Privacy Policy

Last updated: September 3, 2026

This Privacy Policy explains how VesnaGlow (“VesnaGlow,” “we”) collects, uses, and protects information when businesses (“Merchants”) use the VesnaGlowplatform, and when their clients interact with booking, payment, and messaging features.

1. Two roles, plainly

  • For a salon’s client data (the people booking appointments): the Merchant is the controller and VesnaGlow is the processor acting on the Merchant’s instructions. If you are a salon client with a question about your information, contact the salon first; we support them in answering.
  • For Merchant account data (the business, its staff logins, its billing): VesnaGlow is the controller.

2. What we collect

  • Account data: business name and type, staff names and roles, email, phone, login credentials, and settings.
  • Client data entered by Merchants and their clients: contact details, appointments, visit history, purchases, gift card and membership balances, messages, notes, and preferences.
  • Health information, where a Merchant uses clinical features: charts, intake and consent forms, treatment records, and clinical photos. See Section 5.
  • Photos and potential biometric information, where a Merchant uses those features. See Section 6.
  • Payment data: card and bank details are collected and vaulted by our payment processing providers (Finix Payments, Inc. and its processors and member banks). We store only tokens, card brand, and last four digits — never full card numbers. Merchant underwriting information (business identity, ownership, bank account for payouts) is collected for and shared with the processing providers.
  • Usage and device data: log data, IP address, and analytics needed to operate, secure, and improve the Service.

3. How we use information

  • To provide, maintain, secure, and improve the Service.
  • To process bookings, payments, payouts, refunds, and disputes.
  • To send appointment confirmations, reminders, and — only at the Merchant’s direction and with required consent — marketing messages. Every text supports STOP to opt out, honored automatically.
  • To power AI features (a booking assistant, drafting tools, a clinical scribe) that operate on the relevant data to produce their output for the Merchant.
  • To detect and prevent fraud and abuse, and to comply with law.
  • We do not sell personal information, and we do not use Merchant or client data to advertise to anyone.

4. Who we share with

We share information only with service providers that help us run the Service, under contracts requiring appropriate protection: cloud hosting and infrastructure, our database provider, the payment processing providers named above, text messaging carriers and providers, email delivery providers, and AI model providers that process content to generate the features’ output. We may also disclose information to comply with law, enforce our agreements, or protect rights and safety. If VesnaGlow is involved in a merger or acquisition, information may transfer with the business, under this policy.

5. Health information

Health related information stored by Merchants is treated as protected health information. It is encrypted at rest with dedicated keys, access is role restricted and audit logged, and we use it only to provide the Service or as the Merchant directs. Where a Business Associate Agreement is in place with a Merchant, it governs our handling of that information. We do not place health details into text messages or marketing email.

6. Biometric information

Some Merchant features involve client photographs or scans that may qualify as biometric information under laws such as the Illinois Biometric Information Privacy Act. The Merchant controls whether to collect it and must obtain written consent through the consent tooling the Service provides. We store such data encrypted, do not sell or profit from it, and retain it only per the Merchant’s retention settings and applicable law; it is destroyed when the Merchant deletes it or closes the account, subject to legal retention duties.

7. Security

We use encryption in transit and at rest for sensitive fields, role based access controls, two factor authentication for accounts, audit logging of activity, and monitoring for errors and abuse. Payment card data never touches our servers in raw form. No system is perfectly secure; if a breach affects your information, we will notify affected Merchants without undue delay consistent with applicable law.

8. Retention and your data’s portability

  • We retain information while an account is active and as required by law (for example, transaction records kept for tax and audit purposes).
  • Merchants can export their complete data at any time from within the Service, and for 60 days after termination, after which it may be deleted.
  • Clients of a salon can ask that salon to correct or delete their information; we act on the Merchant’s instruction, subject to legal retention duties.

9. Your choices and rights

  • Text recipients can reply STOP at any time; email marketing includes unsubscribe.
  • Depending on where you live (for example under the CCPA or GDPR), you may have rights to access, correct, delete, or receive a copy of your personal information, and to not be discriminated against for exercising them. For salon client data, direct requests to the salon that collected it; for anything else, contact us at hello@vesnaglow.com.

10. Children

The Service is not directed to children under 13, and we do not knowingly collect their information.

11. Changes

We may update this policy and will post the new effective date; material changes will be communicated to Merchants by email or in the Service.

12. Contact

Privacy questions or requests: hello@vesnaglow.com.

Pending final review by counsel; the current version applies until an updated version is posted.