JADA
Privacy Policy
Last updated 19 August 2026
JADA is scheduling and business-management software for independent beauty providers. This policy explains what information we handle, why, who it goes to, and how we protect it.
Information we collect
From providers, when an account is created and used:
- Name and email address.
- A password, stored only as a salted cryptographic hash — never in readable form.
- Business and workspace details you enter: business name, services, pricing, availability, and time zone.
- Team membership, role and permissions where a business has more than one member.
Information providers enter about their clients:
- Client name and phone number; email address if the provider records one.
- Appointments, times, services, assigned team member, cancellations and no-shows.
- Notes the provider writes, including service-formula notes.
- Photos a provider attaches to a client record.
- Consent records showing which policy version a client agreed to, and when.
- Prepaid package and membership balances, recorded as an append-only ledger.
Technical information created by using the service:
- A session cookie that keeps you signed in. It is set httpOnly and SameSite=Lax, and marked Secure in production.
- Session records: when a session started, when it was last seen, when it expires, and whether it was revoked. Each session stores a short truncated hash used only to label a device in your session list — not a browser fingerprint, and not your raw browser user-agent string.
- Audit events for security-relevant actions inside a workspace.
- Error diagnostics when something fails, so we can fix it.
- Your IP address is read when you sign in or submit a public booking, and is used only in-memory to rate-limit abuse. It is not written to our database.
Payments and card information
JADA does not store card numbers. Payment functionality in JADA is currently simulated — no real card is charged and no real payment credential is held. Where a card is represented in a client record, we store only a brand label, the last four digits, and a simulated reference.
When real payments are introduced, they will be processed by Stripe. In that model the provider — not JADA — is the merchant for her clients’ payments, card details are collected and held by Stripe under its own terms and security programme, and JADA stores only references and amounts needed to show a record and reconcile it.
How we use information
- To provide the service: scheduling, client records, availability, checkout records and reporting.
- To authenticate you, keep your account secure, and let you see and revoke your own sessions.
- To send transactional messages you or your provider triggered — for example email address verification and password resets.
- To protect the service against abuse, fraud and automated attacks.
- To diagnose and fix faults.
- To meet legal obligations.
We do not sell personal information, and we do not use client information to market to your clients.
Messages
Appointment-related text messages inside JADA are currently simulated and are not delivered to real phones; they are recorded so a provider can see what the system would have sent. Account emails — such as address verification and password resets — are sent for real through our email provider.
Service providers we use
We keep this list short on purpose, and it reflects what production actually uses today:
- Postmark — sends transactional account email on our behalf.
- Cloudflare — DNS for itsjada.com and routing for inbound email sent to our addresses.
- Hetzner — the hosting provider whose servers run JADA and store its database and backups.
- Stripe — will process payments when payment functionality becomes live; not yet handling any real payment for JADA.
These providers process information only to deliver their service to us. We do not grant them rights to use it for their own purposes.
When we disclose information
- To the service providers above, to operate the service.
- To a provider, for the clients and records belonging to her own business.
- To a client, through a private link that shows only her own record.
- When required by law, or to respond to valid legal process.
- To protect the rights, safety or property of JADA, our providers, or the public.
- In connection with a merger, acquisition or sale of assets — with notice, and the information stays subject to a policy at least as protective as this one.
Storage, retention and deletion
Information is stored on servers in the United States. We keep account and business information for as long as the account is active, and afterwards only as long as we need it for the purposes described here or to meet a legal obligation. We take regular backups, and backups persist for a period after deletion before they age out.
Security
- Passwords are stored only as salted cryptographic hashes and compared in constant time.
- Sessions are signed, expire, and can be revoked individually or all at once — including automatically on password reset or account deactivation.
- Access is enforced on the server for every page and action, not merely hidden in the interface.
- Each business's data is isolated from every other business, and that isolation is tested adversarially.
- Sign-in and other sensitive endpoints are rate-limited.
- Traffic is served over HTTPS.
- Backups are taken daily and stored off the primary server.
No system is perfectly secure, and we do not claim certification under any particular security standard.
Your choices
- Providers can view their client records inside JADA, and add to them.
- Correcting or deleting a client record is handled by request rather than by a button in the product today — contact us through the support page and we will tell you what we can do and by when.
- Providers can export business data.
- You can see your active sessions and sign out of one or all of them.
- You can ask us to access, correct or delete information we hold about you, or to close your account.
- Clients: JADA holds your information on behalf of the beauty provider you booked with. Contact her first — she controls that record. If you cannot reach her, contact us and we will help.
Children
JADA is for businesses and is not directed to children. Provider accounts are for adults. A provider who serves a minor client is responsible for having the appropriate consent from a parent or guardian before entering that client’s information into JADA.
Changes
We may update this policy. When we do, we will change the date at the top, and for material changes we will give notice through the service or by email.
Contact
Questions about this policy, or a request about your information: see our support page.