Legal

Privacy Policy

Effective date: 19 March 2026 · Last updated: 19 March 2026

GreenParrot UAB (“GreenParrot”, “we”, “us”) is the data controller for personal data collected through this platform. This policy explains how we handle your data in compliance with the EU General Data Protection Regulation (GDPR).

1. Data We Collect

We collect the following categories of personal data:

CategoryExamplesPurpose
IdentityFirst name, last nameAccount management, booking
ContactEmail address, phone numberBooking confirmations, support
AccountLogin credentials (via Clerk)Authentication and security
TransactionalBooking history, services booked, amounts paidService delivery, dispute resolution
FinancialStripe payment references (no raw card data)Payment processing
Partner bankingIBAN, BIC, account holder namePayout processing (Partners only)
ReviewsStar ratings, written reviewsPlatform quality, partner ranking
TechnicalIP address, browser, device, session dataSecurity, fraud prevention, analytics
UsagePages visited, clicks, search queriesPlatform improvement (Vercel Analytics)

3. Who We Share Data With

We do not sell your personal data. We share data only as needed to operate the platform:

  • Partners — receive your name, contact details, and booking information to fulfil your appointment.
  • Stripe — processes payments. Stripe is PCI-DSS compliant. We never see or store raw card numbers.
  • Clerk — manages authentication and identity verification.
  • Resend — sends transactional emails (booking confirmations, reminders).
  • Supabase / Vercel — cloud infrastructure for data storage and platform hosting (EU region).
  • Sentry — receives anonymised error reports (no PII in error logs).
  • Authorities — where required by law or a valid court order.

All third-party processors are bound by data processing agreements and comply with GDPR.

4. Data Retention

We retain your data for as long as your account is active or as needed to provide services.

  • Account data — retained while your account is open, deleted within 30 days of account deletion request
  • Booking records — retained for 7 years for tax and financial compliance (Lithuanian law)
  • Payment references — retained for 7 years (Stripe records)
  • Reviews — retained while the Partner profile is active; anonymised after account deletion
  • Technical logs — retained for 90 days

5. Your Rights Under GDPR

As an EU resident, you have the following rights:

  • Access — request a copy of all personal data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request deletion of your account and personal data (right to be forgotten)
  • Portability — receive your data in a machine-readable format
  • Objection — object to processing based on legitimate interests
  • Restriction — request we limit processing of your data
  • Withdraw consent — at any time for consent-based processing

You can exercise your rights from your account settings page (data export and deletion) or by emailing privacy@greenparrot.lt.

You have the right to lodge a complaint with the State Data Protection Inspectorate of Lithuania (VDAI).

6. Cookies

We use cookies and similar technologies. See our Cookie Policy for full details. You can manage your cookie preferences via the banner shown on your first visit.

7. International Transfers

Your data is primarily stored within the European Economic Area (EEA). Where any transfer outside the EEA is necessary (e.g. certain Stripe or Clerk infrastructure), it is protected by Standard Contractual Clauses (SCCs) approved by the European Commission.

8. Children

GreenParrot is not intended for users under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

9. Contact and DPO

For privacy questions, data requests, or complaints, contact our privacy team:

privacy@greenparrot.lt
GreenParrot UAB, Vilnius, Lithuania

We aim to respond to all data requests within 30 days as required by GDPR.