Privacy statement
What HairConnect does with data. Derived from what the software actually does rather than from a template — so you can check every line below.
Last updated on 22 August 2026
1. Two roles, and mixing them up is the classic mistake
There are two kinds of data in this story, and they need two different answers.
The data of a salon’s customers — their name, their appointments, their colour formulas, their receipts — belongs to the salon. The salon decides why it is kept and what happens to it. The salon is therefore the controller and we are the processor: we store and process that data on the salon’s instruction, and we do nothing with it that the salon does not ask for.
The salon’s own data, as a customer of ours — the company name, the VAT number, the address, the owner’s e-mail address, the invoices — is a different matter. There, we are the controller.
Are you a customer of a salon and do you want to know what happens to your data, or have it corrected or deleted? Go to your salon. We are not allowed to decide that ourselves. That is not a dodge; it is precisely what that division of roles means.
2. This site
hairconnect.be is a stack of pre-built HTML files. No JavaScript is sent to your browser, no cookies are set and there are no visitor statistics.
There is no Google Analytics, no Facebook pixel, no advertising script and no error-collection service. The typeface and the photographs sit on our own server, so opening a page makes your browser send no request at all to a third party. That is also why there is no cookie banner: there is nothing to ask consent for.
The web server does keep the ordinary technical logs that every web server keeps.
If you write or call us, we keep what you send for as long as your question is open and for as long as there is reason to come back to it.
3. The booking page and the customer portal do set cookies
That is a different piece of software from this site. When someone books online with a salon or signs in to the customer portal, three cookies are involved. All three are there because the page does not work without them; nothing is measured with them and nothing goes from them to a third party.
| Cookie | What for, and how long |
|---|---|
| hc_booking | The half-filled booking, so the next step knows what the previous one said. Two hours. |
| hc_portal | The sign-in proof for the customer portal. Thirty days. |
| hc_result | The confirmation shown on screen after booking. Ten minutes. |
- All three are httpOnly: no script on the page can read them.
- There is no fourth cookie. No tracker, no preference cookie, no measurement cookie.
4. What the software stores
Below is what ends up in HairConnect, per type of data. This is the list for the role in which we are the processor: it concerns the data of a salon’s customers and staff.
| Type of data | What it holds |
|---|---|
| Customer record | First and last name, e-mail address, mobile and landline number, address, date of birth, language, sex, preferred staff member, and whether the customer wants e-mail or SMS. |
| Appointments | Date and time, which service, which staff member, how it was booked, the status — including a no-show — and the notes the salon adds. |
| Colour formulas | The stylist’s literal note and, where it can be read by machine, the parsed lines: brand, product, grams and developer. The original text always stays. |
| Till receipts | The receipt lines with amount and VAT, which staff member did the work, the payment method and the payment terminal’s reference. The paper ticket carries no customer name. |
| Customer portal | Sign-in codes and session tokens, both only as a hash and never as a readable code, with the IP address a code was requested from and the browser line of the session. |
| E-mails sent | Which kind of e-mail, in which language, to which address, with which subject and when. The content of the message is not kept. |
| Staff | Roster, hours worked, clocked times — both the raw measurement and the corrected one — and absences. |
| Audit log | Who changed what and when, with the IP address and the old and new value. |
5. What it does not hold
It is just as useful to say what is not stored. There is no field for it, so nothing can be filled in there by accident.
- No national registry number, no ID card number and no bank account number of a customer.
- No health data as a separate field. If a salon writes something like that in a free-text note, it sits in that note — that is the salon’s choice, not the software’s.
- No card details. During a payment they travel from the card to the terminal to the payment provider; they never enter HairConnect.
- No wages and no bank account number of a staff member.
6. No advertising goes out
HairConnect sends four kinds of e-mail to a salon’s customers: a confirmation, a reminder, a note that an appointment has been moved, and a note after a no-show. On top of that there is the sign-in code for the customer portal.
That is all. There is no campaign module, no newsletter, and no SMS is sent — not even when the customer record says SMS is allowed.
If a customer switches “accepts e-mail” off, those four kinds stop going out. The portal sign-in code still goes: that is not a message from the salon but the key with which the customer lets themselves in.
