Clipsper legal
Privacy Policy
Version 2026-07-20-v2.1-draft-counsel-review · Effective draft dated July 17, 2026
Draft status and scope
This launch draft must be reviewed by privacy counsel before publication. It covers Clipsper’s websites and native apps. A shop may separately act as a business or controller for customer information it enters or receives through its workspace; the Data Processing Addendum describes that relationship.
Data we collect
We collect account identifiers, name, email, phone, optional birthday, profile photo and address; appointment and service details; limited guest-customer contact details entered by authorized staff; shop and barber applications; professional or business-license submissions; portfolio, gallery, review and CRM content; device, notification, text-message consent and delivery-status, phone-verification, and security information; legal acceptances; and payment-status identifiers supplied by Stripe. Clipsper does not store complete card or bank-account details.
Why we use data
We use data to authenticate users, operate appointments, show relevant shop locations, support customer service, send requested email, text, push, and in-app notifications, verify phone possession where requested, verify professionals and businesses, prevent misuse, process payment instructions, maintain audit evidence, improve reliability, and meet legal obligations. Text-message consent is recorded separately from acceptance of the Terms or this Policy.
Location and addresses
Customer addresses are optional profile data. Shop addresses are used for discovery and directions. Google Places and Google Address Validation receive the business address text and a short-lived autocomplete session token so Clipsper can suggest, normalize, and verify the address. The Google credential stays on the server. Approximate device location is used only with platform permission.
Processors and AI
Supabase supports authentication and data storage; Stripe processes payments and payouts; Resend supports email; Twilio supports transactional text delivery, delivery status, opt-out handling, and phone verification; Apple and Google support sign-in, address, push, and native-app services. Twilio receives the destination phone number, concise appointment message, and operational delivery metadata needed to provide those services. When an authorized business user invokes the AI Business Assistant, the question and minimum scoped business tool results are sent to OpenAI with storage disabled for the API request. The assistant cannot book, cancel, message, or change payments. Clipsper does not include an AI receptionist in this release. Current provider contracts, data locations, subprocessors, and retention settings must be confirmed in the production vendor review.
Cookies and analytics
Necessary browser storage supports sessions, preferences, and security. Optional analytics storage is not loaded before web consent. No marketing-cookie integration is enabled in this codebase. Native apps do not show the web cookie banner. See the separate Cookie Policy and change preferences from the footer.
Sharing and access
Shops and assigned barbers may view customer contact and profile details needed to provide booked services. They cannot edit customer-owned identity fields, but may maintain private business CRM notes. Administrators receive controlled access for support, safety, verification, and enforcement.
Retention and deletion
Open account data is kept while the account is active. Deletion requests are acknowledged and targeted for completion within 30 days, unless identity verification, an active dispute, or law requires more time. Unneeded profile and authentication data is deleted or anonymized; financial, appointment, tax, legal-acceptance, refund, fraud-prevention, and security evidence is retained only for the applicable legal or dispute period. Completion is confirmed to the requester. Apple authorization should be revoked when an Apple-linked account is deleted.
US state privacy notices
Depending on residency and legal thresholds, users may have rights to know, access, correct, delete, port, restrict, or appeal processing and to opt out of sale, sharing, or targeted advertising. Clipsper does not enable cross-context behavioral advertising or sell personal information in this release. State-specific categories, metrics, appeal method, authorized-agent procedure, and financial-incentive disclosures require counsel confirmation before launch.
International transfers
Clipsper and its providers may process information in the United States and other locations. Required transfer mechanisms, regional representatives, and supplemental safeguards must be documented before offering the service in jurisdictions that require them.
Your choices and rights
Account settings let you update personal information, manage notifications, view accepted legal versions, request an export, and initiate deletion. A public deletion-request page is also available for users who cannot access the app. Additional access, correction, objection, restriction, or appeal rights may apply by location. Clipsper may verify identity before fulfilling a request.
Security, children, and contact
We use access controls and operational safeguards, but no internet service can promise absolute security. Clipsper is not directed to children under 13, and business accounts require legal adulthood. Privacy questions and requests may be sent to legal@clipsper.com.

