Clipsper legal
Privacy Policy
Version 2026-09-19-v3 · Updated 2026-09-19
Scope
This policy covers Clipsper’s websites and native apps. A shop may separately act as a business or controller for customer information it enters or receives through its workspace; the Data Processing Addendum describes that relationship.
Data we collect
We collect account identifiers, name, email, phone, optional birthday, profile photo and address; appointment and service details; limited guest-customer contact details entered by authorized staff; shop and barber applications; professional or business-license submissions; portfolio, gallery, review and CRM content; device, notification, text-message consent and delivery-status, phone-verification, and security information; legal acceptances, age-group and guardian-permission declarations; kiosk attendance, waitlists, referrals, packages, memberships, gift cards, email preferences and booking restrictions; and payment-status identifiers supplied by Stripe. Clipsper does not store complete card or bank-account details.
Why we use data
We use data to authenticate users, operate appointments, show relevant shop locations, support customer service, send requested email, text, push, and in-app notifications, verify phone possession where requested, verify professionals and businesses, prevent misuse, process payment instructions, maintain audit evidence, improve reliability, and meet legal obligations. Text-message consent is recorded separately from acceptance of the Terms or this Policy.
Location and addresses
Customer addresses are optional profile data. Shop addresses are used for discovery and directions. Google Places and Google Address Validation receive the business address text and a short-lived autocomplete session token so Clipsper can suggest, normalize, and verify the address. The Google credential stays on the server. Device location, which may be precise, is requested through platform permission for nearby-shop discovery. Camera access is requested for kiosk QR scanning. Scanning itself does not upload camera video.
Processors and AI
Supabase supports authentication, database storage, uploaded files, and realtime updates; Vercel hosts the website and backend functions and processes requests, IP addresses and operational logs; Stripe processes payments, subscriptions and payouts; Resend supports email; Twilio supports transactional text delivery, delivery status, opt-out handling, and phone verification; Apple and Google support sign-in, address, push, and native-app services. Twilio receives the destination phone number, concise appointment message, and operational delivery metadata needed to provide those services. When an authorized business user invokes the AI Business Assistant, the question and minimum scoped business tool results are sent to OpenAI with storage disabled for the API request. The Business Assistant is distinct from the AI receptionist. For businesses that enable the receptionist, Retell, Twilio and, depending on the configured voice implementation, OpenAI process calls, phone numbers, conversations, booking instructions and relevant business information. Clipsper keeps operational call records such as masked caller identifiers, timing, outcomes and tool activity, and may retain short messages a caller asks to leave for a shop. The current call logging avoids storing full audio and transcripts in Clipsper. Voice providers may process or retain audio/transcripts under their own settings. Authorized shop staff can access relevant operational call records. Receptionist tools may look up availability, create or change bookings and send requested links. Shops must provide required AI and recording notices and obtain any required consent. Disabling recording does not necessarily disable transcription. Provider retention depends on the service and account settings; disabling storage on an OpenAI request is not a promise of zero retention by every provider.
Cookies and analytics
Necessary browser storage supports sessions, preferences, and security. Optional analytics storage is not loaded before web consent. No marketing-cookie integration is enabled in this codebase. Native apps do not show the web cookie banner. See the separate Cookie Policy and change preferences from the footer.
Sharing and access
Shops and assigned barbers may view customer contact and profile details needed to provide booked services. They cannot edit customer-owned identity fields, but may maintain private business CRM notes and booking restrictions. A restriction may be matched using an account, guest identity, email or phone within that business. Public shop profiles, portfolios and published reviews are visible to other visitors. Administrators receive controlled access for support, safety, verification, and enforcement.
Retention and deletion
Data is retained as needed to operate the account and bookings, resolve disputes, prevent abuse and comply with legal obligations. Deletion requests may require identity checks; some financial, appointment, legal-acceptance and security records may need to be retained. Backup copies and provider records may remain until their retention periods expire. We retain a minimal email suppression record to honor an unsubscribe request. Contact us for help with a deletion request or information about a specific retained record.
US state privacy notices
Depending on residency and legal thresholds, users may have rights to know, access, correct, delete, port, restrict, or appeal processing and to opt out of sale, sharing, or targeted advertising. Clipsper does not enable cross-context behavioral advertising or sell personal information. Contact us using the address below to exercise applicable rights or appeal a decision. We may need to verify your identity or an agent's authority.
International transfers
Clipsper and its providers may process information in the United States and other locations, including locations outside your state or country. Applicable protections and legal requirements may differ by location. Contact us for information about processing relevant to your account.
Your choices and rights
Account settings let you update personal information, manage notifications, view accepted legal versions, request an export, and initiate deletion. A public deletion-request page is also available for users who cannot access the app. Additional access, correction, objection, restriction, or appeal rights may apply by location. Clipsper may verify identity before fulfilling a request. Optional emails include an unsubscribe link that works without signing in. Security, requested support and payment-critical communications may still be sent. Email preferences do not automatically change SMS or push preferences.
Security, children, and contact
We use access controls and operational safeguards, but no internet service can promise absolute security. Clipsper is not directed to children under 13. They must not create their own accounts; a parent or guardian may arrange a haircut using the adult's account. Users aged 13–17 need parent or guardian permission. Age declarations are not identity verification or verifiable parental consent for children under 13. Business accounts require legal adulthood. If you believe a child has supplied personal information in violation of this policy, contact us so we can investigate and address it. Privacy questions and requests may be sent to Clipsper Support.

