SalonSync is a cloud-based salon management software (SaaS) operated by OXIO Solutions for hairdressers, barbershops, beauty centers, spas, and studios. This Privacy Policy explains for which purposes, on which legal grounds, and how we process your personal data when you use the services we provide through salonsync.cloud and app.salonsync.cloud. Our policy has been prepared in compliance with the provisions of the Turkish Personal Data Protection Law No. 6698 (KVKK) in force in Turkey and the European Union General Data Protection Regulation (GDPR/AVG).
Our Roles: Distinction Between Data Controller and Data Processor
Due to SalonSync's multi-tenant architecture, our position with respect to your data is split into two distinct roles, and understanding this distinction is important:
As a Data Controller: With respect to the salon operator's (our subscriber's) account registration, identity and contact information, invoicing/subscription data, service usage records, and marketing communications, we determine the purposes and means of processing.
As a Data Processor: With respect to the data that a salon enters into the system regarding its own customers (customer name and surname, phone, e-mail, appointment history, purchase/payment records, etc.), we act solely in accordance with the salon's instructions. The controller of this data is the salon operator that collects it. SalonSync does not use this data for its own purposes other than to provide the service.
If you are a salon's customer and wish to make requests regarding your data, you must first apply to the salon from which you receive service; we forward any requests submitted to us to the relevant salon.
Personal Data We Collect
In order to provide our services, we process the following data categories:
Account and business information: Name and surname, e-mail address, phone number, business (salon) name, business address, and title.
Authentication data: Your password (stored only in encrypted/hashed form) and session information.
Usage and technical data: IP address, browser and device information, transaction logs, and access dates and times.
Invoicing and subscription data: Subscription plan, payment status, and billing-related information.
Salon customer data (in our capacity as processor): End-user customer information entered into the system by salons (name, contact, appointment, sales/POS, and loyalty records).
Data Collection Methods
We collect your personal data through various means:
Directly from you via account creation, registration (app.salonsync.cloud/en/register), and login forms;
Automatically during your use of the service (server logs, session cookies, technical data);
Through salon operators entering data regarding their own customers into the system via the panel;
Through the information you provide when you contact us via e-mail or support channels.
Purposes of Processing
We process your personal data for the following purposes:
To create and manage your account and verify your identity;
To provide salon management services (online appointments, POS/cash register, customer management, staff and commission tracking, reporting);
To send appointment reminders and transactional notifications via SMS and e-mail;
To manage your subscription and billing;
To ensure service security and to prevent misuse and fraud;
To fulfill our legal obligations and respond to legal requests;
To send product updates and marketing communications where your consent is present.
Legal Bases for Processing
We process your personal data only on a valid legal ground:
Performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6/1-b): Data processing necessary to establish and perform the service contract.
Legal obligation (KVKK Art. 5/2-ç; GDPR Art. 6/1-c): To comply with tax, commercial, and other regulatory requirements.
Legitimate interest (KVKK Art. 5/2-f; GDPR Art. 6/1-f): Service security, fraud prevention, and service improvement.
Explicit consent (KVKK Art. 5/1 and Art. 6/2; GDPR Art. 6/1-a): Consent-based processing such as marketing communications and non-essential cookies.
Sharing with Third Parties
We do not sell your personal data. We share data only to the extent necessary to provide the service and with trusted service providers:
Hosting: Your data is stored on the MongoDB Atlas infrastructure.
E-mail delivery: Transactional and notification e-mails are sent via the Hostinger SMTP infrastructure.
SMS provider: SMS infrastructure providers are used for appointment reminders and notifications.
In addition, pursuant to applicable legislation, we may be obliged to share data in response to the lawful requests of authorized public authorities.
International Data Transfers
Your data is hosted on MongoDB Atlas in the European Union (Frankfurt / Germany) region. With respect to data accessed from Turkey, this may constitute a transfer abroad within the meaning of the KVKK; such transfer is carried out in compliance with the KVKK's provisions on transfers abroad and with the necessary safeguards (an adequate level of protection and contractual undertakings) in place. Our choice to host within the EU aims to maintain the GDPR level of protection. Because we operate in the Turkish and Dutch markets, we observe the requirements of both legal regimes together.
Retention Periods
We retain personal data for as long as the purpose of processing requires and for the statute-of-limitations and retention periods stipulated in the relevant legislation:
Account and business data are retained for as long as your subscription is active;
After the subscription ends, data is deleted or anonymized within a reasonable period; however, records subject to statutory retention (for example, invoice and accounting records) are kept for as long as our obligations require;
Transaction logs and technical logs are kept limited to the period required by our security needs;
Salon customer data, in our capacity as processor, is retained for as long as the relevant salon instructs and its subscription continues.
Data Security
We apply appropriate technical and administrative measures to ensure the security of your personal data. These include encryption in transit and at rest, storing passwords in hashed form, restricting access on an authorization basis, logically isolating each salon's data in the multi-tenant architecture (tenant isolation), and regular monitoring against security vulnerabilities. Although no system is one hundred percent secure, in the event of a potential data breach we fulfill the notification obligations stipulated by the relevant legislation.
Rights of the Data Subject
Under the data protection legislation, you have the right to learn whether your data is being processed, to request information, to learn the purpose of processing, to request that incomplete or incorrectly processed data be corrected, deleted, or destroyed, to object to processing, to request the portability of your data, and to seek compensation in the event that you suffer damage. To exercise these rights, you may apply to info@salonsync.cloud. As a salon's customer, however, you must first submit your requests regarding your data to the salon from which you receive service.
Contact
For all questions, requests, and complaints regarding this Privacy Policy, you may contact OXIO Solutions (SalonSync) at info@salonsync.cloud. Our website: salonsync.cloud.