Privacy Policy
Last updated: October 2, 2026
At GlowSync, accessible via our mobile application and web services hosted by Synkn ("Developer", "We", "Us", or "Our"), user privacy is a paramount priority. This Privacy Policy outlines how we collect, process, secure, and disclose data across our platform, which encompasses our mobile application for salon owners and automatically generated public web booking pages accessible to end-clients.
1. Information We Collect
To provide business management tools, direct in-app appointment scheduling, specialist roster management, and public web booking portals, GlowSync processes the following categories of data:
- Salon Owner Account Data: Real names, verified active phone numbers (dial code and number), business emails, salon business names, business operation hours, and address parameters.
- Google Sign-In Data: If you choose to sign in with Google, we receive your name, email address, and Google account identifier from Google to create and authenticate your account. We do not receive your Google password.
- Staff & Specialist Profiles: Specialist names, working schedules, break times, and service assignments configured by the salon owner.
- Customer & Appointment Data: Client names, contact numbers, direct in-app appointment entries, and appointment logs managed by salon owners.
- Public Web Booking Submissions: Information submitted by end-clients through a salon's auto-generated public web page URL—including requested time slots, service selections, specialist preferences, client names, and contact phone numbers.
- Salon Location Data (Sensitive Personal Information): With explicit operating system permissions, we process business address data and geographic coordinates via Flutter frameworks to display salon storefronts and mapping details on public web booking pages.
- In-App Subscription Status: SaaS access tiers for salon management features are processed through Google Play In-App Purchases. We store only transaction status tokens and subscription tier IDs. We do not collect, process, or store financial payment details, cards, or bank records on our servers. All client appointments booked via the app or web portal are settled physically via cash directly at the salon business location.
- System & Identifier Storage:
- Secure tokens stored via
flutter_secure_storagefor active session management. - Device tokens for Push Notifications (via Firebase Messaging) to alert salon owners of new incoming booking requests and system updates.
- Local caching via
HiveandSharedPreferencesfor app responsiveness and offline functionality.
- Secure tokens stored via
- No Analytics or Advertising Trackers: GlowSync and its public booking pages do not use analytics tools, advertising trackers, or third-party tracking cookies. Only strictly necessary technical cookies (such as security and form-protection tokens) may be used to keep the service working securely.
2. Legal Basis for Processing & Data Retention
Our legal grounds for processing personal data depend on the specific feature and user role:
- Performance of a Contract: Operating salon owner accounts, hosting auto-generated public web pages, maintaining specialist availability calendars, and processing direct/web appointment bookings.
- Consent: Accessing location coordinates for public web mapping, sending transactional push notifications, and processing public booking requests submitted by end-clients.
- Legitimate Interests: Preventing automated booking spam on public web links, ensuring server infrastructure stability, and securing backend endpoints.
Roles & Responsibilities: Salon owners decide which customer and appointment data they enter into GlowSync and are responsible for having a lawful basis to do so. For that customer data, Synkn acts on the salon owner's behalf to provide the service. Information an end-client submits through a salon's public booking page is made available to that salon so it can fulfil the booking. For salon owner account data, Synkn determines the purposes of processing.
Data Retention Window: Active salon records, specialist profiles, and client appointment histories are retained while the business account remains active. Executing an account deletion completely purges all associated production server records within 72 hours. Where we maintain database backups, they are kept only for a limited rolling period, after which they are overwritten, and data deleted from production is not restored from them. Because GlowSync does not process payments or collect financial transactions, no financial or billing tax records are retained following account deletion.
3. Data Sharing & Cross-Border Transfers
We do not sell, rent, or trade personal or customer data. Data is shared exclusively with necessary service infrastructure providers:
- DigitalOcean: Primary cloud infrastructure host for databases, API backends, application business logic, and public web booking page hosting.
- Google Firebase: Used strictly for transmitting transactional push notifications and real-time booking alerts to salon owner devices.
- Google Sign-In: Used, if you choose it, to sign in to your account with your Google account.
- Google Play Billing: Used to manage in-app SaaS subscriptions and access tiers.
- Mapping Services: We use
flutter_mapandgeocodingto process address data and display salon locations on public booking pages.
Cross-Border Data Transfers: Data hosted across DigitalOcean cloud clusters and Firebase messaging servers may be processed internationally. We rely on encrypted transport layers and on the contractual safeguards of our infrastructure providers, including Standard Contractual Clauses where applicable, to protect cross-border transfers.
4. Your Global Privacy Rights
Regardless of geographic location, Synkn extends core privacy controls to all business owners and web page users:
- Right to Access & Portability: Request copies of business profiles, specialist records, or web booking logs.
- Right to Rectification: Salon owners can edit business hours, specialist availability, services, and appointment listings directly within the app.
- Right to Erasure: Salon owners can delete and permanently remove their account and all associated data themselves, directly from within the GlowSync app, without contacting us (see Section 6 for the steps). You may also request permanent deletion of business profiles, specialist lists, or public booking submissions by contacting us.
- Right to Withdraw Consent: Revoke device location or notification permissions at any time via operating system settings.
5. Jurisdiction-Specific Provisions
Additional region-specific statutory terms apply to businesses and end-clients operating in these regions:
5.1 United States (CCPA / CPRA / COPPA)
- No Sale or Sharing: We do not sell personal data or share user information for cross-context behavioral marketing.
- Sensitive Location Data: Business location data is processed strictly to render mapping views on public web booking portals.
- COPPA Compliance: GlowSync mobile applications and public web booking portals are not directed to children under 13.
5.2 European Economic Area (EEA, including Finland, France, Germany, Italy, the Netherlands and Spain) & United Kingdom (GDPR / UK GDPR)
- Supervisory Complaints: Users have the right to lodge complaints with their local Data Protection Authority or the UK ICO.
