operations and the database is limited. No transmission or storage is completely secure
More about the measures, and that 100% uptime is not guaranteed: security measures and the terms of use sections 8–9.
5c. Email
Transactional email is sent from noreply@klarte.no via Bird (MessageBird B.V.). That covers account verification and notices to you, and — on behalf of the business — booking confirmations and reminders to the booker. Bird sees the recipient’s email address, often a name, and the content of the message. Sending goes to Bird’s EU region eu1. Messages, recipient data, and event logs stay in that region. The address does not accept replies. The basis for account email is contract (Article 6(1)(b)). Booking email is sent on the business’s instruction; the business is the controller.
Under Bird’s data processing agreement of 21 November 2024, email content is kept for 72 hours. Bird’s privacy statement says that email address, subject, IP address, and other traffic data may be kept for up to six months after sending. SMS content and traffic data are kept for six months. The agreement is accepted electronically by using the Bird account. The EU standard contractual clauses apply only if information is transferred to a Bird entity outside the EEA or Switzerland, not to processing that stays in eu1.
Email to hjelp@klarte.no and kontakt@klarte.no, and replies that are nevertheless sent to the noreply address, is received by ImprovMX and forwarded to Klarte’s mailbox. ImprovMX sees the sender, subject, content, and attachments while the message is in transit, deletes the message content once it is delivered, and keeps delivery logs only briefly, as the provider describes (on the order of 7 days). We use the content to answer the enquiry. The basis is contract for account help and legitimate interest for other enquiries (Article 6(1)(b) and (f)). We delete inbound email when the matter is finished, and no later than 24 months after the last message, unless the law requires longer retention. A reply to noreply is not a support channel. Account help and privacy questions about your Klarte account go to hjelp@klarte.no.
6. Cookies
We use cookies on the marketing site and the account pages as described in the cookie notice. Strictly necessary cookies apply to dashboard sign-in regardless of optional choices on the marketing site. If you choose Google sign-in, Google’s own cookies and technology on Google’s domains also apply during the OAuth redirect. Channel statistics without a cookie do not store an IP address or an identifier. The marketing cookie, only after consent, stores a random id, coarse device, browser, and operating system for 180 days.
7. Your rights
You may request access, rectification, or erasure of your account information, and complain to the supervisory authority (for example Datatilsynet in Norway).
8. Contact
hjelp@klarte.no — account, privacy, and support.
kontakt@klarte.no — partnerships and other enquiries that are not support.
Klarte has considered Article 37 and has not currently appointed a statutory data protection officer. See the internal assessment. Use hjelp@klarte.no for privacy enquiries about your Klarte account.