Version 1.1.2 · Effective
Slotlyy is a salon booking platform operated from Ghana. When you use Slotlyy — whether as a salon owner, staff member, or client booking an appointment — this policy explains what personal data we collect, why, and how we protect it.
Contact: [email protected]
[redacted] so the analytics event records only that you visited a manage/cancel/reschedule, review or confirmation page, never which specific booking. Session recordings are disabled on these routes entirely. On a salon's public booking pages we may record how the page is used (a session recording of the layout, clicks and scrolls), with all text on the page and everything you type masked and payment windows blocked; no recording is made for salons in health-related categories./waitlist for the Slotlyy pilot, we collect your contact name, phone number, optional email, business name, staff count, business location, optional Instagram handle, and business phone. We use this to contact you about pilot participation and your demo. Data is retained while the pilot is active + 12 months after for follow-up; you can request deletion at any time via [email protected], under the Ghana Data Protection Act 2012 (Act 843).The full list of every third-party subprocessor that processes Slotlyy data — including vendor name, purpose, data categories, residency, and contract status — is published at slotlyy.com/subprocessor. Slotlyy commits to 30 days' advance notice before adding any new subprocessor to that list.
We do not sell your personal data to any third party.
Slotlyy holds data in seven retention tiers. Active bookings and client profiles are retained for as long as the salon has an active Slotlyy account. Financial records (bookings, orders, gift cards) are retained for 7 years from last activity to comply with Ghana Revenue Authority tax record-retention requirements. Audit logs are hash-chained in our primary database and are kept for fraud investigation and dispute resolution; archival to write-once storage is planned and not yet running.
When a salon closes its account, client names + phone numbers + emails are anonymised within 30 days; staff profiles are deactivated; photos and other uploaded assets are deleted. Individual clients can also ask for their own data to be erased at any time by emailing [email protected].
To exercise any of these rights, email [email protected]. We will respond within 30 days (Ghana DPA §20) or sooner where required by your country's law. Client accounts can download their data, and request erasure by email, at /account/data-privacy; salon owners can self-serve tenant-wide data export at /partner/settings/data-export.
We use strictly necessary session cookies to keep you logged in. We do not use advertising or tracking cookies. Analytics data is collected via PostHog using a random identifier — no cross-site tracking.
All data is transmitted over HTTPS. Our database enforces row-level security — each salon can only access their own data. Payment credentials are never stored on our servers. We conduct regular security reviews.
If we make material changes to this policy, we will notify active salon owners via email at least 14 days before the changes take effect. The updated date at the top of this page always reflects the most recent revision.
Questions about this policy? Email us at [email protected].