PRIVACY

Draft Privacy Policy

1. Scope and responsible operator

This policy applies to the Sổ Tiệm website, application, booking pages, QR check-in, income-verification links and support channels. The operator’s legal name and address have not been confirmed; see Contact or email info@sotiem.com while this document remains a draft.

2. Data we process

3. Why we use data

We use data to authenticate users; operate salon and Studio workspaces; record tickets, turns, hours and payouts; provide booking, check-in, import, export, optional OCR suggestions and verification links; send enabled notifications; administer subscriptions; prevent fraud and cross-tenant access; recover data; answer support requests; and improve reliability.

Sổ Tiệm has minimal first-party product events stored in the application infrastructure. Users can turn this choice off in the app. Events are designed not to contain customer names, ticket contents or financial amounts. The current repository does not integrate an advertising network or third-party advertising tracker.

Sổ Tiệm does not sell a salon's customer list or use that list to advertise another business.

4. Who can access data

5. Confirmed service providers

Providers may process data outside the user’s country. Exact primary storage location, transfer mechanism and applicable legal terms require owner confirmation before this policy is finalized.

6. Retention, export, correction and deletion

The application keeps data while the account or record is needed to provide the service, preserve audit history and handle requests. Some queue and customer retention settings can be configured by the salon owner. Default periods, backup retention and legal exceptions have not been confirmed, so this draft does not promise a fixed duration.

Every account, including Free, can download one portable JSON file containing its permitted account data, owned salons, technician history and private Studio records. Users can also correct editable information or create an export, correction, restriction or deletion request in Settings. Customer deletion may anonymize identity while preserving ticket and financial-history integrity. Cancelling a paid plan does not automatically delete records. Backup copies may expire only through the backup cycle once retention decisions are confirmed.

7. Cookies, local storage and sensitive links

Sổ Tiệm uses authentication sessions and browser storage needed for sign-in, preferences, PWA cache and offline synchronization. No advertising cookie is confirmed in the current repository. Booking-management and verification links use unpredictable tokens with expiration or revocation depending on the link type; users should not forward them to unauthorized people.

8. Security

Sổ Tiệm uses HTTPS in transit, Supabase Auth, tenant separation, Row Level Security, server-side authorization, hashed tokens for certain public links and audit history for important actions. Migration procedures include backup and restore checks. No system is perfectly secure; report concerns through the Security instructions.

9. Children

Sổ Tiệm is a business operations tool and is not designed for children. The minimum account age and child-data process require a legal decision before the final policy is published.

10. Changes and contact

We will update the date and provide appropriate notice when this draft or policy changes materially. While legal decisions remain pending, send questions, data requests or privacy reports to info@sotiem.com or use the in-app privacy-request flow.