1. Home
  2. Privacy Policy

Beautonomi Privacy Policy

People collaborating

Privacy Policy

Last updated: July 2026. This policy describes how Beautonomi ("we", "us", "our") collects, uses, discloses, and protects personal information when you use our websites, the Beautonomi and Beautonomi Partner mobile applications, and related services (together, the "Platform"). By using the Platform, you acknowledge this policy.

Notices by jurisdiction. Depending on where you live, additional rights and requirements may apply. Sections below summarise common regions; they do not limit any mandatory protections you have under local law.

1. Who we are & roles

Beautonomi operates an online marketplace connecting customers with independent or business beauty and wellness providers. Depending on the activity, we may act as a controller (POPIA: responsible party) of your account and platform usage data, while providers are typically controllers of information they collect to deliver services (for example notes about your appointment, client records, or point-of-sale records they keep using our tools — where we host those records we act as a processor / operator on the provider's behalf). Payment, identity verification, hosting, and messaging partners act as processors or independent controllers as described below.

2. Geographic scope

We aim to comply with applicable privacy laws in the regions where we operate or where users access the Platform, including without limitation:

  • South Africa — Protection of Personal Information Act (POPIA).
  • European Economic Area (EEA), United Kingdom, and Switzerland — GDPR, UK GDPR / Data Protection Act 2018, and Swiss FADP (as applicable).
  • United States — Federal and state laws (including California Consumer Privacy Act / California Privacy Rights Act where applicable, and similar state statutes).
  • Brazil — Lei Geral de Proteção de Dados (LGPD).
  • Australia — Privacy Act 1988 (Cth) and Australian Privacy Principles.
  • Canada — Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial laws where they apply.
  • Singapore — Personal Data Protection Act (PDPA).
  • India — Digital Personal Data Protection Act (DPDPA), where applicable.

If local law conflicts with a provision of this policy, local law prevails to the extent required.

3. Personal information we collect

We may collect:

  • Account & profile: name, email, phone, password hash, photo, language, marketing preferences, referral codes.
  • Booking & commerce: appointments (including group, recurring, and custom-offer bookings), cart and retail product orders, gift card purchases and redemptions, memberships, service addresses for at-home or mobile appointments, in-platform messages, reviews, and support tickets.
  • Guest & portal bookings: if you book without an account (for example through a booking link or the guest portal), we process the contact and booking details you provide to deliver and manage that booking.
  • Payments: transaction metadata for online payments, in-person card machine payments, and point-of-sale integrations (we use payment partners; we do not store full card numbers). For providers this includes payout, settlement, and reconciliation records.
  • Identity verification: where verification is required (for example for safety, payouts, or fraud prevention), our verification partner collects images of your government-issued identity document and a selfie, and performs facial matching and liveness checks. We receive the verification outcome, risk signals, and limited extracted identity details (such as name and document validity). See section 6.
  • Provider & business data: business profile, services, pricing, staff, availability, cancellation policies, business registration and director details for business (KYB) verification, bank details for payouts, and card machine / terminal registration details (such as device serial numbers and merchant identifiers).
  • Device & technical: IP address, device identifiers, app version, push notification tokens, crash logs, coarse location from IP, and — with permission — precise location for features such as travel, at-home services, or nearby search.
  • Analytics & communications: product analytics (where consented or permitted), email / SMS / WhatsApp / push engagement, and marketing attribution data (such as campaign or referral parameters) where allowed by your settings.
  • Cookies & similar technologies: as described in our Cookie Policy. You can change your choices at any time via the Cookie settings link in the site footer.
  • Inferences: we may derive preferences, fraud risk scores, or segment labels from usage patterns to operate and secure the Platform.

4. Where we get personal information

You provide information when you register, book, list services, pay, verify your identity, message, or contact support. Automatic technologies collect device and usage data when you use the Platform. Third parties may provide information where you connect an account (e.g. sign-in with Apple or Google), where payment partners confirm transaction, settlement, or chargeback status, where our identity verification partner returns verification results, or where providers enter details about appointments and clients.

