Privacy Policy
Last updated: 25 September 2026
1. Who processes your data
Mesto — the directory at mesto.ge, the business owner’s account at app.mesto.ge and the businesses’ booking pages at *.mesto.ge — is provided by DoSieci.pl, al. Piastów 30, 71-064 Szczecin, Poland, NIP 9552273002, REGON 321094745 (“we”). We are the controller of the personal data processed in the service.
For any question about your data, write to info@mesto.ge.
We are established in the European Union, so the EU General Data Protection Regulation (GDPR) applies. For users in Georgia we also follow the Law of Georgia on Personal Data Protection.
2. What data we process
Business owners (account)
- name, email, phone and password — the password is stored only as a hash, we never know it;
- business details: name, category, city and address, phone numbers, social links, description, photos, logo, opening hours, services and prices;
- names, photos and schedules of the staff members you add.
Clients who book online
- name and phone number, and — if the business asks for it — an Instagram or Facebook handle or link;
- booking details: service, specialist, date and time, status (confirmed, cancelled, completed, no-show) and the number of visits and no-shows at that business.
Business directory
Name, address, phone, website, social links, opening hours and location of businesses from open sources, mainly OpenStreetMap, and from the owners themselves. This is usually company data, but for independent specialists it may relate to an individual.
Requests
- reporting a mistake in a directory profile: the message, an optional contact and the IP address;
- claiming a directory profile: the claim details, the IP address and, when confirmed by SMS, the number published in the profile and a one-time code (stored only as a hash and valid for 10 minutes).
Technical data
- server logs: IP address, time, requested address, browser and response code — for security and troubleshooting;
- anonymous directory statistics: which city, category or profile was opened — without IP addresses or cookies.
3. Why, and on what legal basis
- the owner’s account, booking page, calendar and notifications — performance of the contract to use the service (Art. 6(1)(b) GDPR);
- making your booking, confirming it, reminding you and letting you cancel — steps taken at your request and performance of the booking (Art. 6(1)(b) GDPR);
- the business directory — our legitimate interest in publishing a public guide to local services (Art. 6(1)(f) GDPR); you can object and we will remove the profile;
- security, preventing abuse and defending legal claims — legitimate interest (Art. 6(1)(f) GDPR);
- complying with legal obligations (Art. 6(1)(c) GDPR).
We do not sell data, show advertising or make automated decisions about you.
4. Who receives the data
- The business you book with. It sees your name, phone, booking and booking history in its account and decides itself how to contact you. For that data the business is an independent recipient and is responsible for how it uses it.
- Hosting. The data is stored on OVHcloud servers in Poland.
- SMS provider (uBill, Georgia) — only when SMS notifications are switched on: the phone number and the message text.
- Public authorities — only where the law requires it.
5. Transfers outside the EU
The data is stored in the EU. The businesses in the directory operate in Georgia, so by booking you ask us to pass the booking details to the business you chose; the same applies to SMS sent through a Georgian provider. Such transfers are necessary to carry out your booking (Art. 49(1)(b) GDPR).
6. How long we keep data
- the account and business details — while the account exists; after a deletion request we delete them within 30 days, except what the law requires us to keep longer;
- client bookings — while the business account exists; on your request we delete or anonymise them unless there is a legal ground to keep them longer;
- server logs — no longer than 30 days;
- password reset links — 60 minutes, SMS codes — 10 minutes;
- requests and claims — as long as needed to handle them and to prevent abuse.
7. Cookies
We use strictly necessary cookies only:
- mesto-session — the session: logging in and submitting forms;
- XSRF-TOKEN — protects forms against forged requests;
- remember_web_… — only if you tick “Remember me” when logging in.
There are no analytics or advertising cookies and no trackers such as Google Analytics or Meta Pixel, so no consent banner is needed. If that ever changes, we will ask for your consent first and update this policy.
8. Your rights
You can ask for access to your data, its correction, deletion, restriction and portability, and you can object to processing based on legitimate interest — including the listing of a business in the directory. Write to info@mesto.ge; we reply within one month.
You can also complain to a supervisory authority: in Poland the President of the Personal Data Protection Office (uodo.gov.pl), in Georgia the Personal Data Protection Service (personaldata.ge), or the authority where you live.
9. Security
Every page is served over HTTPS only, passwords and one-time codes are stored as hashes, a business’s data is visible only to its owners and the service administrators, and access to the server is restricted. We make regular backups.
10. Changes
A new version of this policy is published on this page with its update date. We tell business owners about material changes by email in advance.