Loading...

Privacy Policy

Release: Beta / MVP
1. Who We Are (Platform Data Controller)

The Brushy platform is developed and operated by two independent freelance developers based in Switzerland ("Providers"). For any privacy or account-related inquiries, contact: support@Brushy.ch.

2. Data Processing Roles (FADP)

Under the Swiss Federal Act on Data Protection (FADP):

  • Salon End-Customer Data: The Salon acts as the Data Controller for all personal data of its clients. The Providers act solely as a Data Processor on behalf of the Salon.
  • Salon Account Data: The Providers process Salon contact and authentication details solely to maintain and secure the service.
  • Technical Sub-processors: Specialized third-party vendors are engaged for hosting infrastructure (servers located in Germany) and deployment pipelines (GitHub Actions). These providers hold no ownership rights over the data.
3. Types of Processed Data and Purposes

Only data strictly necessary for service delivery is processed:

  • Authentication data (Email, Passwords hashed via BCrypt);
  • Salon operational data (Appointments, Staff, Services, Customer profiles);
  • System and error logs (IP addresses, timestamps, diagnostic traces for cybersecurity).
4. Cookie Policy (Zero Trackers)
Zero Profiling or Third-Party Cookies

The Platform does NOT use any profiling cookies, tracking pixels, advertising tags, or third-party analytics (such as Google Analytics or Meta Pixel).

Only technical session cookies and encrypted security tokens strictly necessary to keep user login sessions secure are utilized.

5. Data Storage Location, Infrastructure, and Security

Databases and hosting servers are located in Germany (European Union), a country recognized as providing an adequate level of data protection under Annex 1 of the Swiss Data Protection Ordinance (DPO).

Application deployment is automated via Docker packages and GitHub Actions. No database containing end-customer personal data is stored within GitHub code repositories. All network transmissions are protected with TLS/HTTPS encryption.

6. User Rights and Data Retention

Under the FADP, users have the right to access, rectify, or request deletion of their data by contacting support@Brushy.ch. Upon account closure, operational data is retained for a maximum of 30 days to allow data export, after which it is permanently purged from all active servers.

7. Changes to this Privacy Policy

The Providers reserve the right to update this policy to reflect platform enhancements or regulatory changes.