ISIPHOSENDALO SOLUTIONS · CUTFLOW
Privacy Policy
How Isiphosendalo Solutions handles personal information through CutFlow
1. Who we are
Isiphosendalo Solutions operates CutFlow. For personal information where we determine the purpose and means of processing - such as account administration, subscription billing, security, support and platform operations - Isiphosendalo Solutions acts as the responsible party.
For customer information that a salon, barber or other participating Business enters into CutFlow for its own booking, customer-management or service-delivery purposes, that Business may be the responsible party and Isiphosendalo Solutions may process the information as an operator on its behalf.
2. Scope of this Policy
This Policy applies to personal information processed through CutFlow websites, business dashboards, public storefronts, booking and queue features, support interactions, subscription billing and related platform services.
Individual salons, barbers and other Businesses may have their own privacy notices governing how they use customer information for their own purposes. Where a customer deals directly with a Business, that Business's privacy practices also apply.
3. Personal information we may collect
Business owners and staff
- Name, email address, mobile number and account identifiers.
- Business name, branch details, address, opening hours, services, staff information and public storefront content.
- Login, authentication, role and access information.
- Subscription plan, payment status, billing references and transaction metadata. We do not intend to store full payment-card details where payment is processed by a third-party payment provider.
- Support messages, feedback and communications with us.
Customers of participating businesses
- Name, mobile number, email address or other contact details provided during booking or queue entry.
- Appointments, service selections, preferred staff member, visit history and queue information.
- Payment status or payment-record information entered by the Business, where applicable.
- Loyalty, rewards and promotion-related information where enabled by the Business.
Technical and usage information
- Device, browser, IP address, session, security and diagnostic information reasonably required to operate and protect the service.
- Basic usage and event information used for troubleshooting, security, service improvement and operational reporting.
4. Why we process personal information
Depending on the context and applicable law, we process personal information to:
- create, authenticate and administer CutFlow accounts;
- provide public storefronts, bookings, queues, customer records, staff management, payments settings, loyalty, promotions and reports;
- process and verify CutFlow subscription payments;
- provide customer support, onboarding and service communications;
- protect accounts, investigate suspected fraud, prevent misuse and maintain platform security;
- maintain records required for billing, accounting, legal and compliance purposes;
- improve CutFlow features, reliability and usability; and
- send marketing communications where permitted, with an appropriate opportunity to opt out.
5. Lawful processing and POPIA
We aim to process personal information lawfully, reasonably and in a manner that does not unjustifiably infringe privacy. The lawful basis or justification depends on the context and may include consent, performance of an agreement, compliance with a legal obligation, protection of a legitimate interest, or another basis permitted by POPIA.
Participating Businesses are responsible for ensuring that they have an appropriate lawful basis for the customer information they collect and use through CutFlow, including any direct marketing or promotional use.
6. Bookings, reminders and marketing
CutFlow may enable Businesses to contact customers about bookings, reminders, queues, service updates, loyalty and promotions. Service messages that are necessary to manage a booking or requested service may be different from promotional marketing.
Businesses are responsible for complying with applicable direct-marketing rules, obtaining consent where required, keeping appropriate records and respecting opt-out requests. Isiphosendalo Solutions may also send CutFlow service notices and, where permitted, product or promotional messages to Business users.
7. Children's personal information
CutFlow business accounts are intended for adults and authorised business users. A salon or barber may provide services to minors. Where children's personal information is processed, the relevant Business must ensure that it has a lawful basis and any required consent or authorisation under applicable law. We do not intentionally invite children to create CutFlow business accounts.
8. Sharing personal information
We may share personal information only where reasonably necessary for the purposes described in this Policy, including with:
- the participating Business and its authorised staff;
- hosting, database, authentication, cloud, communications, analytics and security service providers acting under appropriate arrangements;
- banking and payment records used to verify CutFlow EFT subscription payments;
- third-party payment, map or other services selected or enabled by a Business;
- professional advisers, auditors or insurers where reasonably necessary; and
- regulators, courts, law-enforcement bodies or other persons where disclosure is required or permitted by law.
We do not sell personal information to advertisers.
9. Third-party payment services
Subscription payments and some customer payment options may redirect users to or use third-party payment providers. Those providers process information under their own terms and privacy policies. CutFlow should not be used to store full card numbers, PINs or other payment credentials that a third-party payment provider is designed to collect directly.
10. International or cross-border processing
Some cloud or service providers may process or store information outside South Africa. Where cross-border processing occurs, we take reasonable steps to use providers and arrangements that support an appropriate level of protection as required by applicable law.
11. Security safeguards
We use reasonable technical and organisational measures to protect personal information against loss, misuse, unauthorised access, alteration or disclosure. These measures may include authenticated access, role-based controls, database access restrictions, secure hosting, encrypted transmission where supported, credential protection, logging and other operational safeguards appropriate to the service.
No electronic system is completely secure. Business users must also protect their devices, passwords and staff access and must not share sensitive credentials through insecure channels.
12. Security incidents
If we become aware of a security compromise involving personal information, we will investigate and take reasonable containment and remediation steps. Where required by POPIA or another applicable law, the responsible party will notify the Information Regulator and affected data subjects in the required manner.
Businesses should notify us promptly if they suspect a CutFlow account or customer-data compromise.
13. Data retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to provide the service, resolve disputes, meet accounting or legal requirements, protect legitimate interests or comply with applicable law.
When a trial or subscription ends, access may be locked while information remains stored for a reasonable period. Information may later be deleted, de-identified or retained where lawful and necessary. A Business may contact us about account closure or data requests.
14. Your privacy rights
Subject to applicable law and verification of identity, a data subject may have the right to:
- ask whether we hold personal information about them and request access;
- ask for inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained information to be corrected or deleted where applicable;
- object to certain processing where permitted by law;
- withdraw consent where processing is based on consent, without affecting prior lawful processing;
- opt out of direct marketing where applicable; and
- lodge a complaint with the Information Regulator of South Africa.
If the request relates to information controlled by a participating salon or barber, we may refer the requester to that Business or assist the Business in responding, depending on our role for that information.
15. Cookies and local storage
CutFlow may use cookies, browser storage or similar technologies that are necessary for authentication, session management, preferences, security and basic platform functionality. Where non-essential analytics or marketing technologies are used, additional notice or consent may be provided where required.
16. Changes to this Policy
We may update this Privacy Policy as CutFlow develops or legal requirements change. The current version will show an effective date. Where a change materially affects how we use personal information, we will take reasonable steps to notify affected users where required.
Contact us
Privacy requests should include enough information for us to identify the relevant account or record and verify the requester where reasonably necessary. Do not send passwords, PINs or full card details by email or WhatsApp.
17. Information Regulator
Data subjects may also contact or lodge a complaint with the Information Regulator (South Africa). Current public contact information is available from the Information Regulator's official website and eServices portal.