Privacy statement
What HairConnect does with data. Derived from what the software actually does rather than from a template — so you can check every line below.
Last updated on 3 October 2026
1. Two roles, and mixing them up is the classic mistake
There are two kinds of data in this story, and they need two different answers.
The data of a salon’s customers — their name, their appointments, their colour formulas, their receipts — belongs to the salon. The salon decides why it is kept and what happens to it. The salon is therefore the controller and we are the processor: we store and process that data on the salon’s instruction, and we do nothing with it that the salon does not ask for.
The salon’s own data, as a customer of ours — the company name, the VAT number, the address, the owner’s e-mail address, the invoices — is a different matter. There, we are the controller.
Are you a customer of a salon and do you want to know what happens to your data, or have it corrected or deleted? Go to your salon. We are not allowed to decide that ourselves. That is not a dodge; it is precisely what that division of roles means.
2. This site
hairconnect.be is a stack of pre-built HTML files. No framework is sent to your browser; the only script on the page is a handful of lines that puts the question about measurement on screen and does nothing else.
For as long as you have not answered yes to that question, no request at all goes to Google and no cookie from this site sits on your device. Refuse, and that is remembered, so the question does not come back on every visit. A button at the foot of every page lets you change your choice.
Say yes and Google Analytics 4 loads, and Google sets two cookies: “_ga” and “_ga_6RC567LGTL”. We set their lifetime to thirteen months; GA4 would keep them for two years by default.
What is sent then: which page you are looking at — the address without the parameters that may follow it — and whether you have been here before. Google derives the country and region you come from out of your IP address. For visitors from the European Union, Google does not store that IP address: it is used to derive that rough location and then discarded. That is not a setting we switch on but how Google Analytics 4 works for European traffic.
Your choice itself is not kept in a cookie but in your browser’s own storage (localStorage, under the key “hc-meting”). That value never leaves your device: it is not sent along with any request. Clear your browser storage and the question comes back.
Beyond that there is no Facebook pixel, no advertising script and no error-collection service. The typeface and the photographs sit on our own server.
The web server does keep the ordinary technical logs that every web server keeps.
If you write or call us, we keep what you send for as long as your question is open and for as long as there is reason to come back to it.
3. The apps on your phone and tablet
There are two apps. HairConnect is the calendar for a salon’s staff; HairConnect Platform is our own administration screen and is not in the stores for ordinary use.
Neither carries an advertising network, a measurement script, or an error-collecting service. There is no library in them that reports your behaviour to a third party. What the app sends out goes to our own server and nowhere else.
The app does keep something on your device, and deliberately so: the calendar for the days you have looked at, plus any changes you made while the network was down. That sits in a file inside the app itself, so that you can still see today when the salon’s wifi drops. Delete the app and that file goes with it.
If you switch notifications on, Apple or Google gives your device a key and we store that key so we can send a notification to it. That key says nothing about who you are; it points at a device. It disappears as soon as your account is gone or you turn notifications off.
The camera only comes into play at the moment you scan a barcode while booking in a delivery. No photo is stored and no image goes to our server — what leaves is the number printed on the packaging.
To have an app account deleted, the page “Deleting your data” explains how; it is listed at the foot of this page with the other legal texts.
4. The Chrome extension for Optios
Salons switching from Optios can install a Chrome extension that keeps HairConnect up to date in the background with what happens in Optios. It exists for that transition period only It reads from Optios and delivers to HairConnect, and in Optios it only sets what you switched on yourself in HairConnect.
It reads the Optios sign-in token from your browser cookie and sends it along to Optios itself — where it came from and where it belongs. That token goes nowhere else. Our server never sees it; that is not a promise but a property of the design, and a test enforces it.
What does go to hairconnect.be is your salon’s data as Optios returns it: appointments, customers, services. Exactly the same data as in an ordinary migration, and it lands in your salon and nowhere else. Which data, and how far back, HairConnect decides per round; the extension itself knows no Optios address at all.
On your computer it stores one thing: the device key with which this installation identifies itself to HairConnect. That key designates a computer, not a person. Remove the extension or unlink the computer in HairConnect and the key is worthless.
It opens no tabs, looks into no tab and changes no page. There is no analytics script in it and nothing that passes your behaviour to a third party. At Optios it only changes what you expressly switched on in HairConnect: cleaned-up customer records, sale prices, and the appointments booked, moved or cancelled in HairConnect. It deletes nothing there and never starts a full migration on its own — that remains a button a person presses.
From version 1.3.0 it keeps a connection open to hairconnect.be, so that an appointment is in Optios within seconds. All that comes over that connection is a signal that something needs to go to Optios, with no customer or time in it; the data itself travels the same way as above.
Removing it works like any extension, via chrome://extensions. That removes the device key as well.
5. The booking page and the customer portal do set cookies
That is a different piece of software from this site. When someone books online with a salon or signs in to the customer portal, three cookies of ours are involved. All three are there because the page does not work without them; nothing is measured with them and nothing goes from them to a third party.
