Privacy Policy
Last updated: July 2026
1. Who we are
Aurelia Beauty ("we", "us") provides a salon-management platform (the "Service"). This policy explains what personal data we collect, why, and the choices you have. It covers visitors to our websites, people who sign up, and users of the Service.
2. Data we collect
- Sign-up data — name, email, phone, salon name, business details (locations, team size, services of interest), chosen plan, and a hashed password when you request access.
- Account data — profile details, role, and settings of workspace users.
- Customer Data you enter — your clients' records (names, contact details, visit history, notes, payments). For this data, the salon is the data controller and we act as a processor on the salon's instructions.
- Usage and technical data — log data such as IP address, browser type, pages viewed, and timestamps, used for security (e.g. rate limiting) and reliability.
- Cookies — we use a strictly necessary session cookie to keep you signed in, and a preference for your language/theme. We do not use advertising cookies.
3. How we use data
- To provide, secure, and improve the Service (contract performance and legitimate interests).
- To contact you about your workspace, including onboarding after sign-up (contract performance).
- To send appointment reminders and notifications configured by your salon.
- To comply with legal obligations.
We do not sell personal data and we do not use Customer Data for advertising.
4. Where data is stored and who processes it
Data is hosted with our infrastructure subprocessors, currently including our database provider (Turso), our hosting provider (Vercel, including file storage for uploaded images), and — when email delivery is configured — our email provider. Subprocessors process data only to provide their service to us. [Finalize the subprocessor list and data-location commitments before launch.]
5. Retention
We keep personal data for as long as your workspace is active. After termination, we delete or anonymize workspace data within a reasonable period, except where longer retention is required by law. Sign-up requests that are not provisioned are deleted after a reasonable follow-up window.
6. Security
We use industry-standard safeguards: encrypted connections (HTTPS/TLS), bcrypt-hashed passwords, session hardening, role-based access control, rate limiting, and parameterized database access. No system is perfectly secure; we encourage strong, unique passwords.
7. Your rights
Depending on your location, you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal data, and to lodge a complaint with a supervisory authority. To exercise these rights, contact us at [contact email to be added]. If your data is held in a salon's workspace, we may direct your request to that salon, which controls it.
8. Children
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal data from children for our own purposes.
9. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email or an in-app notice before they take effect.
10. Contact
Privacy questions and requests: [contact email to be added].