Summary
This is a translation. The Portuguese version is the official one and prevails in case of any discrepancy.
1. Who processes your data
KAMPLISH – Desenvolvimento de Sistemas LTDA, CNPJ 35.977.805/0001-74, Av. Marquês de São Vicente, 1619, Edif. LED Barra Funda, Conj. 1510, Várzea da Barra Funda, São Paulo – SP, 01.139-003, Brazil ("Cutspot", "we") is the controller of the data needed to run the platform: accounts, profiles, bookings made through the app, subscriptions, notifications, security and support.
Each Business (barbershop, salon or professional) is an independent controller of the data it receives to serve you and of the data it enters on its own about its clients (records, notes, tabs, photos, birthday, tags). For that data, Cutspot acts as a processor, following the Business's instructions set out in the Terms of Service. Questions about how a Business uses your data should go to that Business; we can help route them if needed.
This Policy covers the iOS and Android apps, the web dashboard, the website and Cutspot support.
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Account & access | Name, email, password (stored hashed by the authentication provider), Google or Apple sign-in identifier, account type (client or business). | You; Google/Apple |
| Profile | Phone, photo, birth date, gender, language, theme, preferences and favorites. | You |
| Bookings | Business, location, professional, service, date, time, price, notes, chosen reference photo, status, attendance confirmation, reschedules, cancellations, no-shows, waitlist, applied discounts and campaigns. | You; the Business |
| Loyalty & clubs | Stamps, vouchers, redemptions, club subscriptions, service usage and balance. | You; the Business; Stripe |
| Beauty history (Premium) | Haircut and nail photos, personal notes, polish colors. | You |
| Reviews | Rating and comment about a service. | You |
| Business data | Name, CNPJ (optional), phone, WhatsApp, email, address and coordinates, logo, photos, before-and-after, services, prices, hours, professionals (name, photo, bio, level, commission), inventory, goals, management financial data and dashboard address. | The Business |
| Clients entered by the Business | Name, phone, birthday, tags, notes, tabs, visit history and metrics. | The Business (Cutspot as processor) |
| Location | Approximate or precise device position, if you allow it. | Your device |
| Payments & subscriptions | Plan, status, dates, customer, purchase and transaction identifiers, amounts and fees. We do not receive full card numbers, security codes or banking passwords. | Apple, Google, RevenueCat, Stripe |
| Technical data | IP address, access date and time, device model and OS, app version, notification token, error reports without personal data (when crash reporting is on). | Your device; our systems |
| Support & reports | Messages and emails sent to support; review reports (reason and details). | You |
| Document acceptance | Version of the Terms and Policy accepted, birth date provided, guardian's permission (for under-18s), date, time and IP of acceptance. | You; our systems |
We do not ask for sensitive data (health, racial origin, religion, political opinion, sex life, biometrics). Please don't include it in notes, photos or reviews. We do not perform facial recognition or biometrics on photos.
3. Purposes & legal bases
| Purpose | Legal basis (LGPD, art. 7) |
|---|---|
| Create and maintain your account, authenticate you, sync your data across devices | Performance of contract (V) |
| Show businesses, open slots, prices and distance; make, reschedule and cancel bookings; waitlist | Performance of contract (V) |
| Send the Business the data needed to serve you | Performance of contract (V) |
| Reminders, confirmations and notices about your bookings | Performance of contract (V) |
| Loyalty, clubs, vouchers and discounts offered by the Business | Performance of contract (V) |
| Paid plans, billing, payment fraud prevention | Performance of contract (V); legal obligation (II); legitimate interest (IX) |
| Precise device location | Consent (I), via the system permission |
| Offers from businesses you use, last-minute slots, birthday greetings and unfinished-booking reminders | Legitimate interest (IX), with an opt-out; consent (I) where required |
| Security, abuse prevention, crash diagnostics and Service improvement, including aggregated statistics | Legitimate interest (IX) |
| Keeping access logs and tax records and responding to authorities | Legal obligation (II) |
| Knowing whether someone is a minor and keeping the guardian's permission | Regular exercise of rights (VI); for children, specific consent from the guardian (art. 14, §1) |
| Keeping proof of acceptance of the Terms and reviewing content reports | Regular exercise of rights (VI); legitimate interest (IX) |
| Defending rights in lawsuits and complaints | Regular exercise of rights (VI) |
| Beauty history (Premium) | Performance of contract (V) |
We don't sell personal data, don't use it for third-party advertising and don't build profiles for advertisers. Where we rely on legitimate interest, we assess the impact on you and you may object (Section 13).
