Legal

Privacy Policy

Effective: · Last reviewed: (product draft — not counsel-approved)

Draft pending legal counsel review. Not legal advice — do not treat as final production language. This page does not claim PCI Level 1, HIPAA, or any other certification.

Disclaimer

This document is a draft and has not been approved by legal counsel. It does not constitute a PCI certification (including PCI DSS Level 1), HIPAA compliance attestation, or any other regulatory certification. Do not rely on this document for legal compliance until it has been reviewed and approved by a qualified attorney.

1. Who we are

Cutzop ("Cutzop," "we," "us") provides a front-desk barbershop kiosk. Contact: hello@cutzop.com.

This draft Policy applies to cutzop.com, related marketing pages, and the authenticated kiosk. It is not legal advice and is pending counsel review. Related: Terms of Service.

2. Intended audience & children (COPPA)

The Service is intended for shops and users who are at least 18 years old. We do not knowingly collect personal information from children under 13. Walk-in guests at a shop kiosk are collected by the shop; the shop owner is responsible for notices and consents required for guest data.

If you believe a child under 13 has created an account, contact hello@cutzop.com.

3. Information we collect

  • Account data: email, password (hashed by our auth provider), and profile name.
  • Shop & staff data: organization and location names, staff display names, roles, and terminal PIN hashes.
  • Guest data: walk-in name and phone, registered-guest PIN mappings the shop stores, queue and pay session metadata.
  • Payments: amounts, method, Stripe PaymentIntent IDs. Card PAN/CVV are handled by Stripe, not stored in kiosk JavaScript.
  • Technical data: IP, device/browser, app version, and error diagnostics when reporting is enabled.

4. How we use information

  • Provide, secure, and improve the kiosk
  • Authenticate shop accounts and authorize staff PINs
  • Process the $59 seat and guest card-present payments via Stripe
  • Provide support and billing notices
  • Comply with law and enforce our Terms

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising.

5. Processors & sharing

  • Supabase — authentication and database
  • Stripe — subscription billing, Customer Portal, Terminal / card-present pay
  • Google — optional OAuth / SSO
  • Hosting / CDN / fonts
  • Error monitoring — when enabled (for example, Sentry)

6. Retention

We retain account and operational records while your account is active and as needed for tax, accounting, dispute, and legal obligations. You may request deletion as described below; some records may be retained where law requires.

7. Your privacy rights (including CCPA)

Depending on where you live, you may have rights to access, correct, delete, or export personal information. California (CCPA/CPRA): we do not sell or share personal information for cross-context behavioral advertising. Email hello@cutzop.com with "Privacy request (CCPA)" in the subject.

8. Security

We use HTTPS, hashed credentials and staff PINs, and row-level access controls separating shop data. Card payments rely on Stripe. This Policy does not assert a PCI DSS certification level. No method of transmission or storage is 100% secure.

9. International transfers

We primarily serve shops in the United States. Information may be processed in the United States or other locations where our providers operate.

10. Changes

We may update this Policy. Related: Terms of Service.