Legal & Compliance
Last updated: June 19, 2026
BraidFlow is committed to operating in compliance with applicable federal and state laws governing software platforms, communications, data privacy, and payment processing. This page summarizes our key compliance positions. It is provided for informational purposes and does not constitute legal advice.
1. TCPA Compliance — Text Message Communications
The BraidFlow platform is designed to comply with the Telephone Consumer Protection Act (TCPA). Appointment reminder SMS messages are sent only to clients who have provided their phone number and given explicit consent through the booking process. Our booking flow includes a clear SMS consent disclosure and opt-in checkbox. Clients may opt out at any time by replying STOP to any message. We maintain records of consent as required by law. Salon owners using our platform are independently responsible for TCPA compliance in their own client communications.
2. CAN-SPAM Act Compliance
All transactional and marketing emails sent through BraidFlow comply with the CAN-SPAM Act. Our emails clearly identify the sender, include a valid physical mailing address, and provide a straightforward method to opt out of non-transactional communications. Opt-out requests are honored promptly.
3. GDPR — General Data Protection Regulation
For users located in the European Economic Area (EEA) or United Kingdom, BraidFlow processes personal data in accordance with the General Data Protection Regulation (GDPR). Our legal bases for processing include performance of a contract (providing the Service), legitimate interests (platform security and fraud prevention), and consent (marketing communications). Users have the right to access, correct, port, restrict, or erase their personal data. To exercise these rights, contact legal@thebraidflow.com.
4. CCPA — California Consumer Privacy Act
California residents have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and how it is used, the right to delete personal information we hold, the right to opt out of the sale of personal information (we do not sell personal information), and the right to non-discrimination for exercising CCPA rights. To submit a CCPA request, contact us at legal@thebraidflow.com. We will respond within 45 days as required.
5. PCI-DSS Compliance — Payment Card Security
All payment card transactions on the BraidFlow platform are processed by Stripe, which is certified as a PCI-DSS Level 1 Service Provider — the highest level of payment security certification. BraidFlow does not store, transmit, or process raw cardholder data. Our integration with Stripe uses tokenization and secure iframes to ensure cardholder data never touches our servers.
6. ADA / Web Accessibility
BraidFlow is committed to making its platform accessible to users with disabilities. We strive to conform to the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA. If you encounter accessibility barriers on our platform, please contact us at legal@thebraidflow.com so we can address them promptly.
7. Children's Privacy — COPPA
The BraidFlow platform is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete it. If you believe a child has submitted information to us, contact legal@thebraidflow.com immediately.
8. Data Retention and Deletion
We retain subscriber and client data for as long as an account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements. Subscribers may request deletion of their account and associated data at any time. Upon account deletion, we will remove personal data within 30 days, except where retention is required by law.
9. Data Breach Notification
In the event of a data breach affecting personal information, BraidFlow will notify affected subscribers and relevant regulatory authorities within the timeframes required by applicable law (e.g., 72 hours under GDPR, as required by applicable state breach notification laws). Notification will include the nature of the breach, data affected, and steps we are taking to address it.
10. Anti-Spam and Anti-Fraud Policy
BraidFlow has a zero-tolerance policy for spam, fraud, and platform abuse. Accounts found to be sending unsolicited messages, engaging in fraudulent transactions, or misrepresenting services will be suspended or terminated immediately. We cooperate fully with law enforcement investigations involving platform abuse.
11. Salon Owner Compliance Responsibilities
Salon owners who use the BraidFlow platform are independently responsible for compliance with: applicable state cosmetology and braiding licensing laws; local business licensing requirements; employment and contractor laws for staff; consumer protection laws in their jurisdiction; proper collection and remittance of applicable taxes. BraidFlow is a software provider and does not assume legal responsibility for the business operations of its users.
12. Export Controls
The BraidFlow platform may not be used in violation of U.S. export control laws and regulations. By using the Service, you represent that you are not located in a country subject to a U.S. government embargo and are not on any U.S. government list of prohibited or restricted parties.
13. Governing Legal Framework
This platform operates primarily under the laws of the United States. Our full legal framework is documented across the following pages:
- Terms of Service — General platform terms and conditions
- Privacy Policy — Data collection, use, and protection practices
- SaaS Subscription Agreement — Subscription terms for salon owners
- Safety & Disclaimers — Platform limitations and safety notices
14. Compliance Contact
For compliance-related inquiries, data subject requests, or to report a legal concern, contact our legal team at legal@thebraidflow.com. We aim to respond to all compliance inquiries within 5 business days.