SalonBiz Software

Privacy Policy

Last Modified: 05/28/2021

This Privacy Policy (“Policy”) of SalonBiz, Inc.  (“SalonBiz,” “our,” “we” or “us”), which will always be at https://salonbizsoftware.com/privacy-policy/ is intended to help you understand our privacy practices and how we collect, use, disclose and process your personal information. We also describe your rights and choices with respect to how we process your personal information. This Policy applies to www.salonbiz.com and www.salonbizsoftware.com (including all sub-domains, the “Sites”), which are owned and operated by SalonBiz as well as the use of any mobile device application created by SalonBiz (each, a “Mobile App” collectively the “Mobile Apps”) and our web-based salon management software  (the “Web App”).  Services provided via the Mobile Apps and Web App may be collectively referred to as our “Services.”  This policy also applies to the online stores, online ordering pages and associated payment pages, portals hosted on salonbiz.com on behalf of SalonBiz Salons, and the customer facing Pocket Salon Mobile Apps provided on behalf of SalonBiz Salons (collectively referred to as our “Patron Services”). This Privacy Policy does not apply to information collected by us offline or through any other means or to any data stored as part of a SalonBiz customer’s on-premises Software installation.

ACCEPTANCE:

Any entity accessing or using the Sites, Services or Patron Services (“you”) represents and warrants that you accept the data practices and terms described in this Policy and as applicable, the Terms of Service and Patron Terms. If you do not agree with this Policy, please discontinue your use of the Sites and Services immediately. 

CHANGES TO THIS POLICY:

We may revise this Policy from time to time and without prior notice to you. Except as otherwise noted in this Policy, such changes may apply to any personal information we already hold about you or personal information collected after the Policy is modified. Changes will be posted on this page and are effective as of the “Last Modified” date at the top of this Policy. Please visit this page regularly so that you are aware of our latest updates. Continuing to access or use the Sites, Services, or Patron Services after any changes become effective indicates your acceptance of the revised Policy.

In addition, we may provide you with “just-in-time” disclosures or additional information about the data processing practices of specific parts of our Sites, Services, or Patron Services. Such notices may supplement this Policy or provide you with additional choices about how we process your personal information.

OUR RELATIONSHIP TO YOU:

To understand SalonBiz’s data protection obligations and your rights to your Personal Data under this Policy, it is important that you identify which relationship(s) you have with SalonBiz.

“Salons” refers to the registered users of the SalonBiz Services including Salons with both paid and free or trial accounts. SalonBiz has a “data controller” or direct relationship with Salons using and accessing the Sites and Services with regard to their own Personal Data. (Authorized users of a Salon’s SalonBiz paid, free, and/or demo account are collectively and individually referred to as “Salons.”)

“Patrons”  refers to individuals doing business with a Salon utilizing SalonBiz Services and/or to individuals utilizing a Salon’s integration with or individual instance of a Pocket Salon Mobile App,  whether your data was entered by the Salon or whether you enter it in a Mobile App or on a form hosted by SalonBiz on behalf of a Salon. SalonBiz has a “data processor” relationship with any Patron and will collect your Personal Information solely on behalf of a Salon. Your agreement with the relevant Salon should explain how the Salon shares your Personal Information with SalonBiz and other third parties, and if you have questions about this sharing, then you should direct those questions to the Salon.

“Visitors” refers to any individual accessing the Sites as well as to any individual submitting Personal Data via the Sites for any reason including, but not limited to submitting a “contact us” or other online inquiry form, subscribing to a newsletter or blog, registering for a demo or webinar, or completing an online survey. SalonBiz has a “data controller” or direct relationship with all Visitors accessing or submitting Personal Data via the Sites for any reason.

THIRD PARTIES:

This Policy does not apply to information processed by third parties, for example, third parties who incorporate our Services or Patron Services into their own websites, when you integrate third-party services with our Services, when you visit a third party website or interact with third party services including those you may access by following a link from the Sites or those with whom we may share information as set forth in this Policy. You acknowledge that your use and access to any third-party services in conjunction with SalonBiz Services is solely at your own risk. Please review any third parties’ privacy policies before disclosing information to them. 

PERSONAL INFORMATION:

 “Personal Data” means any information about an identified or identifiable individual and any device information that may be linked with an identifiable individual. We collect and process the following types of information. Note: Specific Personal Data elements listed are provided for example only and may change. We may create anonymous records from Personal Data for certain business purposes of SalonBiz and our Affiliates as defined below. Any information that is anonymized or aggregated is no longer Personal Data and we may indefinitely use it, share it and retain it for any reason. 

