Privacy Policy
Last updated: September 28, 2026
This policy explains what personal information we collect when you use MyStudioWalker, why we collect it, who we share it with, and the choices you have. Privacy matters and we try to collect as little as we can to do the job.
If you have questions, email leon@mystudiowalker.com.
Who controls what data
For information about your business (your account, billing details, the salon you operate), we are the data controller.
For information about your customers (people who book appointments with you), you are the data controller and we are a data processor — meaning we hold their information on your behalf and only use it to provide the Service to you.
Your customers should read your salon's own privacy notice for how their data is handled by the salon.
What we collect
Account & billing information
- Your name, email, phone number
- Your business's name, address, business type, country
- Payment method details (held by our processor Stripe, never by us)
- Tax / registration numbers if you provide them (e.g. UEN, GST number)
Usage information
- Actions you take in the app (logins, bookings created, settings changes) for security and product improvement
- Technical telemetry: IP address, browser type, device type, time zone
- Cookies for authentication and (limited) analytics — see “Cookies” below
In the mobile app
- Camera — only while you are scanning a product barcode or a staff clock-in QR code. Frames are read on your device to decode the code; no image is stored or transmitted.
- Bluetooth — only to find and connect your receipt printer. We read the printer's name and signal strength to show you the list; we do not scan for, log, or use nearby devices for anything else, and never for tracking.
- Location — only at two moments you start yourself: when an owner taps “Use my current location” to set the studio's clock-in point, and when a staff member clocks in or out. The clock-in position is saved on that attendance record so the studio can see it was made on site. The app never reads your location in the background and never tracks where you go.
- Push notifications — if you allow them, a device token so we can alert you to new bookings, cancellations and customer messages that need you. Turning notifications off in your device settings stops this.
- Photos — only the treatment photos you choose to attach to a customer record (see “Treatment records”). We do not read your photo library.
Communications
- Emails / WhatsApp you send to us at leon@mystudiowalker.com
- Records of email + WhatsApp messages the platform sends to your customers on your behalf, including delivery status (for troubleshooting + your audit log)
- For marketing emails specifically: whether the email was opened and which links were clicked, so we can show you campaign performance (sent / opened / clicked / booked). We don't track opens or clicks on transactional emails like booking confirmations.
Your customer data (held on your behalf)
- Customer names, emails, phone numbers, birthdays you import or collect
- Booking history, services purchased, packages, sales records
- Notes you write about customers
- Treatment photographs you upload against a customer's record
- Consent forms your customers sign, including their signature, the answers they gave, and the exact wording they agreed to
Sensitive information. We never require you to collect special-category data (health, biometrics, and so on). However, the Service does provide tools capable of holding it: you can build health questionnaires and store treatment photographs, and one of our starter templates asks about medical conditions, allergies, medication and pregnancy.
Whether to use those tools is entirely your decision. If you do, that information is still your customers' data and you remain the controller of it — you are responsible for obtaining appropriate consent, for honouring its withdrawal, and for complying with the heightened protections that apply to sensitive data where you operate. Our role is limited to storing it securely on your behalf.
Treatment photos & signed forms
These are the most sensitive records the Service holds, so they are handled differently from ordinary content.
- Treatment photographs are stored privately. Unlike a salon logo or team photo, they are never reachable from a public link. Each viewing address is generated on request and expires within minutes, so a link that leaks from a browser history or a forwarded screenshot stops working.
- Access follows your own staff permissions. Only staff whose role allows them to see customer notes can open treatment photos or signed forms.
- Signed forms record what was actually agreed. Each signature is stored with the exact wording shown at the time, your registered business name as it then stood, the staff member who witnessed it, and a checksum that makes later alteration detectable. Revising a form creates a new version; it never rewrites a signature already given.
- A copy may be sent to the customer. Where you enable it, the customer receives their own copy by email at the moment of signing.
We do not use treatment photographs or form responses for any purpose other than storing and displaying them back to you. They are never used for analytics, benchmarking, or training.
Why we collect it
- To provide the Service — log you in, store your data, deliver appointment reminders, process payments.
- To bill you — process subscription charges, the email marketing add-on, and WhatsApp / email credit top-ups.
