Security and data protection
Updated 24 September 2026
The data of a salon's clients belongs to that salon. We hold and process it only so that the program can work, and only on the salon's instructions. Here is what we do to keep it safe.
A separate database for every salon
Each salon works with its own separate database. Which salon you are in is decided by your login, not by the address of the page, so no one can reach another salon's data by putting a different name in the link.
Encrypted connection
Everything travels over HTTPS with TLS 1.2 or higher. Certificates are issued and renewed automatically, and an unencrypted address is redirected to the encrypted one. For a year after the first visit the browser is not allowed to open the site without encryption. Login cookies are marked Secure and HttpOnly: they never travel in the clear and page scripts cannot read them.
Passwords and signing in
- Passwords are stored as bcrypt hashes. Neither we nor anyone with access to the database can read a password.
- Two-step login can be switched on: after the password the program sends a six-digit code to your e-mail. A device you confirm is remembered for 30 days.
- Five wrong tries for one login name, or twenty five from one address, close the door for 15 minutes.
- A password reset link lives for 30 minutes and is not stored in readable form.
Who sees what inside the salon
The owner decides which sections each member of staff may open, down to single actions inside a section. Only the owner can add staff, change rights and change passwords. Every 90 days the program reminds the owner to review the list of access.
Money and cards
Card numbers are never typed into the program and never stored. The database keeps only the card brand and the last four digits, so one payment can be told from another. Payment itself happens on the payment provider's side. The key to the bank feed and the descriptions of bank transactions are stored encrypted.
Backups
Every night a copy is taken of every salon's database and of the files: client photos, appointment photos and signed documents. Copies are kept for 30 days, older ones are deleted. Every night an encrypted archive also goes to separate storage outside the server, where it is kept for 60 days: if the server is lost, the data is restored from there. The encryption key is kept apart from the archives.
The server
The program runs on a server in New York, USA. A firewall is on, the server can only be reached with a key, and password guessing is blocked automatically. A vulnerability scan report arrives every week.
How long data is kept, and deleting it
Data is kept while the salon uses the program. The e-mail and SMS journals can be set to clean themselves after a chosen period. The client base and the other tables export to Excel at any time, including after you stop subscribing. At the owner's request we delete the salon's account.
Who receives data
Only the services the salon switched on itself, and only what those services need:
- Stripe and Square — taking payments and deposits.
- QuickBooks — sending clients and sales to the books.
- Google Calendar — appointments in a master's calendar.
- The mail service — sending e-mail on behalf of the salon. SMS are sent from the salon's own phone: the program only prepares the text and hands the number to no one.
- WhatsApp — messages to clients, if the salon connected it.
- Facebook and Instagram ads — only scrambled fingerprints of a phone and an e-mail, never the numbers themselves.
- Bank feed — the salon's own accounts, not its clients.
- Translation service — the text of message templates, with no client details filled in.
If an integration is off, nothing goes there.
What we do not do
- We do not sell data and do not pass it on for advertising.
- We do not write to your clients ourselves.
- We do not store card numbers.
- We do not read the salon's conversations with clients for marketing.
If something goes wrong
Write to support@kaizerbooking.com. If a salon's data is ever affected, we tell the owner.
See also our Privacy Policy and Terms.
Безопасность и защита данных
Обновлено 24 сентября 2026
Данные клиентов салона принадлежат салону. Мы храним и обрабатываем их только для того, чтобы программа работала, и только по поручению салона. Ниже — что именно мы для этого делаем.
Отдельная база у каждого салона
Каждый салон работает со своей отдельной базой данных. Нужный салон определяется по вашему входу в программу, а не по адресу страницы, поэтому получить чужие данные, подставив чужое имя в ссылку, нельзя.
Защищённое соединение
Весь обмен идёт только по HTTPS, TLS 1.2 и выше. Сертификаты выпускаются и обновляются автоматически, обращение по незащищённому адресу переводится на защищённый. Браузеру запрещено открывать сайт без шифрования в течение года после первого визита. Куки входа помечены как Secure и HttpOnly: они не уходят по открытому каналу и недоступны скриптам страницы.
Пароли и вход
- Пароли хранятся в виде хешей bcrypt. Ни мы, ни кто-либо с доступом к базе не может прочитать пароль.
- Можно включить вход в два шага: после пароля программа присылает шестизначный код на почту. Устройство, которое вы подтвердили, запоминается на 30 дней.
- Пять неверных попыток по одному логину или двадцать пять с одного адреса закрывают вход на 15 минут.
- Ссылка на восстановление пароля живёт 30 минут и хранится не в открытом виде.
Кто что видит внутри салона
Владелец сам решает, какие разделы открыты каждому сотруднику, вплоть до отдельных действий внутри раздела. Заводить сотрудников, менять права и пароли может только владелец. Раз в 90 дней программа напоминает проверить список доступов.
Деньги и карты
Номера карт в программу не вводятся и нигде не хранятся. В базе остаются только тип карты и последние четыре цифры, чтобы отличить один платёж от другого. Оплата проходит на стороне платёжных систем. Ключ доступа к банковской выписке и описания операций хранятся зашифрованными.
Резервные копии
Каждую ночь снимается копия базы каждого салона и файлов: фотографий клиентов, фотографий записей и подписанных документов. Копии хранятся 30 дней, более старые удаляются. Каждую ночь зашифрованный архив уходит и в отдельное хранилище за пределами сервера, где хранится 60 дней: если сервер погибнет, данные восстанавливаются оттуда. Ключ шифрования хранится отдельно от архивов.
Сервер
Программа работает на сервере в Нью-Йорке, США. Включён сетевой экран, вход на сервер возможен только по ключу, перебор паролей блокируется автоматически. Раз в неделю приходит отчёт сканера уязвимостей.
