Last updated
June 7, 2026
Privacy
Salonera processes personal data to provide appointment booking, booking management, and customer communication for salons and their clients.
Data controller for Salonera accounts
Arams Frisør AS
Org. no.: 923 947 167 MVA
Address: Pedersgata 50, 4013 Stavanger
Roles and responsibilities
Salonera has a dual role under data protection law. For salon business data (account settings, business details, staff) Salonera is the data controller (GDPR Art. 4(7)). For client data that salons collect through the platform (names, emails, phone numbers, booking history) the salon is the data controller and Salonera is the data processor (GDPR Art. 4(8)).
As a data processor, Salonera processes client data only on the salon's instructions and in accordance with our Data Processing Agreement (DPA). Salons are responsible for having a valid legal basis for their processing of client data.
What we process
We may process names, email addresses, phone numbers, booking history, and other information required to provide the service.
For businesses, we may also process business details, staff, services, pricing, and platform settings created in the product.
How data is used
We use data to operate and improve the platform, send booking confirmations, manage sign-in, and maintain reliable service.
We do not use personal data for purposes that are incompatible with the reason it was collected.
Storage and sharing
Data is stored with subprocessors where necessary for hosting, analytics, security, and communication.
We do not share personal data beyond what is needed to deliver the service or where we are legally required to do so.
Retention
Cancelled appointments: 30 days after cancellation, then hard-deleted automatically by a daily cleanup job. The audit log keeps a record for traceability.
Deleted accounts: Better Auth credentials and the `users` profile row are removed immediately when the account is deleted. Linked client rows are anonymized at the same time so booking history keeps its foreign-key integrity without retaining direct identifiers.
Audit log: 1 year, enforced by a daily cleanup job (general entries only). Used to resolve disputes about bookings, refunds, and account actions long after the underlying personal data has been removed.
Audit-log entries that document financial transactions (issued invoices, received payments, refunds) are classified as accounting documentation under the Norwegian Bookkeeping Act (Bokføringsloven §13) and retained for 5 years. This activates the moment Salonera issues its first invoice — pre-billing, no entries qualify.
Sent emails (Resend): we do not override the provider's default retention.
Sentry events (error reporting): 90 days.
PostHog events (product analytics, consent only): 90 days. The window is reviewed when we reach 100 active salons.
Active business data (bookings, services, staff, customer history): retained while the account is active so the salon can operate normally.
The numbers above mirror our internal policy. The full schedule, including rationale and review triggers, lives in our source repository.
Cookies, analytics, and troubleshooting
We use cookies and similar technologies that are necessary for sign-in, language preference, security, and reliable operation.
Optional — only after you choose in the banner or via “Cookie settings”: PostHog (product analytics, EU) to improve the product; Vercel Analytics and Speed Insights for performance and stability; Sentry Session Replay for debugging (typically only when errors occur, with text masked and media blocked). Subprocessors are covered by data processing agreements where required.
You can withdraw or change consent anytime via “Cookie settings” in the footer. Your choice is stored in the browser with a version and timestamp so we can show the right prompt after future updates.
Your rights
You may request access, correction, deletion, or a portable copy (data portability under GDPR Article 20) of data that relates to you, subject to legal retention requirements.
For data related to bookings at a salon: contact the salon directly — they are the data controller for their client data. For data related to your Salonera account: contact us at personvern@salonera.no.
To receive a portable copy of your Salonera account data, contact us at personvern@salonera.no. To exercise other rights — or receive data in a different format — contact the relevant controller above. We respond within one month, as required by GDPR Article 12(3).