Contact Data: Personal Data about you used to contact you. For example: your name, company name, title, email address, physical address, phone number.

Profile Data”: Personal Data related to a free or paid Salon user account on our Services. For example: business name, phone number, e-mail address, website, physical address and basic business and industry information, employer, colleague names, username, password, credit card and bank account information.

“Paid Account Data”Personal Data of a Salon related to you and your business used for account configuration and providing the Services. For example: your social security number (we may use the last 4 digits provided to obtain and store the full social security number), driver’s license state and number, Employer Identification Number (Tax ID), payment processing merchant account information, employee names and contact information.

“Diligence Data”Personal Data of a Salon required to verify identity and eligibility for a payment processing account and/or payment processing merchant account with a SalonBiz partner. We may obtain information about you from public databases, credit bureaus, and ID verification partners, for example information about your current and past name, address, job role, public employment profile, credit history, status on any sanctions lists maintained by public authorities, and other relevant data.

Patron Data: Personal Data of a Salon’s customers (“Patrons”) utilized by SalonBiz on behalf of the salon to provide services to a Salon’s Patrons. For example: customer name, customer phone number, customer postal address, customer email address, services a customer utilized, appointment details, credit card and bank account numbers, user ids and passwords. Patron Data may be entered by Salons utilizing our Services or by Patrons using our Patron Services to do business with Salons on websites and Mobile Apps we host on behalf of those Salons.

NOTE: By entering Patron Data into our systems via the Services, you understand that SalonBiz is acting as a data processor providing services to you. You represent and warrant that you have the requisite authority to provide such Personal Data to us, and that the disclosure does not violate any applicable law or regulation, including but not limited to the Payment Card Industry Data Security Standard (PCI DSS), the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA), the Personal Information Protection and Electronic Documents Act (PIPEDA), or the EU General Data Protection Regulation (GDPR).

“Appointment Data”:  Any data included in an Appointment created, transmitted, and/or stored via the Services, including any data entered by Patrons via the Patron Services. This includes any such data not classified as “Patron Data” including but not limited to services requested, staff requested, preferences registered, images uploaded, appointment times, cancellation requests, amounts due or overdue, contact information, and any data entered in a free-form or custom field.

“Order & Invoice Data”:  Any data included in an Order or Invoice created, transmitted, and/or stored via the Services, including any data entered by Patrons via the Patron Services. This includes any such data not classified as “Customer Data” including but not limited to items purchased, services received,  amounts due or overdue, shipping address and contact information, and any data entered in a free-form or custom field.

“Transaction Data”: When Patrons use our Patron Services to submit a payment or otherwise make a purchase from a Salon, we collect information necessary to process that transaction, that may include your name, address, zip/postal code, email address, phone number, credit card or financial account number, IP address, and any other information necessary to process or authenticate the transaction. Our PCI Compliant payment processing partners securely store credit card and bank account information you enter via the Patron Services so that it may be used for authorized future one-time transactions. Furthermore, we may collect information about you and your purchase, as well as any Personal Information or demographic data that you provide at the time of purchase, including (without limitation) your email address, contact information, and other information related to the products/services purchased.  Transaction Data is also collected when Salons use the Services to collect payments from their Patrons.

Billing Data: When Salons subscribe to our Services or when Salons incur additional fees as part of utilizing the Services, we collect information about your or your business’ payment methods, such as credit or debit card numbers, bank account numbers, merchant account identifiers, and billing address.

“Support & Inquiry Data”: We collect information that you provide to us, such as when you create an account, submit a support ticket, engage in an online Chat, email or call our sales or service team, when you comment to a blog, or when you email, call, write, fax or otherwise initiate contact with SalonBiz regarding our Sites and/or Services. We record your contact information and support & inquiry details in our CRM (Customer Relationship Management) and support ticketing system.

“Device Data”: When you download and use a Mobile App we may collect certain information automatically, such as the type of mobile device you use, your unique device ID, the IP address of your mobile device, your mobile phone number, your mobile operating system, the type of mobile internet browsers you use, geolocation information and information about the way you use the Mobile App.

