Privacy Policy
Last updated: February 18, 2026
SalonOS (“we,” “us,” or “our”) operates the SalonOS platform, a cloud-based salon and spa management service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
1. Information We Collect
1.1 Information You Provide
- Account information: Name, email address, phone number, and password when you create an account.
- Profile information: Hair type, style preferences, face shape, and other profile details you choose to provide.
- Photos: Images you upload for the AI virtual try-on feature.
- Booking data: Service selections, appointment dates, staff preferences, and notes.
- Organization data: If you are a salon owner, business name, branch addresses, staff information, and service catalogs.
1.2 Information Collected Automatically
- Usage data: Pages visited, features used, booking interactions, and try-on sessions.
- Device information: Browser type, operating system, device type, and screen resolution.
- Log data: IP address, access times, and request identifiers for security and debugging.
2. How We Use Your Information
- Provide and operate the SalonOS platform and its features.
- Process AI virtual try-on transformations using the photos you upload.
- Manage bookings, notifications, and communication between salons and customers.
- Personalize your experience (e.g., tone of notifications based on profile preferences).
- Enforce subscription plans and feature limits.
- Improve platform performance, security, and reliability.
- Comply with legal obligations.
3. Data Isolation & Multi-Tenancy
SalonOS is a multi-tenant platform. Each salon chain's data — customers, bookings, staff, and services — is logically isolated. No organization can access another organization's data. This isolation is enforced at the API middleware level on every request.
4. Data Sharing & Disclosure
We do not sell your personal information. We may share data with:
- Salon chains: When you book an appointment or interact with a chain, your relevant data is shared with that organization to fulfill the service.
- AI processing providers: Photos submitted for virtual try-on are sent to third-party AI engines for processing. These providers process images solely for transformation and do not retain them beyond processing.
- Infrastructure providers: AWS (hosting, storage), email/SMS delivery services — operating under data processing agreements.
- Legal requirements: When required by law, court order, or to protect our rights and safety.
5. Data Retention
- User accounts: Retained while the account is active. Anonymized after 2 years of inactivity.
- Try-on sessions: Retained for up to 2 years for analytics. Original uploaded photos are deleted after 30 days.
- Booking data: Retained for 2 years for history and analytics purposes.
- Facial analysis (biometric data): Face geometry measurements derived from a photograph are retained for 90 days from the date of analysis, after which they are permanently deleted from our database by an automated job that runs daily. You may withdraw consent or request deletion at any time, which removes the analysis and everything derived from it immediately. Photographs submitted for analysis are not retained after the measurements are taken.
- Audit logs: Retained for 7 years for compliance.
6. Your Rights
Depending on your jurisdiction (including under GDPR and CCPA), you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data (“right to be forgotten”).
- Export your data in a portable format.
- Object to or restrict certain processing activities.
- Withdraw consent for optional data processing.
To exercise these rights, contact us at our support page.
7. Security
We implement industry-standard security measures including: HTTPS encryption for all communications, bcrypt password hashing, JWT-based authentication with token rotation, role-based access control, rate limiting and brute-force protection, and organization-scoped data isolation. While no system is perfectly secure, we take reasonable measures to protect your information.
8. Personal Data Masking & Staff Privacy
SalonOS enforces role-based privacy masking on all API responses containing personal information. This protects both staff and customers from unwanted exposure of their contact details.
- Role-based visibility: Phone numbers and email addresses are masked, partially hidden, or fully hidden depending on the viewer's role. Only authorized roles (chain admins, platform admins) see full contact details.
- Staff identity protection: Staff members use professional nicknames for customer-facing interactions. Customers see “Stylist {nickname}” instead of real names. Staff profile photos are not shown to customers.
- Server-side enforcement: Privacy masking is applied at the API layer before data leaves the server. The frontend never receives personal data it is not authorized to display.
- Self-service controls: Staff can set their own professional nickname through their profile settings. Nicknames are validated to prevent accidental exposure of real names.
9. Children's Privacy
SalonOS is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page with an updated date. Continued use of the platform after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us through our support page.