Privacy Policy

Last updated: 18 May 2026

This Privacy Policy explains how the Equilibrium Property Management System (the "Service", "PMS", "we", "us") collects, uses, stores and protects your personal data when you use the application available at pms-equilibrium-calendar-sync.web.app and admin-pms-equilibrium.web.app.

We follow the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Romanian Law 190/2018.

1. Who we are (Data Controller)

The data controller is JTHERUSSIAN TECH ART SRL, registered in Romania under registration number CUI 45569309, J27/132/2022, with registered office at Ale. Tineretului nr. 13A, Piatra Neamț, jud. Neamț, 610003, România.

Trading name: Equilibrium. Operator contact: Ioan Rusu.

For any privacy-related question or request, contact us at officejta95@gmail.com.

1.1 Data Protection Officer

We have not appointed a formal Data Protection Officer under GDPR Art. 37, as our core activities do not consist of large-scale monitoring of data subjects or processing of special categories of data at scale. For all data protection matters, please use the contact details above; we respond on behalf of the controller.

1.2 EU representative

Because the controller is established in Romania (an EU member state), no Article 27 representative is required. EU users can exercise their rights directly with us.

2. What personal data we collect

2.1 Account data

2.2 Application data you enter

The Service stores the data you create while using it:

Guest data you enter into the Service is processed by us as a data processor on your behalf - you are the controller of that data with respect to your own guests.

2.3 Payment and invoice metadata

2.4 Optional integration data (only with your explicit consent)

2.5 Technical and audit data

3. Why we process this data (purposes and legal bases)

PurposeCategories of dataLegal basis (GDPR Art. 6)
Providing the Service: authentication, storing and displaying your bookings, properties, settings Account, application, technical Performance of contract (Art. 6(1)(b))
Processing payments and issuing invoices via Stripe / SmartBill Payment and invoice metadata Performance of contract + legal obligation (Art. 6(1)(b) and (c))
Connecting to Google Sheets, Booking.com, Airbnb, other optional integrations OAuth tokens, iCal URLs Consent (Art. 6(1)(a)) - you can disconnect at any time
Security, fraud prevention, abuse detection, audit logs Account, technical, audit Legitimate interests (Art. 6(1)(f))
Compliance with Romanian tax / accounting law (where applicable) Invoice metadata Legal obligation (Art. 6(1)(c))

4. How long we keep your data

4.1 How to delete your account and your Google data

You can delete your account in two ways:

When you delete your account:

You can also revoke this app's access to your Google account directly at any time at myaccount.google.com/permissions; this stops Sheets sync immediately but does not delete your PMS account.

5. Who we share your data with (sub-processors)

We use carefully selected third-party processors who provide infrastructure for the Service. We do not sell your data and we do not share it with advertisers.

ProviderPurposeLocation of processing
Google LLC / Google Ireland Ltd (Firebase Authentication, Cloud Firestore, Firebase Hosting) Authentication, data storage, hosting EU and US (under EU Standard Contractual Clauses)
Cloudflare, Inc. Serverless backend (Workers) that brokers Stripe checkout sessions, SmartBill invoice calls, the Google Sheets sync (including AES-GCM-encrypted storage of your Google OAuth refresh token in Workers KV), iCal channel-sync fetches, and admin-side service-account calls to Firebase Global edge network
Microsoft Corporation (Microsoft sign-in) Identity provider - only invoked when you sign in with a Microsoft account. We receive your verified email and display name from Microsoft. EU and US (under EU Standard Contractual Clauses)
Yahoo (Verizon Media) Identity provider - only invoked when you sign in with Yahoo. We receive your verified email and display name from Yahoo. US (under EU Standard Contractual Clauses)
Stripe Payments Europe Ltd Payment processing (only when you use Stripe integration) EU and US (under EU Standard Contractual Clauses)
Intelligent IT SRL (SmartBill) Electronic invoice issuance (only when you use SmartBill integration) Romania
Open-Meteo Weather forecast lookup (no personal data sent - coordinates only) EU

We may also disclose your data when required by law, court order, or other legal process, or to protect our rights, property or safety, or those of our users or the public.

5b. Use of Google API services and user data

PMS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5b.1 OAuth scopes we request and why

ScopeWhat it doesWhy we need it
openid Confirms your identity when you sign in with Google. Required by Firebase Authentication to issue a session for you.
https://www.googleapis.com/auth/userinfo.email Reads your primary Google account email. Used as your account identifier and to send service notifications.
https://www.googleapis.com/auth/userinfo.profile Reads your display name and (optional) profile picture. Shown in the application interface so you know which account is signed in.
https://www.googleapis.com/auth/spreadsheets Reads tab metadata and writes values into Google Sheets that you choose to connect. Lets the Service push monthly revenue figures to a spreadsheet you own. We only read tab names and write to cells you configure; we do not read or modify other content in your Sheets, and we do not access any Sheet you have not explicitly connected.

5b.2 What we do NOT do with Google user data

We do not, and will not, use Google user data to:

Google user data is used only to operate the features you have explicitly enabled (sign-in and, if you connect it, the Google Sheets revenue sync), and is shared only with the sub-processors listed in §5 to the extent strictly necessary to deliver those features.

5b.3 Revoking Google access

You can revoke this app's access to your Google account at any time at myaccount.google.com/permissions. Doing so stops the Sheets sync immediately. To also delete your PMS account and all associated data, see §4.1.

6. International data transfers

Where data is transferred outside the European Economic Area (e.g. to Google or Stripe US infrastructure), the transfer is protected by the European Commission's Standard Contractual Clauses or another lawful transfer mechanism under GDPR Chapter V.

7. Cookies and local storage

The Service uses only essential cookies and browser storage. We do not use advertising or analytics cookies.

8. Your rights under the GDPR

You have the following rights regarding your personal data. We will respond to any verified request without undue delay and, in any case, within one month.

To exercise any of these rights, email us at officejta95@gmail.com.

9. Security

We apply industry-standard technical and organisational measures to protect your data, including encrypted transport (HTTPS), encrypted-at-rest storage with our infrastructure providers, OAuth refresh tokens encrypted with AES-GCM before storage, strict Firestore security rules scoped per user, role-based access control on administrative endpoints, signed and verified authentication tokens, and audit logging of administrative actions. No system is perfectly secure, so we cannot guarantee absolute security.

9.1 Personal-data breach notification

If we become aware of a personal-data breach likely to result in a risk to your rights and freedoms, we will notify the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) without undue delay and, where feasible, within 72 hours of becoming aware (GDPR Art. 33). Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay (GDPR Art. 34), using the email address on your account.

9.2 Automated decision-making and profiling

We do not subject you to decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (GDPR Art. 22). The Service does not build behavioural profiles of you or your guests.

10. Children

The Service is intended for use by professional accommodation operators and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the application interface or by email. The "Last updated" date at the top of this page reflects the most recent revision.

12. Contact

For privacy questions, data-subject requests, or to report a concern:
Email: officejta95@gmail.com
Postal: Ale. Tineretului nr. 13A, Piatra Neamț, jud. Neamț, 610003, România