Privacy Policy

Effective date: January 1, 2026
Last updated: June 26, 2026
Version: 2.1

Plain-English Summary: LuxeGlamour POS collects information you provide to us and data generated by your use of our platform. We use it to operate the service, process payments, and improve your experience. We do not sell your personal data. We share it only with service providers necessary to run the platform (like Stripe for payments and Twilio for SMS). You have the right to access, correct, or delete your data at any time.

This Privacy Policy describes how [LEGAL ENTITY NAME], a general partnership doing business as LuxeGlamour POS ("LuxeGlamour," "we," "us," or "our") collects, uses, and discloses information about you when you use our software platform, website, mobile applications, and related services (collectively, the "Services"). By accessing or using our Services, you agree to the practices described in this policy.

This policy applies to:

  • Business Customers — salons, spas, barbershops, studios, and other beauty businesses that subscribe to LuxeGlamour POS.
  • End Clients — the customers of those beauty businesses who book appointments, receive services, or interact with a LuxeGlamour POS-powered booking page.
  • Staff Members — employees, contractors, and booth renters who access LuxeGlamour POS on behalf of a business customer.
  • Visitors — anyone who visits our marketing website or landing pages.

1 Who We Are

[LEGAL ENTITY NAME], a general partnership doing business as LuxeGlamour POS is the data controller responsible for your personal information collected through our platform and website. We operate primarily in the United States.

Our platform serves beauty industry businesses (salons, spas, barbershops, nail studios, med spas, makeup artists, and similar establishments) and provides them with tools to manage appointments, process payments, manage staff, track inventory, and engage clients.

For privacy inquiries, please contact our Privacy Team at privacy@luxeglamourpos.com.

2 Information We Collect

2.1 Information You Provide Directly

We collect information you voluntarily provide when you:

  • Create an account: business name, email address, password (stored hashed, never plaintext), phone number, business address, tax ID, and billing information.
  • Set up your business profile: business hours, service menu, staff profiles, custom booking URL, social media links, and uploaded photos.
  • Add clients: client names, email addresses, phone numbers, birthdays, allergy information, appointment notes, and payment preferences.
  • Process transactions: service details, product details, payment method type, tip amounts, and discount/promo code usage.
  • Communicate with us: name, email, and message content when you contact our support team.
  • Book an appointment (end clients): name, email address, phone number, and selected service/staff/time preferences.

2.2 Information Collected Automatically

When you use our Services, we automatically collect:

  • Log data: IP address, browser type, browser version, pages visited, time and date of visits, time spent on pages, and referring URLs.
  • Device information: device type (desktop, tablet, mobile), operating system, and unique device identifiers.
  • Usage data: features used, buttons clicked, actions taken within the platform, and session duration.
  • Cookies and similar technologies: session cookies for authentication, preference cookies, and analytics cookies (see Section 7).

2.3 Information from Third Parties

We may receive information about you from:

  • Stripe: payment confirmation data, card brand, last four digits of card, and expiry date (we never receive or store full card numbers).
  • Twilio: SMS delivery status and error logs for appointment reminders.
  • Resend / Email providers: email open and delivery status.
  • Review platforms (Google, Yelp): review submission status when clients follow our review request links.
CategoryExamplesRequired?
IdentityName, username, email, phoneYes
Business ProfileBusiness name, address, hours, tax IDYes
FinancialSubscription billing info, payout bank detailsYes (for billing)
Client RecordsClient names, contact info, allergies, visit historyEntered by you
Transaction DataServices rendered, products sold, payment amountsGenerated by use
TechnicalIP address, device info, cookiesAutomatic
CommunicationsSupport emails, feedbackWhen you contact us

3 How We Use Your Information

We use the information we collect to:

3.1 Provide and Operate the Services

  • Create and manage your account and business profile
  • Process appointments, transactions, and payments
  • Send appointment confirmation and reminder notifications (SMS/email)
  • Generate reports and analytics for your business
  • Enable staff logins, time tracking, and permissions
  • Display your public booking page to prospective clients

3.2 Billing and Subscriptions

  • Process subscription payments and renewals
  • Manage billing cycles, plan upgrades, and cancellations
  • Send invoices, receipts, and billing notifications

