Skip to content
Salonora

Privacy Policy

Last updated: October 8, 2026

Beta draft — this policy is being reviewed and may change before general availability. Questions: privacy@salonora.app.

Who we are

Salonora is a booking, payments and management platform for salons, barbershops and spas, operated by TwoQM. Each business on Salonora decides how it uses its clients' information; for that information Salonora acts as a service provider (processor) on the business's behalf. For your Salonora account itself (sign-in email, password, language), Salonora is responsible.

What we collect

Account details: name, email, phone (optional), language and a securely hashed password.

Bookings and purchases: appointments, services, notes you choose to share, receipts, gift cards, packages and memberships.

Information a business asks for: intake and consent forms, and photos you or the business upload. Health-related answers and before/after photos are only visible to staff the business authorizes, and every access is logged.

Payments are processed by Stripe. Salonora never receives or stores full card numbers.

Technical data: IP address and device/browser details when you accept a policy or sign a form (kept as a record of consent), and basic security logs.

How it is used

To run your bookings and payments, send confirmations, reminders and receipts, keep the business's records, prevent fraud and abuse, and comply with law. Marketing messages are only sent if you opt in, and you can opt out at any time from your profile or the message itself.

Sharing

Your information is shared with the business you book with, and with providers that help run the service (hosting, email/SMS delivery, push notifications, Stripe for payments). We do not sell personal information.

Retention and your choices

Financial records are kept as long as the law requires. You can download your data or ask a business to erase your personal details from your account page or by contacting the business; identity details are then removed while legally required financial records are kept without them. Expired sessions and sign-in links are deleted automatically.

Security

Data is encrypted in transit, each business's data is isolated at the database level, passwords are hashed with Argon2, and sensitive records are access-controlled and audited.

Contact

privacy@salonora.app