Privacy

What we hold, where it lives, and who else sees it. Written to be read, not to be survived.

Zuletzt aktualisiert: 7 August 2026

Who is responsible for what

When a salon uses Salonis to manage its appointments, the salon decides what it collects about its clients and why — in data-protection terms it is the controller. Salonis stores and processes that data on the salon's behalf, as its processor. For your own Salonis account — the login you create — we are the controller.

What we collect

From everyone with an account:

  • Name, email address and (optionally) phone number
  • Your password, stored only as a bcrypt hash — we cannot read it
  • Whether you are a salon owner or a client

From salons, additionally: business name, address, city, canton, phone, opening hours, services and prices.

From appointments: which service, which salon, the date and time, and whether the client attended.

There is deliberately no free-text notes field on a booking. Clients choose from a fixed list of preferences instead, because open text fields collect health information whether or not anyone intended them to.

What we do not collect

  • No payment card data of any kind. Payment happens at the salon; Salonis never touches it.
  • No health information, and no fields inviting it.
  • No advertising trackers, no analytics profiling, no third-party cookies.

Where it is stored

On a private server in France (European Union). Switzerland recognises EU states as providing adequate data protection, so nothing extra is needed for that. Backups are held in the same region.

Who else sees it

Only these, and only what each needs:

  • Twilio — sends appointment reminders and cancellation notices by SMS. Receives the recipient's phone number and the message text (salon name, service, time). Only when SMS is enabled.
  • Google (Gemini API) — generates the salon's monthly business summary and rebooking suggestions. It receives aggregate figures only: booking counts, cancellation rates, service names, prices and free time slots. No client names, phone numbers, email addresses — and not even the salon's own name or town, because a Swiss sole proprietorship's registered name contains the owner's family name. We use a paid tier, under which Google states it does not use submitted content to train its models.
  • OVH — hosts the server. Has no access to the application data in the ordinary course of running it.

We do not sell data, and we do not share it with anyone for advertising.

Cookies

None for tracking. Your login token and your light/dark preference are kept in your browser's local storage, which never leaves your device except to authenticate you. Logging out removes the token.

How long we keep it

Appointment records are kept while your salon uses Salonis, since they are its business records. Close your account and we delete your data, except anything we are legally required to retain. A client can ask the salon they booked with to delete their record, and can ask us directly if the salon does not respond.

Your rights

Under the Swiss Federal Act on Data Protection you may ask what we hold about you, have it corrected, have it deleted, or receive a copy in a portable format. Write to privacy@salonis.ch. We will answer within 30 days. If a salon holds the data as controller, we will pass the request on and tell you we have.

Security

Traffic is encrypted in transit (HTTPS). Passwords are hashed, never stored in a readable form. Access to a salon's data requires being signed in as that salon. If a breach occurs that is likely to put anyone at meaningful risk, we will notify the affected salons and the Federal Data Protection and Information Commissioner as required.

Changes

If this policy changes materially, account holders will be told by email rather than left to notice a new date at the top of the page.

Contact

privacy@salonis.ch