Last updated: April 22, 2026
Timberlodge Parlor ("we," "us," or "our") provides salon booking and related services through timberlodgeparlor.com. This Privacy Policy describes what information we collect, how we use it, who we share it with, and the choices you have.
This policy applies to customers who book appointments, visitors who browse the site, and staff members ("bookable persons") who use the platform to manage their schedules.
Information we collect
Information you give us directly
- Account information. Name, email address, password (stored only as a cryptographic hash — never in readable form), date of birth, and any alternate email addresses you add to your profile.
- Contact information. Phone number (when you opt in to SMS reminders), mailing or billing address (when you pay for services).
- Booking details. Appointment history, booked services, preferred staff members, notes you leave for your stylist, and — optionally — allergy or sensitivity notes you share so staff can accommodate you safely.
- Notification preferences. Your per-channel opt-in state for appointment confirmations, reminders, and announcements across email, SMS, and browser push notifications. You can change these at any time from your account.
- Staff profiles. If you are a bookable person, you provide your display name, booking email, phone number, bio, portfolio images, and optional social handles for display on your public profile.
Information collected automatically
- Device and session data. IP address, browser type and version (user-agent), operating system, and the pages you visit. This is standard web-server and CDN log data used for security, performance, and troubleshooting.
- Push subscription data. If you enable browser push notifications, we store the push-service endpoint URL your browser issues to us, along with its cryptographic subscription keys. This is how we route a notification to your specific device — we cannot identify other devices from it.
- Cookies and similar technologies. See "Cookies and similar technologies" below.
Information from third parties
- Payment confirmations. Our payment processors report whether a charge succeeded, the card brand and last four digits, and — where applicable — a token we can use for future charges with your consent. We never see your full card number.
- Calendar events. Staff who connect a personal calendar (Google Calendar, Apple iCloud, or Outlook) allow us to read or write event data on their behalf within the scope they authorise.
How we use your information
- To create and maintain your account and authenticate you.
- To schedule, confirm, remind you about, and complete your appointments.
- To process payments, issue receipts, and handle refunds.
- To send appointment-related communications on the channel(s) you have opted into.
- To operate and secure the site — including rate-limiting, fraud detection, and preventing abuse of the booking system.
- To import publicly posted reviews about our business from Google, Facebook, and Yelp for display on our site (we do not send customer data to those platforms in the process).
- To comply with legal obligations, including tax reporting and responding to lawful requests.
Third-party services we share with
We share information only with service providers that help us run the business. Each provider receives only the data needed for its function, and each is contractually bound to use that data only on our behalf.
Payment processing
- Stripe. Processes online and in-person card payments. Stripe receives your name, email, billing address, the amount of the transaction, and — when you pay — your card details directly through Stripe's own secure form (we never handle raw card numbers). Stripe's privacy policy: stripe.com/privacy.
Communications
- Twilio. Sends our SMS appointment reminders and receives your STOP/START replies. Twilio receives your phone number and the text of each message. Twilio's privacy policy: twilio.com/legal/privacy.
- Apple iCloud Mail. We send our appointment emails, receipts, and account notifications through Apple iCloud Mail. Apple receives your email address, your name as it appears on your account, and the contents of each message sent. Apple's privacy policy: apple.com/legal/privacy.
- Web Push services. If you enable browser push notifications, delivery passes through your browser vendor's push service (Google FCM for Chrome/Edge/Android, Mozilla AutoPush for Firefox, or Apple's push service for Safari). The payload is end-to-end encrypted with keys your browser generated — the push service routes the notification but cannot read its contents.
Infrastructure
- Cloudflare. Provides our content delivery network, DDoS protection, and web application firewall. Cloudflare sees visitor IP addresses, user-agent strings, and request metadata in the course of routing traffic. Cloudflare's privacy policy: cloudflare.com/privacypolicy.
- Cloudflare Turnstile. Provides the bot-detection challenge shown on booking and sign-up forms. When you solve a challenge, your IP and browser signals are sent to Turnstile for verification. No advertising cookies are set. Privacy policy as above.
Calendar integrations (staff only)
- Bookable persons may connect Google Calendar, Apple iCloud Calendar, or Microsoft Outlook to synchronise appointments with their personal calendars. These integrations are authorised per-staff-member using industry-standard OAuth (or app-specific passwords for iCloud) and scoped to the staff member's own calendar.
- Bookable persons may also subscribe to external iCalendar URLs they provide (for example, a ClassPass schedule). We fetch those feeds from the URL the staff member supplies.
Review platforms (read-only)
- Google Places, Yelp, and Facebook. We retrieve public reviews about our business from these platforms to display on our site. We do not send any customer data to these platforms in the course of doing so.
Business listings
- Salon Republic. We synchronise our public shop listing (business name, hours, services, staff biographies and photos, address, social links) to Salon Republic. No customer data is shared.
