Salon POS helps salons manage customers, staff, appointments, inventory, and sales. The till keeps working from data stored on the device, and connecting a salon account for cloud sync is optional. This policy covers the Android and iOS apps, our website and online booking pages, and connected WhatsApp and AI features. Features and permissions can differ between platforms and versions.
Salon POS is a product operated and published by Sakivi. It is developed and published under the alfaOne name, a brand owned by Alfa Systems — which is why the contact address below is an alfasystemscv.com one. If you have a privacy question or want to request access to or deletion of information connected to your account, contact support@alfasystemscv.com.
Depending on the features you use, Salon POS may store the following on your device and, when cloud sync is enabled, in the salon's Supabase workspace:
We receive information when you enter it, when the salon's owner or a staff member enters it, when you connect an account, or when the app performs a feature you request. We do not sell personal information.
Customer names, phone numbers, appointments and notes are entered by the salon or supplied by a customer through an online booking. Booking creates or updates a customer record linked to the appointment, which becomes available on the salon’s connected devices. The salon decides what to keep. The salon is responsible for telling its customers that it keeps these records and for handling their requests. A customer who wants a record corrected or deleted can ask the salon directly, or write to us at the address below and we will pass the request to the salon and delete the cloud copy on its instruction.
Salon POS uses Supabase for account authentication and sessions. Android and website sign-in use Google Sign-In. iOS also offers Sign in with Apple. The sign-in provider processes authentication under its own privacy terms and shares the account details needed to sign you in; we never receive your Google or Apple password. Salon POS receives only the account details and tokens needed to identify you and keep you signed in.
The owner and staff PINs are a separate, local thing. They unlock the till on that phone, they are not an account, and they create no record on any server. Creating an account is optional: the till runs without one.
When you connect Salon POS to the cloud, business records are synchronized through Supabase so authorized members can work across enrolled devices. Access is limited by organization membership, role, location, and permissions. Only the salon's owner can end someone's access or revoke a device, which prevents future sync from that person or device.
The salon's owner can invite staff or enroll a device using a link or QR code. A current invitation is single-use, can be revoked, and expires after 15 minutes. The link or QR code contains a temporary secret, so treat it like a password and share it only with the intended person. The server stores a one-way hash of that secret rather than the secret itself. A preview may show limited salon, location, staff, and role information so the recipient can confirm the invitation; it does not include customer or financial records. Claiming an invitation creates or confirms the relevant membership and device enrollment.
A salon can have a public booking page at salonpos.alfaone.app/book/…. It is genuinely public: anyone with the address can open it, and search engines may index it. It shows the salon's name, services, staff, and available times — never customer or financial records.
Someone booking an appointment enters their first and last name, phone number, and optionally an email address and a note. These details become a customer record and appointment in the salon’s records and sync to its connected devices. The form also offers an optional WhatsApp permission choice, described below. Booking does not require permission for WhatsApp messages. The page is hosted by Vercel, which handles the ordinary technical information any web host sees — network address, time of the request, which page was asked for, and errors — and our booking measurement is described below. On supported app versions, the salon owner can turn off “Accept online bookings” in the booking-page settings. You can also contact us at the address below for help switching a page off.
The booking page uses this browser tab’s session storage to recover an unfinished booking, including the contact details, booking choices, note, and WhatsApp choice you entered. A draft is used for recovery only while it is less than 30 minutes old, and is cleared after a completed booking or when an expired draft is checked. Browser storage can also hold visit identifiers and a receipt used to retry an uncertain submission without creating a duplicate. Clearing the tab’s site data removes these local copies; it does not cancel a submitted booking.
If you choose the WhatsApp option on a salon’s booking page, you agree to receive WhatsApp messages from that salon, including booking confirmations, reminders, appointment updates, offers, and promotions. The choice is optional and starts unchecked. Permission applies to the salon named on the page; it is not permission for unrelated businesses to contact you. Earlier permission for booking notifications alone is not treated as permission for offers.
We save the phone number, salon and customer association, what permission was given, its source and wording version, the time it was recorded, and any withdrawal. These records help the salon respect your choice. Messaging services process the recipient’s phone number, message content, and delivery information. Automated messages use Meta’s WhatsApp Business Platform, rather than relying only on the WhatsApp app installed on the salon’s phone.
You can reply STOP on WhatsApp to stop automated customer messages, or STOP OFFERS to stop offers. You can also ask the salon to withdraw permission. A recorded opt-out blocks the corresponding messages; a later booking or another check of the booking box does not silently remove that block. Sending an ordinary message to the salon’s WhatsApp assistant does not, by itself, grant permission for offers or cancel an existing opt-out. You can still book without choosing WhatsApp messages.
If you message a salon’s WhatsApp assistant, we process your message and the context needed to reply. Replies may be generated with OpenAI using relevant salon information. WhatsApp, our service, and the AI provider process the information you include in that conversation. Avoid sending information that is not needed for your request. Salon owners can separately link their own WhatsApp number for requested assistant replies and business alerts; this does not change customers’ permissions.
Owner and staff PINs control access to the till on a device. They are stored on that device as salted one-way hashes, never as readable PINs, and they are not uploaded by cloud sync. What does sync for each staff member is their name, role, whether they are active, their permission settings, and their pay and commission rate. Salon POS does not offer fingerprint or face unlock, and never asks you to prove who you are with one. On Android, the Google Sign-In component declares biometric permissions that may appear in the Play listing. Salon POS does not use those permissions to unlock the till. A sign-in provider or the operating system may handle its own authentication; Salon POS does not receive fingerprint or face data.
