mudro
Home
Sign inTry it freeTry free
← Home
Legal information

Privacy policy

What data Mudro processes, what it is needed for, who it may be passed to, and how responsibility is divided between the platform and the Business.

Updated: 10 September 2026mudro.com.uaUkraine
Only the data needed

We process data to run Mudro, to keep it secure and to develop it.

The Business runs its own base

The Business decides which customer and employee data goes into the CRM.

Cookies are here too

Analytics, cookies and third-party technology are described in one document.

Contents
01General provisions02The roles of Mudro and of the Business03What data we may process04What we process data for05The data of a Business's customers and employees06Online booking07Signing in with Google and other ways in08Google Analytics, cookies and local storage09Payments10Messages, SMS and other communications11Third-party suppliers and access to data12Where data is held and where it is sent13Security of data14How long data is kept15Rights over personal data16Deleting an account, exporting, and data after use ends17Children's data18Changes to this Policy19Contacts
01

General provisions

This Privacy policy describes how personal data is processed when using the mudro.com.ua website, the Mudro web application, the booking pages and the features connected to them (the Service).

When using the Service, a User may give data to Mudro directly or place data belonging to their Business into the Service. The roles and the grounds for processing may differ between those two cases.

This Policy applies alongside the Terms of use and public offer.

02

The roles of Mudro and of the Business

For the data Mudro receives in order to register, support, secure, charge and analyse, and to manage its own relationship with the User, Mudro itself decides the purpose and extent of processing within the law.

For the personal data of customers and employees that the Business itself enters into the CRM, the Business decides the purpose, the composition and the lawful grounds for processing it. In those cases Mudro supplies the technical platform and processes the data to the extent needed to run the Service and to perform the contract.

The Business is itself responsible for obtaining such data lawfully, for informing the people concerned, for holding the necessary permissions or other legal grounds, and for the actions of its employees to whom it gave access to the data.

03

What data we may process

Depending on how the Service is used, this may be:

  • account data: first name, surname, email, phone number, profile photo, account identifiers;
  • business data: name, locations, services, rotas, employees, settings, roles and access rights;
  • data entered by the Business: information about customers, bookings, notes, the history of dealings, operational and other data the Business chose to keep in the CRM;
  • technical data: IP address, device type, browser, operating system, event logs, the date and time of signing in, technical identifiers and data about which features were used;
  • payment information: the status, the amount, the date, the plan and the payment identifier. Full bank card details may be processed by the payment provider rather than by Mudro;
  • support requests: the messages and information a User voluntarily provides when getting in touch.

Mudro does not require a Business to put excessive or special categories of personal data into the CRM where the functionality of the Service does not need them. A Business must not upload data it has no proper legal ground to process.

04

What we process data for

Data may be used to create and protect an account, to provide the CRM features, to keep Businesses and locations in step, for online booking, for technical support, for raising and recording payments, for security, for preventing abuse, for backups, for diagnosing errors, for analytics of use and for developing the Service.

We may also process information where it is necessary to perform the contract, to comply with the law, or to protect the rights and safety of Mudro, of Users or of others.

Marketing messages from Mudro are sent only where there is a proper legal ground, and can be stopped through the means of opting out that is provided.

05

The data of a Business's customers and employees

Mudro does not decide which customers a Business adds to the CRM, what notes it writes, which services it provides or which of its employees it opens access to. Those are the Business's decisions.

The Business confirms that it has lawful grounds to pass the data to Mudro for technical processing, and is responsible for the content, the accuracy and the lawfulness of the data it or its authorised people enter into the Service.

Mudro processes such data to provide the functionality of the Service, to store, display and back it up, for technical support, for security and for anything else needed to perform the contract with the Business.

If an end customer of a Business wants to correct data, to find out what it is used for or to exercise another right over data that a particular Business keeps, they may approach that Business directly. Mudro assists with proper requests within its technical role and the requirements of the law.

06

Online booking

When an end customer books with a particular Business through a Mudro page, the data they enter is passed to that Business in order to create and service the booking.

Mudro supplies the technical infrastructure for booking and does not decide what the Business then uses the data for. The Business is itself responsible for how it deals with its customers, for the lawfulness of its communications and for answering data subjects' requests within its own activity.

07

Signing in with Google and other ways in

If a User chooses to sign in with Google or another third-party service, Mudro may receive the profile data the User permitted, as needed to create, find or link an account — for example the email, the name, the photo and a technical identifier.

Mudro does not receive the User's password for their Google account. How the third-party supplier itself processes data is governed by its own terms and privacy policy.

08

Google Analytics, cookies and local storage

On its public pages Mudro may use Google Analytics 4 and similar tools to understand how visitors use the site: page views, sessions, approximate geography, browser and device type, interaction with elements of the page and other technical events.

Google Analytics may use the _ga cookie and other technical identifiers to tell users and sessions apart. Mudro does not pass a name, an email, a phone number or other data that directly identifies a person to Google Analytics.

Cookies and local storage may also be used for authorisation, for security, for remembering settings, for the working of the interface and for other features the Service cannot work properly without.

