Privacy Policy
Salon Guild CRM, part of the Opti Flo ecosystem
Last updated: 28 July 2026
This policy is not legal advice and should be reviewed by a solicitor before publication. It is written to be comprehensive and accurate to how Salon Guild CRM actually operates, but Opti Flo Apps Ltd should confirm final wording with qualified legal counsel, particularly the international transfers section.
1. Who we are
Salon Guild CRM is operated by:
Opti Flo Apps Ltd
Company number: 17284323
Registered office: SIU Offices, 4-6 Greatorex Street, London, E1 5NF, United Kingdom
Data protection contact: support@optiflo.app
Opti Flo Apps Ltd is registering with the Information Commissioner's Office (ICO) as a data controller. This registration is in progress. Once complete, the registration number will be added to this policy.
This service is currently offered to salons, spas, and similar businesses based in the United Kingdom only.
2. Two roles: controller and processor
This is the most important section of this policy to understand, because Opti Flo Apps Ltd acts in two different capacities depending on whose data is involved.
When you are a salon owner using Salon Guild CRM (the operator): Opti Flo Apps Ltd is the data controller for your own account information, billing details, and platform usage data. We decide how and why that data is processed, and this policy governs it directly.
When your clients use your Salon Guild CRM website, booking system, or client portal: you, the salon, are the data controller for your clients' personal data. Opti Flo Apps Ltd acts as your data processor: we process your clients' data only on your instructions, to provide the CRM, booking, portal, and communications features you've configured. If you are a salon owner, you are responsible for your own compliance with UK GDPR toward your clients, including having your own privacy notice for them, a lawful basis for processing their data, and honouring their rights. Salon Guild CRM gives you the tools to do this (a hosted portal, consent capture at signup, unsubscribe handling) but the underlying legal responsibility toward your clients sits with you as the controller.
A Data Processing Agreement covering this processor relationship applies automatically and is incorporated into our Terms of Service. A signed version is available on request.
3. What data we collect
From salon owners (operators)
- Account details: name, email, phone number, business name and address
- Billing information: processed by Stripe. We do not store full card details ourselves
- Platform usage data: login activity, feature usage, support interactions
- Communications with our support team
From salon clients, on behalf of the salon (as processor)
- Contact details: name, email, phone number
- Booking history: appointments, services booked, staff seen
- Payment history related to salon services, where processed through the platform
- Communications sent and received through the platform (SMS, email)
- Notes and records the salon chooses to keep on their client relationship
Automatically collected
- Website analytics via Google Analytics: pages visited, general location (country/city level, not precise), device and browser type, referral source
- Standard server logs: IP address, timestamps, error logs, for security and reliability
We do not currently use any cookie or analytics tooling beyond Google Analytics. If this changes, this policy and the accompanying Cookie Policy will be updated first.
4. Why we process this data (lawful basis)
| Purpose | Lawful basis |
|---|---|
| Providing the Salon Guild CRM service to operators | Contract |
| Processing salon clients' data on the salon's instructions | Contract (with the salon) / processor obligations |
| Billing and payment processing | Contract, legal obligation (tax records) |
| Account security and fraud prevention | Legitimate interests |
| Website analytics | Consent (where required) or legitimate interests, subject to cookie consent |
| Sending service-related emails (e.g. billing, account notices) | Contract, legitimate interests |
| Marketing communications to salon owners | Consent |
| SMS and email sent by a salon to their own clients | Consent, collected by the salon at client signup |
5. How long we keep data
- Operator account data: retained for the duration of the subscription, plus a reasonable period afterward for legal, accounting, and dispute-resolution purposes, typically no longer than 7 years for financial records.
- Salon client data: retained per the salon's own instructions and retention settings. If a salon closes their account, client data is retained for a limited grace period to allow account recovery, then deleted, unless a longer period is required by law.
- Call recordings (where a salon has opted in to this feature): retained for 90 days by default, per the salon's configured setting.
- Analytics data: retained per Google Analytics' standard retention settings, configurable by us.
6. Who we share data with
We share data with the following categories of recipient, and only where necessary to provide the service:
- Sub-processors: the technical infrastructure and services that power the platform. The full current list is maintained on our Sub-processors page, and includes Supabase (database hosting), Vercel (application hosting), Railway (backend services), Stripe (payment processing), Twilio (SMS and voice communications), Resend (email delivery), Deepgram (call transcription, where recording is enabled), and Anthropic (AI Workforce features).
- Professional advisors, such as our accountants or legal counsel, where necessary.
- Regulators or law enforcement, where required by law.
- We do not sell personal data to third parties, and we do not share salon client data with other salons or third-party marketers.
7. International data transfers
Salon Guild CRM is offered to UK-based salons only, and our intention is to keep client data within the UK wherever practical. However, some of our sub-processors are based outside the UK, principally in the United States (including Stripe, Twilio, and Anthropic). Where personal data is transferred outside the UK, we rely on appropriate safeguards under UK GDPR, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, as put in place by each sub-processor. Details of the specific safeguard used by each sub-processor are available on request to support@optiflo.app.
8. Your rights
Under UK GDPR, individuals have the right to:
- Access the personal data we hold about them
- Request correction of inaccurate data
- Request erasure of their data, subject to legal retention requirements
- Object to or restrict certain processing
- Request data portability
- Withdraw consent at any time, where processing is based on consent
- Complain to the ICO (ico.org.uk) if they believe their data has been mishandled
If you are a salon client and want to exercise these rights, please contact the salon directly in the first instance, as they are the data controller for your information. If you're unable to reach them, contact support@optiflo.app and we will assist in routing your request.
If you are a salon owner, contact support@optiflo.app directly for any request relating to your own account data.
9. Security
We apply industry-standard technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls scoped by workspace, and regular review of our sub-processors' own security practices. No system is completely secure, and we encourage salons to use strong, unique passwords and enable any available account security features.
10. Children's data
Salon Guild CRM is not directed at children. Where a salon's own clients include minors (for example, a parent booking a service for a child), the salon is responsible for ensuring they have an appropriate lawful basis and, where relevant, parental consent for processing that minor's data.
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified to operators by email or in-platform notice. The "last updated" date at the top of this page reflects the most recent revision.
12. Contact us
For any question about this policy or how your data is handled:
Opti Flo Apps Ltd
SIU Offices, 4-6 Greatorex Street, London, E1 5NF, United Kingdom
support@optiflo.app
If you remain unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk.
