Privacy Policy
日本語Last updated: August 19, 2026
1. Information We Collect
For customers, we collect the name, email address, phone number, and booking history provided at sign-up and when making a reservation. For salons (business users), we collect the account holder's name, email address, shop information, and business records such as reservations, customers, and sales entered into the service.
2. How We Use Information
We use the information to provide and operate the service: creating and managing reservations, sending confirmations and reminders, providing the salon with the information needed to serve its customers, responding to enquiries, and improving the service. We do not use it for any other purpose.
3. Disclosure to Third Parties
We do not sell or disclose personal information to third parties, except where required by law, where necessary to protect a person's life or safety, or where we engage service providers (such as hosting, email delivery, and payment processing) under contract and appropriate supervision to perform part of the service on our behalf.
4. Opting Out of Messages
You can stop receiving promotional messages at any time from your account settings or by using the unsubscribe link in the message. Transactional messages required to operate a booking (such as confirmations and reminders) are sent regardless of this setting.
5. Google User Data
Salons may optionally connect their Google Calendar. For a connected salon, we store the Google account email address, the identifier of the connected calendar, and the access and refresh tokens. To calculate availability, we also retrieve and store the identifier, start and end time, and title of events on that calendar. We use this data only for two purposes: (1) to create, update, and delete events on the salon's calendar for reservations made through the service, and (2) to prevent double-booking against existing events. We do not use it for advertising or any other purpose, and we do not sell it or disclose it to third parties except as required by law. We do not read the contents by hand, except with the user's explicit consent for troubleshooting, where required by law, or where necessary for security. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. A salon can disconnect at any time from its admin console. On disconnection, the stored tokens and all calendar-derived data are deleted.
6. How We Protect Sensitive Data
We apply the following data protection mechanisms to the information we hold, and in particular to the Google user data described above. (1) Encryption in transit: all traffic between the user's device and the service, between the service and the Google APIs, and between the service and its database is encrypted with TLS. (2) Encryption at rest: data is stored in a managed PostgreSQL database (Supabase), whose storage is encrypted at rest by the provider. (3) Access control: Row Level Security is enabled on every table involved in the Google integration, so each salon's data can be read only by accounts belonging to that salon. Access and refresh tokens are handled only on the server and are never sent to a browser or mobile app. Administrative credentials are held as server environment variables and are not exposed. (4) Minimum scope: we request from Google only the permission required to create, update, and delete calendar events (calendar.events). We do not request contacts, message contents, or any other data. (5) Retention and deletion: calendar events are retained only for the next 90 days or so, as needed to compute availability, and are replaced with current data on each sync. Events deleted or changed in Google are deleted or updated in the service accordingly. On disconnection, we first delete the future events the service created in Google Calendar, then delete all stored tokens and calendar-derived data, and revoke the tokens with Google. (6) Restricted personnel access: stored calendar contents are not read by our staff, except with the user's explicit consent for troubleshooting, where required by law, or where necessary for security.
7. Data Retention and Deletion
We retain information for as long as the shop or user continues to use the service, and only to the extent needed to provide it. (1) Treatment records: treatment notes (history, products used) and counselling sheets (allergies, medical history) are deleted three years after the customer last visited. We do not keep sensitive information such as allergies once there is no longer a prospect of using it. (2) Deletion requests: to request deletion of the information we hold, please contact us using the form on our support page (/support). After verifying your identity, we will delete it without undue delay. A shop can also delete individual customer records from its own admin console. (3) Google user data: as described in section 6(5), calendar events we import are retained only as far as needed to compute availability, and disconnecting the integration deletes all stored tokens and calendar-derived data. (4) Retention required by law: receipts and other records of transactions must be kept under Japan's Corporation Tax Act, Consumption Tax Act and Electronic Books Maintenance Act. We therefore retain them for the period those laws prescribe (in principle seven years) even after a deletion request, and use them only to meet that obligation.
8. Contact
For questions about this policy or about the handling of personal information, please contact CodeNest Inc., the operator of this service, using the form on our support page (/support).