3.3 Customer Support

  • Respond to your support requests and questions
  • Troubleshoot technical issues with your account
  • Provide onboarding and training assistance

3.4 Security and Fraud Prevention

  • Detect, investigate, and prevent fraudulent transactions and account abuse
  • Enforce our Terms of Service and acceptable use policies
  • Authenticate users and protect account security

3.5 Service Improvement

  • Analyze aggregate usage trends to improve product features
  • Conduct internal research and product development
  • Monitor platform performance and fix bugs

3.6 Communications

  • Send transactional emails (password resets, billing alerts, account notices)
  • Send product update announcements and new feature releases
  • Send marketing emails if you have opted in (you can opt out at any time)

3.7 Legal Compliance

  • Comply with applicable laws, regulations, and legal processes
  • Respond to lawful government or regulatory requests
  • Establish, exercise, or defend legal claims

Legal Basis (for GDPR users): We process your personal data under the legal bases of contractual necessity (to provide the service), legitimate interests (to improve the platform and prevent fraud), legal obligation (to comply with applicable laws), and consent (for optional marketing communications).

4 How We Share Your Information

We do not sell your personal information. We share your information only as described below:

4.1 Service Providers

We share information with vendors and third-party service providers that perform services on our behalf, bound by confidentiality obligations:

ProviderPurposeData Shared
StripePayment processing, card-on-file, Connect payoutsBilling info, payment amounts, business identity
TwilioSMS appointment remindersClient phone numbers, message content
ResendTransactional email deliveryEmail addresses, email content
Vercel / Cloud HostPlatform hosting and infrastructureAll platform data (encrypted at rest)
Neon / PostgreSQLDatabase storageAll structured platform data
Analytics ProviderProduct usage analyticsAnonymized/aggregated usage events

4.2 Business Customers and Their Clients

If you are an end client who has booked an appointment through a LuxeGlamour POS-powered booking page, your information (name, contact details, appointment history) is accessible to that business. LuxeGlamour POS operates as a data processor on behalf of that business, which is the data controller for your information in this context.

4.3 Legal Requirements

We may disclose your information if we believe in good faith that disclosure is necessary to:

  • Comply with applicable laws, regulations, court orders, or legal processes
  • Respond to requests from government or law enforcement authorities
  • Protect the rights, property, or safety of LuxeGlamour POS, our users, or the public
  • Detect, prevent, or address fraud, security, or technical issues

4.4 Business Transfers

If LuxeGlamour POS is involved in a merger, acquisition, asset sale, or bankruptcy, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our website before your information becomes subject to a different privacy policy. (See also Section 14.)

4.5 With Your Consent

We may share your information with other parties when you direct us to or give us explicit consent to do so.

5 Data Retention

We retain your personal information for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law.

Data TypeRetention Period
Account and business profile dataDuration of your subscription + 90 days after cancellation
Client records you createDuration of your subscription + 90 days
Transaction records7 years (for tax/legal compliance)
Appointment history5 years
Log and security data12 months
Billing records7 years
Support communications3 years
Marketing email preferencesUntil you opt out or request deletion

After the applicable retention period, we will securely delete or anonymize your information. You may request earlier deletion of certain data (subject to legal retention obligations) by contacting us at privacy@luxeglamourpos.com.

6 Security

We implement industry-standard security measures to protect your personal information:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (HTTPS).
  • Encryption at rest: Data stored in our databases is encrypted at rest.
  • Password hashing: Passwords are hashed using bcryptjs and never stored in plaintext.
  • Access controls: Role-based permissions limit staff access to only the data their role requires.
  • Multi-tenant isolation: Each business's data is logically isolated from all other businesses.
  • PCI compliance: We do not store raw card numbers. All payment card data is tokenized and handled by Stripe, a PCI DSS Level 1 certified provider.
  • Regular security reviews: We conduct periodic security assessments and vulnerability testing.

Security Incident Notification: In the event of a data breach that affects your personal information, we will notify you and applicable regulatory authorities within 72 hours of becoming aware of the breach, as required by applicable law.

While we use commercially reasonable measures to protect your information, no security system is impenetrable. We cannot guarantee the absolute security of your information. You are responsible for keeping your account credentials confidential.