- To support you — answer your questions, debug issues you report, send service updates.
- To improve the Service — understand how features are used, build better ones. We aggregate or anonymise where possible.
- To prevent abuse — detect spam, fraud, or violations of our Acceptable Use Policy.
- To meet legal obligations — keep records that tax / consumer protection law requires.
Who we share data with
We use a small number of trusted third-party processors to run the Service. They're only allowed to use your data to provide the service we've hired them for — never to market to you independently.
- Supabase — database hosting (Singapore region for SG accounts).
- Vercel — application hosting + serverless infrastructure, and cookieless visitor statistics for our own website only (see “Cookies & tracking” below).
- Stripe — payment processing. Your card details are stored with Stripe, not us.
- Resend — transactional and marketing email delivery (booking confirmations, birthday / win-back / campaign emails, billing receipts). For marketing emails, Resend records opens and link clicks on our behalf, which we surface to you as campaign performance.
- Twilio — WhatsApp delivery for the WhatsApp reminder / confirmation features, and for the WhatsApp AI assistant where a salon has enabled it.
- Anthropic — the AI model behind the WhatsApp AI assistant, reached through the Vercel AI Gateway. Only used by salons that have switched the assistant on. See The WhatsApp AI assistant below for exactly what is sent.
- Google Analytics — traffic analytics for our own marketing pages (page views, device / country breakdowns), so we can see how people find us.
- Google Ads — conversion measurement and remarketing on our own marketing pages. It records when a visit that arrived from one of our ads goes on to create an account, which is how we tell whether an ad was worth paying for.
- Meta (Facebook) Pixel — the same measurement for the ads we run on Facebook and Instagram.
We do not sell your personal information. The three advertising and analytics tools above do share visit data with Google and Meta — that is how ad measurement works — but only for our own marketing pages (this site's homepage, blog, and sign-up). They are not loaded in the admin app you work in, and never on a salon's own booking page, so neither your day-to-day use of the product nor your customers' bookings are shared with any advertiser. We may disclose data when legally required (court order, regulator demand) and will challenge requests that look overbroad.
The WhatsApp AI assistant
Some salons switch on an AI assistant that answers their customers on WhatsApp — quoting prices, checking free times and making bookings. It is off by default and a salon has to buy and enable it. If your salon has not, nothing in this section applies to you.
Where it is on, the assistant is powered by a large language model from Anthropic, reached through the Vercel AI Gateway. Both act as sub-processors for this feature.
What is sent to the model, for each reply:
- The customer's WhatsApp messages in that conversation, and the assistant's own earlier replies.
- The salon's public information — services, prices, durations, opening hours, address, payment methods, and any notes the salon has written for the assistant.
- Where the customer is already in the salon's records: their name, and the details of their own upcoming appointments, so the assistant can answer “when is my appointment?” and move it.
What is never sent: payment card details, any other customer's data, treatment records and consultation notes, staff pay or commission, and the salon's revenue or reports. The assistant reads only through a fixed set of functions, and the customer it is acting for is fixed from the verified WhatsApp sender rather than anything the model produces — so it cannot be talked into reading somebody else's record.
Training. Anthropic does not train its models on data sent through the API by business customers. We do not use conversations to train any model of our own.
Retention. Conversations are stored in our database so the salon can read the transcript and so the assistant remembers the thread. They follow the same retention rule as the rest of a salon's customer data (see Data retention).
A person is always reachable. The assistant hands over to the salon's team for cancellations, complaints, anything about money already paid, and any question about hair, scalp or health. A customer can ask for a person at any time and the salon is notified.
It can be wrong. It is a machine writing sentences, and it may occasionally say something inaccurate. Prices, times and bookings it quotes come from the salon's live data rather than the model's memory, but a booking or an answer that looks wrong should be checked with the salon.
Platform administrator access
Authorised MyStudioWalker staff (“platform administrators”) may access your account data — including customer records, bookings, sales, and settings — for the following purposes only:
- Technical support — investigating issues you have reported or that affect your account.
- Security & incident response — detecting fraud, abuse, or unauthorised access.
