Skip to content

Legal

Privacy policy

What Rose collects, why it collects it, and what you can do about it. Written against the app as it is actually built — every permission and every provider named below is one the app really uses.

Effective
2 August 2026
Last updated
2 August 2026
Published by
RuyaTech, Tunisia

The short version

  • Rose is the app your salon runs on. Most of what it holds is your business's own record-keeping: your team, your clients, your appointments, your takings.
  • We do not sell data, we do not run advertising, and the app carries no third-party analytics or tracking SDK.
  • Card numbers never touch Rose. Apple, Paddle or Stripe take the payment; we only see that a subscription is active.
  • You can delete your account and its data from Settings, or by writing to us.

This summary is not the policy. Everything below it is.

1. Who we are and what this covers

Rose is a salon management app for iOS and Android, published by RuyaTech in Tunisia. It is used by salon owners, managers and stylists to run bookings, the calendar, client records, the service menu, checkout and reports. Each salon also gets a public booking page where its own clients can book an appointment.

This policy covers:

  • the Rose mobile app on iOS and Android
  • the public booking page a salon shares with its clients
  • the backend API and services behind both
  • this website

It does not cover what an individual salon does with its own client records outside Rose, or any third-party site you reach from a link in the app.

2. Two kinds of data, two different roles

This distinction runs through the whole policy, so it comes first.

  • Your account and your salonWhen you sign up, subscribe and use Rose, we decide how that information is handled. In GDPR terms we are the controller, and you can bring any request about it straight to us.
  • The records your salon keeps in RoseYour clients, their visit history, your team's schedules, your sales. The salon decides what goes in and why; we only store and process it so the app works. In GDPR terms the salon is the controller and we are the processor. If you are a client of a salon and want your record changed or removed, ask the salon — and if you ask us, we will pass it on to them.

3. What Rose collects

3.1 Your account

  • First and last name, email address, phone number (optional) and business name
  • Your password, which is stored only as a salted hash — we never see or store it in readable form
  • One-time codes sent by email to verify your address or reset your password
  • If you sign in with Google or Apple: the account identifier, your email address and your basic profile (name and picture). Nothing else from that account is requested
  • Sign-in and refresh tokens, and which language, currency, date and time format your salon has chosen
  • A profile photo, if you add one

3.2 Your salon

  • Salon name, business type, contact details, opening hours and your booking-page address
  • Your service menu with prices and durations, your product list and stock levels
  • A logo or salon photos, if you upload them
  • The salon's location coordinates — only if you set them on the map, so clients can find the shop. This is the salon's address, not a record of where anyone has been

3.3 Your team

  • Each staff member's name, position, contact details and photo
  • Working schedule, blocked periods, and the services they perform
  • Their role and permissions, which decide what they can open in the app
  • Performance figures the app calculates from their appointments and sales

3.4 The client records your salon keeps

Entered by the salon, or by clients themselves through the booking page:

  • Name, and phone number or email address
  • Address, if the salon records one
  • Notes and preferences the salon writes down, such as a colour formula or an allergy the stylist needs to know
  • Visit history: which services, with which stylist, on which date, and what was spent — including totals like visit count, total spent and last visit
  • A VIP marker, if the salon uses one

Notes are a free-text field. If a salon writes health information there — an allergy, a scalp condition, a pregnancy — that is special category data under GDPR, and the salon is responsible for having a lawful basis and telling its clients. Rose does not require it and does not ask for it.

3.5 Appointments and bookings

  • The service, stylist, date, time slot and status of every appointment
  • Any note attached to the booking
  • Whether the booking came from the salon, from a staff member or from the public booking page

3.6 Sales and checkout

  • The services and products on each ticket, quantities and prices
  • Discounts, tax, tips and the total
  • How it was settled — recorded as a label such as cash, card or mobile payment
  • Which staff member closed the ticket, and the client it was linked to

Rose does not read cards and never receives a card number. When you take a card payment at the chair, that happens on your own terminal; Rose only records that the ticket was settled by card.

