Privacy Policy
Last Updated: November 17, 2025
1. Introduction
GlamConnect.in ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cloud-based salon billing and WhatsApp CRM platform.
By using GlamConnect, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this policy, please do not use our Service.
2. Information We Collect
2.1 Information You Provide
We collect information you directly provide when you:
- Create an Account: Salon name, your name, email address, phone number, location
- Use Our Service: Customer data (names, phone numbers, service preferences, visit history), billing information, staff details, service catalog
- Make Payments: Payment method details (processed securely through our payment partners)
- Contact Support: Communications with our support team
- Participate in Surveys: Feedback and survey responses
2.2 Automatically Collected Information
- Usage Data: Pages visited, features used, time spent, clicks, and navigation patterns
- Device Information: IP address, browser type, operating system, device identifiers
- Location Data: General location based on IP address
- Cookies and Tracking: We use cookies and similar technologies to enhance your experience
2.3 WhatsApp Integration Data
When you use our WhatsApp messaging features, we collect message content, delivery status, and customer phone numbers. This data is processed in accordance with WhatsApp Business API policies and Meta's privacy standards.
3. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve our Service
- Process your transactions and billing
- Send service-related notifications and updates
- Provide customer support and respond to inquiries
- Send marketing communications (with your consent)
- Monitor and analyze usage patterns and trends
- Detect, prevent, and address fraud and security issues
- Comply with legal obligations
- Personalize your experience
- Develop new features and services
4. Legal Basis for Processing
We process your personal data based on:
- Contract Performance: To provide the Service you've subscribed to
- Consent: For marketing communications and optional features
- Legitimate Interests: To improve our Service, ensure security, and analyze usage
- Legal Obligations: To comply with applicable laws and regulations
5. How We Share Your Information
We may share your information with:
5.1 Service Providers
We work with third-party service providers who perform services on our behalf:
- Cloud hosting providers (AWS, Google Cloud, etc.)
- Payment processors (Razorpay, Stripe, etc.)
- WhatsApp Business API providers
- Email service providers
- Analytics platforms
- Customer support tools
5.2 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.
5.3 Legal Requirements
We may disclose your information if required by law or in response to valid requests by public authorities (e.g., court orders, government agencies).
5.4 Aggregated Data
We may share aggregated, anonymized data that cannot be used to identify you for analytics, research, or marketing purposes.
6. Data Security
We implement industry-standard security measures to protect your information:
- 256-bit SSL/TLS encryption for data in transit
- AES-256 encryption for data at rest
- Regular security audits and penetration testing
- Secure authentication and access controls
- Automated backups and disaster recovery procedures
- Employee training on data protection
- Compliance with ISO 27001 standards (in progress)
While we strive to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
7. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy:
- Account Data: Retained while your account is active
- Customer Records: Retained as long as required by law (typically 7 years for financial records)
- WhatsApp Messages: Retained for 90 days unless deleted earlier
- Backup Data: Retained for 30 days after deletion
- Analytics Data: Aggregated data may be retained indefinitely
After account termination, you have 30 days to export your data. After this period, all data will be permanently deleted.
8. Your Privacy Rights
You have the following rights regarding your personal data:
8.1 Access and Portability
You can access and export your data at any time from your account dashboard.
8.2 Correction
You can update your account information and customer data directly through the Service.
8.3 Deletion
You can request deletion of your account and data by contacting support. Some data may be retained for legal compliance.
8.4 Opt-Out
You can opt out of marketing communications by clicking "unsubscribe" in our emails or updating your preferences in your account.
8.5 Restriction and Objection
You can request restrictions on how we process your data or object to certain processing activities by contacting us.
9. Cookies and Tracking Technologies
We use the following types of cookies:
- Essential Cookies: Required for the Service to function properly
- Preference Cookies: Remember your settings and preferences
- Analytics Cookies: Help us understand how you use the Service
- Marketing Cookies: Track your activity for advertising purposes (with consent)
You can control cookies through your browser settings. Disabling certain cookies may affect Service functionality.
10. Third-Party Links and Services
Our Service may contain links to third-party websites or integrate with third-party services (like WhatsApp, payment gateways). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
11. Children's Privacy
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete such information.
12. International Data Transfers
Your data is primarily stored on servers located in India. However, some of our service providers may process data outside India. We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses and adequacy decisions.
13. Data Breach Notification
In the event of a data breach that may compromise your personal information, we will notify affected users within 72 hours of becoming aware of the breach, as required by law. We will also notify relevant authorities as necessary.
14. Your Obligations
When using GlamConnect to store and process your customer data, you are responsible for:
- Obtaining necessary consents from your customers
- Complying with applicable data protection laws
- Ensuring the accuracy of customer data
- Respecting your customers' privacy rights
- Not uploading illegal or unauthorized data
- Maintaining the confidentiality of your account credentials
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a prominent notice on our Service. The "Last Updated" date at the top of this policy reflects the most recent revision. Your continued use of the Service after changes constitute acceptance of the updated policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Email: privacy@glamconnect.in
Support Email: support@glamconnect.in
Phone: +91 9933 232 486
Location: Hyderabad, Telangana, India
Response Time: We aim to respond within 48 hours
17. Regulatory Compliance
GlamConnect is committed to complying with:
- Information Technology Act, 2000 (India)
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- Digital Personal Data Protection Act, 2023 (when implemented)
- Payment Card Industry Data Security Standard (PCI DSS)
- WhatsApp Business API Terms and Policies
18. Your Consent
By using GlamConnect, you consent to the collection, use, and processing of your information as described in this Privacy Policy. You can withdraw your consent at any time by discontinuing use of the Service and requesting deletion of your data.