A User can manage cookies through their browser settings. Blocking technically necessary cookies or local storage may stop some features working correctly.

If Mudro connects advertising cookies, pixels or personalised advertising technology in the future, how they are used and, where it is required, the way consent is obtained will be updated in line with the applicable requirements.

09

Payments

To take payment Mudro may engage independent payment providers. Such providers may process the details of the payment method themselves, under their own rules and the requirements of the law.

Mudro may receive from a provider the information needed to confirm a payment and to run the subscription: the transaction identifier, the amount, the currency, the status, the date and other technical details. Unless expressly stated otherwise, Mudro does not store the full bank card number or the CVV/CVC.

10

Messages, SMS and other communications

The Service may let a Business send its customers service or other messages by SMS, email, push or third-party channels. To deliver them, the data needed may be passed to the relevant communications provider.

The Business itself decides the recipients and the content of such messages and is responsible for having a lawful ground to send them. Mudro does not use a Business's customer base for its own marketing unless there is a separate and proper legal ground for it.

11

Third-party suppliers and access to data

To run the Service, Mudro may engage suppliers of hosting and cloud infrastructure, analytics, authorisation, payments, communications, monitoring, technical support and other necessary services.

Such suppliers receive access only to the information needed to perform their function, or process data as parties in their own right under their own terms where the nature of the service requires it.

Mudro may also disclose information where the law expressly requires it, on a proper demand from a competent authority or a court decision, or where it is necessary to protect the rights, the safety and the legitimate interests of Mudro or of others.

Mudro does not sell the customer bases of Businesses to anybody.

12

Where data is held and where it is sent

The technical infrastructure of Mudro and of particular suppliers may be located in Ukraine or outside it. Where personal data is sent abroad, Mudro applies the requirements and mechanisms provided by law, to the extent they apply to that transfer.

Using international technology suppliers does not by itself mean that all CRM data is passed to every such supplier: how much is passed depends on the particular feature and on the settings of the Service.

13

Security of data

Mudro applies reasonable technical and organisational measures to protect information against accidental loss, unlawful access, alteration, disclosure or destruction. The particular measures may change as the Service develops and as the risks change.

At the same time, no web service, transmission channel or storage system can guarantee absolute security. This provision does not release Mudro from obligations placed on it directly by law that cannot be limited by contract.

For their part, the User is responsible for the security of their own devices and passwords, for their employees' access, and for ending in good time the access of people who should no longer work with the Business.

14

How long data is kept

Data is kept no longer than is necessary to provide the Service, to perform the contract, to keep it secure, to protect the parties' legitimate interests and to meet the requirements of the law.

How long depends on the kind of data, the state of the account, the purpose of processing and the applicable legal requirements.

After use of the Service ends, data may remain for a time in the live systems and in backups. It is deleted or made anonymous in line with what the Service can technically do, the ordinary backup cycle and the requirements of the law.

Particular technical logs, payment, accounting and other data may be kept longer where that is necessary to meet legal obligations, to keep the Service secure or to protect the parties' rights.

15

Rights over personal data

In the cases and within the limits the law provides, a person may obtain information about the processing of their personal data, demand access to it, its correction or updating, the stopping of unlawful processing or its deletion, and exercise the other rights the law provides.

Where a request concerns data a particular Business keeps in its customer or personnel base, Mudro may direct the applicant to that Business or work with the Business to carry out a proper request technically.

To protect the data, Mudro may ask for information sufficient to verify the person and their authority before acting on a request.

16

Deleting an account, exporting, and data after use ends

A User may ask Mudro to close their account, or use the feature in the Service that does it.

Closing a personal account does not necessarily mean that all of a Business's data is deleted at once, where that data belongs to a workspace other authorised people run, or where keeping it is necessary to perform the contract or to meet the requirements of the law.

The Business must export the data it needs before the period it stays available ends. After that period Mudro is not obliged to restore deleted data, unless the law or a separate agreement expressly provides otherwise.

17

Children's data

Mudro is a B2B service and is not intended for children to register with or use on their own. Where a Business processes the data of under-age customers within its lawful professional activity, it is the Business that is responsible for holding the necessary legal grounds and meeting the special requirements that may apply to such processing.

18

Changes to this Policy

Mudro may update this Policy in connection with changes to functionality, to suppliers, to technology or to legal requirements. The current version is published on this page with the date it was updated.

Where changes materially affect how personal data is processed, Mudro may additionally announce them through the Service or through the contact details available.

19

Contacts

For questions about privacy, personal data or exercising rights, Mudro can be contacted at:

ServiceMudro

It helps to include enough information for us to understand which data the request concerns and to verify the applicant properly.

If the suppliers, the analytics, the advertising technology or the way data is kept changes, this Policy is brought up to date as well.

mudro

Made in Ukraine for small service businesses

ProductWho it is forOnline bookingHow it worksPricing
InformationFAQ
DocumentsTerms of usePrivacy policy
Mudro — a CRM for service businesses© 2026 Mudro