Performance & Log Data: Information created by your use of our Sites, Services, and Patron Services. For example: your IP address, browser type, operating system, command line information, diagnostic information related to the Sites (i.e. crash activity reports), the referring webpage, pages visited, date, your geolocation, your mobile carrier, your device and application IDs and search terms. Note that depending on the law of your country of residence, your IP address may legally be considered personally identifiable information.

Cookies: A cookie is a small amount of data generated by a website and saved by your web browser. Its purpose is to remember information about you, similar to a preference file created by a software application. In some cases, Cookies and similar automated data collection technologies may be used to collect personal information, or information that becomes personal information if we combine it with other information.

Other Data: Any other information that an individual provides to us. For example: survey responses, blog comments, or other communications submitted to SalonBiz.

COLLECTION AND PROCESSING:

We collect your Personal Data through our Sites, Services and Patron Services. Our Sites are public, any information that is disclosed on our Sites may appear on search engines, or other publicly available platforms and may be “crawled,” searched and used by unaffiliated third parties. Please do not post any information that you do not want to reveal publicly.

Providing the Services: We process your Personal Data when you sign up for and use our Services with a free or paid account. For example, we use your Contact Data, Profile Data, and Paid Account Data to configure your account and your user credentials, and to communicate with you as it relates to your use of the Services.  We use Patron Data, Appointment Data, Order & Invoice Data, and Transaction Data to enable Salons to utilize the Services and manage customer relationships and to enable Patrons to do business with Salons via the Services and Patron Services. We may share this Contact Data, Profile Data, Patron Data, Appointment Data, Order & Invoice Data, and Transaction Data with our service providers and partners to the extent necessary to provide you with the Services and Patron Services.

Qualification Diligence: We use Diligence Data collected via registration for a paid account to verify your identity, perform a credit check and qualify you to use SalonBiz’s paid Services. We may share this information with our service providers for them to utilize as part of the process of underwriting you for a payment processing merchant account.

Appointment, Order, and Invoice Processing: We use Patron Data, Appointment Data, and Order & Invoice Data to schedule appointments, and process orders and invoices on behalf of Salons, including those placed through the Patron Services. Patron Data, Appointment Data, and Order & Invoice Data may be used to communicate with a Patron on behalf of a Salon regarding an appointment, order, or invoice. 

Patron Transaction Processing: We use Patron Data and Transaction Data to process payments Patrons make to Salons via the Services and/or Patron Services. Transaction Data, including credit card and bank account information, is transmitted to our integrated third-party payment processors. Salons or Patrons may request that payment account information be vaulted by the third-party payment processors for use in future transactions. These service providers are contractually required to maintain compliance with the PCI DSS for storage, processing, and transmission of cardholder data and to adhere to all NACHA rules for ACH payment processing.

Payment Processing: We use Salon Billing Data to collect fees associated with the Services as applicable. We use vaulted credit card and bank account numbers to process authorized one-time transactions and to automatically process payments as part of recurring subscription payment schedules.

Customer Service: When you contact us through the Sites or Services, including submitting a “contact us” or other online inquiry form, subscribing to the Services, submitting a review, contacting customer support team, utilizing the chat function on our Sites, submitting questions, answers, or comments on a an Answer Board, subscribing to a newsletter or blog, entering a contest, registering for a demo or webinar, completing an online survey or any other means, we may record your Contact Data and your Support & Inquiry Data in our customer relationship management system and use your Personal Data to respond to you. If you provide a mobile phone number to us, you are explicitly granting us permission to send text messages to that number to respond to your request and to contact you at that number via an auto-dialer, which we may do at our discretion. 

Marketing: We may use your Personal Data including Contact Data and Support & Inquiry Data to keep you updated about our products and services and send you promotional material about SalonBiz and as permitted by applicable law, on behalf of our parent company, affiliates, subsidiaries, joint ventures, or other companies under common control with us (collectively, “Affiliates”) and partner companies. Promotional materials may include marketing communications, online surveys, notifications regarding our events and webinars and those of our Affiliates and partners. If you provide a mobile phone number to us, you are explicitly granting SalonBiz permission to send text messages, recorded messages, and/or use an auto-dialer to contact that number for marketing and promotional purposes, which we may do at our discretion. This consent is not a condition of purchasing SalonBiz Services. You may opt-out of our marketing communications at any time.

