What we hold, where it lives, and who else sees it. Written to be read, not to be survived.
Zuletzt aktualisiert: 7 August 2026
When a salon uses Salonis to manage its appointments, the salon decides what it collects about its clients and why — in data-protection terms it is the controller. Salonis stores and processes that data on the salon's behalf, as its processor. For your own Salonis account — the login you create — we are the controller.
From everyone with an account:
From salons, additionally: business name, address, city, canton, phone, opening hours, services and prices.
From appointments: which service, which salon, the date and time, and whether the client attended.
There is deliberately no free-text notes field on a booking. Clients choose from a fixed list of preferences instead, because open text fields collect health information whether or not anyone intended them to.
On a private server in France (European Union). Switzerland recognises EU states as providing adequate data protection, so nothing extra is needed for that. Backups are held in the same region.
Only these, and only what each needs:
We do not sell data, and we do not share it with anyone for advertising.
None for tracking. Your login token and your light/dark preference are kept in your browser's local storage, which never leaves your device except to authenticate you. Logging out removes the token.
Appointment records are kept while your salon uses Salonis, since they are its business records. Close your account and we delete your data, except anything we are legally required to retain. A client can ask the salon they booked with to delete their record, and can ask us directly if the salon does not respond.
Under the Swiss Federal Act on Data Protection you may ask what we hold about you, have it corrected, have it deleted, or receive a copy in a portable format. Write to privacy@salonis.ch. We will answer within 30 days. If a salon holds the data as controller, we will pass the request on and tell you we have.
Traffic is encrypted in transit (HTTPS). Passwords are hashed, never stored in a readable form. Access to a salon's data requires being signed in as that salon. If a breach occurs that is likely to put anyone at meaningful risk, we will notify the affected salons and the Federal Data Protection and Information Commissioner as required.
If this policy changes materially, account holders will be told by email rather than left to notice a new date at the top of the page.