Salon Ledger Privacy Policy
1. Introduction
Salon Ledger replaces the paper service-ticket pad in a nail salon. Techs log each ticket on their own phone, and the salon owner sees every ticket, corrects what needs correcting, and gets each tech's totals for payday. It is made by NeuEra Apps LLC and runs on iOS and Android.
This policy describes what Salon Ledger records, what it deliberately does not record, who else is involved, how long things are kept, and what you can ask us to do.
Salon Ledger is in a closed pilot with a small number of salons. Where something is not finished yet, this policy says so rather than describing an intention as though it were already true.
2. Who This Policy Is About
Salon Ledger is a business tool, and three groups of people are involved in different ways.
- The salon owner is our customer. The owner signs in, sets up the salon, decides which techs use it, and can see and correct every ticket.
- Techs — employees or contractors of the salon — use Salon Ledger at the owner's invitation. A tech has no account of their own: the owner adds them by name and links their phone, and the phone logs their tickets.
- The salon's customers are not part of it at all. A ticket has no customer name, phone number, email address or any other customer detail, and has no field in which to enter one.
3. Information We Collect
About the owner. The email address you sign in with, an identifier for signing in that is derived from that address, the name of your salon and its time zone. Each owner account has one salon.
The salon's setup. The service menu you create, and the pay periods you close.
About techs. The name and short code (for example, OP3) that the owner enters for each tech. That is all we hold about a tech as a person.
About linked phones. When a phone is linked by QR code we create a random identifier for it, and record when it was linked, when it last connected, and whether it has been unlinked. We do not collect the phone's number, its contacts, its location, or its advertising identifier.
Tickets. For each ticket: the services and their prices; a tip amount if one was entered, marked cash or card; whether the ticket was voided; the time of the work, as recorded by the phone; the time our server received it; its ticket number; and how long it took to enter (see below).
Ticket history. Every version of every ticket is kept, together with who made each change — the owner, or which tech — and when. If a phone sends a change that the server does not accept, that change is kept too, so the owner can review it.
Server logs. Our server's request logs record the method, path, status and duration of each request. Our hosting provider necessarily processes IP addresses to deliver traffic to and from the server.
4. What Stays on a Tech's Phone
Salon Ledger works without a connection, so a linked phone keeps a local database of that tech's own tickets from the last 45 days, and sends new tickets and changes to our server when it next connects. A phone holds only the tickets of the tech it is linked to.
The token that lets a linked phone talk to our server is stored in the iOS Keychain or the Android Keystore, the places each system provides for credentials.
Deleting the app from a phone removes its local database of tickets.
5. What We Do Not Collect
This list is specific on purpose, because a general assurance is worth very little.
- No customer information. Nothing about the people whose nails were done: no name, no phone number, no email address, no appointment details.
- No payments. Salon Ledger does not take or process payments of any kind, including tips. A tip on a ticket is a record that a tip was given, not a transaction. There is no card number, bank account or payment processor involved.
- No payroll or tax information. Salon Ledger adds up tickets. It does not calculate wages, commission splits, withholding or tax, and does not hold anyone's tax or bank details.
- No analytics. The app contains no analytics SDK. We do not measure screens viewed, sessions or engagement.
- No advertising. There is no advertising SDK, no ad network, no advertising identifier and no ads.
- No crash-reporting SDK.
- No tracking across other companies' apps or websites.
- No phone number, contacts, location or photos from a tech's phone. The camera is used for one thing only — see the next section.
6. The Camera and QR Code Scanning
The camera is used for one purpose: to scan the one-time QR code that links a tech's phone to the salon. The camera frames are read on the phone to find the code, and are not stored and not sent to us.
On iOS, the code is read by Apple's Vision framework, which is part of iOS and runs on the phone.
On Android, the code is read by Google's ML Kit barcode scanner, which is built into the app and also runs on the phone. Google states that ML Kit processes the image on the device and does not send the image, or what it read from it, to Google. Google also states that ML Kit sends Google metrics about how the scanner performs and how it is used, together with information about the device and the app, and may contact Google's servers from time to time for things like fixes and updated models. Google uses those metrics to measure performance, maintain and improve ML Kit, and detect misuse. That data goes to Google, not to us, and is handled under Google's own practices rather than ours.
Your phone will ask for camera permission before the first scan. You can refuse it or withdraw it in your phone's settings; you would then need another way to link the phone, and during the pilot the QR code is the only one.
7. How This Fits Our Data Charter
The NeuEra Data Practices Charter commits us to attempting every product question with counted totals that carry no identifier and no timestamp, and to moving to per-person records only when we can say plainly why a total will not do. It calls those two categories Tier A and Tier B.
Most of what Salon Ledger holds is Tier B by its nature, and we should say which and why.
- Tickets and their history are Tier B because a service ticket is a work record. A payday total is only worth something if it can be checked against the tickets behind it, which means each ticket has to say who did the work, what was charged and when — and a correction has to show what it changed.
- Techs' names and codes are Tier B because the owner needs to know whose tickets are whose.
- Linked-phone records are Tier B because a ticket can only be credited to the right tech if the server knows which phone sent it, and an owner can only unlink a lost phone if the server knows it exists.
- The owner's email address is Tier B because it is how the owner signs in.