7. Who else gets to see it
As few as possible, and only what is genuinely in place. Anything marked “only if the salon switches it on” does nothing while that connection is off: the keys belong to the salon, and without keys nothing leaves.
| Party | What goes there |
|---|---|
| Mollie, the payment terminal | The amount, the receipt reference and the terminal number. No name, no e-mail address, no card details. |
| The salon’s mail server | The salon configures its own mail server. Appointment e-mails go out through it, so that server sees the customer’s e-mail address and what the message says. |
| ClearFacts, only if the salon switches the accounting connection on | One day’s takings, totalled per VAT rate, as a single document. No customer names and no individual receipts: in that document the customer is literally called “Diverse klanten (particulieren)”. |
| Peppol Directory | The salon’s company number, to look up whether the salon can receive electronic invoices. A lookup only; nothing is sent. |
| Stripe, only for our own subscription | The name and e-mail address of the salon as a business, and the subscription amount. No data about any customer of the salon. |
| The invoicing service, only for our own subscription | The invoicing details of the salon as a business: name, address, VAT number and the invoice lines. No data about any customer of the salon. |
- And what is not there: no Google Analytics, no Facebook pixel, no ad network, no error-collection service, no SMS provider, no CDN and no storage with a cloud service.
8. Where the data sits
On one server that we manage ourselves. The database, the files a salon uploads and the logs sit on that same machine; no third-party storage service is connected.
9. How long it is kept
Two things are fixed by law, two are a choice, and the rest is up to the salon. The table below says which is which.
| What | How long |
|---|---|
| Till receipts and the till journal | Seven years. That is the Belgian retention period and it is not a choice: the journal is append-only, nothing can be removed from it, and a correction is a counter-entry rather than a change. |
| Audit log: money, access, hours and privacy requests | 2,555 days, roughly seven years, so that a log line does not disappear before the document it explains. This is a choice, not a law. |
| Audit log: changes to customers and appointments | 730 days, two years. Also a choice. |
| Customer portal sign-in code | Fifteen minutes, and at most three codes per quarter of an hour per e-mail address. |
| Customer portal session | Thirty days. |
| A half-filled booking | Two hours. |
| Customer records, appointments and colour formulas | For as long as the salon keeps them. The software deletes nothing here of its own accord: that is a decision for the controller, and that is the salon. |
- The audit log is pruned every night. The rest is not: there is no task that quietly deletes customer data, and that is deliberate.
10. What a salon’s customer can ask for
The GDPR gives everyone the right to know what data is held about them, to have it corrected, and to ask for it to be deleted. You exercise that right with your salon, because the salon is the controller.
The customer portal has two buttons for it. The first downloads everything the salon holds about you in a single file: your record, your appointments, your colour formulas with the original note, your closed receipts, your gift card balance and the e-mails sent to you.
The second records a deletion request. Nothing is deleted automatically, and that is deliberate: till receipts and invoices must be kept for seven years, and a button that threw everything away at once would put the salon in breach of another law. Your salon decides what can actually go.
What is not in the download are the internal notes the salon writes about a customer. Those belong to the salon and were not supplied by the customer; anyone who wants to see them asks the salon directly.
If you feel your data is not being handled properly, you can lodge a complaint with the data protection authority of your country.
11. How it is secured
No badges, but measures you can find back in the software.
- Every salon sits in its own walled-off space. A database query without a salon returns zero rows rather than “everything”. That is the default, not a filter someone can forget.
- The customer portal has no password. You request a code that is valid for fifteen minutes, and that code is stored only as a hash.
- The portal’s sign-in proof sits in an httpOnly cookie: no script on the page can reach it.
- Nothing carries an incrementing database number on the outside. Every address and every API response uses a uuid, so you cannot reach the next record by adding one.
- The till journal is a chain: every receipt carries the fingerprint of the previous one. Changing a receipt after the fact breaks that chain, and there is a check that looks for it.
- The audit log cannot be changed. That is enforced not only by the code but by the database itself.
12. If this text changes
If what the software does changes, this text changes with it. The date at the top says when that last happened.
This statement was written by checking what the software actually does: which fields sit in the database, which messages go out, and which parties are connected to. If you read something here that you cannot find back in the software, tell us — one of the two is wrong, and we want to know which.