Privacy Policy
Effective date: 31 July 2026 · Last updated: 31 July 2026
In accordance with the Information Technology Act, 2000 · IT (SPDI) Rules, 2011 · Digital Personal Data Protection Act, 2023
Contents
- 1.Introduction
- 2.Information We Collect
- 3.Sensitive Personal Data
- 4.How We Use Your Information
- 5.How We Share Your Information
- 6.Data Retention
- 7.Data Security
- 8.Your Rights
- 9.Children's Privacy
- 10.Push Notifications
- 11.Cookies & Tracking
- 12.Cross-Border Data Transfers
- 13.Changes to This Policy
- 14.Grievance Officer
- 15.Contact Us
1.Introduction
BookAnySalon ("we", "our", "us") is a digital marketplace that connects customers with independent salon and beauty service providers across India. The platform is operated by Zetabyte Tech Solutions Private Limited, a company incorporated under the Companies Act, 2013, with its registered office at Nakate Chowk, opp. Baliraj Colony, Jyotiba Colony, Baderaj Colony, Rahatani, Pimpri-Chinchwad, Maharashtra 411017.
This Privacy Policy describes how we collect, use, store, share, and protect your personal data when you use the BookAnySalon mobile application ("App") and our website at bookanysalon.com ("Website") (collectively, the "Platform").
By using the Platform, you confirm that you have read and agree to this Privacy Policy. If you do not agree, please do not use the Platform.
2.Information We Collect
2.1 Information you provide directly
- •Name, email address, and phone number — provided during account registration
- •Profile photograph — optional, uploaded by you
- •Password — managed securely by Firebase Authentication; we never see or store your plain-text password
- •For home visit bookings: your delivery address and the GPS coordinates of that address (entered manually by you during booking)
- •Booking notes or preferences you type when making an appointment
2.2 Salon Owner information (Salon Owners only)
- •Salon name, address, phone number, and email
- •Service catalogue, pricing, working hours, and gallery photographs
- •Bank account holder name, account number, and IFSC code
- •UPI ID
- •PAN (Permanent Account Number)
- •Business licence number and KYC documents (uploaded for verification)
- •Razorpay-linked account details for split-payment settlements
These details are collected solely to facilitate payouts and regulatory compliance. They are treated as Sensitive Personal Data under Section 3 below.
2.3 Booking and transaction data
- •Selected services, appointment date and time, and assigned artist
- •Payment status, Razorpay Order ID, and transaction reference number
- •Coupon codes applied, discount amounts, and commission amounts
- •We do NOT store your card number, CVV, expiry date, or full UPI PIN — these are processed exclusively by Razorpay
2.4 Information collected automatically
- •Device identifiers, operating system version, and app version
- •IP address and approximate network location
- •App usage data (screens visited, features used, session length) via Firebase Analytics
- •Crash reports and performance data via Firebase Crashlytics
- •Firebase Cloud Messaging (FCM) token for push notifications
2.5 Location
With your explicit permission, the App accesses your device GPS to show salons near you. Location is accessed only when the App is open and you initiate a location-based search. We do not track your location in the background and do not store your real-time GPS coordinates beyond your current session. For home visit bookings, you manually enter your address, which is stored as part of the booking record.
2.6 User-generated content
- •Reviews (star rating, text, and optionally photos) you submit after a completed booking
- •In-app chat messages exchanged between you and a Salon within the context of a booking
- •Favourites (the list of salons you have saved)
2.7 In-app notifications
We store a record of notifications sent to you (booking confirmations, reminders, status updates) in a private subcollection linked to your account.
3.Sensitive Personal Data & Information (SPDI)
Under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("IT SPDI Rules"), certain categories of personal data are classified as Sensitive Personal Data or Information (SPDI) and require additional protection.
The following data we collect qualifies as SPDI:
- •Bank account name, account number, and IFSC code (Salon Owners only)
- •UPI ID (Salon Owners only)
- •PAN number (Salon Owners only)
We collect SPDI solely to facilitate payouts to Salon Owners via Razorpay. We do not collect SPDI from Customers. SPDI is not shared with any third party except Razorpay for the stated purpose and will not be used for any other purpose without your explicit consent.
You have the right to withdraw consent for the processing of your SPDI at any time by contacting us at privacy@bookanysalon.com. Withdrawal may affect your ability to receive payouts.