One field exists only for the pilot: the time it took to enter each ticket. The pilot is testing whether logging a ticket on a phone is fast enough to replace the paper pad, and this is how that is measured. It is stored on the ticket, so it is tied to a tech and a time, and it is Tier B. We are disclosing it here rather than leaving it to be found.
On Android, ML Kit's own metrics, described in the previous section, are Google's rather than ours. They are not a bare total, so by the Charter's test they would not qualify as Tier A.
8. How We Use It
- To sign the owner in, and to link and recognise techs' phones.
- To store tickets, keep them in step between a tech's phone and the owner's view, and keep the history of every change.
- To show the owner every ticket, let the owner correct them, close pay periods, and export each tech's totals.
- To measure, during the pilot, how long a ticket takes to enter.
- To keep the service running, diagnose faults and prevent abuse.
- To reply when you write to us.
We do not use any of it for advertising, we do not sell it, and we do not use it to train machine-learning models.
9. Who Can See What
- The owner can see and correct every ticket in the salon, and its full history.
- A tech's phone holds only that tech's own tickets.
- A CSV export is a file the owner downloads. Once it is exported, it is the owner's file, and where it goes after that is outside Salon Ledger.
- We can access the salon's data to operate the service, investigate a fault, or act on a request the owner makes of us.
10. Legal Bases
For people in places whose law asks us to name one, we rely on the following.
- Performance of a contract for the owner's account, the salon's setup, and storing and showing the salon's tickets. Without these the service the owner asked for cannot be delivered.
- Legitimate interests — the salon's, in keeping accurate work records, and ours, in running a reliable service — for techs' names and codes, linked-phone records, ticket history, the pilot entry-time measurement, and server logs.
- Consent for the camera, which the phone asks for and which can be withdrawn at any time.
The salon owner decides which techs to add and what is recorded about the salon's work, and is responsible for having the right to record it. We hold and process those records to provide the service to the salon.
11. How Long We Keep It
- Tickets are never deleted in normal use, by design. Voiding a ticket marks it void and keeps it, so that a total can always be traced back to what changed it.
- Ticket history, techs, linked-phone records, and changes the server refused — kept for as long as the salon uses the service.
- The owner's account — kept for as long as the salon uses the service.
- On a tech's phone — that tech's tickets from the last 45 days.
We should be straightforward about a gap: there is no in-app way to delete an account or a salon's data yet. Deletion is done by asking us at hello@neuera.app. When a salon owner asks us to close their salon's data, we delete its tickets, its techs and its linked phones. Otherwise, business records are kept for as long as the salon uses the service. We will update this section, with a version entry, when in-app deletion exists.
13. Pilot Status and Security
Sign-in during the pilot is a simplified mechanism built for the pilot. It is not yet the authentication system Salon Ledger will use in production, and it should not be relied on as though it were. We are telling you this so that you can decide what to record while the pilot lasts. We will update this section, with a version entry, when that changes.
Connections between the app and our server are encrypted in transit: the server accepts HTTPS connections only.
On a linked phone, the token that connects it to our server is kept in the iOS Keychain or Android Keystore. An owner can unlink a phone at any time, for example if it is lost or a tech leaves. Access to the production database is limited to the people who operate the service.
No service can promise perfect security, and a pilot less than most.
14. Children
Salon Ledger is a business tool for salon owners and the people who work for them. It is not directed at children, and we do not knowingly collect information about anyone under 13. If you believe we hold such information, write to hello@neuera.app and we will delete it.
15. Your Rights
Depending on where you live you may have the right to access the information we hold about you, to correct it, to delete it, to object to or restrict how we use it, to receive a copy in a portable form, and to complain to your data protection authority. Residents of California and other US states with comparable law have similar rights, including the right not to be discriminated against for exercising them. We do not sell personal information, so there is nothing to opt out of on that front.
To exercise any of these, write to hello@neuera.app. We will respond within 30 days.
If you are the owner, you can already see, correct and export your salon's records in the app. Deleting your account or your salon's data is done by asking us.
If you are a tech, the records of your work are part of your salon's business records, which the owner can see and correct. You can write to us to ask what we hold about you. Where a request would change or remove the salon's records, we will involve the salon owner, because those records are theirs to keep.
16. Where Information Is Stored
We are based in the United States, and Salon Ledger's server and database are hosted there, in Fly.io's Chicago region. If you use Salon Ledger from outside the United States, your information is transferred to and processed in the United States.
17. App Store Disclosures
For Apple's privacy labels and the Google Play Data safety form, the data collected is: the owner's email address, the names of techs, an identifier for each linked phone, the ticket records and their history, and the time each ticket took to enter. None of it is used for advertising or for tracking across other companies' apps and websites. On Google Play, the form also declares the diagnostics and device information that ML Kit sends to Google.
18. Changes to This Policy
When this policy changes we publish a new version at a new dated address, leave the old one online permanently, and write a summary of what changed and why in the version history.
For a change that materially affects you, we will tell salon owners before it takes effect.
19. Contact
NeuEra Apps LLC
Email: hello@neuera.app
Legal documents: legal.neuera.app
Salon Ledger's website, www.ledger.salon, is not live yet.
If something in this document does not match what the software actually does, that is a defect and we want to hear about it.