GlamPOS Privacy Policy
Last updated: August 25, 2026
GLAMRENO LLC ("GlamPOS," "we," "us," or "our") provides a
point-of-sale, scheduling, loyalty, payments, AI-assistance, marketing, and customer-engagement platform used by
beauty salons and similar businesses ("Merchants"). This Privacy Policy
explains what information we collect, how we use it, how we share it, and the
choices you have — including with respect to text (SMS) messages. It applies to
Business Owners, managers, staff/technicians, and the customers of participating
Merchants.
Our Role
For a Merchant's business and customer data, the Merchant is the
"controller" and GlamPOS acts as a "processor" that handles data on the
Merchant's behalf. For account registration and our own operations, GlamPOS is
the controller.
For merchant onboarding and verification information collected to activate
GlamPOS Payments, for our SMS suppression records, and for data we use to
secure, support, and improve the Service, GlamPOS acts as the controller (or
"business") because we process that information to meet our own legal and
operational obligations.
Information We Collect
- Account information (Owners/staff): name, email, phone
number, password, role, and staff PIN (stored only as a secure hash). If you
sign in with Google or Apple, we receive your basic profile (name and
email) to create and authenticate your account; we do not receive your
Google or Apple password. If you use Apple's Hide My Email, we receive
only the private relay address Apple generates for you.
- Customer information provided to a Merchant at the point
of sale: name, mobile phone number, email, birthday.
- Business & transaction data: services, prices,
appointments, visits, sales, tips, discounts, payroll and commission figures,
gift cards, and rewards.
- Loyalty & messaging activity: points, rewards issued
or redeemed, message delivery, and opt-in/opt-out status.
- Device & usage data: app and log data used to operate
and secure the Service, including device/browser type, app version, IP or
network information, crash diagnostics, security events, and feature usage.
- AI Support and Cashier data: questions and prompts,
conversation history, microphone audio and transcripts when voice is used,
current screen and available actions, and limited business context needed to
answer or act—such as staff, services, appointments, check-ins, customer
names, and transaction totals. Do not submit card numbers, passwords, PINs,
government identifiers, health information, or unnecessary sensitive data.
- Marketing Autopilot content and connections: salon photos
and derived versions, captions, scheduling and approval status, campaign and
booking-attribution data, connected Meta/Facebook/Instagram and Google
Business Profile account/page/location identifiers and OAuth tokens, public
reviews and reviewer information supplied by Google, and drafted or published
replies. We do not receive your Google or Meta password.
- Merchant onboarding & verification information
(Business Owners who apply for GlamPOS Payments): legal entity name and
DBA, business address and phone, EIN / tax identification number,
ownership structure, and — for the control person and each beneficial
owner with 25% or greater ownership — name, date of birth, home address,
Social Security number or other government identifier, and a
government-issued photo ID; plus the business bank account (routing and
account number) used for settlement. This information is collected to
verify identity, underwrite the account, and meet our and our payment
partners' legal obligations (including anti-money-laundering and
"know-your-customer" laws).
We do not collect or store full payment-card numbers;
card payments are captured by certified payment terminals and processed by
our payment services providers (see Payment Processing below).
How We Use Information
- To provide the Service: loyalty programs, scheduling, checkout, payroll
and commission tracking, reporting, and rewards.
- To send SMS messages you have opted in to receive (see SMS section).
- To authenticate users, secure accounts, and prevent fraud or abuse.
- To maintain, troubleshoot, and improve the Service.
- To provide AI-generated support, voice transcription, cashier assistance,
marketing drafts, photo analysis, and review-reply assistance.
- To connect authorized social/business profiles, prepare and schedule
marketing, publish content after authorization, synchronize reviews, and
measure campaign-related bookings.
- To comply with legal obligations.
SMS / Text Messaging
We do not sell or share your phone number or SMS
opt-in/consent data with third parties for their own marketing.
Mobile information is used only to deliver the messages you have agreed to
receive and to operate the messaging program.
- Opt-in: Customers opt in to receive reward and
promotional texts when they provide their mobile number to a participating
Merchant and affirmatively agree to messaging (for example, by selecting the
SMS opt-in option at check-in).
- Content: Messages relate to loyalty rewards (such as
birthday rewards, "we miss you" offers, and promotional discounts).
- Frequency: Varies; sent on an as-needed basis.
- Opt-out: Reply STOP to unsubscribe,
START to resubscribe, and HELP for help.
