Account and authentication
Email, display name, user identifier, sign-in sessions, role, language choice, recovery requests and account-protection events.
This policy applies to the Sổ Tiệm website, application, booking pages, QR check-in, income-verification links and support channels. The operator’s legal name and address have not been confirmed; see Contact or email info@sotiem.com while this document remains a draft.
Email, display name, user identifier, sign-in sessions, role, language choice, recovery requests and account-protection events.
Salon name and settings, ownership, memberships, technician profiles, services, working hours, turn status and change history.
Name, phone, email, notes entered by the customer or salon, services, selected technician, time, booking status, check-in and contact-consent choices.
Services, prices, tips, technician shares, payout records, adjustments, reasons, expenses, mileage, receipts and OCR results. Do not enter card numbers, SIN/SSNs or full tax identifiers in Sổ Tiệm.
Private customers, services, appointments, tickets, expenses, mileage, receipts and independent-business records belonging to the Studio operator.
Support-case content, privacy requests, feedback, minimal diagnostics, error logs, synchronization events and notification history.
Plan, subscription state, Stripe customer and subscription identifiers, billing period and payment events. Stripe receives and processes card information on Stripe-hosted pages; Sổ Tiệm does not receive full card numbers.
The browser may store preferences, sign-in sessions, PWA cache and queued offline operations in local storage or IndexedDB. Pending data can remain on the device until it synchronizes or is cleared.
We use data to authenticate users; operate salon and Studio workspaces; record tickets, turns, hours and payouts; provide booking, check-in, import, export, optional OCR suggestions and verification links; send enabled notifications; administer subscriptions; prevent fraud and cross-tenant access; recover data; answer support requests; and improve reliability.
Sổ Tiệm has minimal first-party product events stored in the application infrastructure. Users can turn this choice off in the app. Events are designed not to contain customer names, ticket contents or financial amounts. The current repository does not integrate an advertising network or third-party advertising tracker.
Sổ Tiệm does not sell a salon's customer list or use that list to advertise another business.
Providers may process data outside the user’s country. Exact primary storage location, transfer mechanism and applicable legal terms require owner confirmation before this policy is finalized.
The application keeps data while the account or record is needed to provide the service, preserve audit history and handle requests. Some queue and customer retention settings can be configured by the salon owner. Default periods, backup retention and legal exceptions have not been confirmed, so this draft does not promise a fixed duration.
Every account, including Free, can download one portable JSON file containing its permitted account data, owned salons, technician history and private Studio records. Users can also correct editable information or create an export, correction, restriction or deletion request in Settings. Customer deletion may anonymize identity while preserving ticket and financial-history integrity. Cancelling a paid plan does not automatically delete records. Backup copies may expire only through the backup cycle once retention decisions are confirmed.
Sổ Tiệm uses authentication sessions and browser storage needed for sign-in, preferences, PWA cache and offline synchronization. No advertising cookie is confirmed in the current repository. Booking-management and verification links use unpredictable tokens with expiration or revocation depending on the link type; users should not forward them to unauthorized people.
Sổ Tiệm uses HTTPS in transit, Supabase Auth, tenant separation, Row Level Security, server-side authorization, hashed tokens for certain public links and audit history for important actions. Migration procedures include backup and restore checks. No system is perfectly secure; report concerns through the Security instructions.
Sổ Tiệm is a business operations tool and is not designed for children. The minimum account age and child-data process require a legal decision before the final policy is published.
We will update the date and provide appropriate notice when this draft or policy changes materially. While legal decisions remain pending, send questions, data requests or privacy reports to info@sotiem.com or use the in-app privacy-request flow.