Privacy Policy
August 31, 2026
1. Data Controller
The data controller is NORM WARSZAWA SP. Z O.O. (NIP 5273066259), located in Warsaw. Contact: hi@norm.place.
2. Data We Collect
We collect anonymous analytics data using Google Analytics (cookies): device type, browser, location (country/city), pages visited, time spent on site. In the booking panel we also collect the data described in sections 8–11, including the name and phone number needed to create an appointment.
3. Cookies
We use Google Analytics cookies (ID: G-8PVSKMW4YE) for statistical purposes. In the booking flow after a Meta ad click, the technical _fbc and _fbp identifiers described in section 10 may also be used. If a visit comes from a Monevibe partner campaign, we may use our own norm_mv_clickid cookie for up to 30 days as described in section 11. You can change your choice by clearing site data in your browser.
4. Purpose of Processing
Google Analytics data is used to analyze traffic and improve the website. The separate processing of completed-visit data to measure and optimize Meta advertising is described in section 10, and measurement of Monevibe partner campaigns is described in section 11.
5. Data Sharing
Analytics data is processed by Google LLC as part of the Google Analytics service. Recipients of booking and campaign-measurement data are described in sections 8–11. We do not sell personal data.
6. Your Rights
Under GDPR you have the right to: access your data, rectify it, erase it, restrict processing, data portability, and object to processing. To exercise your rights, contact us at hi@norm.place.
7. Data Retention
Google Analytics cookie data is retained for up to 14 months, in accordance with Google Analytics data retention settings.
8. Telegram Bot, Booking Panel and Customer Communication
This section covers data processed in the @normplacebot Telegram bot, booking panel, and customer communication (SMS, WhatsApp). Data controller — see section 1. A Data Protection Officer has not been appointed. We collect: name, phone number, Telegram user ID and username, message content, visit data (Booksy customer ID, dates, services, amounts). Information about allergies or medical contraindications is treated as special category data (Art. 9 GDPR) — processed only with your explicit consent and solely to deliver the service safely. Purposes: appointment booking, visit-related contact, reminders, responding to inquiries. Legal basis: consent (Art. 6(1)(a) GDPR, Art. 9(2)(a) for allergens), contract performance (Art. 6(1)(b)), our legitimate interest — security and accounting (Art. 6(1)(f)). Recipients (processors): Booksy (booking system), HostedSMS (SMS), Meta Platforms (WhatsApp Business — transfer to the USA based on Standard Contractual Clauses and Data Privacy Framework), Hetzner Online GmbH (hosting, Germany), Google Ireland (Analytics — transfer to the USA based on DPF). Retention: linked Telegram account data — until consent is withdrawn; message content — up to 12 months; visit data — up to 5 years after the last visit (tax records and claim defence). Rights: access, rectification, erasure, restriction, portability, objection, consent withdrawal at any time (contact: hi@norm.place). Complaint: President of the Polish Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.
9. Online payment and booking
When you book an appointment online we take a deposit via the Stripe payment operator (Stripe Payments Europe, Ltd., Ireland), which processes the transaction as a processor. We pass it the data needed for the payment (amount, booking ID); card/BLIK details are entered directly with the operator — we do not store card data. Legal basis: performance of the contract (art. 6(1)(b) GDPR) and accounting/tax obligations (art. 6(1)(c) GDPR). Billing data is kept for the period required by law. Booking and deposit rules are set out in the Booking Terms (norm.place/en/regulamin-rezerwacji).
10. Meta Ads — Conversions API
To better target ads toward people who actually purchase our services, we share with Meta Platforms Ireland Limited a hashed (SHA-256) version of the client's phone number and information about a completed, paid visit (amount, currency, timestamp) — solely to optimize and measure the performance of Meta ad campaigns. If the booking followed a Meta ad click, we also include Meta's technical click and browser identifiers (_fbc and _fbp) when available. We keep those identifiers for no more than 90 days and delete them sooner after Meta confirms receipt. The phone number is shared only in an irreversibly hashed form, never in plain text. Legal basis: our legitimate interest in effective marketing (Art. 6(1)(f) GDPR). Data is transferred to the USA under Standard Contractual Clauses and the Data Privacy Framework. You may object to this processing at any time — contact: hi@norm.place.
11. Monevibe partner campaigns
If a visit to our site comes from a Monevibe partner campaign and the address contains a click identifier, we may store that identifier in our own norm_mv_clickid cookie for up to 30 days so attribution is preserved through the booking flow. Only after a completed, paid visit may we share with the Monevibe platform the click identifier, the “approved” conversion status, and the actual paid PLN value of the visit. This postback does not include the client's name, phone number, card data, or other payment-instrument details. We delete the full identifier for an unresolved conversion no later than 180 days after booking, after a terminal failure within 30 days, and immediately from the active queue after confirmed acceptance. A technical record without the full identifier may remain for audit and duplicate prevention. Legal basis: our legitimate interest in measuring and settling partner-campaign performance (Art. 6(1)(f) GDPR). You may object at any time by contacting hi@norm.place. This mechanism may be used only for Monevibe campaigns when the integration is active.
12. Policy Changes
We reserve the right to update this policy. The current version is always available on this page.