Privacy Policy
How personal data is handled for salon owners, staff and their clients.
Last updated:
01Overview
This Privacy Policy explains how personal data is handled in connection with the Salon Director service (the "Service"). It applies to visitors to the website, salon owners and staff who hold accounts, and clients of salons whose data is entered into the Service by those salons.
- Trading name
- Salon Director
Nothing in this document excludes or limits any rights or liabilities that cannot be excluded or limited under applicable mandatory law (including consumer protection and data protection law).
02Our roles: controller and processor
Controller. For data we collect and use to operate the Service — for example, account owner and staff profiles, website visits, billing metadata generated by our tooling, support correspondence, security logs, and product analytics we may enable — Salon Director is the data controller.
Processor. For personal data that a salon enters into the Service about its clients (appointments, contact details, notes, hair and colour records, allergies, and messages sent from the salon), the salon is the controller and Salon Director acts as its processor. We process that data on the salon's documented instructions as reflected in these terms and in-product settings.
03Categories of personal data
- Identification and contact: name, email address, salon name, role.
- Authentication and security: hashed credentials, session identifiers, logs.
- Client records entered by the salon: contact details, appointment history, service notes and (where the salon chooses to record them) allergy or health-related notes and colour formulas.
- Communications data: message content and delivery status returned by messaging providers.
- Payment metadata (never full card numbers) generated by a payment processor if paid features are used.
- Technical data: IP address, device and browser information, timestamps and diagnostic logs necessary to operate and secure the Service.
- Support correspondence.
04Purposes and legal bases
- Providing the Service to the account holder (contract).
- Sending transactional communications and, on the salon's instruction, appointment messages to its clients (contract with the salon; salon's own legal basis toward its clients).
- Security, fraud prevention, abuse detection, and audit logging (legitimate interests and legal obligation).
- Billing, tax and accounting records where paid features are used (contract and legal obligation).
- Product improvement and diagnostics using minimised data (legitimate interests).
- Complying with legal requests and enforcing our terms (legal obligation and legitimate interests).
05Service providers we use
We use trusted providers to run the Service under contractual safeguards. The current list may change as the Service evolves; the categories below reflect providers actually used at the date of this policy:
- Supabase — managed database, authentication and file storage.
- Lovable — application platform and hosting layer used to deploy the Service.
- Infobip — messaging delivery (WhatsApp, Viber, SMS) and delivery-status callbacks, when messaging is enabled.
- Where paid features are used, a payment processor may be introduced; details will be presented at checkout.
Additional infrastructure or analytics providers may be added or replaced; this policy will be updated accordingly.
06International transfers
Some providers may process personal data outside the European Economic Area. Where that occurs, transfers rely on lawful transfer mechanisms such as adequacy decisions or the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate. Details are available on request.
07Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, taking into account contractual commitments, legal obligations (for example, accounting and tax records), the need to resolve disputes and enforce agreements, security investigations and the realistically short retention of operational backups. Salon client records are retained while the salon's account is active and are deleted, returned or anonymised within a reasonable period after account closure or on instruction from the salon, subject to legal retention obligations and to the ordinary rotation of backup systems.
08Security
We use reasonable technical and organisational measures — including encryption in transit, encryption at rest at the storage layer of our providers, role-based access, row-level authorisation policies and audit logging — to protect personal data. No system is completely secure; we cannot guarantee absolute security and we ask that you use strong credentials and keep them confidential.
09Your rights
Subject to applicable law, you may have rights to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. If you are a client of a salon that uses the Service, please contact the salon first, as the salon is the controller of your records.
You may exercise your rights or ask questions by emailing privacy@salondirector.net. You also have the right to lodge a complaint with your competent data protection supervisory authority.
10Children
The Service is not directed to children. If you believe a child has provided personal data to us directly, contact privacy@salondirector.net so we can take appropriate action.
11Automated decision-making
We do not carry out automated decision-making that produces legal or similarly significant effects on individuals.
12Where we act as processor
Where Salon Director acts as a processor for salon client data, we process that data only on the salon's documented instructions as reflected in these terms and in-product settings, keep it confidential, apply appropriate security measures, engage sub-processors under written terms, assist the salon with data-subject requests and security incidents to the extent reasonably possible, and delete or return client data at the end of the engagement subject to legal retention obligations. A separate data processing addendum is not automatically in force; if your salon requires one, contact privacy@salondirector.net.
13Data breaches
We maintain procedures to detect, assess and respond to personal-data breaches. Where a breach is likely to result in a risk to individuals, we will notify affected controllers (including salons acting as controllers) without undue delay so they can meet their own notification obligations.
14Changes
We may update this Privacy Policy from time to time. The "Last updated" date above reflects the current version. Material changes will be communicated in the product or by email to account owners.
15Contact
Privacy and data-rights requests: privacy@salondirector.net. General support: support@salondirector.net.
Questions? Email support@salondirector.net.