3.7 Your subscription

  • Which plan you are on, its term, renewal date and status
  • On iOS, the App Store purchase receipt and transaction identifier that prove the subscription is valid
  • Elsewhere, the subscription and customer identifiers issued by our payment provider, plus the invoices they generate
  • The country used to determine your currency and applicable tax

Payment details are entered with Apple, Paddle or Stripe and stay there. RuyaTech never receives or stores your card number.

3.8 Device and technical data

  • A push notification token from Apple (APNs) or Google (FCM), so the right phone gets the right alert
  • Device model, operating system version and app version, so a token can be tied to the device it belongs to and so we can support you
  • Your IP address and standard request logs at our API, kept for security and troubleshooting
  • Error and diagnostic logs when something fails

3.9 What Rose does not collect

  • Your contacts or address book
  • Your microphone, or any audio
  • Your fingerprint or face — biometric unlock is handled entirely by iOS or Android, which only tells Rose yes or no. No biometric data reaches the app or our servers
  • Card numbers, CVVs or bank details
  • Advertising identifiers. Rose carries no advertising SDK, no third-party analytics SDK and no cross-app tracking
  • Continuous or background location. Location is read only when you press the button to place your salon on the map

4. How we use it

  • To run the appCreate and secure your account, keep you signed in, show the calendar, take bookings, close tickets and produce your reports.
  • To let clients bookPublish your booking page, show real availability, and put the booking on the right stylist's column.
  • To notify the right personNew bookings, cancellations, no-shows, reminders before an appointment, completed transactions, staff invitations, low stock and billing notices.
  • To bill youStart and renew subscriptions, apply the correct currency and tax, and handle cancellations and refunds.
  • To support youAnswer your messages and investigate a problem you have reported.
  • To keep the service safeDetect abuse, prevent fraudulent sign-ups, rate-limit our API and keep an audit trail.
  • To improve RoseUnderstand which parts of the app fail or are slow, from our own server logs and error reports — not from tracking you across apps or sites.
  • To meet legal obligationsTax, accounting, and responding to lawful requests.

We do not sell personal data, we do not share it with data brokers, and we do not use your clients' records to market anything to them.

6. Notifications

Rose sends notifications by push, by email, and by SMS where a salon has enabled it. In Settings you can turn each type on or off individually — appointment created, cancelled, no-show, the 24-hour and 2-hour reminders, completed transactions, staff invitations and system alerts.

Some messages cannot be switched off while your account is open, because they are part of the service rather than marketing: email verification, password resets, security alerts and billing notices.

Turning off notifications at the operating system level stops delivery on that device. Deleting the app removes its push token from that device.

7. Permissions the app asks for

Every permission is requested at the moment the feature needs it, and refusing one only disables that feature.

  • NotificationsTo deliver appointment and business alerts to your phone.
  • CameraTo take a photo for a profile, a staff member or a nail design instead of choosing one from your library.
  • Photos and mediaTo pick an existing image, and to save your booking QR code to your gallery.
  • LocationRead only when you place your salon on the map so clients can find it. Rose does not track your location in the background.
  • Files and storageTo save reports you export as PDF, CSV, JSON or HTML, and to attach a file you choose.
  • Local network and Wi-Fi stateTo find a receipt printer on the same network as your till. This scan stays on your local network — nothing about it is sent to us.
  • Biometrics (Face ID, Touch ID, fingerprint)To unlock the app. The check is performed by your operating system, which returns only a yes or no.
  • Internet accessTo reach our API. Rose does not work offline.

8. Integrations you choose to connect

Rose can connect to Google Calendar so your appointments appear there. Connecting it opens Google's own sign-in screen inside the app; you see exactly which permissions Google asks for, and you grant them to us there. We use the resulting access to write and update calendar entries for your salon, and nothing else.

You can disconnect the integration in Settings at any time, which revokes our access going forward. Entries already written to your calendar stay with Google under Google's own privacy policy.

9. Who else touches this data

We use a small set of providers to run Rose. Each is bound by a contract that limits them to processing data on our instructions.

