Data and privacy

SalonSync holds the data a salon needs to run: appointments, client names and phone numbers, staff, services and payments recorded at the counter. It is stored in a PostgreSQL database on a European server, and the only third parties that receive any of it are the ones a feature you switch on genuinely needs.

What is held

For a shop: its name, address, opening hours, services with prices and durations, staff and their schedules, products, and the payments recorded against visits.

For a client: the name and phone number given when booking, their appointment history, and any review they leave. No card details are held anywhere — SalonSync does not take payments online.

Where it is stored

In a PostgreSQL database on a European VPS, reached over HTTPS. Uploaded images — service photos, gallery pictures — are stored alongside it.

Platform credentials such as API keys are encrypted in the database rather than stored in readable form.

Which third parties receive data, and what

The AI assistant sends the message a client typed, plus the shop's own services, staff and free times, to OpenAI in order to answer. It is sent per message and is not used to train a model on your shop's behalf. Turning the assistant off stops it entirely.

Telegram receives a notification's text and the chat id of the barber or administrator who connected it — appointment reminders and staff alerts. Nothing is sent to anyone who has not connected their own account.

Meta receives WhatsApp messages and the recipient's number, but only once WhatsApp is switched on for the platform and a shop has connected a number. It is off today.

Unsplash and Pexels receive a search phrase when a shop looks for a photograph for a service. They receive no client or shop data — just the words being searched.

What is not done

No shop or client data is sold, rented or shared with advertisers, and there is no advertising or tracking network embedded in the product.

Website analytics are off unless an administrator sets a measurement id, send no personal data, and record events like “a call to action was pressed” rather than who pressed it.

The formal policy

This page describes what the software actually does with data, verified against the code. A formal privacy policy — the legal document covering retention periods, the responsible legal entity, how to make a data request and which law governs it — is still to be published, because those are decisions rather than facts and inventing them would be a commitment nobody made.

For any question about your shop's data in the meantime, email [email protected].

[email protected]