SMS messaging program
If you opt in to SMS appointment notifications, the following terms apply:
- By providing your phone number and opting in, you agree to receive informational text messages related to your appointments from Timberlodge Parlor. Consent is not a condition of purchase.
- Message frequency varies based on your appointment activity.
- Message and data rates may apply — consult your mobile carrier.
- Reply STOP at any time to opt out. Reply HELP for help. You may also remove your phone number or disable SMS from your account's notification settings.
- Opting out of SMS does not unsubscribe you from email or push notifications; manage each channel separately from your account.
Cookies and similar technologies
We use a small set of cookies and browser-local storage for functional purposes. We do not use advertising cookies, cross-site tracking pixels, third-party analytics, Meta Pixel, or Google Analytics.
- Session cookies. Keep you logged in and tie your browser to your active session. These expire when you close your browser or log out.
- CSRF tokens. Prevent cross-site request forgery on forms you submit.
- Booking protection cookie. A short-lived cookie (24 hours) may be set if a booking is flagged as repeatedly cancelled, so our staff can follow up directly. It contains only a flag, not your identity.
- Turnstile challenge tokens. Cloudflare Turnstile issues short-lived tokens to validate that a form submission came from a human. No cross-site tracking is performed.
- Browser-local storage. We store small preference flags in your browser's localStorage (for example, whether you dismissed the notification opt-in banner). These never leave your device.
How long we keep your data
- Account and profile data — retained as long as your account is active, plus a reasonable period afterward to fulfil legal, accounting, and tax obligations.
- Appointment records — retained for at least seven years to support accounting, tax, and dispute resolution. They may be retained longer to support repeat-customer preferences unless you request deletion.
- Payment records — retained as required by payment-card network rules and applicable tax law.
- SMS suppression records — when you reply STOP, we retain the fact that you opted out indefinitely so we do not accidentally re-contact you.
- Push subscriptions — removed automatically when a browser reports the subscription as expired, when you revoke it from your account, or when your account is deleted.
- Server logs — retained for up to 30 days for operational troubleshooting, then deleted or compressed.
Your rights and choices
You can manage most of your information directly from your account:
- Access and edit. Log in and visit your profile to view or update your name, phone, email, notification preferences, and other account details.
- Unsubscribe from promotional emails. Follow the "unsubscribe" link in the footer of any promotional email, or adjust settings in your account. Operationally essential emails (appointment confirmations, payment receipts) will still be sent where required to deliver service.
- Stop SMS. Reply STOP to any SMS, or toggle the SMS channel off from your notification preferences.
- Revoke push notifications. Remove devices from the "Devices" page in your account, or revoke the notification permission in your browser settings.
- Request export or deletion. Contact us at [email protected] to request a copy of the personal data we hold about you or to request deletion. We will respond within 30 days. Some data must be retained for legal or security reasons and cannot be deleted on request.
California residents (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the right to request (a) the categories and specific pieces of personal information we have collected about you, (b) the categories of sources we collected it from, (c) the business purpose for collecting it, (d) the categories of third parties we share it with, and (e) deletion of your personal information. We do not sell personal information or share it for cross-context behavioral advertising. To exercise your rights, contact us at the address below.
Visitors from the European Economic Area and the United Kingdom
If you are located in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, the General Data Protection Regulation ("GDPR") or its UK equivalent gives you the following rights with respect to personal data we process about you:
- Access, correction, or deletion of your personal data.
- Restriction of, or objection to, our processing.
- Portability — a machine-readable copy of data you have provided to us.
- Withdrawal of any consent you previously granted, without affecting the lawfulness of processing carried out before the withdrawal.
- Lodging a complaint with your local supervisory authority.
We process your personal data on the following legal bases: performance of a contract (delivering the appointments you book), our legitimate interests (securing the site, maintaining our business records, and communicating with you about your appointments), your consent (where you opt in to SMS or push notifications), and compliance with legal obligations (tax and accounting records).
Our business is based in California, United States. When you use our services from the EEA, UK, or Switzerland, your personal data is transferred to and processed in the United States. We rely on appropriate safeguards — including the service-provider contractual commitments of the third parties listed above — to protect that data in accordance with applicable law. To exercise any of these rights, contact us at [email protected].
Security
We use industry-standard safeguards to protect your information: encrypted connections (HTTPS) across the entire site, password hashing with modern algorithms, encrypted storage of credential secrets, scoped OAuth tokens for calendar integrations, and network-level protection via Cloudflare. No system is perfectly secure; we aim to promptly detect and respond to any incident that could affect your data.
Children's privacy
Our services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be highlighted at the top of this page and — for account holders — communicated via email or an in-app notice before they take effect. The "Last updated" date above shows the most recent revision.
Contact
Questions about this policy or our handling of your data? Reach us at [email protected].