  • SupabaseAuthentication and identity, including the Google and Apple sign-in flows.
  • Google Firebase Cloud MessagingDelivery of push notifications on Android, and routing them on iOS.
  • Apple Push Notification serviceDelivery of push notifications on iOS.
  • Google and Apple sign-inOnly if you choose to sign in that way.
  • Apple App Store, Paddle and StripeSubscription payments, invoicing and tax. They act as merchant of record or payment processor, under their own privacy policies.
  • Email and SMS delivery providersTo send verification codes, confirmations and reminders.
  • Our hosting and database providersTo run the API and store your salon's data.

Beyond those, we disclose data only where the law requires it, to protect our rights or someone's safety, or — with notice to you — if the business is sold or reorganised. We never sell it.

10. How it is protected

  • All traffic between the app and our API travels over HTTPS/TLS
  • Passwords are stored only as salted hashes
  • Sign-in tokens are held in the iOS Keychain or the Android Keystore, not in ordinary app storage
  • Roles and permissions limit what each staff account can open — a stylist can work their own column without seeing your revenue
  • Biometric or device-passcode lock can be switched on so the app cannot be opened from an unattended phone
  • Access to production systems is restricted to the people who need it

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant supervisory authority as the law requires.

11. What stays on your device

  • Sign-in tokens in the operating system's secure store
  • A local cache of recent screens so the app opens quickly, plus your language, currency and display preferences
  • Files you export or receipts you print, saved wherever you choose to put them

Signing out clears the cached session. Deleting the app removes everything Rose has stored locally, but not the data held in your salon's account on our servers — see section 12.

12. How long it is kept

  • While your account is openYour salon's data is kept so the app can show you your history — that is the point of a client record.
  • When you delete your accountYou can delete it from Settings in the app, or ask us to. We remove your account and your salon's data from our production systems, and it ages out of encrypted backups within 30 days.
  • Financial recordsInvoices and transaction records are kept for as long as tax and accounting law requires, even after deletion.
  • LogsServer and security logs are kept for a short period and then discarded.
  • A single client's recordThe salon can delete it in the app at any time.

13. Your rights

Depending on where you live, you have some or all of these rights over your personal data:

  • Access — get a copy of what we hold
  • Rectification — correct anything wrong or incomplete
  • Erasure — have it deleted
  • Portability — receive it in a machine-readable format. Reports export as CSV, JSON, PDF or HTML from inside the app whenever you want
  • Restriction and objection — limit or object to certain processing
  • Withdraw consent — for anything you agreed to, without affecting what was lawful before
  • No discrimination — using a privacy right does not change the service you get

Write to support@barberos.io with "Privacy Request" in the subject line. We answer within 30 days, or sooner where the law requires it. We may need to verify who you are first.

If your request concerns a record a salon keeps about you as its client, contact that salon — they control it. Tell us and we will forward the request and help them action it.

In the EU, EEA or UK you may also complain to your national data protection authority. We do not sell personal information as that term is defined under California law, so there is nothing to opt out of.

14. International transfers

We are based in Tunisia and our providers operate globally, so your data may be processed outside the country you are in — including in the EU and the United States. Where that involves personal data leaving the EU or UK, we rely on the European Commission's Standard Contractual Clauses or another approved safeguard in our contracts with those providers.

15. Children

Rose is a tool for businesses and is not directed at children. We do not knowingly create accounts for anyone under 16. A salon may hold an appointment record for a minor booked by a parent or guardian; that record is the salon's responsibility and should hold no more than the booking needs. If you believe a child's data has reached us in error, write to us and we will delete it.

16. This website and the booking pages

This marketing site sets no advertising or tracking cookies.

A salon's booking page uses only what a booking needs: a session cookie to hold your selection while you move through the steps, and the name and contact details you type in, which go to that salon. Blocking essential cookies will stop the booking from completing.

17. Changes to this policy

When this policy changes we update the date at the top. If a change materially affects how your data is handled, we will tell you in the app or by email before it takes effect. The current version always lives at this address and inside the app under Settings → Privacy Policy.

18. Contact

RuyaTech, Tunisia — support@barberos.io

For anything about your data, put "Privacy Request" in the subject line so it reaches the right person.

Questions about any of this? support@barberos.io.