After opting out, we keep a suppression record so we do not text you again.
Because messages from participating businesses are sent from our shared
number, replying STOP stops texts from all businesses that message you
through GlamPOS.
- Costs: Message and data rates may apply. Carriers are
not liable for delayed or undelivered messages.
How We Share Information
- With the Merchant you transacted with (for customer
data) and within the business's authorized staff.
- With service providers that help us run the platform —
such as cloud hosting (Google Firebase), crash and error diagnostics
(Google Crashlytics, Sentry), SMS delivery (Twilio), payment
services providers (Finix Payments, Inc. and its sponsor acquiring banks;
Square for Merchants using the Square integration; Stripe for platform
subscription billing), subscription entitlement management (RevenueCat),
web application hosting (Railway), email delivery (SendGrid when enabled),
AI processing and transcription (OpenAI), and identity-verification providers used during
merchant onboarding — who may use the data only to provide services to
us or the Merchant.
- With connected providers such as Meta/Facebook/Instagram
and Google Business Profile when a Merchant connects an account, requests a
sync, or approves publishing. Those providers process information under
their own terms and privacy policies.
- With payment partners, card networks, and financial
institutions as needed to onboard a Merchant for payment
processing, underwrite and monitor the account, settle funds, prevent
fraud, handle disputes and chargebacks, and satisfy card-network rules
and financial regulations (including anti-money-laundering laws).
- For legal reasons: to comply with law, enforce our
Terms, or protect rights, safety, and security.
- Business transfers: in connection with a merger,
acquisition, or sale of assets.
We do not sell personal information or share it for cross-context
behavioral advertising. We do not share phone numbers or SMS consent
with third parties for their own marketing. See our
Subprocessor List for provider details.
Payment Processing
GlamPOS Payments. GlamPOS offers integrated card
processing to eligible Merchants through our payment services provider,
Finix Payments, Inc., and its sponsor acquiring banks. When a customer pays
by card at a participating Merchant, the card is read by a certified
payment terminal and the card data is encrypted and transmitted directly to
the payment services provider — GlamPOS systems do not store or
process full card numbers. GlamPOS receives only masked card details (such as
card brand and last four digits) and transaction records (amount, tip, date,
status) needed to run the Merchant's point of sale, receipts, reporting, and
loyalty features.
Merchant onboarding. To activate GlamPOS Payments, a
Merchant's onboarding and verification information (described above) is
shared with our payment services provider, identity-verification providers,
and sponsor acquiring banks, which use it under their own privacy policies
to verify identity, underwrite and monitor the account, and meet legal
obligations. Records connected to payment processing may be retained for as
long as required by financial regulations and card-network rules (typically
up to seven years) even after an account closes. If an application is
declined, withdrawn, or abandoned, we retain the associated verification
information only as long as needed for fraud-prevention and legal compliance
and then delete it from our systems.
Other processors. Merchants may instead connect their
own Square account, and platform subscriptions are billed through Stripe or
the Apple App Store; those payments are handled by the applicable provider
under its own terms and privacy policy. GlamPOS does not hold or transmit
funds itself and is not a bank; all funds are processed and settled by
licensed payment providers and their partner banks.
AI, Voice & Automated Assistance
Glam Support, AI Cashier, and Marketing Autopilot use OpenAI's API to
process the prompt, audio or transcript, instructions, and limited context
needed for the requested feature. Voice audio is streamed for transcription
and response generation. Text-support requests are sent with provider-side
application storage disabled. OpenAI states that API data is not used to train
its models by default, although limited abuse-monitoring logs may be retained
for up to 30 days unless a different enterprise control applies.
GlamPOS stores text support conversations in Firestore for continuity and
support for up to 90 days, then automatically deletes them. Operational AI
events that do not contain message text follow the same 90-day schedule.
Realtime voice audio is not intentionally stored by GlamPOS; a displayed
transcript may remain on the device for the session. Marketing prompts,
generated captions, photo analyses, approvals, and audit history remain with
the Merchant's marketing records until deleted or the location is purged.
AI features can make mistakes. Authorized users should review proposed
content and transaction details. AI tools are restricted by account role and
available actions; payment-card data is handled by the payment terminal, not
the AI model.
