Privacy Policy
Last updated: June 15, 2026
This Privacy Policy explains how Dianova Beauty Connect (“Dianova”, “we”) collects, uses, and shares personal information through our booking platform, websites, and apps. For each salon you book with, the salon is the data controller and Dianova acts as its processor, except where we act as a controller for our own platform operations.
1. Information we collect
- Account & identity — name, email, phone, password or Google/Microsoft sign-in, phone one-time-passcodes, and bot/abuse signals (Cloudflare Turnstile).
- Booking & service history — appointments, services, stylists, preferences, and salon-entered notes including allergy/sensitivity flags and colour formulas.
- Payment information — processed by Stripe; we receive limited metadata (amount, status, card last-4/brand) and do not store full card numbers. Gift-card and tip records.
- Photos & images — uploaded or captured for the style quiz, virtual try-on, selfie timeline, and AI hair-health analysis.
- Biometric information — facial-geometry features may be derived from photos you submit to vision features (see §4).
- Voice & call data — recordings, transcripts, and summaries from AI voice-receptionist calls (with disclosure and, where required, consent).
- Communications — email, SMS, and WhatsApp messages and your messaging/marketing preferences.
- Usage, device & cookies — interactions, impressions/clicks, device/browser data, IP, and cookies for essential functions and analytics.
- Search activity — the search terms you enter on our marketplace, tied only to a first-party visitor key (not your identity). We use these in aggregate to power autocomplete and “trending” suggestions and to improve search relevance, on a legitimate-interests basis.
- Location — coarse, opt-in location (≈1 km) for location-aware promotions.
2. How we use information
To provide bookings, payments, reminders and receipts; operate AI features (recommendations, try-on, hair-health, price quotes, marketing); personalise content and promotions; run loyalty and referral programs; for security and fraud prevention; to comply with law; and, with consent where required, for marketing.
3. Legal bases (GDPR / UK GDPR)
Performance of a contract; consent (marketing, biometric vision features, cookies/analytics, geolocation); legitimate interests (security, service improvement, basic analytics); and legal obligation.
4. AI, automated processing & biometric data
- Consent-gated AI. Vision/analysis features run only after you opt in; consent is explicit, versioned, and revocable. Images are EXIF-stripped on upload, encrypted at rest, and served via signed, expiring URLs.
- Biometric notice (BIPA & similar). Where a feature derives facial geometry from your photo, that is biometric information; we collect it only with consent, use it solely to provide the feature, do not sell it, and delete it on request or at end of retention.
- On-device biometrics. Fingerprint/face unlock authenticates you locally; the biometric is never collected by or transmitted to Dianova.
- Cosmetic, not medical. Hair-health analysis is cosmetic guidance, not medical advice or diagnosis.
- Human oversight. AI suggestions are reviewable by salon staff. We do not make solely-automated decisions with legal or similarly significant effects; you may request human review and an explanation.
- Predictive retention analytics. We score the risk of a cancellation, no-show, or lapse from your booking behaviour with the salon (e.g. prior cancellations/no-shows, deposit on file, lead time, visit cadence) to enable timely reminders and offers. These scores use behavioural/transactional signals only and exclude protected attributes and known proxies; adverse actions such as deposit requirements are human-approved. You can opt out of profiling or predictive messaging, or request human review, in account settings. See our Responsible AI statement for details.
5. Payments (PCI-DSS)
Card payments, deposits, gift-card purchases and tips are processed by Stripe (PCI-DSS Level 1). Dianova does not store full card data.
6. Communications & marketing (CAN-SPAM / TCPA)
Transactional messages operate your bookings. Marketing email/SMS is sent only with the required consent; unsubscribe from email or reply STOP to SMS at any time. Message/data rates may apply.
7. Cookies, analytics & tracking
We use essential cookies (sign-in, security, tenant routing) and, subject to your choices where required, analytics to measure content performance. We also log marketplace search terms (against a first-party visitor key, not your identity) to power autocomplete, trending suggestions, and search-relevance improvements. Location features require separate opt-in.
8. Your rights
- GDPR/UK GDPR: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and rights regarding solely-automated decisions (Art. 22).
- CCPA/CPRA: know, delete, correct, and opt out of sale/sharing. We do not sell personal information. You may limit use of sensitive personal information.
- Exercise rights via privacy@dianovabeauty.company or account settings. Identity verification may apply; deletion propagates to derived analyses and images.
9. How we share information
With service providers/processors acting on our instructions (e.g. Stripe, Anthropic and vision/AI providers, Twilio, Cloudflare, Supabase, an email provider, optional Google/Microsoft sign-in); with the salon you transact with; and where required by law. We do not sell personal information.
10. Retention
We keep personal information only as long as needed for these purposes and as required by law. Photos, biometric data, and analyses follow a defined retention period and are deleted on request.
11. Children
The Services are not directed to children under the applicable age, and we do not knowingly collect their data without verifiable guardian consent.
12. International transfers & security
Cross-border transfers rely on appropriate safeguards (e.g. Standard Contractual Clauses). We use tenant isolation, encryption in transit and at rest, signed image URLs, access controls, and audit logging. No method is 100% secure.
13. Mobile apps & wallet
Our mobile apps may process device identifiers and push tokens (to deliver notifications) and, only with your operating-system permission, coarse geolocation for features such as digital check-in. Wallet passes (e.g. membership, loyalty or gift-card passes) contain the data shown on the pass and a reference used to update it. You can disable push and location in your device settings, and remove a wallet pass at any time.
14. On-device biometrics
Where you enable biometric unlock (such as Face ID or Touch ID) or passkeys, the biometric match happens on your device via the operating system. Dianova does notcollect, receive, or store biometric identifiers — we only receive the device's yes/no authentication result. This mirrors our consent-first stance on facial/photo analysis.
15. Third-party developer apps
You or your salon may authorize third-party applications to access salon data through our API. Such access happens only after explicit authorization on the consent screen, is limited to the specific permission scopes granted (sensitive categories such as client, payment and analytics data require explicit consent), and can be revoked at any time. Authorized developers act as sub-processors under our Developer & API Terms and must not use the data for any purpose beyond the integration you authorized. When you delete your data, the deletion propagates to those integrations.
16. Changes & contact
We may update this Policy; material changes will be notified. Contact us at privacy@dianovabeauty.company.