Patron Marketing: We may use a Patron’s Personal Data including Contact Data, Appointment Data, Order & Invoice Data, and Transaction Data, to send marketing communications on behalf of the Salon with which the Patron is associated.  Such marketing communications are sent solely at the direction of the Salon, and the Salon is wholly responsible for obtaining opt-in consent for marketing communications and is responsible for implementing opt-out programs as required by all applicable laws.   

Site Experience: We may use and Profile Data and Device Data to tailor your experience on the Sites, provide content that we think might be of interest, and to display content according to your stated preferences. 

Research & Development: We may use Cookies and Performance & Log Data, for functional purposes, to improve the performance and usability of our Sites, and to analyze how users interact with the Services and Direct Payment Services. 

Cookies & Similar Tech: When you access the Sites, Services or Patron Services or open one of our HTML emails, we may automatically record Performance & Log Data and Device Data, set Cookies, or use web beacons, pixel tags, click-stream tracking and similar automated data collection technologies. We use this Personal Data for essential and functional purposes including for site administration, to improve the performance and usability of the Sites, Services and Patron Services, and to analyze how users interact with the Sites, Services and Patron Services. On certain portions of our Sites, Services and Patron Services, we may collect Personal Data through these technologies for advertising, remarketing or other similar purposes. 

Security & Enforcement: We process your Personal Data to enhance the security of our Sites, Services and Patron Services and to combat spam, malware or other security risks. This may include monitoring your activities on our Sites, Services and Patron Services. Without processing your Personal Data for such purposes, we may not be able to ensure the security of our Sites, Services and Patron Services. We may also process Personal Data to monitor, investigate, prevent and mitigate any alleged or actual prohibited, illicit or illegal activities or violations of our services and agreements with you. We may use your Personal Data to enforce agreements with third parties and collect fees based on your use of our Services. 

Additional Processing: If we process Personal Data in connection with your use of the Sites, Services or Patron Services in a way not described in this Policy, this Policy will still apply generally (e.g. with respect to Your Rights and Choices) unless otherwise stated when you provide Personal Data. 

SHARING:

Information we collect may be shared with a variety of parties depending upon the purpose for and context in which that information was provided. In all cases where we share Personal Data with third parties, we will use a “minimum necessary” standard to disclose only that information required for satisfying the purpose of or performing the service for which the information is disclosed. We generally transfer Personal Data as follows:

Consent: We will share your Personal Data in accordance with your consent for us to do so. 

Salons: When Patrons make a purchase from or schedule an appointment with a Salon using our Patron Services, we may share Personal Data with that Salon except where that disclosure is prohibited by law, regulation or other obligations. 

Service Providers: In connection with our general business operations, to enable certain features, and in connection with our other legitimate business interests, we may share your Personal Data with service providers or sub-processors who provide certain services or process data on our behalf. Our contracts with these service providers dictate that they only use your information in connection with the services they perform for us and you consent to our sharing of information with these parties by using our Sites, Services or Patron Services subject to this Policy. 

Affiliates: In order to streamline certain business operations, develop products and services that better meet the interests and needs of our customers, and inform our customers about relevant products and services, we may share a Salon’s or Visitor’s Personal Data with any of our current or future affiliated entities, subsidiaries and parent companies (“Affiliates”). Salons and Visitors hereby agree to our sharing some or all of your information and Personal Data with our Affiliates. We never share Patron Data with Affiliates.

Third-Party Partners: When you complete an online inquiry form to which you were referred by a third-party partner, any information collected through the SalonBiz hosted online inquiry form may be shared with the referring third party partner. We may share your Personal Data with third parties for marketing or adverting purposes, as permitted by law. For example, when you sign up for a webinar co-hosted by us and a third-party partner, we may share your Personal Data with the third-party partner. Third party partners may use your Personal Data for their own purposes subject to their own privacy policies. 

Third-Party Integrated Services: SalonBiz provides the ability to integrate the Services with certain third-party payment processing, accounting and marketing services (“Integrated Services”). When a Salon establishes a connection with an Integrated Service, SalonBiz may share all data in your account with the Integrated Service including data regarding consumer and non-consumer customers and prospects and related Personal Data. Although SalonBiz facilitates the Integrated Services for Salons, SalonBiz does not control the policies or procedures of third parties providing the Integrated Service. Third party providers of Integrated Services may collect, use, and share data and personal information subject to their own policies and procedures. You should consult such third party’s terms and privacy policies for their use of your information. Salons acknowledge that the use of Integrated Service is at their own risk. Salons are responsible for ensuring that their use of Integrated Services is compliant with applicable laws. SalonBiz may provide Personal Data to Integrated Service providers for their marketing purposes, if you have not opted out of such disclosure.