Camera features depend on the platform. The app can scan a QR code to join a salon or enrol a device. On Android, receipt scanning reads words on the phone; the receipt picture is not uploaded, and only the extracted words are sent if the owner includes them in an assistant question. Separately, if you choose an image attachment or an image for AI editing in a supported iOS feature, that image is sent for the requested processing, as described below.
Salon POS includes an optional assistant the salon owner can ask about their sales, clients, and marketing. For typed questions, the owner's question, the recent messages of that conversation, and the salon information needed for the answer — such as service names and prices, sale totals, client names, and opening hours — are sent over an encrypted connection through our server to OpenAI to work out an answer. This happens when the owner chooses to use the assistant after its in-app disclosure. Information typed, pasted, attached, or spoken by the owner may also contain personal details; only include what is needed for the request.
Salon POS does not process payments and does not connect to any payment provider. The published app has no payment credentials built into it, so it cannot send a payment request to M-Pesa, Safaricom, a card network, or anyone else. Money is taken outside the app.
What the app records is what a staff member types at checkout: the payment method chosen for a sale, the amount, and — if they enter one — a payment reference such as an M-Pesa confirmation code the customer read out. Those details are stored with the sale, and they sync with the rest of the salon's records when cloud sync is enabled. No card numbers, PINs, or payment credentials are ever entered into or stored by Salon POS.
You can create or share backups, receipts, reports, price lists, and other exports. You choose the destination, such as files, email, cloud storage, or a messaging app, and that destination's privacy and retention rules apply. On Android, eligible app data may also be included in encrypted Google account backup or device-to-device transfer according to the device's backup settings. This is separate from Salon POS cloud sync. You are responsible for securing and deleting copies saved outside Salon POS.
We use service providers only to operate the feature you choose:
These providers may process technical information such as network addresses, request times, service identifiers, and error information needed to run and protect their services.
Our booking website measures page views, interactions, and started bookings to help salons understand how people reach their booking page and whether they book. It sends event and visit identifiers, the salon’s booking-page identifier, and any campaign source or inquiry identifier carried by the link to our service. These measurement events do not include the names, phone numbers, notes, or other form text you type. A successful booking can be linked to the visit and its campaign or inquiry source, however, so the resulting association is not anonymous. This helps the salon measure bookings following a campaign or customer inquiry.
The page keeps visit identifiers in browser session storage and uses them for measurement and safe booking retries. The visit identifier is renewed after 30 minutes without activity or after 24 hours, but a pending submission receipt can remain for retry. These are browser-session limits, not promises to delete the server’s booking, event, or attribution records at those times. Booking still works if measurement or browser storage is unavailable. This first-party measurement is separate from WhatsApp messaging consent and does not grant permission to send offers.
Salon POS does not currently include advertising, third-party analytics, or third-party crash-reporting SDKs, and it does not track you across other apps. The app and the services above may create operational logs needed for security, synchronization, and troubleshooting. If you choose to share diagnostic information with support, it may contain technical app or device details; review it before sending. These operational records are separate from customer consent for WhatsApp offers.
The marketing homepage uses Vercel Web Analytics to measure page visits and setup-button clicks. Click events include the button position and campaign source. We remove URL query strings and fragments from analytics page URLs. Campaign identifiers supplied in a link may be retained for the browser tab and passed to signup to attribute a completed setup; they are not sent as custom click-event properties. Analytics collection may be blocked by browser settings and is separate from permission for WhatsApp messages.
We use measures designed to protect salon data, including encrypted network connections, private app storage, one-way PIN and invitation-secret hashes, short-lived invitations, access controls, and Supabase row-level security. No system can guarantee absolute security. Keep devices locked, protect account access and invitation links, assign only the permissions staff need, and revoke lost devices promptly.
You can delete your Salon POS account at any time, and you do not need the app installed to do it. Full instructions are at salonpos.alfaone.app/delete-account.
Deleting your account removes your sign-in and your membership of the salon. If the salon carries on without you, your name remains attached to your past work there. Because a salon's records belong to the business and to the staff whose work and pay they document, deleting one person does not automatically erase them:
We complete deletion within 30 days of confirming the request. The deletion page explains exactly what is removed, what is kept, and how to export your data first.
Cloud records are kept while the salon account exists. When an owner deletes their account and no other owner remains, the salon's cloud records are deleted within 30 days and the last backup copies age out within 90 days. Salon owners can also delete individual records through the app at any time, and can contact us for any other cloud-data request. We may retain records where reasonably needed for security, disputes, legal obligations, or the integrity of financial and audit records.
You can choose whether to connect an online account at all, whether to import a contact, whether to send a message, whether to agree to WhatsApp offers and updates, whether to use AI or live voice, and whether to share an export. Device settings control notifications, platform backups, and app permissions. The salon's owner controls organization membership, staff roles, invitations, and enrolled devices. You can delete your account yourself, or contact us for help accessing or correcting your information; some business records may need to be handled by the salon that controls them.
Salon POS is a business tool intended for salon owners and staff. It is not directed at children and does not knowingly collect information from children.
We may update this policy as Salon POS changes. We will revise the effective date on this page and provide any additional notice required for a material change.