Legal
Privacy Policy
Last updated: June 21, 2026
WebGlow ("we", "us", "our") provides a website and booking platform for beauty salons. This policy explains what personal data we collect, how we use it, and your rights. We've written it in plain language — no unnecessary legalese.
1. What data we collect
Salon owner accounts
- Email address and password (stored as a secure hash — we never store your password in plain text)
- Salon name, subscription tier, and subscription status
End-client data (collected on behalf of salons)
When a visitor uses a salon's WebGlow-powered website to book an appointment, place an order, check loyalty points, or chat with an AI concierge, we collect:
- Name, email address, and phone number
- Appointment details (service, date, time)
- Order details (products, quantities, amounts)
- Loyalty points balance (linked to email address)
- AI chat conversation messages
Usage data
- Rate-limit counters (a session token and request count used to prevent abuse — not linked to your identity and deleted within 24 hours)
2. How we use this data
- To operate the booking, storefront, loyalty, and AI concierge features
- To allow salon owners to view and manage their clients' interactions via the WebGlow dashboard
- To send appointment confirmations and order acknowledgements to clients (via the salon's configured contact method)
- To generate AI responses in the chat concierge feature (see Section 4)
- To prevent abuse of our public-facing functions
We do not sell personal data to third parties. We do not use client data for advertising purposes.
3. Infrastructure — where data is stored
All platform data is stored using Supabase (supabase.com), a managed PostgreSQL database and authentication service. Supabase stores data in secure, encrypted infrastructure. You can review Supabase's own privacy policy and data processing terms on their website.
4. AI chatbot and Groq
When you send a message to a salon's AI concierge, your conversation content is transmitted to Groq, Inc. for AI response generation. Groq processes this content on their infrastructure to produce the AI's reply. WebGlow does not retain conversation content beyond what is stored for the session in our own database.
Groq's API is used only for Elite-tier salons that have explicitly enabled the chatbot feature. If you do not wish to have your messages processed by Groq, do not use the AI chat feature. You can still book appointments and browse services without interacting with the chatbot.
Groq's privacy policy is available at groq.com/privacy-policy.
5. Who can see your data
- Salon owners can view their own clients' bookings, orders, loyalty balances, and chat sessions via the WebGlow dashboard. They cannot see data belonging to other salons.
- WebGlow administrators have access to platform-level data for operational and support purposes only.
- No other parties have access to client data through our platform.
6. Data retention and deletion requests
Client data is retained for as long as the associated salon account is active on the platform. Salon owners may delete individual client records from their dashboard.
To request deletion of your personal data, or to ask what data we hold about you, please contact us at: privacy@webglow.pro (placeholder — update before going live). We will respond within 30 days.
7. Cookies and tracking
WebGlow uses essential session cookies for authentication (so you stay logged in to the dashboard). We do not currently use any third-party advertising trackers, analytics pixels, or retargeting technologies. If this changes in a future update, this policy will be updated and you will be notified.
8. Changes to this policy
We may update this policy as the platform evolves. The "Last updated" date at the top of this page reflects when changes were last made. Continued use of the platform after changes constitutes acceptance of the updated policy.
9. Contact
Questions about this privacy policy? Email us at privacy@webglow.pro (placeholder).
Note: This privacy policy is a working template tailored to WebGlow's current feature set. It should be reviewed by a qualified legal professional before being relied upon for formal compliance with applicable privacy regulations (such as GDPR, CCPA, or others relevant to your jurisdiction).