Marketing Photos, Reviews & Connected Accounts
Merchants control the content and accounts they connect. We use OAuth tokens
to access only the permissions granted and encrypt provider credentials at
rest. We use uploaded photos to prepare requested crops, variants, captions,
and posts. We use Google Business Profile review data to display reviews and
draft or publish replies after authorization. Disconnecting a provider stops
future access but does not automatically delete content already published on
that provider. A Merchant can delete unpublished content in GlamPOS or remove
published content through the connected provider.
Cookies & Local Storage
We use only essential cookies and browser storage —
the minimum needed for the Service to work:
- Sign-in sessions: our authentication provider
(Firebase Authentication) stores a session token in your browser so you
stay signed in.
- Payment & fraud prevention: on billing pages, our
payment processor Stripe sets cookies (such as
__stripe_mid
and __stripe_sid) used solely to process payments securely
and prevent fraud.
- Preferences: we use local storage to remember
device-level settings such as language, theme, and kiosk/lock state.
- Abuse prevention: our public booking pages use Google
reCAPTCHA (via Firebase App Check) to block automated abuse; Google may set
a cookie for this purpose.
We do not use advertising, analytics, or cross-site
tracking cookies, and we do not respond to "Do Not Track" signals because we
do not track you across other sites. Because these essential cookies are
required for the Service to function, they cannot be disabled while using
it; you can clear them at any time through your browser settings, which may
sign you out.
Data Security
We use administrative, technical, and organizational safeguards designed to
protect information, including hashed staff credentials and PINs, encryption
in transit, and role-based access controls. Gift-card PINs are, by design,
retrievable by the issuing business's authorized staff (for printing and
balance checks) and are protected by access controls rather than hashing. No
method of transmission or storage is completely secure, and we cannot guarantee
absolute security.
Data Retention & Deletion
- Account profiles and access data: while the account is
active, then deleted through the account-deletion process, subject to short
backup persistence and specific legal holds.
- Merchant operations, customer, appointment, loyalty, and
transaction data: while the location is active and during its
30-day recovery period; Merchants may retain or export records longer where
required for tax, employment, chargeback, or other legal purposes.
- AI support conversations and content-free support events:
up to 90 days.
- Marketing content and connection records: while the
location or content is active, until the Merchant deletes it, disconnects
the provider where applicable, or the location purge runs. Public posts may
remain with the connected provider.
- SMS opt-out/suppression records: retained as needed to
honor the request not to receive further messages.
- Payment, underwriting, tax, fraud, dispute, and KYC records:
for the period required by financial, tax, card-network, and anti-money-
laundering obligations, commonly up to seven years.
- Security logs and backups: for a limited period based on
security and disaster-recovery needs, then overwritten or deleted.
When you delete a business (location), it is first deactivated and enters a
30-day recovery window during which you can restore it. After 30 days, the
business and its associated data are permanently and automatically deleted from
our active systems. Residual copies may persist in backups for a limited
period.
You can delete your account at any time from the app or web (Account
settings). For your security, deletion requires re-verifying your identity —
re-entering your password and confirming a one-time code we send to your phone
by SMS or to your email. You must delete or transfer any active locations
before deleting your account. The process removes the Firebase authentication
account, user profile, profile photos, account-linked memberships, AI support
conversations, support events, and subscription entitlement record. Merchant-
controlled employment or transaction records may remain with the Merchant,
and payment/KYC records may remain where legally required. Residual copies may
persist in backups for a limited period. See
Account Deletion for instructions.
Your Choices & Rights
- Opt out of marketing texts at any time by replying STOP.
- Request access to, correction of, or deletion of your information by
contacting us (for Merchant-controlled customer data, we may direct the
request to the Merchant).
- Depending on where you live and whether the relevant law applies, request
a portable copy; learn the categories and sources of information; opt out of
sale, targeted advertising, or qualifying profiling; limit certain sensitive
information uses; use an authorized agent; and appeal a denied request. We
do not currently sell personal information or use it for cross-context
behavioral advertising.
- We may verify a request using account, email, phone, or transaction
information. We will respond within the time required by applicable law and
will not discriminate against you for exercising a privacy right.
Children
The Service is not directed to children under 13, and we do not knowingly
collect their information. If we learn that information from a child under 13
has been entered into the Service, we will delete it. Merchants may not
enroll children under 13 in loyalty or SMS programs.
Changes to This Policy
We may update this Policy from time to time. We will revise the "Last
updated" date and, where appropriate, provide additional notice.
Contact Us
GLAMRENO LLC
3112 Sunset Ave, Atlantic City, NJ 08401
Email: contact@glamreno.com