This policy explains how SoftBela handles personal information when you visit softbela.com, when your business uses the SoftBela workspace, and when a client books an appointment through a salon page hosted by us. It applies to every plan and every country in which we operate.
1. Controller and processor roles
For your own account data (name, work email, phone, billing details, sign-in records) SoftBela is the controller. For the business records you create inside the workspace — clients, appointments, sales, invoices, stock — your business is the controller and SoftBela acts only as a processor, following your instructions.
- We never sell business or client data, and never use it for advertising.
- We do not use your client records to train machine-learning models.
- Salon staff only see the data of the organisation they belong to; isolation is enforced at database level.
2. Information we collect
We limit collection to what the service needs to work.
- Account data: full name, email, phone, preferred language, role and organisation.
- Business data you enter: services, prices, staff, schedules, clients, appointments, sales, payments, invoices, stock movements and expenses.
- Booking data from your clients: first and last name, phone, email, chosen service, professional, date, notes and deposit reference.
- Billing data: plan, subscription status, invoice history and payment references. Full card numbers are never stored by SoftBela.
- Technical data: IP address, device and browser type, pages viewed, error reports and security events such as failed sign-ins.
3. Why we process it, and on what legal basis
Each purpose has a lawful basis under the GDPR and equivalent frameworks such as POPIA in South Africa.
- Contract: creating your workspace, running bookings and POS, sending appointment confirmations and reminders, issuing invoices.
- Legitimate interests: keeping the platform secure, preventing fraud and abuse, measuring aggregate product usage, improving features.
- Legal obligation: retaining accounting, tax and invoicing records for the period required by local law.
- Consent: optional marketing emails and non-essential analytics. You can withdraw consent at any time.
4. Automated messages sent to your clients
When your business enables confirmations, reminders or marketing, the messages are sent in the language configured for your organisation, from SoftBela infrastructure on your behalf and with your business name visible. You are responsible for having a lawful basis to contact each client. Every marketing message carries an opt-out, and opt-outs are honoured immediately across your organisation.
5. Service providers we rely on
We use a small number of vetted sub-processors, each bound by a data processing agreement and permitted to use the data only to deliver their service to us.
- Supabase — managed PostgreSQL database, authentication and file storage.
- Vercel and Cloudflare — application hosting, content delivery and protection against attacks.
- Resend — delivery of transactional and notification email.
- Payment providers such as Débito Pay, M-Pesa, e-Mola, mKesh, PayFast and card acquirers — processing of deposits, subscription charges and payouts.
6. International transfers
SoftBela serves businesses in Africa, Europe and the Americas, so data may be processed outside your country by the providers listed above. Where personal data leaves the EEA, the United Kingdom or South Africa we rely on Standard Contractual Clauses or an equivalent transfer mechanism, together with encryption in transit and at rest.
7. Security measures
Security is designed into the platform rather than added on top.
- TLS for all traffic; encryption at rest for the database, backups and uploaded files.
- Row-level security so every query is scoped to a single organisation.
- Role-based permissions (owner, manager, receptionist, professional, cashier, accountant).
- Privileged operations run only on the server, never in the browser, and secrets are never shipped to client code.
- Audit logging of sensitive actions, automated daily backups and least-privilege access for our own staff.
8. How long we keep data
Retention is tied to purpose, not kept indefinitely.
- Business and client records: for as long as your subscription is active.
- After cancellation: 30 days so you can export your data, then deletion or irreversible anonymisation within 90 days.
- Invoices and accounting records: retained for the minimum period required by tax law in your country.
- Security and audit logs: up to 12 months.
9. Your rights
You may request access, correction, a portable export, deletion, restriction of processing or an objection to processing, and you may withdraw consent for marketing at any time. Write to privacy@softbela.com; we answer within 30 days and never charge for a first request. If your client contacts us directly about data held by your salon, we forward the request to you and support you in answering it. You can also complain to your national data protection authority.
10. Children and data breaches
SoftBela is a business tool and is not intended for use by children. Where a minor is a salon client, their record should be entered by a parent or guardian with consent. If a breach affecting personal data occurs, we notify affected businesses and the relevant supervisory authority without undue delay and within 72 hours where the law requires it, together with the facts known, the likely impact and the steps we have taken.
11. Changes to this policy
We update this policy when the product or the law changes. Material changes are announced by email and inside the workspace at least 14 days before they take effect, and the revision date at the top of this page always reflects the current version.
Questions about this policy?
Write to us and a person will answer — we do not use automated replies for legal requests.
privacy@softbela.com
Registered office: SoftBela — 90 Rivonia Road, 2nd Floor, Webber Wentzel Building, Sandton, 2097, Wakkermans Office Tower Building, South Africa · (+27) 63 595 7929