Privacy Policy

Last updated: September 2026

1. Data controller

The data controller is Luca Sciurti, sole trader, with registered address at Via Aldo Moro 64, 20066 Melzo (MI), Italy, VAT number IT12286070961. For any request concerning your personal data you can write to support@pianotunernow.com. The data is hosted on servers within the European Union.

2. What data we collect

Registration data (name, email, date of birth to verify age); profile data (for technicians: introduction, instruments, rates, city, photos and any introduction video); content you create using the service (appointment requests, messages, reviews, community discussions, job notes and piano record cards); the minimum technical data needed for the service to work (access logs, session). Direct contact details (full surname, phone, address) stay hidden from the other party until the unlock provided for by the service takes place. Fee and subscription payments are handled by Stripe: full card details never pass through our systems.

3. Why we process it (purposes and legal bases)

To deliver the service you asked for - account, search, appointment requests, messages, reviews, billing - on the basis of the contract (art. 6.1.b GDPR); to send you the emails the service needs (confirmations, reminders, notifications) on the basis of the contract; optional communications and non-essential cookies only with your consent (art. 6.1.a), which you can withdraw at any time; security, fraud and abuse prevention (anti-disintermediation, referral anti-fraud, moderation) on the basis of legitimate interest (art. 6.1.f); to meet legal, accounting and tax obligations (art. 6.1.c).

4. How long we keep it

Account data is kept for as long as the account is active. If you delete your account, personal data is erased or anonymised within a short technical time, except for what we must keep under legal obligations (for example accounting records, 10 years) or to defend a right. Precise periods: an account that was registered but never confirmed is deleted after 30 days; service emails already sent stay in the queue for at most 180 days; addresses converted into coordinates stay in a technical cache for 180 days; conversations between client and technician are kept for 24 months from the last contact between the same two people, and are not deleted while a dispute or a report is open; moderation decisions and the register of privacy requests are kept for 5 years, so we can show how and why they were handled.

5. Who processes data on our behalf (processors)

We rely on providers that process data on our behalf, as data processors (art. 28 GDPR): Supabase (database, authentication and photo storage, in the EU); Render (application hosting); Stripe (payments of fees, subscriptions and featured profiles); Loops (service emails and, only to those who asked for them, news: unsubscribing through the link at the bottom of an email unsubscribes you here too); OpenStreetMap/Nominatim (turning addresses into coordinates), OSRM on the FOSSGIS community servers (driving time between the technician’s starting point and their first appointment of the day: it only receives two pairs of coordinates, no names or addresses) and, if enabled, Google Maps Platform; OpenFreeMap (the maps you see on the pages, which receive your IP address when they load); your browser’s notification services (Apple, Google, Mozilla, Microsoft), only if you enable push notifications; YouTube, in no-cookie mode, and Vimeo for the presentation videos embedded in technicians’ profiles; an SMS provider, if enabled, for phone number verification. Google and Microsoft calendars are described below.

6. Transfers outside the EU

The data is stored within the European Union. Some providers (for example Stripe or Loops) may involve transfers to third countries: where that happens, they take place with the safeguards provided for by the GDPR (adequacy decisions or standard contractual clauses).

7. Who we share the data with

To other users, only what the service provides for (for example, contact details are exchanged between client and technician after the unlock); to the suppliers listed in section 5; to the authorities, where the law requires it. We do not sell your data and we do not run advertising based on profiling. If you give another person access to your calendar, that person sees your appointments and your address book: you choose them and you can remove their access whenever you want.

8. Your rights

You have the right to access your data, rectify it, erase it (the “right to be forgotten”), restrict its processing, object, receive your data in a portable format and withdraw any consent you have given. From your account Settings you can export your data and request the deletion of your account yourself; for everything else, write to support@pianotunernow.com. You also have the right to lodge a complaint with the supervisory authority in your country (for Italy, the Garante per la protezione dei dati personali).

9. No automated decision-making

We do not make decisions based solely on automated processing that produce legal effects concerning you. The order of search results depends on relevance criteria and on any featured profiles, which are clearly labelled.

10. Security

We apply appropriate technical and organisational measures: encryption in transit, database-level access rules (row-level security), minimisation of the data visible between users and periodic security reviews. No system is 100% secure, but data protection has been part of the design from the start.