Business Transactions: Your Personal Data may be processed in the event of a business transaction, such as a merger, acquisition, liquidation, or sale of all or a portion of our assets. For example, Personal Data may be disclosed (subject to confidentiality restrictions) during the due diligence process for a potential transaction or may part of the assets transferred, in such case the acquiring company will possess any rights granted to us under this Policy.

Legal Disclosures: In limited circumstances, we may, without notice to you or your consent, access and disclose your Personal Data, any communications sent or received by you, and any other information that we may have about you to the extent we believe such disclosure is legally required, to prevent or respond to a crime, to investigate violations of our Terms of Service or Patron Terms, or in the vital interests of us or any person or entity. Note, these disclosures may be made to governments that do not ensure the same degree of protection of your Personal Data as your home jurisdiction. We may, in our sole discretion (but without any obligation), object to the disclosure of your Personal Data to such parties. 

RETENTION:

We retain Personal Data for so long as necessary to service the purpose(s) for which your Personal Data was processed and for a reasonable time thereafter, or as necessary to comply with our legal obligations, to resolve disputes or enforce our agreements. While retention requirements can vary by jurisdiction, we generally apply the retention periods noted below:

Services Usage: We will retain Personal Data for as long as a Salon remains an active user of our Services and for a reasonable time thereafter, to serve the purpose(s) for which the Personal Data was processed. We may store any information about your activity on our Services, including Contact Data, Profile Data, Paid Account Data, Diligence Data, Appointment Data, Order & Invoice Data, Transaction Data, Billing Data, Support & Inquiry Data, and any Other Data created, posted or shared by you while using our free or paid Services for as long as we deem it necessary or until you provide specific instructions to delete it, which may be indefinitely, or where a valid business reason exists for such storage such as retaining a comprehensive transaction history, maintaining the integrity of our systems and logs or for the establishment or defense of legal claims, audit and crime prevention purposes.

Patron Data: We may store on behalf of Salons, for as long as a valid business reason exists, which may be indefinitely, any Personal Information collected about a Patron or other individual, whether entered directly into our systems by the Patron via our Patron Services, or whether entered by an authorized Salon via the Services.

Note that Salons control any consumer data we collect and process on their behalf, whether that Personal Data is entered by a consumer Patron via the Patron Services or whether it is entered by a Salon via the Services, and it is up to the Salon to determine how long they will store their customers’ Personal Information in our systems.

Billing: Our third-party service providers will store any Billing Data you provide to us for as long as you remain an active user of our Services and for a reasonable time thereafter. These service providers are contractually required to maintain compliance with the PCI DSS for storage, processing, and transmission of cardholder data and to adhere to all NACHA rules for ACH payment processing.

Site Activity: We may store any information about your activity on our Sites or any Other Data created, posted or shared by you on our Sites for as long as we deem it necessary or until you provide specific instructions to delete it, which may be indefinitely, or where a valid business reason exists for such storage such as maintaining the integrity of our systems and logs or for the establishment or defense of legal claims, audit and crime prevention purposes.

Marketing: We store information used for marketing purposes indefinitely until you unsubscribe or provide specific instructions to delete it. When you unsubscribe from marketing communications, we add your contact information to our suppression list to ensure we respect your unsubscribe request.

Cookie Data: We retain any information collected via cookies, clear gifs, flash cookies, webpage counters and other technical or analytics tools up to one year from the expiry of the cookie or date of collection. Cookies owned by third parties may have other retention periods. 

YOUR RIGHTS AND CHOICES:

Rights:

Salons and Visitors with whom SalonBiz has a data controller relationship have the following rights in relation to your Personal Data, in each case to the extent required/permitted under applicable law, and subject to our rights to limit or deny access or disclosure under applicable law.  

Patrons and other consumers who do business with Salons utilizing SalonBiz Services must contact the Salon(s) utilizing SalonBiz Services or Patron Services to exercise these rights. Patrons can request that the Salon provide you with access to the Personal Data SalonBiz stores on its behalf, that it make changes to that Personal Data, and/or that the Personal Data be deleted from SalonBiz systems. SalonBiz cannot honor such requests directly from Patrons but will assist Salons with honoring them.

Access: Salons and Visitors with whom SalonBiz has a data controller relationship, may request a list of your Personal Data that we process by submitting an official request in writing via email to address provided below. 