5. Sensitive, health-related, or special category information

Beauty and wellness services may involve information about allergies, skin conditions, or similar topics that providers record to deliver services safely. Providers who enter such information are typically responsible as controllers for that treatment data; we host and process it on their behalf to operate messaging, bookings, client records, and compliance features. Where GDPR applies, we rely on applicable Article 6 and, where relevant, Article 9 bases (such as explicit consent or health care/treatment with professional secrecy as permitted by law). Do not upload unnecessary medical records through the Platform unless a feature explicitly requires it.

6. Identity verification & biometric data

To keep the marketplace safe and meet legal obligations, we may ask customers or providers to complete identity verification through a specialist third-party verification partner. That process can involve:

  • capturing images of a government-issued identity document (front and back);
  • capturing a selfie or short video and comparing it to the document photo (facial matching); and
  • automated liveness detection to confirm a real person is present.

This may involve biometric data. Where required by law we obtain your explicit consent in the verification flow before processing begins. The verification partner processes document and biometric data under contract with us and retains it in line with its own retention rules; we receive and store the outcome (approved / declined / needs review), limited extracted identity details, and risk warnings — not raw biometric templates. Verification records are sanitised of unnecessary personal information before storage. If you decline verification, some features (such as booking, payouts, or higher-risk actions) may be unavailable; contact support to discuss alternatives where the law provides them.

Providers may additionally be asked to complete business verification (KYB), including business registration documents and director or owner details, as required by payment partners and financial-crime laws.

7. How we use information & legal bases (EEA/UK/CH)

We use data to operate, secure, and improve the Platform; process bookings, orders, and payments (online and in person); verify identity and business details; provide support; prevent fraud and abuse; enforce booking and cancellation policies; comply with law; and send service messages. Where GDPR-style laws apply, we rely on:

  • Contract — providing services you request.
  • Legitimate interests — security, analytics, product improvement, and marketplace integrity (balanced against your rights).
  • Consent — optional marketing, non-essential cookies, biometric identity verification, or tracking where required.
  • Legal obligation — tax, financial-crime, regulatory, or law enforcement requests subject to due process.

8. How we share information

We share personal information with the following categories of recipients (current key partners named for transparency; they may change over time):

  • Providers you book — your name, contact details, booking details, and (for at-home services) the service address, so they can deliver the appointment.
  • Payment & acquiring partners — e.g. Paystack for online payments, subscriptions, and payouts; PayCloud for Beautonomi in-person card machines; Yoco where a provider connects that point-of-sale integration.
  • Identity verification partner — to perform document, facial-match, and liveness verification described in section 6.
  • Hosting & infrastructure — e.g. Supabase (database, authentication, storage) and Vercel (web hosting).
  • Analytics — e.g. Amplitude for product analytics, subject to your cookie/consent choices.
  • Communications — e.g. OneSignal for push notifications, plus email, SMS, and WhatsApp Business Platform providers for booking and account messages you have requested or consented to.
  • Error & crash monitoring — e.g. Sentry, to diagnose and fix faults.
  • Delivery & courier partners — to fulfil retail product or card machine orders you place.
  • Professional advisers and authorities — where required by law, subject to due process.

We use contracts (including standard contractual clauses where appropriate) to protect international transfers from the EEA/UK/CH, and comparable safeguards for cross-border transfers from South Africa under POPIA.

9. Advertising, sponsored placement & attribution

Providers can pay for sponsored placement on the Platform; sponsored results are labelled. This placement is first-party: we do not sell your personal information to third-party advertising networks. We may use campaign and referral attribution parameters (such as UTM tags) to measure our own marketing, subject to your cookie choices.

10. Retention

We keep information only as long as needed for the purposes above, including legal, tax, and dispute resolution. As a guide: booking and transaction records and payment receipts are kept for around 5 years for financial and tax compliance; fraud or safety records up to 7 years; support tickets around 3 years; anonymised analytics indefinitely. Full details, including what is deleted immediately when you close your account, are on our Account & Data Deletion page.

11. Security

We implement technical and organisational measures appropriate to the risk (encryption in transit, access controls, audit logging, monitoring). No method of transmission or storage is 100% secure. Where required by law we will notify you and regulators of qualifying data breaches.