11. Cookies

We use only essential technical cookies (login and language); any optional cookies are installed only with your consent. Full details are in the Cookie Policy.

12. Minors

The platform is for adults only: to register, whether as a client or as a technician, you must be at least 18. We do not knowingly collect data about minors and no account may be held on their behalf.

Data about people who are not registered (technicians’ address books and calendars)

A technician can upload their own client address book (name, phone, email, address) to the platform and connect their personal calendar, from which the platform may read the title and place of their commitments. This information may concern people who are not registered with PianoTunerNow and have no direct relationship with us. The technician who uploads them is responsible for those data: it is up to them to have the right to do so, and at upload time they are expressly asked to declare it; the declaration is recorded with date and wording. PianoTunerNow processes them on their behalf, to make their calendar and address book work, and protects them so that they can be read only by the technician and by the people the technician gives access to their own calendar - neither other technicians nor clients can see them. The technician can switch off the storage of calendar titles at any time, and deleting entries from the address book removes the data. If you are one of these people and want to know which of your data we hold, or ask for its deletion, write to support@pianotunernow.com: we will reply and, if necessary, involve the technician who uploaded it. If the technician gives another person access to their calendar, that person sees the address book and the appointments; the titles, places and notes of the commitments read from the connected calendar they do not, those stay with the technician alone.

Data from your connected calendar (Google, Microsoft and published calendars)

If you are a technician and you connect your Google or Outlook calendar, the platform reads the next 60 days of events to block those hours in your schedule, so no client can book you when you are not available; of the guests it only looks at whether you declined the invitation, because an event you declined does not take up your time. With Google and Outlook it also reads the list of your calendars, that is their names and colours, so you can choose which ones to read besides the main one: we only keep which ones you chose, and the calendars you don’t choose are not read. If instead you connect a calendar published through a link (for example from Apple), the platform reads the file: the address stays secret, and when you remove the link its hours disappear too; if you published it showing only when you are busy, only the times arrive. From Google and Outlook, where the permission allows it, and from calendars published with their details, it also reads the event’s title, location and notes, to show them in your own schedule, to offer to save into your address book the contact details it finds there (name, phone, email, address) and to fill in the appointment when you turn an event into a real appointment: only you can see them, you decide whether to save them, and you can turn this reading off at any time in Settings. In the connected calendar the platform writes only PianoTunerNow appointments: it creates them, updates them when they change and deletes them if they are cancelled; it does not modify or delete your other events. We do not use this data for advertising, we do not sell it and we do not give it to any other user. When you disconnect the calendar, that data is removed. PianoTunerNow’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. If you give another person access to your calendar, they do not see these texts: the title, place and notes of your commitments stay yours alone.

The piano’s QR tag

Every registered piano has a QR code that the owner can print and stick on the instrument. Whoever scans it opens a public sheet, with no login, showing only data about the instrument: type, brand, model, year and size; the owner decides whether to add the photo, the date of the last tuning and the name of the technician who serviced it. The owner’s name, address, city, serial number and notes never appear. The code is random and the owner can regenerate or switch it off at any time: from that moment old stickers open nothing.

If you manage a tuner’s calendar

A tuner can give someone they trust access to their calendar. If that someone is you, we keep: the first name, surname, email address, language and date of birth of your account; the confidentiality undertaking you signed, with its date, version and the exact text you read, for five years from signing; and the record of your entries into that calendar - when you went in, when you left, and the name you appeared under - for ninety days, visible to the tuner. We do not record your IP address or your device. Inside the calendar you see the tuner’s appointments, customers and contacts: that data stays theirs, and you handle it on their behalf. We send you no marketing email and your address does not enter our lists: you receive service email only. If you close your account the accesses disappear; the signed undertaking and the name in the entry record stay until they expire, because the tuner has a right to know who went into their calendar.

If you were invited and never sign up

When a tuner invites an email address to manage their calendar, that address stays written in the invitation and in the row that records the send, even if you never open the link and never sign up. We delete them within thirty days. The provider that sends our email (section 5) keeps its own send logs, with your address. If you want them gone sooner, write to support@pianotunernow.com: we look for them, we delete them, and we pass the request on to the provider too. The invitation creates no account and signs you up to nothing: without your click, nothing happens.

← Back to home