Сроки хранения и удаление
Данные хранятся, пока салон пользуется программой. Для журналов писем и SMS можно включить автоочистку за выбранный период. Клиентскую базу и другие таблицы можно выгрузить в Excel в любой момент, в том числе после отказа от подписки. По запросу владельца мы удаляем аккаунт салона.
Кому уходят данные
Только тем службам, которые салон сам включил в настройках, и только то, что нужно для их работы:
- Stripe и Square — приём оплат и депозитов.
- QuickBooks — выгрузка клиентов и продаж в бухгалтерию.
- Google Календарь — записи в календаре мастера.
- Почтовая служба — отправка писем от имени салона. SMS уходят с телефона самого салона: программа только готовит текст и никому не передаёт номер.
- WhatsApp — сообщения клиентам, если салон подключил его.
- Реклама Facebook и Instagram — только обезличенные отпечатки телефона и почты, не сами номера.
- Банковская выписка — данные счетов салона, не его клиентов.
- Служба перевода — тексты шаблонов писем без подставленных данных клиентов.
Если интеграция выключена, данные туда не уходят.
Чего мы не делаем
- Не продаём данные и не передаём их для рекламы.
- Не пишем вашим клиентам от себя.
- Не храним номера карт.
- Не читаем переписку салона с клиентами ради маркетинга.
Если что-то пошло не так
Напишите на support@kaizerbooking.com. Если данные салона пострадают, мы сообщим об этом владельцу.
См. также Политику конфиденциальности и Пользовательское соглашение.
Seguridad y protección de datos
Actualizado el 24 de septiembre de 2026
Los datos de los clientes del salón pertenecen al salón. Los guardamos y tratamos solo para que el programa funcione, y solo por encargo del salón. Esto es lo que hacemos para protegerlos.
Una base de datos aparte para cada salón
Cada salón trabaja con su propia base de datos. El salón se determina por su inicio de sesión, no por la dirección de la página, así que nadie puede llegar a los datos de otro salón cambiando el nombre en el enlace.
Conexión cifrada
Todo viaja por HTTPS con TLS 1.2 o superior. Los certificados se emiten y renuevan solos, y una dirección sin cifrar se redirige a la cifrada. Durante un año desde la primera visita el navegador no puede abrir el sitio sin cifrado. Las cookies de acceso están marcadas como Secure y HttpOnly: nunca viajan en claro y los scripts de la página no pueden leerlas.
Contraseñas y acceso
- Las contraseñas se guardan como hashes bcrypt. Ni nosotros ni nadie con acceso a la base puede leerlas.
- Se puede activar el acceso en dos pasos: tras la contraseña el programa envía un código de seis cifras al correo. El dispositivo que confirme se recuerda 30 días.
- Cinco intentos fallidos con un mismo usuario, o veinticinco desde una misma dirección, cierran el acceso 15 minutos.
- El enlace para restablecer la contraseña dura 30 minutos y no se guarda en claro.
Quién ve qué dentro del salón
La propietaria decide qué secciones puede abrir cada empleado, hasta acciones concretas dentro de una sección. Solo la propietaria da de alta empleados y cambia permisos y contraseñas. Cada 90 días el programa recuerda revisar la lista de accesos.
Dinero y tarjetas
Los números de tarjeta no se escriben en el programa ni se guardan en ningún sitio. En la base quedan solo el tipo de tarjeta y los cuatro últimos dígitos, para distinguir un pago de otro. El cobro ocurre del lado de la pasarela de pago. La clave del extracto bancario y las descripciones de las operaciones se guardan cifradas.
Copias de seguridad
Cada noche se copia la base de cada salón y los archivos: fotos de clientes, fotos de citas y documentos firmados. Las copias se conservan 30 días y las más antiguas se borran. Cada noche un archivo cifrado va además a un almacenamiento separado fuera del servidor, donde se guarda 60 días: si el servidor se pierde, los datos se restauran desde allí. La clave de cifrado se guarda aparte de los archivos.
El servidor
El programa funciona en un servidor de Nueva York, EE. UU. Hay cortafuegos, al servidor solo se entra con clave y los intentos de adivinar contraseñas se bloquean solos. Cada semana llega un informe del escáner de vulnerabilidades.
Cuánto se guarda y cómo se borra
Los datos se guardan mientras el salón use el programa. Los registros de correo y SMS pueden limpiarse solos pasado el período que elija. La base de clientes y las demás tablas se exportan a Excel cuando quiera, también después de dejar la suscripción. A petición de la propietaria borramos la cuenta del salón.
Quién recibe datos
Solo los servicios que el salón activó, y solo lo que necesitan:
- Stripe y Square — cobros y depósitos.
- QuickBooks — envío de clientes y ventas a la contabilidad.
- Google Calendar — citas en el calendario del profesional.
- El servicio de correo — envío de correos en nombre del salón. Los SMS salen desde el propio teléfono del salón: el programa solo prepara el texto y no entrega el número a nadie.
- WhatsApp — mensajes a clientes, si el salón lo conectó.
- Publicidad de Facebook e Instagram — solo huellas cifradas del teléfono y del correo, nunca los números.
- Extracto bancario — las cuentas del propio salón, no las de sus clientes.
- Servicio de traducción — el texto de las plantillas, sin datos de clientes.
Si una integración está apagada, allí no va nada.
Lo que no hacemos
- No vendemos datos ni los cedemos para publicidad.
- No escribimos a sus clientes por nuestra cuenta.
- No guardamos números de tarjeta.
- No leemos las conversaciones del salón con sus clientes con fines de marketing.
Si algo va mal
Escriba a support@kaizerbooking.com. Si los datos de un salón se ven afectados, avisamos a la propietaria.
Vea también la Política de privacidad y los Términos.