Privacy Policy
Last updated: June 2026
BraidFlow ("we," "us," or "our") is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information.
1. Information We Collect
Account information: Name, email address, and password when you register.
Business information: Salon name, address, phone number, and other details you provide.
Client data: Information salon owners store about their clients, including names, phone numbers, appointment history, and hair profiles.
Usage data: Pages visited, features used, device type, and IP address.
Payment data: Processed securely by Stripe. We do not store full card numbers.
2. How We Use Your Information
We use collected information to: provide and improve the platform; send transactional and appointment-related communications; detect and prevent fraud; comply with legal obligations; and respond to support requests.
3. Sharing of Information
We do not sell your personal data. We share information only with:
- Service providers: Stripe (payments), Twilio (SMS), Resend (email), and our cloud hosting provider — each bound by data processing agreements.
- Law enforcement: When required by valid legal process.
- Business transfers: In connection with a merger or acquisition, with notice to users.
4. Data Retention
We retain account data for as long as your account is active and for 90 days after deletion. Appointment records may be retained longer for legal compliance.
5. Security
We use industry-standard encryption (TLS in transit, AES-256 at rest) and access controls. No system is perfectly secure; please use a strong, unique password.
6. Cookies
We use essential cookies for authentication and session management. We do not use third-party advertising cookies without your consent.
7. Your Rights (GDPR/CCPA)
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Portability — receive your data in a structured format
- Opt out of certain processing activities
To exercise these rights, contact us at privacy@braidflow.app.
8. Children's Privacy
BraidFlow is not directed at children under 13. We do not knowingly collect data from minors.
9. International Transfers
Data may be processed in the United States. By using our platform, you consent to this transfer. We ensure appropriate safeguards are in place for international transfers.
10. Third-Party Links
Our platform may link to third-party sites. We are not responsible for their privacy practices.
11. Changes to This Policy
We may update this policy and will notify registered users of material changes by email or in-app notice.
12. Contact Us
For privacy-related requests: privacy@braidflow.app
BraidFlow Legal Department United States