Rectification: Salons and Visitors with whom SalonBiz has a data controller relationship may correct any Personal Data that we hold about you by emailing us at the address provided below and indicating both the inaccurate and corrected information. Salons may also login to your SalonBiz user account and modify your Personal Data.

Erasure: Salons and Visitors with whom SalonBiz has a data controller relationship may request that we delete your Personal Data from our systems once per year by making an official request in writing via email to the address provided below and indicating the specific information you would like permanently deleted from our systems. Note that Salons who request removal of their Personal Data will no longer have access to any existing SalonBiz account and will not be able to use any SalonBiz product or service. SalonBiz reserves the right to retain certain account information for its recordkeeping or compliance purposes. 

Salons may also login to their SalonBiz user account and delete any Profile Data, Contact Data or Patron Data to which they have access. However to ensure that Personal Data is completely removed from our systems, you must submit an official request in writing to SalonBiz at the address provided below, as using a system delete function may merely restrict viewing that data from any system interface and prevent utilizing that data for any system function rather than permanently deleting it.

Data Export: Salons and Visitors may request a copy of your Personal Data in a common portable format of our choice by submitting an official request in writing via email to the address provided below.

We may require that you provide additional Personal Data to exercise these rights, e.g. information necessary to prove your identity. We also reserve the right to retain this additional information for our recordkeeping or compliance purposes.

Choices:

It is possible for you to access and use the Sites without providing any Personal Data, but you may not be able to access certain features or view certain content and some portions of the Sites may not function properly.  You must provide Personal Data in order to utilize the Services and Patron Services. You have the following choices regarding Personal Data we process: 

Consent: If you consent to processing you may withdraw your consent at any time to the extent required by law. 

Cancellation: Salons may cancel their SalonBiz accounts, per the Terms of Service and any individual SalonBiz contract, by contacting us using the contact information provided below.

Opt-Out: You may opt-out of all information collection from your mobile device by uninstalling the Mobile App. You may use the standard uninstall processes as may be available as part of your mobile device or via the mobile application marketplace or network.

You may opt-out of receiving marketing communications from us by following the opt-out instructions included in such communications. Any communications from us that are not service-related or transactional in nature will offer you an “unsubscribe” option. To the extent required by law, you may choose to opt-out of sharing Personal Data with third parties. 

Cookies: If you do not want information collected through the use of cookies or similar technologies, you can manage/deny cookies (and certain technologies) using your browser’s settings menu or by using a variety of tools. 

  • • You can visit the Google Ads Settings page here.
  • • You can use the Google Analytics Opt Out Browser add on.
  • • Digital Advertising Alliance’s opt-out page here allows you to opt out from receiving third party advertiser cookies. 
  • • You can visit the Network Advertising Initiative opt-out page here.
  • • You can control Facebook’s use of interest-based ads through your Facebook account settings or can visit the customer support page here. 
  • • To learn more about cookies and similar tracking technologies, and how they can affect your privacy, visit allaboutcookies.org. 

As there is no consistent industry understanding of how to respond to “Do Not Track” signals, we do not alter our data collection and usage practices when we detect such a signal from your browser. 

CALIFORNIA PRIVACY RIGHTS:

This section only applies to Salon and Visitor users of our Sites, Services and Patron Services, with which we have a data controller relationship and that are residents of the State of California at the time of data collection. Rights in this section are in addition to the rights set forth above. California residents have certain additional rights subject to the California Consumer Privacy Act of 2018 (“CCPA”).  Any residents of the State of California with whom SalonBiz has a data processor relationship (Patrons) must contact the Salon(s) utilizing SalonBiz Services or Patron Services to exercise these rights. SalonBiz cannot honor such requests directly from Patrons or other consumers but will assist Salons with honoring them.

Consumer Information collected through the Sites, Services and Patron Services is collected for our use and/or the use of the Salon identified at the collection point and is not transferred to any third party for valuable consideration. However, if you are a California resident, you may send us specific instructions not to sell your personal information now or in the future. Such requests can be made via phone, email or in writing to the contact information provided below.

Access: You may request a list of your Personal Data that we process by submitting an official request in writing via email to address provided below. 

Rectification: You may correct any Personal Data that we hold about you by emailing us at the address provided below and indicating both the inaccurate and corrected information. Salons may also make changes to Personal Data by logging into your SalonBiz account.

