Security
Salon software data security, described honestly
Your client list is the most valuable thing in your salon. This page says what we do with it, in plain terms, and is equally clear about what we do not claim.
What we do not claim
We hold no SOC 2, ISO 27001, PCI-DSS or HIPAA certification, and you will not find a trust badge on this site implying an audit that has not happened. Plenty of software companies put those logos up before the report exists. We would rather describe the posture and let you judge it.
Posture
What we actually do
Ordinary, boring practice, applied consistently. That is what protects data.
- Encryption in transit
- Every connection to the application and its API is over HTTPS. No page of this product is served unencrypted.
- Encryption at rest
- Databases and backups are encrypted on disk, and backups are held separately from the running system.
- Least-privilege access
- Staff access is limited to what a role needs. Nobody gets standing access to production client data because it is convenient.
- Your data is never resold
- We do not sell, rent or share your client list or your booking data with advertisers, data brokers or anyone else. There is no version of this product where that changes.
- Export whenever you want
- Clients, appointment history, services and notes, to a spreadsheet, on demand, including the day you leave.
- Deletion on request
- Ask us to delete your account data and we will, and we will confirm when it is done, including from backups on their normal rotation.
- Roles and permissions
- On multi-location plans, access is scoped per location so a manager sees their own site.
- SSO with SAML
- Available on Group plans, so a chain can manage access centrally and revoke it in one place.
Client data in a salon context
Salon records are more sensitive than most appointment data. Patch-test results, allergy notes and consent records are health-adjacent information about identifiable people, and they are treated that way: stored against the client record, visible to the stylists who need them, and exportable and deletable like everything else.
Under GDPR and similar regimes, you are the controller of your client data and we are the processor. A data processing agreement is available, and it is included as standard on Group plans.
For a group buying centrally
- A data processing agreement and named points of contact
- Roles and permissions scoped per location
- SSO with SAML and central revocation of access
- An uptime SLA and a named onboarding contact
- Invoicing and purchase order billing
- Data export and deletion on request, in writing
Questions a procurement team needs answered before signing: support@hairdressers.io.
Reporting a vulnerability
If you believe you have found a security issue, email support@hairdressers.io with enough detail to reproduce it. We will acknowledge the report, keep you updated while we work on it, and will not pursue anyone who reports a genuine issue in good faith and gives us reasonable time to fix it.
Related: privacy policy, terms, and the FAQ section on your data.
Get started
Get your chairs booked and your salon found
One flat monthly price. No commission on any booking, ever. It takes an email address to start.
0% commission · Your client list stays yours · No card required to sign up