4.How We Use Your Information
- •Service delivery — create and manage your account, process bookings, confirm appointments, and enable in-app chat with your Salon
- •Payment processing — share necessary transaction details with Razorpay to process online payments
- •Salon Owner payouts — use bank/UPI/PAN details to settle earnings via Razorpay Route split payments
- •Notifications — send appointment confirmations, reminders, booking status updates, and (with your consent) promotional notifications via FCM and in-app alerts
- •Safety and fraud prevention — detect abusive activity, enforce booking limits, verify Salon KYC
- •Analytics and improvement — understand usage patterns, identify bugs, and improve Platform features using Firebase Analytics and Crashlytics
- •Legal compliance — retain booking and payment records as required by Indian tax and consumer protection laws (including GST and TCS obligations)
- •Reviews and rankings — display your reviews publicly on the Platform and use ratings to compute Salon ranking scores
- •Customer support — use your booking and account information to respond to queries and resolve disputes
6.Data Retention
- •Active accounts — your data is retained for as long as your account is active and as needed to provide the service
- •Booking records — retained for a minimum of 7 years in accordance with Indian GST and income tax laws, even after account deletion, in anonymised or archived form
- •Deleted accounts — when you delete your account, your profile, active bookings, reviews, chat messages, and favourites are removed. Archived booking records may be retained in anonymised form for legal compliance
- •FCM tokens — deleted within 30 days of account deletion
- •KYC documents (Salon Owners) — retained as required by Razorpay's KYC obligations and applicable law
7.Data Security
- •All data in transit is encrypted using TLS (HTTPS/SSL)
- •Data at rest is stored with Firebase's built-in encryption
- •Payment data is processed exclusively by Razorpay (PCI-DSS Level 1 certified) — we do not store raw card or UPI credentials
- •Access to the platform's backend is restricted via Firebase security rules, admin custom claims, and role-based permissions
- •All administrative actions are recorded in an immutable audit log
- •We follow reasonable security practices as required by the IT (SPDI) Rules, 2011
Despite these measures, no data transmission over the internet is completely secure. We cannot guarantee absolute security and are not responsible for unauthorised access that is beyond our reasonable control.
8.Your Rights
Under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the IT (SPDI) Rules, 2011, you have the following rights:
- •Right to Information — request details of the personal data we hold about you and the purposes for which it is processed
- •Right to Correction — request correction of inaccurate or incomplete personal data
- •Right to Erasure — request deletion of your personal data; you can also delete your account directly from within the App (Profile → Delete Account for Customers; Profile → Edit Salon Profile → Danger Zone → Delete Account for Salon Owners)
- •Right to Nomination — nominate another individual to exercise your data rights on your behalf in case of death or incapacity
- •Right to Withdraw Consent — withdraw your consent to data processing at any time; withdrawal may limit your ability to use the Platform
- •Right to Grievance Redressal — contact our Grievance Officer (see Section 14) if you believe your rights have been violated
To exercise any of these rights, contact us at privacy@bookanysalon.com. We will respond within 30 days of receiving your request.
9.Children's Privacy
BookAnySalon is intended for users aged 18 and above. We do not knowingly collect personal data from any person under the age of 18. If you are a parent or guardian and believe your child has registered on our Platform, please contact us immediately at privacy@bookanysalon.com with the account details and we will delete it promptly.
10.Push Notifications
We send push notifications for the following purposes:
- •Booking confirmation immediately after a booking is placed
- •Appointment reminders before your scheduled time
- •Booking status updates (confirmed, rescheduled, completed, cancelled)
- •In-app messages from your Salon regarding a booking
- •No-show alerts (if you miss an appointment)
- •Promotional offers (only if you have opted in)
You can manage notification preferences within the App (Profile → Notifications) or disable all push notifications through your device settings. Disabling notifications does not affect your ability to use the Platform.
12.Cross-Border Data Transfers
Our Firebase infrastructure is primarily hosted in the Asia South 1 (Mumbai) region. However, certain Firebase services such as Firebase Analytics, Firebase Crashlytics, and Google Sign-In may process data on servers located outside India, including in the United States.
Such international transfers are subject to Google's standard contractual clauses and Data Processing Agreement, which provide adequate safeguards for personal data as recognised under applicable law. By using the Platform, you acknowledge and consent to these transfers.
13.Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated to you via an in-app notification or email at least 30 days before they take effect. The date of the most recent update is displayed at the top of this page.
Continued use of the Platform after a policy update constitutes your acceptance of the revised policy.
14.Grievance Officer
In accordance with the Information Technology Act, 2000, the IT (SPDI) Rules, 2011, and the Digital Personal Data Protection Act, 2023, we have appointed a Grievance Officer to address privacy-related concerns:
Name: Abhijeet
Designation: Grievance Officer
Email: privacy@bookanysalon.com
Address: Nakate Chowk, opp. Baliraj Colony, Jyotiba Colony, Baderaj Colony, Rahatani, Pimpri-Chinchwad, Maharashtra 411017
Availability: Monday to Saturday, 10:00 AM – 6:00 PM IST
Grievances will be acknowledged within 48 hours and resolved within 30 days of receipt, as required by the IT Rules, 2011.
15.Contact Us
For any privacy-related questions, requests, or concerns:
Privacy queries: privacy@bookanysalon.com
General support: support@bookanysalon.com
Response time: Within 48 hours on business days
For legal notices, please contact our Grievance Officer directly (Section 14).