
Last updated: July 2026. This policy describes how Beautonomi ("we", "us", "our") collects, uses, discloses, and protects personal information when you use our websites, the Beautonomi and Beautonomi Partner mobile applications, and related services (together, the "Platform"). By using the Platform, you acknowledge this policy.
Notices by jurisdiction. Depending on where you live, additional rights and requirements may apply. Sections below summarise common regions; they do not limit any mandatory protections you have under local law.
Beautonomi operates an online marketplace connecting customers with independent or business beauty and wellness providers. Depending on the activity, we may act as a controller (POPIA: responsible party) of your account and platform usage data, while providers are typically controllers of information they collect to deliver services (for example notes about your appointment, client records, or point-of-sale records they keep using our tools — where we host those records we act as a processor / operator on the provider's behalf). Payment, identity verification, hosting, and messaging partners act as processors or independent controllers as described below.
We aim to comply with applicable privacy laws in the regions where we operate or where users access the Platform, including without limitation:
If local law conflicts with a provision of this policy, local law prevails to the extent required.
We may collect:
You provide information when you register, book, list services, pay, verify your identity, message, or contact support. Automatic technologies collect device and usage data when you use the Platform. Third parties may provide information where you connect an account (e.g. sign-in with Apple or Google), where payment partners confirm transaction, settlement, or chargeback status, where our identity verification partner returns verification results, or where providers enter details about appointments and clients.
Beauty and wellness services may involve information about allergies, skin conditions, or similar topics that providers record to deliver services safely. Providers who enter such information are typically responsible as controllers for that treatment data; we host and process it on their behalf to operate messaging, bookings, client records, and compliance features. Where GDPR applies, we rely on applicable Article 6 and, where relevant, Article 9 bases (such as explicit consent or health care/treatment with professional secrecy as permitted by law). Do not upload unnecessary medical records through the Platform unless a feature explicitly requires it.
To keep the marketplace safe and meet legal obligations, we may ask customers or providers to complete identity verification through a specialist third-party verification partner. That process can involve:
This may involve biometric data. Where required by law we obtain your explicit consent in the verification flow before processing begins. The verification partner processes document and biometric data under contract with us and retains it in line with its own retention rules; we receive and store the outcome (approved / declined / needs review), limited extracted identity details, and risk warnings — not raw biometric templates. Verification records are sanitised of unnecessary personal information before storage. If you decline verification, some features (such as booking, payouts, or higher-risk actions) may be unavailable; contact support to discuss alternatives where the law provides them.
Providers may additionally be asked to complete business verification (KYB), including business registration documents and director or owner details, as required by payment partners and financial-crime laws.
We use data to operate, secure, and improve the Platform; process bookings, orders, and payments (online and in person); verify identity and business details; provide support; prevent fraud and abuse; enforce booking and cancellation policies; comply with law; and send service messages. Where GDPR-style laws apply, we rely on:
We share personal information with the following categories of recipients (current key partners named for transparency; they may change over time):
We use contracts (including standard contractual clauses where appropriate) to protect international transfers from the EEA/UK/CH, and comparable safeguards for cross-border transfers from South Africa under POPIA.
Providers can pay for sponsored placement on the Platform; sponsored results are labelled. This placement is first-party: we do not sell your personal information to third-party advertising networks. We may use campaign and referral attribution parameters (such as UTM tags) to measure our own marketing, subject to your cookie choices.
We keep information only as long as needed for the purposes above, including legal, tax, and dispute resolution. As a guide: booking and transaction records and payment receipts are kept for around 5 years for financial and tax compliance; fraud or safety records up to 7 years; support tickets around 3 years; anonymised analytics indefinitely. Full details, including what is deleted immediately when you close your account, are on our Account & Data Deletion page.
We implement technical and organisational measures appropriate to the risk (encryption in transit, access controls, audit logging, monitoring). No method of transmission or storage is 100% secure. Where required by law we will notify you and regulators of qualifying data breaches.
Beautonomi is the responsible party for the processing described in this policy. You may request access to, correction of, or deletion of personal information we hold, and object to processing, subject to exceptions. Direct requests to our Information Officer via support@beautonomi.com or Help & support. If unresolved, you may complain to the Information Regulator (South Africa) (inforeg.org.za).
You may have rights to access, rectify, erase, restrict processing, data portability, object to certain processing, and withdraw consent (including consent to biometric verification). You may lodge a complaint with your local supervisory authority (e.g. ICO in the UK, a lead authority in the EEA, or FDPIC in Switzerland).
California residents (CPRA): You may have rights to know categories and specific pieces of personal information collected; delete; correct inaccuracies; opt out of sale or sharing (including certain cross-context behavioural advertising); and limit use of sensitive personal information. We do not discriminate for exercising rights. You may use an authorised agent where the law allows.
"Sale" and "sharing": We do not sell personal information for money. We may share data with analytics partners in ways that some state laws treat as "sharing"; where required we honour opt-out signals (including Global Privacy Control) and requests.
Other US states: Colorado, Virginia, Connecticut, Utah, and others may grant similar access, deletion, correction, and opt-out rights. Submit requests via our Help centre; we will verify your identity.
You may have rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent, plus complaint to the ANPD.
You may access and request correction of personal information. Complaints may be raised with the OAIC if unresolved.
Canada: access and challenge accuracy under PIPEDA or provincial equivalents. Singapore: access and correction rights under PDPA; you may withdraw consent where processing is consent-based.
Where the DPDPA applies, you may have rights to access, correction, erasure, grievance redressal, and nomination, as provided by law and our processes.
The Platform is not directed to children under the age where parental consent is required in your jurisdiction. We do not knowingly collect personal information from such children without appropriate consent.
We use automated tools for fraud and risk screening (for example payment risk scores and verification warnings). Decisions that produce legal or similarly significant effects — such as declining verification or closing an account — include human review or an appeal route via support, except where law permits otherwise.
If we are involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction subject to confidentiality and continued protection consistent with this policy.
Our apps are distributed through Apple App Store and Google Play. Those platforms have their own privacy terms. Links to third-party sites (including payment pages hosted by our payment partners) are governed by their policies.
If you believe content on the Platform infringes your copyright or other rights, contact us through Help & support with enough detail to locate the material and verify your claim. We may remove or disable access to content where appropriate.
We may update this policy and will post the revised version with a new effective date. Where required, we will notify you or seek consent.
For privacy requests or questions, contact us at support@beautonomi.com or through Help & support. We will respond within timelines required by applicable law.
Please review the supplemental privacy policies linked within the privacy policy documents, such as for certain Beautonomi services, that may be applicable to you.
We'll start with some questions and get you to the right place.
You can also give us feedback.