Privacy Policy
What Salvoro collects, why, who else sees it, and what we deliberately do not claim about how it is protected.
Last updated 13 August 2026
Contents
01Who this covers
Salvoro is operated by JIN Solutions (“we”). It is software that salons and spas use to run their businesses. That creates two distinct relationships, and they are governed differently.
If you are a salon using Salvoro, we hold your business’s data on your behalf. You decide what is collected and why; we process it to provide the service.
If you are a customer of a salon that uses Salvoro, the salon holds your record and decides what to do with it. We store and process it for them. Requests to see, correct or delete your information should go to the salon directly, because it is their record — though we will help them action it.
02What a salon stores about its customers
Through Salvoro, a salon may record:
- Name, phone number and optionally email address
- Date of birth, where the salon records it for birthday messages
- Appointment and visit history, including services taken and staff seen
- Billing history, amounts charged and payment method
- Membership and loyalty balances
- Allergies and preferences, where the salon records them
- Feedback submitted through the post-visit link
Not all of this is required. A salon can operate with nothing more than a name and a phone number; the rest is recorded only if that salon chooses to.
03What we hold about salon staff and owners
- Name, phone number and email address
- Role and the permissions granted to them
- Attendance, shifts and leave
- Salary type, base pay and commission percentage
- Sign-in activity and actions recorded in the audit log
04Why we process it
- To provide the service the salon has signed up for — bookings, billing, records and reporting
- To send messages the salon has configured, such as appointment reminders and invoices
- To authenticate users and keep accounts secure
- To bill for the subscription
- To diagnose faults and keep the service running
We do not sell data, and we do not use a salon’s customer records to market to those customers ourselves.
05Who else receives data
Providing the service requires sharing certain data with these processors:
- WhatsApp gateway (wa.jinsolutions.in) — Delivering messages the salon sends: reminders, invoices, follow-ups and campaigns. Receives the recipient's phone number and the message content.
- Razorpay — Processing subscription payments. Receives billing details; card details are handled by Razorpay and never stored by Salvoro.
- Email provider (SMTP) — Sending invitations and one-time codes, where email is used instead of WhatsApp.
- Object storage (S3-compatible) — Storing uploaded images such as salon logos, when configured.
- Google Analytics — Measuring how Salvoro's own public marketing pages are found and read. Receives page URLs and standard visit data from those pages only. It is not present inside a workspace, on a shared invoice link, or on a salon's booking page, so it receives no salon or customer records.
- Microsoft Clarity — Recording how Salvoro's own public marketing pages are used — scrolling, clicks and movement — to find where the site confuses people. Scoped identically to Google Analytics above, and likewise never present on a page showing salon or customer data.
Messages sent through WhatsApp also pass through WhatsApp’s own systems and are subject to their terms, which we do not control.
06How it is protected
The measures in place are:
- Passwords stored as bcrypt hashes, never in readable form
- Signed session tokens with rotating refresh tokens and reuse detection
- Rate limiting on sign-in and one-time-code endpoints
- Isolation between businesses, applied centrally to every database query the application makes
- Branch-level scoping, so a manager cannot read another branch's records
- An audit log of changes to bills, staff and customer records, tagged with the branch, which the product never edits or deletes
- Traffic served over HTTPS with HSTS
To be precise about what is not in place: personal data is not encrypted at the individual field level within the database. Passwords are hashed and traffic is encrypted in transit, but customer names, phone numbers and history are stored as ordinary database values. We would rather state that plainly than imply a protection we do not currently apply. We also hold no ISO, SOC 2 or comparable certification.
07How long it is kept
Business records are retained for as long as the salon’s account is active, because the salon needs its own history. There is no automatic deletion schedule. If a salon closes its account and asks us to delete its data, we will do so; otherwise the data remains available to them.
09Your rights
You can ask to see what we hold about you, have it corrected, or have it deleted. If you are a salon customer, ask the salon first — the record belongs to them. If you are a salon using Salvoro, contact us at info@jinsolutions.in.
10Contact and grievances
Grievances should be addressed to the contact details below. We are reachable Monday to Saturday, 10:00 AM – 7:00 PM IST and aim to reply within two working days.
Contact us
Questions about this policy, or a request you would like us to action, can go to any of these. We reply within two working days (Monday to Saturday, 10:00 AM – 7:00 PM IST).
- info@jinsolutions.in
- +91 80823 38010
- JIN Solutions1st Floor, Semsons Plaza, Near Dahanukarwadi Metro Station
Kandivali West, Mumbai – 400067
Maharashtra, India