- Service maintenance — routine data integrity checks, migrations, and debugging.
- Legal compliance — responding to valid court orders or regulatory demands.
All platform administrator access sessions are recorded in a tamper-evident audit log (action type, timestamp, and the operator's identity). This access is never used to benefit a competitor of yours, to view your data for commercial purposes, or to share your data with third parties beyond what is described in this policy.
If you believe your account has been accessed improperly, email legal@mystudiowalker.com and we will provide you with the relevant audit log entries within 30 days.
How long we keep it
We keep your data while your account is active. On account termination:
- Most data is deleted within 30 days of termination.
- Billing records and invoices are kept for at least 5 years to satisfy tax + accounting requirements.
- Anonymised aggregate analytics may persist indefinitely.
- Deleting a signed consent record clears its answers and signature but keeps the fact that consent was once given, together with the reason for deletion. “Consented, then withdrew” and “never consented” are different facts, and a salon may need to evidence the first.
You can request a copy of your data before or after termination by emailing legal@mystudiowalker.com.
Your rights
Depending on where you live, you may have rights to:
- Access — get a copy of the personal information we hold about you.
- Correct — update inaccurate information.
- Delete — delete your account yourself, in the product, without asking us (see below), or ask us to delete information we hold (subject to legal retention obligations).
- Restrict / Object — limit how we use it, or object to certain uses.
- Portability — receive your data in a machine-readable format.
- Withdraw consent — where processing is based on consent.
- Lodge a complaint — with your local data protection authority (Singapore PDPC, EU national DPA, UK ICO, California Attorney General, etc.).
Deleting your account
You do not need to email us to delete an account — it is self-service, in the product, and takes effect immediately:
- If you book appointments (a customer of a studio that uses us): open My account and choose Delete my account. Your sign-in is destroyed, and your name, phone, email, photo, birthday and any notes about you are erased from every studio you have visited. Upcoming bookings are cancelled and those studios told. Studios keep their own record of visits you already paid for — required for their accounts and tax — but with your identifying details removed.
- If you run a studio: go to Settings → Business → Danger zone. Deleting takes the studio and all its outlets offline immediately, cancels your subscription so you stop being charged, and signs everyone out. We keep the data for 30 days so we can restore it if you deleted by mistake, then it is removed.
- If you are a staff member: the same Danger zone deletes your own login and access. The studio keeps its records of the work you did, since those are its business records, not yours.
For any other right above, email leon@mystudiowalker.com. We'll verify your identity and respond within 30 days.
Cross-border transfers
The Service is operated from Singapore but our processors (Vercel, Stripe, Twilio, Resend) operate globally. Your data may be processed in the United States, the EU, or other countries. We rely on Standard Contractual Clauses (SCCs) and equivalent safeguards as required by GDPR Article 46 for transfers out of the EEA.
Children
MyStudioWalker is a B2B tool. Accounts are for businesses, and the Service is not intended to be used by anyone under 18. We do not knowingly collect personal information about children for our own purposes.
Your customers are a separate matter. A salon may legitimately treat a minor, and the Service supports recording a parent or guardian's consent on a customer's behalf. Any such information is your customers' data, held on your behalf — you remain the controller, and you are responsible for obtaining consent from a parent or legal guardian where the law requires it.
If you believe we hold data about a child that should not have been provided to us, contact us and we'll delete it.
Security
We take reasonable technical and organisational measures to protect your data:
- Data encrypted in transit (TLS) and at rest (AES-256 via Supabase).
- Passwords stored hashed via Supabase Auth.
- Service-role database access restricted to server functions; public reads gated by row-level security policies.
- Payment card details never touch our servers — handled entirely by Stripe.
No service is 100% secure. If we discover a breach affecting your personal information, we'll notify you and the relevant regulator without undue delay.
Changes to this policy
We may update this policy as the Service evolves. The “Last updated” date at the top reflects the most recent revision. Material changes will be announced by email to your account address with at least 30 days' notice.
Contact
Privacy questions, requests, complaints — leon@mystudiowalker.com. My Studio Walker is owned and operated by Leon Walker Pte. Ltd. (UEN 202622515Z), a company registered in Singapore.