Privacy policy
Last updated: 2026-07-29
This policy describes how Parti AB (559439-2317) handles personal data in the Bastu booking platform. Questions go to hej@parti.design.
Controller and processor
Bastu is used by associations and bathhouses to take bookings. For data about their members and guests, the association is the controller and Parti AB is a processor — we handle that data on their behalf and on their instructions.
For data about an association's own administrators, and for this website, Parti AB is the controller.
What we process
| Category | Examples | Why |
|---|---|---|
| Booking | Name, email, phone, seats, time, optional notes | Fulfil and confirm the booking |
| Account | Email, password hash, role, language | Sign-in and permissions |
| Payment | Amount, currency, receipt details, Stripe reference | Take payment and meet accounting obligations |
| Membership | Plan, period, entitlements | Discounts and access |
| Technical | IP address, timestamps, error reports | Security, operations, debugging |
We never ask for card or bank details. Payments are handled entirely by Stripe; we store only a reference and the amount.
Legal bases
- Contract — to deliver the booking or membership.
- Legal obligation — Swedish accounting law requires records to be kept for seven years.
- Legitimate interests — running the service securely and preventing abuse.
- Consent — newsletters and similar, always with an unsubscribe.
The Google Calendar integration
An association administrator may connect a Google account so bookings are mirrored into a calendar. It is optional and off until someone turns it on.
-
We request only the
calendar.app.createdscope, which grants access to calendars Bastu itself created. We cannot read, modify or even see any other calendar in the account. - We write the booking's time, resource, guest name and seat count. The free-text notes field is never sent.
- We store an access token, encrypted, used only to keep that calendar current.
- We do not sell Google user data, do not use it for advertising, and do not pass it on. Our use complies with Google's API Services User Data Policy, including the Limited Use requirements.
- The connection can be removed in Bastu at any time, or revoked from your Google account permissions. The calendar and its contents stay in the account; it simply stops updating.
Sub-processors
We use the following providers, hosting within the EU/EEA wherever possible.
| Provider | Purpose |
|---|---|
| Hetzner | Servers and database (Germany/Finland) |
| Stripe | Payments and payouts |
| Postmark / Resend | Transactional email |
| Cloudflare | DNS and abuse protection |
| Calendar sync, only where an association enabled it | |
| Sentry / GlitchTip | Error reporting (self-hosted) |
Retention
- Bookings: for as long as the association is a customer, then as agreed.
- Payment records: seven years, as required by Swedish accounting law.
- Accounts: until deleted, or after a long period of inactivity.
- Error reports and logs: 90 days at most.
Your rights
You may ask what data we hold about you, have it corrected or erased, restrict or object to processing, and receive it in a machine-readable format. Contact hej@parti.design. If your request concerns a booking with a particular association, we will point you to them, as they are the controller.
If you believe we handle your data improperly you can complain to the Swedish authority, IMY, or your local supervisory authority.
Security
All traffic uses TLS. Passwords are hashed with scrypt and access tokens are encrypted at rest. Production access is restricted and logged. The database is backed up daily to a separate location.
Changes
We update this policy as the service changes, and notify associations using Bastu of material changes. The date at the top shows when the text last changed.
Contact
Parti AB
Stöcke 410, 905 81 Umeå
hej@parti.design