Privacy Policy
This Privacy Policy explains how Tech Nova AI (“we”, “us”, “our”) collects, uses, shares, and protects personal information when you use Salonfy (the “Service”).
Service
Company
Tech Nova AI
Address
Address available upon request.
Contact
Last Updated
2025-12-24
Important: This template is a practical, detailed baseline, but laws vary by country and business model.
If you operate in the UK/EU (GDPR/UK GDPR) or process payments (Stripe), you should still have a qualified legal review for full certainty.
1) Who We Are
Tech Nova AI provides Salonfy, a multi-tenant platform where each business (“Tenant”) may operate its own site and manage its own customers (“End Users”).
In many cases, the Tenant is the “data controller” for End User information collected on the Tenant’s site, and we act as a “processor” (or service provider) for the Tenant. For information about how a specific Tenant uses your data, please refer to that Tenant’s privacy policy and contact details.
2) Information We Collect
2.1 Information you provide
- Account information: name, email, phone number, password (stored securely as a hash), and profile details.
- Business/Tenant details: business name, address, branding, staff profiles (if provided), and configuration settings.
- Customer/End User data entered by Tenants: appointments, notes, contact details, preferences, and other data the Tenant chooses to store.
- Communications: messages you send to us (support requests, feedback).
2.2 Information collected automatically
- Usage data: pages/screens viewed, actions taken, timestamps, and referring/exit pages.
- Device data: browser type, operating system, language, and approximate location (derived from IP).
- Log data: IP address, event logs, and error diagnostics (see “Logs & Security”).
- Cookies: small files stored on your device (see “Cookies”).
2.3 Payment information
We use Stripe for payment processing. We do not store full card numbers. Stripe may process payment identifiers, billing details, and transaction data (see “Payments (Stripe)”).
3) How We Use Information
We use information to:
- Provide, operate, and maintain the Service (authentication, tenant management, customer management, scheduling features).
- Process payments and prevent fraud.
- Provide customer support and respond to requests.
- Monitor, troubleshoot, and improve performance and reliability.
- Secure the Service and protect against abuse.
- Comply with legal obligations.
4) Legal Bases (UK/EU)
If UK GDPR / EU GDPR applies, we rely on the following legal bases depending on the context:
- Contract: to provide the Service you request.
- Legitimate interests: to secure and improve the Service, prevent fraud, and administer the platform.
- Consent: where required (e.g., some cookies, certain marketing emails depending on law and settings).
- Legal obligation: for compliance, accounting, and lawful requests.
5) How We Share Information
We may share information with:
- Service providers: hosting, analytics, monitoring, email delivery, and payment providers (including Stripe).
- Tenants: if you are an End User interacting with a Tenant site, your information is visible to that Tenant.
- Legal and safety: to comply with law, protect rights, investigate fraud, or enforce agreements.
- Business transfers: in connection with a merger, acquisition, or sale of assets (with appropriate protections).
We do not sell your personal information.
6) Payments (Stripe)
Payments are processed by Stripe. When you pay, Stripe receives and processes your payment information in accordance with Stripe’s policies.
We typically receive limited payment-related data such as payment status, amount, currency, and payment identifiers.
- What we store: transaction references, subscription status (if applicable), and payment outcomes.
- What we do not store: full card numbers or CVV.
- Why: to provide the Service, manage subscriptions, handle refunds (if applicable), and prevent fraud.
7) Email Marketing (Tenant Marketing)
Some Tenants may use the Service to send marketing emails or messages to their own customers (“End Users”).
In that case:
- The Tenant is typically responsible for obtaining any required consents and providing opt-out mechanisms required by law.
- We provide the technical tools to enable email delivery and list management on behalf of the Tenant.
- If you receive marketing from a Tenant and want to stop it, use the unsubscribe link (if provided) or contact the Tenant directly.
If you are a Tenant, you are responsible for your own marketing compliance (e.g., consent, lawful basis, unsubscribe, and content rules) for messages you send to End Users.
8) Logs & Security
We collect logs and technical data to maintain security, prevent fraud, and diagnose issues. This can include:
- IP address, date/time, pages/endpoints accessed, device/browser information.
- Authentication events (login success/failure), rate-limit/security events.
- Error logs and diagnostic information.
We use reasonable administrative, technical, and organizational measures to protect personal data. However, no online service can be 100% secure.
9) Data Retention
We keep personal information only as long as necessary for the purposes described in this policy, including to provide the Service, comply with legal obligations,
resolve disputes, and enforce agreements.
Typical retention approach (example)
- Account data: retained while the account is active.
- Tenant/End User records: retained while the Tenant is active, and deleted or anonymized after account closure, unless legally required to retain.
- Logs/security records: retained for a limited period necessary for security and troubleshooting.
- Billing records: retained as required by tax/accounting laws.
Note: If you are an End User of a Tenant, the Tenant may define different retention periods. Contact the Tenant for details.
10) Your Rights & Choices
Depending on your location, you may have rights regarding your personal information, including:
- Access to your data
- Correction of inaccurate data
- Deletion (see “Account Deletion”)
- Restriction or objection to certain processing
- Data portability
- Withdraw consent where processing is based on consent
To exercise rights, contact us at privacy@Salonfy.uk.
If you are an End User of a Tenant, you may also need to contact the Tenant directly.
11) Account Deletion
You can request deletion of your account. When deletion is completed, we will remove or anonymize your personal information,
unless we must keep certain information for legal, security, or legitimate business purposes (e.g., fraud prevention and accounting records).
If you are a Tenant, deleting your Tenant account may also delete associated End User records you manage within the platform, subject to retention obligations.
12) Cookies
We use cookies and similar technologies to:
- Keep you signed in (authentication cookies)
- Remember preferences
- Improve security and performance
You can control cookies through your browser settings. Disabling certain cookies may affect site functionality.
13) Children
The Service is not intended for children under 13. If you believe a child has provided personal information,
contact us at privacy@Salonfy.uk.
14) International Transfers
Your information may be processed in countries other than where you live, including where our service providers operate.
Where required, we use appropriate safeguards for international transfers.
15) Changes to This Privacy Policy
We may update this policy from time to time. We will update the “Last Updated” date above.
Material changes may be communicated through the Service or by other appropriate means.