7 Cookies & Tracking Technologies

We use cookies and similar technologies to operate and improve our Services:

7.1 Types of Cookies We Use

Cookie TypePurposeDuration
Essential / SessionRequired for authentication and keeping you logged in. Cannot be disabled without breaking core functionality.Session / 30 days
PreferenceRemember your settings and preferences (e.g., timezone, language).1 year
AnalyticsUnderstand how you use the platform so we can improve features. Data is aggregated and anonymized where possible.Up to 2 years
MarketingUsed only on our marketing website to measure ad effectiveness. Not used inside the platform.Up to 90 days

7.2 Managing Cookies

You can manage or disable cookies through your browser settings. Please note that disabling essential cookies will prevent you from logging in and using the platform. For details on how to manage cookies in your browser, visit allaboutcookies.org.

We do not currently respond to browser Do Not Track (DNT) signals, as no uniform standard for DNT has been adopted.

8 Third-Party Services & Links

Our Services may contain links to third-party websites, services, or integrations (such as Google, Yelp, Instagram, or Stripe's onboarding portal). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through our platform.

When you connect a third-party integration (e.g., link your Google Business Profile for reviews), you authorize that third party to share information with us in accordance with their own privacy policy and your relationship with them.

9 Payment Data

We do not store card numbers. LuxeGlamour POS does not store, process, or transmit full payment card numbers. Card details go directly to our payment processors, which tokenize them. We receive only a token, the card brand, the last four digits, and the expiry date — never a complete card number, CVV, or magnetic stripe data.

Payment processing is handled by Stripe, Inc. and, where a business selects it, Block, Inc. (Square). Both are certified PCI DSS Level 1, the highest level defined by the payment card industry. That certification is the processor's, not ours — our role is to avoid handling card data in the first place. When you or your clients enter payment information:

  • Card data is transmitted directly to the processor over an encrypted connection
  • We never receive, transmit, or store full credit card numbers, CVV codes, or unmasked card data
  • We receive only a tokenized reference, the card brand (e.g., Visa, Mastercard), last four digits, and expiry date
  • Charges are processed under the processor's own privacy policy — stripe.com/privacy and squareup.com/legal/privacy

Cards kept on file

Where a business enables card-on-file for deposits or no-show fees, the card is stored as a token held by the processor, not as a card number held by us. The business that collected it is responsible for having obtained its client's authorization to store and later charge it.

Who the merchant is

Each business processes payments through its own connected processor account and is the merchant of record for those transactions. We are not a party to them and do not hold funds. Booth renters who connect their own Stripe Express accounts manage their processing independently; LuxeGlamour POS facilitates the connection only.

10 Your Rights & Choices

Depending on your location and applicable law, you may have the following rights regarding your personal information:

10.1 Access

You have the right to request a copy of the personal information we hold about you.

10.2 Correction

You have the right to request that we correct inaccurate or incomplete personal information. You can update most information directly within your LuxeGlamour POS account settings.

10.3 Deletion

You have the right to request that we delete your personal information. We will honor deletion requests subject to our legal obligations to retain certain data (e.g., transaction records for tax purposes).

10.4 Data Portability

You have the right to receive a copy of your data in a structured, commonly used, machine-readable format (e.g., CSV or JSON) so you can transfer it to another service.

10.5 Opt-Out of Marketing

You can opt out of marketing emails at any time by clicking the "Unsubscribe" link in any marketing email or by emailing us at privacy@luxeglamourpos.com. You will continue to receive transactional emails (such as billing notices and security alerts) even if you opt out of marketing.

10.6 Withdraw Consent

Where we process your data based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal.

10.7 Restriction and Objection

In certain circumstances, you may have the right to restrict or object to our processing of your personal information.

10.8 How to Exercise Your Rights

To exercise any of these rights, contact us at privacy@luxeglamourpos.com with the subject line "Privacy Rights Request." We will respond within 30 days (or 45 days where permitted by applicable law). We may need to verify your identity before fulfilling your request.

If you are an end client of a beauty business that uses LuxeGlamour POS, please contact that business directly regarding your personal information — they are the data controller for your records.

11 Children's Privacy

Our Services are not directed to children under the age of 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately at privacy@luxeglamourpos.com and we will delete it promptly.