Erasure: You may request that we delete your Personal Data from our systems that: is no longer necessary in relation to the purposes for which it was collected or otherwise processed; was collected in relation to processing that you previously consented to but later withdrew such consent; or was collected in relation to processing activities to which you object and there are no overriding legitimate grounds for our processing. 

Data Export: You may request a copy of your Personal Data in a common portable format of our choice by submitting an official request in writing via email to the address provided below.

Third Parties: California law provides you have the right to receive the following information: the categories of information we disclosed to third parties for the third parties’ direct marketing purposes during the preceding calendar year; and the names and addresses of third parties that received such information or, if the nature of their business cannot be determined from the name, examples of the products or services marketed. You are entitled to receive a copy of this information in a standardized format and the information will not be specific to you individually. You may make this request by emailing us at the address provided below.

California residents have the right to exercise the privacy rights in this section twice within any 12-month period under the CCPA by contacting SalonBiz at the contact information provided below. California residents may exercise these rights via an authorized agent who meets the agency requirements of the CCPA. Any request subject to CCPA is subject to an identification and residency verification process. We will not fulfill any CCPA request unless we have received sufficient information for us to verify the requestor is properly authorized to make such request and the request provides sufficient detail for us to properly understand, evaluate and respond.

We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA: we will not deny you goods or services; charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties; provide you a different level or quality of good or services; or suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services. 

SECURITY:

SalonBiz has security measures in place designed to protect against the loss, misuse and alteration of the information under our control.  We protect your Personal Information by maintaining physical, technical and procedural safeguards to protect the confidentiality and security of your Personal Information. Such safeguards include use of secured socket layers (“SSL”), firewalls, data encryption, enforcing physical access controls to our buildings and files, and limiting access to Personal Information only to those employees, agents or third parties who need to know that information in order to process it for us. We do not directly store, process, or transmit cardholder data or bank account information, we integrate with third party service providers for those functions.  Where a third party stores, processes or transmits cardholder data, it is contractually required to maintain industry-standard security controls and maintain Payment Card Industry (PCI DSS) Compliance as a Level 1 Service provider; where a third party stores, processes, or transmits bank account information for ACH processing, it is contractually required to adhere to all NACHA rules for ACH payment processing; however, we do have control over and will not be liable for third parties’ security processes.

You are also responsible for keeping your Personal Information confidential and secure. You should choose a password that is complex (e.g., special characters and numbers, sufficient length, etc.) and keep your password confidential. Do not leave your device unlocked so that other individuals may access your device or account. SalonBiz is not in control of your Internet or wireless connection or the devices you use to log into and/or access the Services/Patron Services, so you should make sure you trust the devices and connections you use for access. Any transmission of Personal Information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Sites or the Services/Patron Services.  If you believe that you have experienced unauthorized access or use of your account, please contact us immediately at [email protected].

MINORS:

Our services are neither directed at nor intended for direct use by individuals under the age of 18 or the age of majority in the jurisdiction where they reside. Further we do not intentionally gather information about such individuals. If we learn that we have inadvertently done so, we will promptly delete it. Do not access or use the Sites, Services, or Direct Payment Services if you are not the age of majority in your jurisdiction unless you have the consent of your parent or guardian.

INTERNATIONAL TRANSFERS:

SalonBiz operates in the United States. If you are accessing the Sites, Services, or Patron Services from outside the United States, your Personal Data may be transferred to, stored, or processed in the United States and maintained on computers or servers located outside of your state, province, country, or other governmental jurisdiction where the privacy laws may not be as protective those in your jurisdiction. Some information may also be stored locally on devices you use to interact with our Sites, Services or Patron Services. By accessing our Sites, Services, and Patron Services, you understand and consent to the transfer of your information to the United States and to those third parties with whom we share it as described in this Policy. If you do not want your information transferred to or processed or maintained outside of the country or jurisdiction where you are located, you should not use our Sites, Services, or Direct Payment Services.

Please note, SalonBiz acts as a data processor on behalf of its Salons and Salons are responsible for obtaining your consent relating to the collection, use, transfer and other processing of your Personal Data. Salons may provide additional notices to you providing additional limitations or permissions with respect to our processing of your Personal Data in order to comply with applicable law.

CONTACT INFORMATION:

SalonBiz, Inc.

3601 Walnut St. Unit 400

Denver, CO 80205

Email: [email protected]

Phone: 1.888.809.2802