The public booking page also asks the same question about measurement as this site does. Say yes there and two cookies from Google are added. The customer portal is not measured: once you are signed in there is no measurement script on the page and the question is not asked.
| Cookie | What for, and how long |
|---|---|
| hc_booking | The half-filled booking, so the next step knows what the previous one said. Two hours. |
| hc_portal | The sign-in proof for the customer portal. Thirty days. |
| hc_result | The confirmation shown on screen after booking. Ten minutes. |
| _ga | From Google, and only after a yes to the question about measurement. Tells visitors apart, so that someone returning is not counted as new. Thirteen months. |
| _ga_6RC567LGTL | From Google, and only after a yes. Keeps the session for the property the measurement goes to. Thirteen months. |
- The first three are ours and are httpOnly: no script on the page can read them.
- The two from Google are only set after you have said yes on the booking page. Say no and they are not there, and that holds on a next visit too.
- We set their lifetime to thirteen months; GA4 would keep them for two years by default.
- Your choice itself is not in a cookie but in your browser’s storage (localStorage, under the key “hc-meting”), and is not sent along with any request.
- We set no cookie beyond those three. No advertising cookie, no preference cookie, no second measurement service.
6. What the software stores
Below is what ends up in HairConnect, per type of data. This is the list for the role in which we are the processor: it concerns the data of a salon’s customers and staff.
| Type of data | What it holds |
|---|---|
| Customer record | First and last name, e-mail address, mobile and landline number, address, date of birth, language, sex, preferred staff member, and whether the customer wants e-mail or SMS. |
| Appointments | Date and time, which service, which staff member, how it was booked, the status — including a no-show — and the notes the salon adds. |
| Colour formulas | The stylist’s literal note and, where it can be read by machine, the parsed lines: brand, product, grams and developer. The original text always stays. |
| Till receipts | The receipt lines with amount and VAT, which staff member did the work, the payment method and the payment terminal’s reference. The paper ticket carries no customer name. |
| Customer portal | Sign-in codes and session tokens, both only as a hash and never as a readable code, with the IP address a code was requested from and the browser line of the session. |
| E-mails sent | Which kind of e-mail, in which language, to which address, with which subject and when. The content of the message is not kept. |
| Staff | Roster, hours worked, clocked times — both the raw measurement and the corrected one — and absences. |
| Audit log | Who changed what and when, with the IP address and the old and new value. |
| Sign-in log | Every sign-in, sign-out, failed attempt and block: the timestamp, the e-mail address entered, the user and the salon where those can be determined, the IP address with the country and city derived from it, and the browser string. Never a password. This log is visible only to the platform administrator, not in a salon’s back office. |
7. What it does not hold
It is just as useful to say what is not stored. There is no field for it, so nothing can be filled in there by accident.
- No national registry number, no ID card number and no bank account number of a customer.
- No health data as a separate field. If a salon writes something like that in a free-text note, it sits in that note — that is the salon’s choice, not the software’s.
- No card details. During a payment they travel from the card to the terminal to the payment provider; they never enter HairConnect.
- No wages and no bank account number of a staff member.
8. No advertising goes out
HairConnect sends four kinds of e-mail to a salon’s customers: a confirmation, a reminder, a note that an appointment has been moved, and a note after a no-show. On top of that there is the sign-in code for the customer portal.
That is all. There is no campaign module, no newsletter, and no SMS is sent — not even when the customer record says SMS is allowed.
If a customer switches “accepts e-mail” off, those four kinds stop going out. The portal sign-in code still goes: that is not a message from the salon but the key with which the customer lets themselves in.
9. Who else gets to see it
As few as possible, and only what is genuinely in place. Anything marked “only if the salon switches it on” does nothing while that connection is off: the keys belong to the salon, and without keys nothing leaves.
| Party | What goes there |
|---|---|
| Mollie, the payment terminal | The amount, the receipt reference and the terminal number. No name, no e-mail address, no card details. |
| The salon’s mail server | The salon configures its own mail server. Appointment e-mails go out through it, so that server sees the customer’s e-mail address and what the message says. |
| ClearFacts, only if the salon switches the accounting connection on | One day’s takings, totalled per VAT rate, as a single document. No customer names and no individual receipts: in that document the customer is literally called “Diverse klanten (particulieren)”. |
| Peppol Directory | The salon’s company number, to look up whether the salon can receive electronic invoices. A lookup only; nothing is sent. |
| Stripe, only for our own subscription | The name and e-mail address of the salon as a business, and the subscription amount. No data about any customer of the salon. |
| The invoicing service, only for our own subscription | The invoicing details of the salon as a business: name, address, VAT number and the invoice lines. No data about any customer of the salon. |
| Google, for visitor measurement — only on this site and on the public booking page, and only after consent | Which page, or which booking step, is reached. On the booking page as a route pattern: “/boeken/moment” and not the real address, so without the salon’s name, without unique identifiers and without anything the visitor types in. Plus the region Google derives from the IP address. No name, no e-mail address, no telephone number, no appointment. |
- Google Analytics is only on this site and on the public booking page, and on both only after consent. Not in the customer portal, not in a salon’s back office and not in the platform panel.
