BeautyReply

BeautyReply beta

Privacy Policy

Effective 28 August 2026

Draft template — not legal advice. This document is provided for internal review and must be verified by qualified legal counsel before a public SaaS launch. BeautyReply does not represent that these terms are complete or compliant.

This Privacy Policy explains how BeautyReply (“we”, “us”) collects and uses personal data when you use the BeautyReply beta platform and when your clients interact with the BeautyReply website widget.

1. Who this applies to

This policy applies to beauty business owners and staff who create a BeautyReply account (“Business Users”) and to visitors who use the Client Assistant widget on a Business User's website (“Widget Visitors”).

2. Data we collect

Account data. When you sign up, we collect your name, email address, password (stored securely by our authentication provider), business name, business type, and optional marketing consent preference.

Business workspace data. You may add services, prices, knowledge base answers, opening hours, contact details, booking links, widget settings, shop product catalog data (including variants and prices), commerce platform metadata, and content imported from your public website. You control what is approved and shown to clients.

Website import data. If you scan or import from your public website, we process page URLs, titles, and extracted text you choose to review and approve. We do not access password-protected areas of your site.

Widget, chat, and lead data. When a Widget Visitor uses the assistant or submits a handoff form, we may process their message, selected options, name, email or phone number, chat context, detected intent, conversation identifiers, and related analytics events. This data is stored for the Business User's lead inbox and conversation history.

Commerce interactions (beta). If you enable Shopify add-to-cart in Widget Settings, a visitor's browser may add a verified product variant to your Shopify storefront cart using Shopify's own cart API on your domain. BeautyReply validates the variant server-side before that action; we do not receive full payment or checkout data.

Widget assets. You may upload branding images (for example launcher icons, avatars, or backgrounds) to our storage provider. Only upload content you have rights to use.

Technical data. We collect standard server and security logs, including IP addresses and browser information, to operate the service, prevent abuse, and verify CAPTCHA challenges.

3. How we use data

  • Provide and improve the BeautyReply beta product
  • Authenticate users and protect accounts
  • Generate AI assistant replies from your approved business information
  • Answer product and pricing questions from your approved shop catalog where configured
  • Facilitate optional Shopify add-to-cart actions on your storefront when you enable that beta feature
  • Deliver leads, conversations, and analytics to your dashboard
  • Send service emails such as account confirmation when enabled
  • Send lead or handoff notification emails you configure in Widget Settings
  • Send optional product updates if you opted in at signup
  • Localise widget and assistant content into supported languages you enable

4. AI processing

When configured, BeautyReply may send a compact set of your approved, active business facts to Groq to generate natural-language replies. Groq is instructed to answer only from that approved context. If Groq is unavailable, a deterministic on-platform assistant is used instead. For some general beauty or product research questions, an optional web search provider (Serper) may supply public snippets; salon prices, hours, policies, and catalog facts still come only from your approved workspace data.

Do not add sensitive personal data to knowledge base content unless you have a lawful basis to share it with clients. Product prices and availability shown in the assistant are based on your approved catalog and may differ at checkout on third-party stores.

5. Service providers

We use trusted processors to run BeautyReply, including:

  • BeautyReply cloud database (authentication, database, and storage)
  • Vercel (application hosting)
  • hCaptcha (bot protection on signup and lead forms)
  • Groq (optional natural-language reply generation)
  • Resend (optional lead and notification email delivery)
  • Serper (optional public web search snippets for limited research questions)
  • Shopify (your own storefront, when a visitor uses add-to-cart on your website domain)

These providers process data on our behalf under their own terms and security practices.

6. Roles and responsibilities

For Widget Visitor data submitted through your widget, you are generally the data controller for your client enquiries and BeautyReply acts as a processor helping you manage those enquiries. You are responsible for having an appropriate legal basis to collect client contact details, for informing visitors about the widget and any optional cart actions on your site, and for providing your own privacy information to website visitors where required.

7. Cookies and local storage

The BeautyReply dashboard uses session authentication through our auth provider. The website widget may store a conversation identifier and security token in the visitor's browser so chats can continue across page views. These are functional, not advertising cookies. Your own website cookie banner may need to mention the widget if required in your jurisdiction.

8. Retention

We retain account and workspace data while your beta account is active. Lead and analytics data is retained to support your dashboard unless you delete it or close your account. We may retain limited logs for security and troubleshooting.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, and to object to certain processing or withdraw consent. To exercise these rights, contact us at hello@beautyreply.com. We will respond within a reasonable time.

10. Security

We use industry-standard measures including authenticated dashboard access, row-level database security, and CAPTCHA verification on sensitive public forms. No online service is completely secure; please use a strong password and keep your login details confidential.

11. Beta notice

BeautyReply is in private beta. Features, data practices, and this policy may change as the product evolves. Material changes will be reflected on this page with an updated effective date.

12. Contact

Questions about this policy: hello@beautyreply.com. See also our Terms & Conditions.