Business customers are responsible for ensuring that client information they enter into LuxeGlamour POS for minors complies with applicable children's privacy laws, including COPPA (in the United States) and any applicable parental consent requirements.

12 California Residents — CCPA / CPRA Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

12.1 Right to Know

You have the right to know what personal information we collect, use, disclose, and sell (we do not sell personal information). You may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.

12.2 Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions permitted by law.

12.3 Right to Correct

You have the right to request correction of inaccurate personal information.

12.4 Right to Opt Out of Sale or Sharing

We do not sell or share your personal information for cross-context behavioral advertising. Therefore, there is nothing to opt out of in this regard.

12.5 Right to Limit Use of Sensitive Personal Information

To the extent we collect sensitive personal information (such as financial account information for billing), we use it only to provide the Services and as permitted by the CPRA.

12.6 Non-Discrimination

We will not discriminate against you for exercising your privacy rights — we will not deny you services, charge different prices, or provide a different quality of service because you exercised a CCPA/CPRA right.

12.7 How to Submit a California Privacy Request

Submit requests by emailing privacy@luxeglamourpos.com with the subject line "California Privacy Request." You may also designate an authorized agent to make a request on your behalf. We will verify your identity and respond within 45 days.

12.8 Categories of Personal Information Collected (Past 12 Months)

CCPA CategoryCollected?Sold?
Identifiers (name, email, IP)YesNo
Commercial information (transactions)YesNo
Financial information (payment card type)YesNo
Internet/network activity (usage data)YesNo
Geolocation data (business address)YesNo
Professional/employment info (staff roles)YesNo
Inferences from personal infoYes (analytics)No
Biometric dataNoNo
Health/medical informationNoNo

13 International Users — GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or equivalent legislation.

13.1 Data Controller

[LEGAL ENTITY NAME] is the data controller for personal information processed through our platform and website. For client data entered by a beauty business, that business is the data controller and LuxeGlamour POS is a data processor acting on their behalf.

13.2 Legal Bases for Processing

  • Contract performance: Processing necessary to provide the Services you subscribed to.
  • Legitimate interests: Fraud prevention, platform security, and product improvement.
  • Legal obligation: Compliance with applicable laws (e.g., financial record-keeping).
  • Consent: Marketing communications (opt-in, revocable at any time).

13.3 International Data Transfers

Our Services are hosted and operated in the United States. If you are located outside the U.S., your information will be transferred to and processed in the U.S. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers of personal data from the EEA to the U.S.

13.4 Your GDPR Rights

Under GDPR, you have the right to: access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and objection to processing. You also have the right to lodge a complaint with your local data protection authority.

13.5 Data Protection Officer

You may contact our data protection team at dpo@luxeglamourpos.com.

14 Business Transfers

If [LEGAL ENTITY NAME] is acquired by, merges with, or transfers its assets to another company, your personal information may be one of the assets transferred. In such an event:

  • We will notify you at least 30 days in advance via email and/or prominent notice on our website.
  • You will have the opportunity to delete your account and data before the transfer takes effect.
  • Any successor entity will be bound by the terms of this Privacy Policy or will provide you with a new privacy policy and an opportunity to opt out.

15 Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other business reasons. When we make material changes:

  • We will update the "Last updated" date at the top of this page.
  • We will notify active account holders via email at least 14 days before material changes take effect.
  • For significant changes, we may also display a notice within the LuxeGlamour POS platform.

Your continued use of the Services after the effective date of any updates constitutes your acceptance of the revised policy. We encourage you to review this policy periodically.

Previous versions of this policy are available upon request by emailing privacy@luxeglamourpos.com.

16 Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your personal information, please reach out:

📧

Email — Privacy Team

For privacy requests, data deletion, and general privacy questions:
privacy@luxeglamourpos.com

⚖️

Data Protection Officer (DPO)

For GDPR-related inquiries and complaints:
dpo@luxeglamourpos.com

📬

Mailing Address

[LEGAL ENTITY NAME]
Attn: Privacy Team
United States

💬

Support

For account or platform issues:
info@luxeglamourpos.com or our contact form — we reply within one business day.

We aim to respond to all privacy-related requests within 30 days. For complex requests, we may extend this period by an additional 60 days and will inform you of any extension.