- The country and city shown next to an IP address in the sign-in log are derived on our own server, from a data file that sits there. No IP address is sent to a lookup service or to any other party.
- And what is not there either: no Facebook pixel, no ad network, no error-collection service, no SMS provider, no CDN and no storage with a cloud service.
10. Where the data sits
On one server that we manage ourselves. The database, the files a salon uploads and the logs sit on that same machine; no third-party storage service is connected.
11. What leaves the European Union
One party processes data outside the European Union, and only where you have said yes to it yourself: Google, for visitor measurement. Say no and nothing goes to Google, and so nothing goes to the United States either.
For visitors from the European Union, Google Analytics collects through servers inside the European Union. Further processing may take place at Google in the United States. For EU visitors the contracting party is Google Ireland Limited; the processing in the United States is done by Google LLC.
The basis for that transfer is the EU-US Data Privacy Framework, under which Google LLC is certified. The current state of that certification is on Google’s own page about data transfers: policies.google.com/privacy/frameworks. We put no certification number and no date here — those age, and this text would then claim something that no longer holds.
We have not concluded standard contractual clauses with Google ourselves. Google’s terms apply, and that is what it is: with a service of that size, nothing is negotiated.
That framework is not uncontested and it can fall away. If it does, this measurement has to be reassessed. We write that down here rather than smoothing it over: it is exactly the kind of thing you want to be able to find again a year later.
12. How long it is kept
Two things are fixed by law, two are a choice, and the rest is up to the salon. The table below says which is which.
| What | How long |
|---|---|
| Till receipts and the till journal | Seven years. That is the Belgian retention period and it is not a choice: the journal is append-only, nothing can be removed from it, and a correction is a counter-entry rather than a change. |
| Audit log: money, access, hours and privacy requests | 2,555 days, roughly seven years, so that a log line does not disappear before the document it explains. This is a choice, not a law. |
| Audit log: changes to customers and appointments | 730 days, two years. Also a choice. |
| Sign-in log: sign-in attempts, IP address and derived location | 90 days, after which the line disappears automatically. An IP address is personal data; a quarter is long enough to work out afterwards whether an account was misused, and longer adds nothing. Also a choice. |
| Customer portal sign-in code | Fifteen minutes, and at most three codes per quarter of an hour per e-mail address. |
| Customer portal session | Thirty days. |
| A half-filled booking | Two hours. |
| Customer records, appointments and colour formulas | For as long as the salon keeps them. The software deletes nothing here of its own accord: that is a decision for the controller, and that is the salon. |
- The audit log and the sign-in log are pruned every night. The rest is not: there is no task that quietly deletes customer data, and that is deliberate.
13. What a salon’s customer can ask for
The GDPR gives everyone the right to know what data is held about them, to have it corrected, and to ask for it to be deleted. You exercise that right with your salon, because the salon is the controller.
The customer portal has two buttons for it. The first downloads everything the salon holds about you in a single file: your record, your appointments, your colour formulas with the original note, your closed receipts, your gift card balance and the e-mails sent to you.
The second records a deletion request. Nothing is deleted automatically, and that is deliberate: till receipts and invoices must be kept for seven years, and a button that threw everything away at once would put the salon in breach of another law. Your salon decides what can actually go.
What is not in the download are the internal notes the salon writes about a customer. Those belong to the salon and were not supplied by the customer; anyone who wants to see them asks the salon directly.
If you feel your data is not being handled properly, you can lodge a complaint with the data protection authority of your country.
14. How it is secured
No badges, but measures you can find back in the software.
- Every salon sits in its own walled-off space. A database query without a salon returns zero rows rather than “everything”. That is the default, not a filter someone can forget.
- The customer portal has no password. You request a code that is valid for fifteen minutes, and that code is stored only as a hash.
- The portal’s sign-in proof sits in an httpOnly cookie: no script on the page can reach it.
- Nothing carries an incrementing database number on the outside. Every address and every API response uses a uuid, so you cannot reach the next record by adding one.
- The till journal is a chain: every receipt carries the fingerprint of the previous one. Changing a receipt after the fact breaks that chain, and there is a check that looks for it.
- The audit log cannot be changed. That is enforced not only by the code but by the database itself.
15. If this text changes
If what the software does changes, this text changes with it. The date at the top says when that last happened.
This statement was written by checking what the software actually does: which fields sit in the database, which messages go out, and which parties are connected to. If you read something here that you cannot find back in the software, tell us — one of the two is wrong, and we want to know which.
