Privacy Policy
Last updated: August 24, 2026 β’ Mi Belleza
1. Introduction & Geographic Scope (NY & NJ)
This Privacy Policy explains how Mi Belleza ('the Platform', 'we', 'us', or 'our') collects, uses, processes, and safeguards your personal data when you access or use our mobile application and web portal. Our services are currently configured, licensed, and offered exclusively to clients, independent beauty stylists, and salon owners operating or receiving services in the States of New York and New Jersey. By accessing or using the platform, you acknowledge and consent to the data practices described in this policy.
2. Information We Collect
We collect information in the following categories: (a) Account & Identity Data β full name, email address, phone number, physical address or salon premises location in NY/NJ, and profile photo. (b) Booking & Operational Records β service choices, appointment times, preferred beauty professionals, client booking history, service notes, and verified customer reviews. (c) Payment & Payout Information β financial records processed securely via Stripe; we do not store raw payment card numbers or bank account login credentials on our servers. (d) Device & Usage Telemetry β unique device identifiers, operating system version, IP address, interaction logs, crash reports, and app diagnostics. (e) Location Data β precise or approximate GPS location, collected only with your explicit mobile device permission to find nearby beauty professionals in NY/NJ. (f) Device Calendar Access β used strictly to export confirmed appointments directly to your device's native calendar upon your permission. (g) Camera & Photo Library Access β used solely to enable profile image uploads, salon showcase photos, and client hairstyle lookbooks.
3. How We Use Your Information & AI Processing
We process personal data for the following legitimate business purposes: (a) facilitating appointment booking, scheduling adjustments, and service delivery; (b) processing client payments and issuing automated Stripe Connect marketplace payouts to salons and stylists; (c) sending transactional appointment confirmations, reminders via SMS, and push notifications; (d) powering the AI Concierge and scheduling assistants to streamline client inquiries (chat inquiries are processed in real-time and are NEVER used to train public foundation models or sold to third parties); (e) monitoring platform security, detecting fraud, and enforcing our Terms; and (f) complying with New York and New Jersey regulatory standards (including the NY SHIELD Act).
4. Cloud Infrastructure, Sub-processors & Data Sharing
We share personal data strictly on a need-to-know basis with trusted infrastructure partners and sub-processors: (a) Independent Stylists & Salons β sharing your booking details and client notes with the specific professional you choose to book with. (b) Convex Inc. β cloud database, reactive backend architecture, and encrypted storage. (c) Clerk Inc. β user authentication, identity verification, and multi-factor session security. (d) Stripe Inc. β secure payment processing, KYC identity checks, and Connected Account payouts. (e) Twilio Inc. β carrier-grade transactional SMS delivery. (f) Google Cloud & Gemini AI β enterprise artificial intelligence processing. (g) Resend Inc. β transactional email confirmations. (h) Apple APNs & Google FCM (via Expo) β secure push notification delivery. (i) Legal & Regulatory Authorities β when strictly required by valid subpoena, court order, or applicable federal/state laws in NY and NJ. We do not sell, rent, trade, or monetize your personal data to third-party data brokers or advertising networks. Mobile Opt-in & SMS Consent: No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties under any circumstances.
5. Local Storage (MMKV), Cookies & Tracking Disclosures
On mobile devices, we utilize MMKV high-performance key-value storage and secure device keychain mechanisms to securely store authentication tokens, user locale preferences, and cached UI state for offline accessibility. On web browsers, we use essential first-party session cookies required for authentication and navigation security. We do not utilize third-party cross-site behavioral advertising cookies or tracking pixels. We honor browser-based Global Privacy Control (GPC) and Do Not Track (DNT) signals.
6. Your Privacy Rights & State Disclosures (NY & NJ)
Residents of New York and New Jersey possess specific rights regarding their personal data: (a) Right to Know & Access β request a copy of personal information we have collected about you; (b) Right to Correction β request correction of inaccurate, outdated, or incomplete account data; (c) Right to Deletion β request permanent erasure of your personal data; and (d) Right to Non-Discrimination β you will never be denied equal service, charged different rates, or penalized for exercising your statutory privacy rights. To submit a request, use the in-app settings or email support@support.my-beauty-app.com.
7. In-App Account Deletion Procedure (App Store Guideline 5.1.1)
In strict compliance with Apple App Store Review Guideline 5.1.1(v) and Google Play Data Safety standards, you may permanently delete your account directly inside the mobile app at any time by navigating to: Profile > Settings > Delete Account (or Salon Preferences > Delete Account for salon owners), or by visiting our public web deletion guide at https://my-beauty-app.com/delete-account. Upon confirming deletion, your authentication records and personal profile identifiers are immediately deactivated and permanently expunged within thirty (30) days, except for financial transaction logs required to be retained by law.
8. Data Retention & Archival Schedule
Active user records are retained for as long as your account remains active. Financial transaction records, booking receipts, chargeback logs, and 1099-K tax reports are retained for seven (7) years to comply with federal IRS, New York State Department of Taxation and Finance, and New Jersey Division of Taxation statutory requirements. Upon account deletion, non-financial identifying data is permanently erased within thirty (30) days.
9. Security Safeguards & NY SHIELD Act Compliance
We implement and maintain reasonable administrative, technical, and physical safeguards conforming to the New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act (N.Y. Gen. Bus. Law Β§ 899-bb) and New Jersey data security standards. All network traffic is encrypted using modern Transport Layer Security (TLS 1.3), and all cloud database storage is encrypted at rest using AES-256. In the unlikely event of a security breach involving private data, we maintain established incident response protocols to promptly notify affected users and state attorneys general in compliance with N.Y. Gen. Bus. Law Β§ 899-aa and N.J. Stat. Ann. Β§ 56:8-163.
10. Children's Online Privacy (COPPA Compliance)
Our platform is strictly intended for individuals who are eighteen (18) years of age or older. We do not knowingly solicit or collect personal information from individuals under the age of 18. If we discover that personal data of a minor has been collected without verified parental or guardian consent, we will promptly delete the data from our active systems.
11. Privacy Inquiries & Data Protection Officer
For any questions, concerns, data access requests, or regulatory inquiries regarding this Privacy Policy or our data protection practices, please contact our privacy team at: Mi Belleza Privacy Office, Email: support@support.my-beauty-app.com.