JADA

JADA

Privacy Policy

Last updated 19 August 2026

JADA is scheduling and business-management software for independent beauty providers. This policy explains what information we handle, why, who it goes to, and how we protect it.

Two different people appear in this policy. A provider is our customer — the beauty professional who has a JADA account. A client is someone who books with that provider. Providers enter information about their own clients into JADA. For that information the provider decides what is collected and why; JADA processes it on the provider’s behalf, under this policy and the provider’s instructions.

Information we collect

From providers, when an account is created and used:

  • Name and email address.
  • A password, stored only as a salted cryptographic hash — never in readable form.
  • Business and workspace details you enter: business name, services, pricing, availability, and time zone.
  • Team membership, role and permissions where a business has more than one member.

Information providers enter about their clients:

  • Client name and phone number; email address if the provider records one.
  • Appointments, times, services, assigned team member, cancellations and no-shows.
  • Notes the provider writes, including service-formula notes.
  • Photos a provider attaches to a client record.
  • Consent records showing which policy version a client agreed to, and when.
  • Prepaid package and membership balances, recorded as an append-only ledger.

Technical information created by using the service:

  • A session cookie that keeps you signed in. It is set httpOnly and SameSite=Lax, and marked Secure in production.
  • Session records: when a session started, when it was last seen, when it expires, and whether it was revoked. Each session stores a short truncated hash used only to label a device in your session list — not a browser fingerprint, and not your raw browser user-agent string.
  • Audit events for security-relevant actions inside a workspace.
  • Error diagnostics when something fails, so we can fix it.
  • Your IP address is read when you sign in or submit a public booking, and is used only in-memory to rate-limit abuse. It is not written to our database.
We do not run analytics, advertising, tracking pixels, session replay or cross-site trackers. Our error diagnostics are built to hold as little about people as possible: a diagnostic record has no field for a form, a request body, a header or a cookie, so those are never captured at all, and the free text that is captured has emails, phone numbers and token-shaped values masked before it is stored. We verify this with automated tests that plant recognisable fake values in real records and then check our own logs for them.

Payments and card information

JADA does not store card numbers. Payment functionality in JADA is currently simulated — no real card is charged and no real payment credential is held. Where a card is represented in a client record, we store only a brand label, the last four digits, and a simulated reference.

When real payments are introduced, they will be processed by Stripe. In that model the provider — not JADA — is the merchant for her clients’ payments, card details are collected and held by Stripe under its own terms and security programme, and JADA stores only references and amounts needed to show a record and reconcile it.

How we use information

  • To provide the service: scheduling, client records, availability, checkout records and reporting.
  • To authenticate you, keep your account secure, and let you see and revoke your own sessions.
  • To send transactional messages you or your provider triggered — for example email address verification and password resets.
  • To protect the service against abuse, fraud and automated attacks.
  • To diagnose and fix faults.
  • To meet legal obligations.

We do not sell personal information, and we do not use client information to market to your clients.

Messages

Appointment-related text messages inside JADA are currently simulated and are not delivered to real phones; they are recorded so a provider can see what the system would have sent. Account emails — such as address verification and password resets — are sent for real through our email provider.

Service providers we use

We keep this list short on purpose, and it reflects what production actually uses today:

  • Postmark — sends transactional account email on our behalf.
  • Cloudflare — DNS for itsjada.com and routing for inbound email sent to our addresses.
  • Hetzner — the hosting provider whose servers run JADA and store its database and backups.
  • Stripe — will process payments when payment functionality becomes live; not yet handling any real payment for JADA.

These providers process information only to deliver their service to us. We do not grant them rights to use it for their own purposes.

When we disclose information

  • To the service providers above, to operate the service.
  • To a provider, for the clients and records belonging to her own business.
  • To a client, through a private link that shows only her own record.
  • When required by law, or to respond to valid legal process.
  • To protect the rights, safety or property of JADA, our providers, or the public.
  • In connection with a merger, acquisition or sale of assets — with notice, and the information stays subject to a policy at least as protective as this one.

Storage, retention and deletion

Information is stored on servers in the United States. We keep account and business information for as long as the account is active, and afterwards only as long as we need it for the purposes described here or to meet a legal obligation. We take regular backups, and backups persist for a period after deletion before they age out.

We have deliberately not published a fixed number of days for retention or deletion, because we will not state a guarantee we cannot yet prove operationally. If you ask us to delete information, we will tell you what we can do and by when.

Security

  • Passwords are stored only as salted cryptographic hashes and compared in constant time.
  • Sessions are signed, expire, and can be revoked individually or all at once — including automatically on password reset or account deactivation.
  • Access is enforced on the server for every page and action, not merely hidden in the interface.
  • Each business's data is isolated from every other business, and that isolation is tested adversarially.
  • Sign-in and other sensitive endpoints are rate-limited.
  • Traffic is served over HTTPS.
  • Backups are taken daily and stored off the primary server.

No system is perfectly secure, and we do not claim certification under any particular security standard.

Your choices

  • Providers can view their client records inside JADA, and add to them.
  • Correcting or deleting a client record is handled by request rather than by a button in the product today — contact us through the support page and we will tell you what we can do and by when.
  • Providers can export business data.
  • You can see your active sessions and sign out of one or all of them.
  • You can ask us to access, correct or delete information we hold about you, or to close your account.
  • Clients: JADA holds your information on behalf of the beauty provider you booked with. Contact her first — she controls that record. If you cannot reach her, contact us and we will help.

Children

JADA is for businesses and is not directed to children. Provider accounts are for adults. A provider who serves a minor client is responsible for having the appropriate consent from a parent or guardian before entering that client’s information into JADA.

Changes

We may update this policy. When we do, we will change the date at the top, and for material changes we will give notice through the service or by email.

Contact

Questions about this policy, or a request about your information: see our support page.