1. Who we are
Flowesce is a salon and wellness business platform operated by Songer Technologies Pte. Ltd., a company incorporated in Singapore. Throughout this policy, "Flowesce," "we," "us," and "our" refer to Songer Technologies Pte. Ltd. trading as Flowesce. "You" refers to the person using our service, whether you are a salon owner, a member of their team, or a client of a salon that uses Flowesce.
This policy explains what information we collect, how we use it, who we share it with, and the choices you have. If anything is unclear, reach out to hello@flowesce.com.
2. Information we collect
We collect information in a few different ways.
Account information
When a salon owner signs up, we collect their email address, full name, business name, and a password (stored as a hash, not in plain text). We also store the country and timezone the business operates in.
Business information
As salon owners use Flowesce, they add information about their branches, services, staff, inventory, expenses, and bookings. This information lives in the salon's workspace and is treated as the salon owner's data.
Client information
Salon owners record information about their clients (name, email, phone, appointment history, optional notes, optional file uploads such as before-and-after photos). The salon is the controller of this information. We process it on the salon's behalf.
Billing information
We use Stripe to process subscription payments. Stripe collects card and billing-address details directly. We never see or store full card numbers. We do store the Stripe customer ID, subscription status, plan, and the last four digits of a card when Stripe makes those available.
Integration information
If a salon connects an external integration (such as Google Calendar) we receive an OAuth refresh token from the provider. We encrypt those tokens at rest using AES-256-GCM with a server-side key. We use the token only to perform the actions the salon authorized.
Support and feedback
If you contact us by email, file a feature request, or reply to one of our messages, we keep that correspondence so we can follow up.
Technical information
We collect standard technical signals such as IP address, browser type, device type, timestamps, and the pages you visited. We use this information to operate the service, diagnose problems, and improve performance.
3. How we use information
We use the information we collect to:
- Provide, maintain, and improve the Flowesce service.
- Process bookings, send confirmations and reminders, and run the features a salon owner has set up.
- Process payments, prevent fraud, and meet our financial and tax obligations.
- Respond to questions, troubleshoot issues, and provide customer support.
- Send service-related emails (account confirmations, billing notices, security alerts) that are necessary to operate the service. These are not marketing.
- Send optional product updates to salon owners who have opted in. They can opt out at any time.
- Detect, investigate, and prevent abuse, security incidents, and violations of our Terms of Service.
- Comply with applicable law.
4. Sharing and disclosure
We do not sell personal information. We share information only with the service providers we need to run Flowesce and only to the extent they need it. Those providers are:
- Supabase (Postgres database, authentication, file storage). Hosted in the region we configure for the project.
- Vercel (application hosting, edge network).
- Stripe (subscription billing and payment processing).
- Resend (transactional and product emails).
- Google (Google Calendar API, only for salons that connect the integration; see Section 5).
- PostHog (product analytics).
We may disclose information if we are required to by law, court order, or a comparable lawful request, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others. If Flowesce is involved in a merger, acquisition, or sale of assets, we will notify affected users before personal information is transferred.
5. Google user data (limited use)
When a salon connects Google Calendar, Flowesce requests access to the following scopes:
https://www.googleapis.com/auth/calendar.events. Used to create, update, and remove the connected staff's appointments on their Google Calendar so the salon owner can see appointments alongside the rest of their day. This is one-way: Flowesce writes to Google, it does not read Google events into Flowesce.userinfo.email. Used to confirm which Google account is connected so the salon owner can see it on the integration settings page.
Limited Use disclosure.Flowesce's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide or improve user-facing features that are prominent in the Flowesce app (writing appointments to the connected calendar).
- We do not use Google user data for advertising, and we do not transfer Google user data to third parties for advertising or any unrelated purpose.
- We do not allow humans to read Google user data unless we have obtained the salon's affirmative consent to do so for specific messages, doing so is necessary for security purposes (such as investigating abuse), or we are required to do so by law.
- The salon can revoke our access at any time by disconnecting the integration in Flowesce or via their Google account permissions page.
6. Cookies and similar technologies
We use cookies and similar storage for:
- Authentication. Session cookies that keep you signed in. These are essential to the service.
- Preferences. Local storage values that remember theme, sidebar state, and similar UI preferences.
- Analytics. PostHog cookies that let us understand how the product is used in aggregate. We proxy these through our own domain so they are not blocked by common ad blockers.
You can clear cookies or block them in your browser, but doing so may break parts of the service (in particular, signing in).
7. Data retention
We keep account and business information for as long as the salon's workspace is active. When a salon owner cancels and asks us to delete their workspace, we delete the workspace's data within 30 days, subject to limited exceptions for backups (purged on the regular backup rotation, within 90 days) and information we are legally required to retain (such as invoices for tax purposes).
Marketing email contacts who unsubscribe are removed from the active list right away.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you, to object to certain processing, and to withdraw consent. To exercise any of these rights, email hello@flowesce.com. We will respond within a reasonable time, and at the latest within the timeframes required by applicable law.
If you are a client of a salon that uses Flowesce and want to exercise rights over the information that salon holds about you, the salon is the controller of that information. Contact the salon directly. We will support them with the request.
If you are based in Singapore, you can also contact the Personal Data Protection Commission. If you are based in the EU or UK, you can contact your local data protection authority.
9. Security
We follow industry-standard practices to protect the information we hold. Passwords are hashed. OAuth refresh tokens are encrypted at rest. Network traffic is TLS-encrypted. Access to production systems is restricted and logged. No system is perfectly secure. If we become aware of a breach that affects your information, we will notify you and the relevant authorities as required by law.
10. International data transfers
Flowesce is operated from Singapore. Our service providers may be located in other regions, including the United States and the European Union. When we transfer personal information across borders, we rely on safeguards permitted by applicable law, such as standard contractual clauses where required.
11. Children
Flowesce is not intended for use by children under 16. We do not knowingly collect information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. When we make material changes, we will notify salon owners by email and update the effective date at the top of this page. Continued use of Flowesce after the change means you accept the updated policy.
13. Contact
Questions about this policy? Email hello@flowesce.com or write to:
Songer Technologies Pte. Ltd.Singapore