Skip to content
Hairdressers.io

Security

Salon software data security, described honestly

Your client list is the most valuable thing in your salon. This page says what we do with it, in plain terms, and is equally clear about what we do not claim.

What we do not claim

We hold no SOC 2, ISO 27001, PCI-DSS or HIPAA certification, and you will not find a trust badge on this site implying an audit that has not happened. Plenty of software companies put those logos up before the report exists. We would rather describe the posture and let you judge it.

Posture

What we actually do

Ordinary, boring practice, applied consistently. That is what protects data.

Encryption in transit
Every connection to the application and its API is over HTTPS. No page of this product is served unencrypted.
Encryption at rest
Databases and backups are encrypted on disk, and backups are held separately from the running system.
Least-privilege access
Staff access is limited to what a role needs. Nobody gets standing access to production client data because it is convenient.
Your data is never resold
We do not sell, rent or share your client list or your booking data with advertisers, data brokers or anyone else. There is no version of this product where that changes.
Export whenever you want
Clients, appointment history, services and notes, to a spreadsheet, on demand, including the day you leave.
Deletion on request
Ask us to delete your account data and we will, and we will confirm when it is done, including from backups on their normal rotation.
Roles and permissions
On multi-location plans, access is scoped per location so a manager sees their own site.
SSO with SAML
Available on Group plans, so a chain can manage access centrally and revoke it in one place.

Client data in a salon context

Salon records are more sensitive than most appointment data. Patch-test results, allergy notes and consent records are health-adjacent information about identifiable people, and they are treated that way: stored against the client record, visible to the stylists who need them, and exportable and deletable like everything else.

Under GDPR and similar regimes, you are the controller of your client data and we are the processor. A data processing agreement is available, and it is included as standard on Group plans.

For a group buying centrally

  • A data processing agreement and named points of contact
  • Roles and permissions scoped per location
  • SSO with SAML and central revocation of access
  • An uptime SLA and a named onboarding contact
  • Invoicing and purchase order billing
  • Data export and deletion on request, in writing

Questions a procurement team needs answered before signing: support@hairdressers.io.

Reporting a vulnerability

If you believe you have found a security issue, email support@hairdressers.io with enough detail to reproduce it. We will acknowledge the report, keep you updated while we work on it, and will not pursue anyone who reports a genuine issue in good faith and gives us reasonable time to fix it.

Related: privacy policy, terms, and the FAQ section on your data.

Get started

Get your chairs booked and your salon found

One flat monthly price. No commission on any booking, ever. It takes an email address to start.

Ready now? List your salon, $39 a month

0% commission · Your client list stays yours · No card required to sign up