12. Your choices & controls

  • Marketing: opt out via unsubscribe links, in-app notification preferences, or account settings.
  • Push notifications: control in your device settings or in-app preferences.
  • Cookies & analytics: use the cookie banner or the Cookie settings link in the footer; see the Cookie Policy.
  • Location: control precise location in your device settings; some features (travel fees, nearby search) will be limited without it.
  • Account deletion: delete your account in-app under Account Settings → Privacy & Sharing → Delete Account, or follow the steps on Account & Data Deletion.

13. Your rights — South Africa (POPIA)

Beautonomi is the responsible party for the processing described in this policy. You may request access to, correction of, or deletion of personal information we hold, and object to processing, subject to exceptions. Direct requests to our Information Officer via support@beautonomi.com or Help & support. If unresolved, you may complain to the Information Regulator (South Africa) (inforeg.org.za).

14. Your rights — EEA, UK, Switzerland

You may have rights to access, rectify, erase, restrict processing, data portability, object to certain processing, and withdraw consent (including consent to biometric verification). You may lodge a complaint with your local supervisory authority (e.g. ICO in the UK, a lead authority in the EEA, or FDPIC in Switzerland).

15. Your rights — United States

California residents (CPRA): You may have rights to know categories and specific pieces of personal information collected; delete; correct inaccuracies; opt out of sale or sharing (including certain cross-context behavioural advertising); and limit use of sensitive personal information. We do not discriminate for exercising rights. You may use an authorised agent where the law allows.

"Sale" and "sharing": We do not sell personal information for money. We may share data with analytics partners in ways that some state laws treat as "sharing"; where required we honour opt-out signals (including Global Privacy Control) and requests.

Other US states: Colorado, Virginia, Connecticut, Utah, and others may grant similar access, deletion, correction, and opt-out rights. Submit requests via our Help centre; we will verify your identity.

16. Your rights — Brazil (LGPD)

You may have rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent, plus complaint to the ANPD.

17. Your rights — Australia

You may access and request correction of personal information. Complaints may be raised with the OAIC if unresolved.

18. Canada & Singapore (brief)

Canada: access and challenge accuracy under PIPEDA or provincial equivalents. Singapore: access and correction rights under PDPA; you may withdraw consent where processing is consent-based.

19. India (DPDPA)

Where the DPDPA applies, you may have rights to access, correction, erasure, grievance redressal, and nomination, as provided by law and our processes.

20. Children

The Platform is not directed to children under the age where parental consent is required in your jurisdiction. We do not knowingly collect personal information from such children without appropriate consent.

21. Automated decisions

We use automated tools for fraud and risk screening (for example payment risk scores and verification warnings). Decisions that produce legal or similarly significant effects — such as declining verification or closing an account — include human review or an appeal route via support, except where law permits otherwise.

22. Business transfers

If we are involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction subject to confidentiality and continued protection consistent with this policy.

23. Third-party links & app stores

Our apps are distributed through Apple App Store and Google Play. Those platforms have their own privacy terms. Links to third-party sites (including payment pages hosted by our payment partners) are governed by their policies.

24. Copyright and intellectual property complaints

If you believe content on the Platform infringes your copyright or other rights, contact us through Help & support with enough detail to locate the material and verify your claim. We may remove or disable access to content where appropriate.

25. Changes to this policy

We may update this policy and will post the revised version with a new effective date. Where required, we will notify you or seek consent.

26. Contact

For privacy requests or questions, contact us at support@beautonomi.com or through Help & support. We will respond within timelines required by applicable law.

Privacy Policy

Supplemental Privacy Policy Documents

Please review the supplemental privacy policies linked within the privacy policy documents, such as for certain Beautonomi services, that may be applicable to you.

  • Terms of Service
  • Cookie Policy
  • Account & Data Deletion
  • Identity verification & biometric data (in policy)
  • Sensitive & health-related data (in policy)
  • South Africa — POPIA summary (in policy)
  • EEA, UK & Switzerland — GDPR summary (in policy)
  • United States — state privacy rights (in policy)

Related articles

Help

Help centre

Get answers and contact support.

Learn

Account & profile

How account settings and privacy controls work on Beautonomi.

Learn

Security & privacy overview

Security practices and how to protect your account.

Need to get in touch?

We'll start with some questions and get you to the right place.

You can also give us feedback.