4. Who sees what
- The Business you book with: your name, phone, service, professional, date, time, notes, attached reference photo, attendance confirmation, your booking and no-show history with it, and your progress in its loyalty program and club. The Business does not see your email, location or beauty history.
- Phone matching: if a Business adds you to its client records or club using your phone number, Cutspot may link that record to your account so you can see your benefits and subscriptions with that Business.
- Other users: the rating and comment of your reviews appear publicly on the Business page, without your name or photo. Public Business content (photos, services, prices, address, before-and-after) is visible to anyone.
- Business staff: people the Business gives access to see the data needed to serve you.
- Providers (Section 5), under contract and only to provide their service.
- Authorities, where legally required or under a valid order, and to defend rights.
- Corporate transactions: in a merger, acquisition or asset sale, data may be transferred to the successor, which will be bound by this Policy.
5. Providers (processors)
| Provider | Purpose | Data |
|---|---|---|
| Supabase | Database, authentication, photo storage and server functions | Account and Service data |
| Google (Firebase Cloud Messaging) and Apple (APNs) | Notification delivery | Device token and notification content |
| Google and Apple (sign-in) | Sign in with Google or Apple | Identifier, email and name they provide |
| Google Maps and Places | Map, search and coordinates for business addresses | Business address; IP of the device loading the map |
| Apple App Store and Google Play | In-app subscription sales | Purchase and payment data, handled by them |
| RevenueCat | Validation of store subscriptions | User identifier, purchases and status |
| Stripe | Web billing and club payments (Stripe Connect) | Payment data handled by Stripe; for Businesses, registration and banking data Stripe requires |
| Sentry | App crash reporting | Error message, version and technical data, without personal data or screenshots |
| Cloudflare | Website and web dashboard hosting, attack protection | IP and technical access data |
| Transactional email provider | Account confirmation and password recovery emails | Email address and message content |
These providers may only use the data to provide their service to us and must protect it. The list may change; the current version is on this page or available on request.
6. Notifications & messages
- About your bookings (confirmation, reminder, attendance confirmation request, reschedule, cancellation, waitlist slot, voucher earned): part of the service.
- Promotional (business offers and campaigns, last-minute slots, birthday, unfinished-booking reminder): you can turn them off in the app's notification settings at any time.
- Notification permission is requested by your device's system and can be revoked in its settings.
- We may send essential emails about your account, security, billing and changes to these documents.
7. Location
With your permission, we use your device location to show nearby businesses, distance and open slots near you. Without permission, the app works with manual search. You can revoke the permission at any time in your device settings. We don't sell or share your location with Businesses.
8. Photos & beauty history
- Beauty history photos are stored in a private area visible only to you.
- If you attach one to a booking, only the Business of that booking can access it, for as long as the booking exists.
- Photos Businesses publish (gallery, before-and-after) are their responsibility, and they must have the consent of the people portrayed. If you appear in a photo without having authorized it, ask the Business or us to remove it.
- Images may be resized and compressed for display.
9. Automated analysis
The Service automatically calculates indicators for the Business, such as average time between visits, clients who are taking longer to return, schedule occupancy and no-shows. These help the Business organize its schedule and run campaigns, and may result in you receiving an offer. They have no legal effect, do not deny access to the Service and are not used for credit or third-party advertising. You may request information about the criteria and a review, under art. 20 of the LGPD, and turn off promotional notifications.
10. International transfers
Some providers (such as Supabase, Google, Apple, Stripe, RevenueCat, Sentry and Cloudflare) may store or process data outside Brazil, especially in the United States and the European Union. These transfers are made to perform our contract with you and rely on the mechanisms allowed by the LGPD (arts. 33 to 36) and ANPD regulations, such as standard contractual clauses, requiring providers to offer a compatible level of protection.