- Age Threshold: Services are not intended for individuals under 16 without verifiable parental consent.
5.3 India (Digital Personal Data Protection Act - DPDP)
- Consent-Based Grounds: Personal data submitted through app interfaces or public web forms is processed based on explicit consent or statutory provisions.
- Right to Nominate: Users may nominate a representative to exercise privacy rights in the event of death or incapacity.
- Grievance Officer: Submit grievances to glowsync@synkn.app for resolution within statutory timelines.
5.4 Saudi Arabia (PDPL) & UAE (Federal Law No. 45)
- Data Safeguards: Your data is processed on DigitalOcean and Firebase infrastructure outside your country. We protect it with encrypted transport and access controls, and process it in line with the cross-border transfer requirements of the Saudi PDPL and UAE Federal Law No. 45 to the extent applicable.
5.5 Canada (PIPEDA)
- Cross-Border Notice: Data processed outside Canada may be subject to foreign law enforcement access under lawful authority.
5.6 Australia (Privacy Act 1988 / APPs)
- Overseas Transfers: Cross-border data infrastructure disclosures are made in line with Australian Privacy Principle 8 (APP 8).
5.7 Bangladesh (Personal Data Protection Act, 2026)
- Consent & Rights: Personal data is processed with informed consent or another lawful basis. You may request access, correction, or deletion of your personal data.
- Cross-Border Transfers: Your data is hosted on servers outside Bangladesh. By using GlowSync you acknowledge and consent to this transfer, which is protected by encrypted transport and access controls.
- Complaints: You may contact us at glowsync@synkn.app or lodge a complaint with the competent Bangladeshi data protection authority.
5.8 Brazil (LGPD - Lei Geral de Proteção de Dados)
- Data Subject Rights: You may request confirmation of processing, access, correction, anonymization, portability, deletion, information about sharing, and revocation of consent.
- International Transfers: Data is hosted outside Brazil and transferred under the safeguards permitted by the LGPD, including contractual clauses and your consent.
- Authority & Contact: You may lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD). Privacy requests can be sent to glowsync@synkn.app.
5.9 China (Personal Information Protection Law - PIPL)
- Consent: Personal information is processed based on your consent. You may withdraw consent at any time through the app or by contacting us.
- Cross-Border Transfer: Your personal information is stored and processed on servers outside mainland China. By using GlowSync you give separate consent to this transfer.
- Your Rights: You may access, copy, correct, delete, and request an explanation of how your personal information is processed.
5.10 Indonesia (Personal Data Protection Law - Law No. 27 of 2022)
- Data Subject Rights: You may access, correct, delete, restrict, and withdraw consent for the processing of your personal data, and request data portability.
- Cross-Border Transfers: Data is transferred to and hosted in countries outside Indonesia, protected by encrypted transport and contractual safeguards.
- Contact: Exercise your rights via glowsync@synkn.app.
5.11 Japan (Act on the Protection of Personal Information - APPI)
- Purpose of Use: Personal information is used only for the purposes described in this Privacy Policy.
- Overseas Transfers: Data is hosted on servers outside Japan. By using GlowSync you consent to this transfer. We do not provide personal data to third parties except the infrastructure providers listed in Section 3.
- Your Rights: You may request disclosure, correction, suspension of use, or deletion of your retained personal data via glowsync@synkn.app.
5.12 Russia (Federal Law No. 152-FZ "On Personal Data")
- Consent: Personal data is processed with your informed consent, which you may withdraw at any time.
- Data Location: Your data is processed on servers located outside the Russian Federation. By using GlowSync you acknowledge this and consent to the cross-border transfer.
- Your Rights: You may request information about, correction of, or deletion of your personal data via glowsync@synkn.app.
5.13 South Africa (Protection of Personal Information Act - POPIA)
- Your Rights: You may request access to, correction of, or deletion of your personal information, and may object to its processing.
- Cross-Border Transfers: Data is hosted outside South Africa under safeguards consistent with POPIA Section 72, including your consent and contractual protections.
- Complaints: You may lodge a complaint with the Information Regulator (South Africa).
5.14 South Korea (Personal Information Protection Act - PIPA)
- Your Rights: You may request access, correction, deletion, suspension of processing, and withdrawal of consent for your personal information.
- Overseas Transfers: Your information is transferred to and hosted on servers outside South Korea (DigitalOcean and Google Firebase) for hosting and push notifications, as described in Section 3. By using GlowSync you consent to this transfer.
- Age Threshold: Services are not directed to children under 14.
6. Google Play Compliant Account & Data Deletion Protocol
In compliance with Google Play Store rules, GlowSync features a direct account deletion option inside the app:
Steps to Delete Account:
- Open GlowSync and navigate to Profile.
- Scroll to the Danger Zone section.
- Tap Delete Account.
- Confirm by entering your current password. Note for Google Authentication Users: If you originally registered or signed in using Google Sign-In, you must first create an account password via Profile > Account / Change Password before executing account deletion.
Note on Subscriptions: Deleting an account purges operational data from our servers but does not cancel active Google Play subscriptions. Subscriptions must be cancelled in your Google Play Store account settings.
Account deletion requests automatically purge business profiles, specialist rosters, business timings, and public web page configurations from DigitalOcean servers within 72 hours.
7. Policy Updates
We may update this Privacy Policy to reflect app updates or regulatory changes. Revisions will be indicated by changing the "Last updated" date at the header. For material changes, we will also notify you through an in-app notice or by email.
8. Privacy Contact & Grievance
For questions, manual deletion requests, or privacy inquiries concerning public web booking pages, contact us at:
- Email: glowsync@synkn.app
- Support Web Endpoint: Contact Us