Access follows the shop.
Staff access should be limited to the roles and booking information needed for their work. Authentication, session handling and account recovery must pass launch testing.
Security
This page states the intended security approach. It does not claim certifications, audits or controls that have not been completed and verified.
Staff access should be limited to the roles and booking information needed for their work. Authentication, session handling and account recovery must pass launch testing.
Google Calendar and messaging connections require the minimum practical permissions. A connection is not treated as live until consent, failure and revocation paths have been tested.
Shops should be able to retrieve their appointment and client records in a practical format. Retention and deletion terms will be stated in the final privacy policy.
Encryption, hosting region, backups, incident response and compliance claims will be published only after the production architecture is confirmed.
The application needs a proportionate security review, dependency and secret checks, form and webhook validation, permissions review, backup verification and an incident contact. The public site alone cannot prove those controls.
A dedicated security contact will be published before customer data is accepted. Until then, the product should be treated as pre-launch and no sensitive information should be submitted through this marketing site.
Salon Booking
Start with a 14-day trial. One shop, unlimited staff, NZ$39 a month after the trial.