11. How long we keep data
| Data | Period |
|---|---|
| Account, profile, photos and beauty history | While the account exists. When you delete your account, they are erased, except for the items below. |
| Bookings made through the app | While both the Client's and the Business's accounts exist. Deleting a Client account erases their bookings; the Business's own records (client records, tabs) remain under the Business's control. |
| Business data and clients it entered | While the Business account exists; erased when the Business account is deleted. |
| Application access logs (IP, date and time) | 6 months, as required by Brazil's Internet Civil Framework (art. 15), or longer under a court order. |
| Purchase, billing and invoice data | Up to 5 years after the transaction, for tax obligations and defense in consumer claims. |
| Proof of acceptance of the Terms | While the account exists and up to 5 years after it closes, for defense in a possible dispute. |
| Content reports | Up to 1 year after review. |
| Notification token | Until you sign out on the device, the token becomes invalid or the account is deleted. |
| Crash reports | Up to 90 days. |
| Backups | Overwritten in the automatic backup cycle; meanwhile they are protected and not used for any other purpose. |
After these periods, data is erased or anonymized. We may keep data longer when the law requires or to defend rights in a dispute, only for as long as needed.
12. Security & incidents
We adopt technical and administrative measures appropriate to the risk, such as encryption in transit, access control and monitoring. No system is fully immune to attacks. If a security incident may cause relevant risk or harm to you, we will notify you and the ANPD within the regulatory deadlines.
Protect your account with a strong password and don't share it. We never ask for your password by email, message or phone. Found a security flaw? Tell us at contato@cutspot.app.
13. Your rights
Under the LGPD (art. 18) you may request: confirmation that we process your data; access; correction; anonymization, blocking or deletion of unnecessary data or data processed unlawfully; portability; deletion of data processed based on consent; information about who we share it with; information about the option not to consent; withdrawal of consent; objection to processing based on legitimate interest; and review of automated decisions.
- In the app: edit your data in Profile; download a copy and delete your account under Profile › Account & data; manage notifications in settings.
- On the web: Delete account.
- By email: contato@cutspot.app, from your account email.
We may verify your identity before acting. For security, we only handle requests sent from the account email and never send a copy of your data by email: you download it in the app, while signed in. We respond within 15 days. Some data may be kept after a request where the law allows (Section 11). Requests about data a Business entered about you will be forwarded to it. You may also file a complaint with Brazil's National Data Protection Authority (ANPD) at gov.br/anpd, preferably after contacting us.
14. Children & teenagers
Cutspot is open to all ages. We ask everyone for their date of birth to know who is a minor and apply the rules below. Children's and teenagers' data is always processed in their best interest (LGPD, art. 14).
- Guardian's permission: anyone under 18 may only use the Service with the permission of a parent or other legal guardian, declared in the app and kept with the proof of acceptance.
- Children (under 12): processing depends on specific consent from a parent or guardian, given in the app by ticking the permission. The account must be created or supervised by the guardian.
- Only what's needed: we collect only what is required to book and use the Service, and share it only with the Business booked and the providers listed in Section 5.
- Rights: the guardian may exercise the rights in Section 13 on the minor's behalf, turn off promotional notifications and request deletion of the account at any time.
- If we learn that a minor uses the Service without permission, we may suspend the account until the guardian confirms, or delete it.
See also our child safety standards.
16. Changes
We may update this Policy. Material changes will be announced in the app or by email before they take effect and, where the law requires, we will ask for new consent. The version and effective date are at the top of this page.
17. DPO & contact
Data Protection Officer (DPO) channel: contato@cutspot.app.
KAMPLISH – Desenvolvimento de Sistemas LTDA · CNPJ 35.977.805/0001-74
Av. Marquês de São Vicente, 1619, Edif. LED Barra Funda, Conj. 1510, Várzea da Barra Funda, São Paulo – SP, 01.139-003, Brazil