aria5.ai
For masters

aria5 · Legal

Privacy Policy

This policy explains how aria5 handles information when clients book appointments and businesses manage their services.

Last updated: 8 August 2026

Who we are

aria5 is operated by ARENA EQUIPMENT LTD. Appointment businesses using aria5 also control the customer records they create for their own services. Privacy questions can be sent to aria5.wbs@gmail.com.

Information we process

We process only the information needed to provide the platform.

  • Account identity and profile information supplied by the sign-in provider.
  • Booking details, contact information, service preferences, notes and policy consents.
  • Photos or reviews you choose to upload.
  • Free-text product feedback, its language, platform and app version; signed-in feedback is associated with the account that sent it.
  • Session, device, app-version and push-notification data needed for security and delivery.
  • Technical logs used to keep the service reliable and prevent abuse. Anonymous feedback is rate-limited with an hourly one-way request fingerprint; the raw IP address is not stored in the feedback record.

Why and with whom

We use this information to authenticate users, provide bookings, let businesses serve their clients, send requested notifications, support users, secure the platform and meet legal obligations. We do not sell personal information. Data is shared only with the relevant appointment business and service providers needed to operate aria5, or when the law requires it.

Retention and deletion

Account and session data is kept while the account is active. When a client deletes an account, aria5 removes the platform identity, login credentials, uploaded booking files, reviews, authored feedback, messages and direct personal details from bookings linked to that identity. If an Apple grant cannot be revoked immediately, its encrypted revocation credential is retained only in a restricted retry queue until revocation succeeds or manual action is required. Limited booking, payment and consent facts may remain as anonymised operational records where a business or the law requires them. Other product feedback is automatically deleted after 24 months, or earlier when it is no longer useful for product improvement or abuse handling. Private evidence attached to an ARIA5 review awaiting moderation is kept for no longer than 90 days and is deleted earlier once a decision is made. If no decision is made within 90 days, the review is rejected and its evidence is deleted.

An appointment business may hold an independent customer or legal record. Contact that business directly to exercise rights over its own records.

Directory ownership requests

If you ask to claim an unclaimed directory entry, we collect your name, business email, phone number, optional message, authority declaration, selected account, the stable Google Place ID, and an hourly rotating one-way request fingerprint. We use these details only to contact you, prevent abuse and manually verify authority before linking the entry to an account. The claim record, including its pseudonymous request fingerprint, is deleted after 180 days. Separate short-lived pseudonymous abuse-control counters are deleted after 2 days; the raw IP address is never stored.

Business ownership verification

ARIA Verify is the shared verification service and service processor for this step in aria5. It sends the requested WhatsApp one-time code through Meta only to the current official Israeli mobile number returned server-side by Google Places. The Beauty application does not store the full number, code or delivery receipt. While verification is pending, it keeps only a keyed one-way digest used to re-match the exact official number, the last four digits and opaque ARIA Verify identifiers.

ARIA Verify holds the number transiently in encrypted form for delivery and keeps keyed digests. Its challenge record is retained for 30 days and its security/audit event log, which contains no code, phone number or direct personal details, for 90 days. The WhatsApp code proves control of the phone only; business ownership also requires an exact match to the official contact or documented manual review. Rejected, expired or cancelled Beauty intake is deleted 30 days after its final update. A successful account keeps the stable Google Place ID and an opaque consumption receipt as its ownership audit. The tenant identity link may remain while the account is active; account deletion queues an ARIA Verify tenant unlink. To prevent accidental recreation after deletion, ARIA Verify retains only keyed pseudonymous deletion tombstones for up to 365 days; they contain no email, phone, raw Google subject or local user ID. Google identities are linked by verified issuer and subject, never by email alone.

Google Maps data

When a directory profile is linked to Google Maps, aria5 requests its current aggregate rating, review count and required provider attribution from Google Places API when the page is opened. aria5 stores only the stable Google Place ID; the displayed Google rating and attribution are not cached or persisted. Google processes the request under its own privacy policy and terms.

Your choices and security

You may access your account, control optional notifications, and request or initiate deletion at any time. We use access controls, encrypted transport and revocable sessions, but no system can promise absolute security. Contact us if you believe your information is at risk.