Legal
Privacy Policy
This policy explains what personal data Flo∞ collects, how we use it, who we share it with, and the choices and rights you have. It covers both the businesses that subscribe to Flo∞ and the end customers whose details those businesses manage in the platform.
Last updated: 27 July 2026
1. Who we are
Flo∞ (“Flo8”, “we”, “us”) is a salon, spa, and clinic management platform operated by a company established in the United Arab Emirates, serving businesses across the MENA region. You can contact us at info@flo8.io.
TODO (owner): registered legal entity name, trade-licence number, and registered address to be inserted here by counsel.
2. Controller and processor roles
Flo∞ serves two kinds of people, and our role differs for each:
- Business accounts (our customers). When a business signs up, configures its workspace, and pays for a subscription, we act as the controller of that account’s own data (e.g. the owner’s login, billing, and team accounts).
- End-customer data (the business’s clients). When a business stores its own clients’ appointments and contact details in Flo∞, that business is the controller of that data and Flo∞ acts as a processor, handling it only on the business’s instructions and to provide the service.
If you are an end customer and want your data corrected or deleted, please contact the business you booked with. They control that record, and we will assist that business in responding to your request.
3. Data we collect
Depending on how Flo∞ is used, we process:
- Account & profile data: name, email address, phone number, business name, role, and login credentials.
- Billing data: subscription plan, billing contact, and payment status. Card details are entered directly with our payment processor (Stripe); we do not store full card numbers.
- End-customer records (on behalf of businesses): client names, contact details, appointment history, notes a business chooses to record, and stock/operations data.
- Communications: the content and metadata of calls, SMS, WhatsApp, web chat, and email handled through the platform, including AI-assisted replies and call transcripts.
- Usage & technical data: log data, device and browser information, IP address, and diagnostic/error data used to operate and secure the service.
4. How we use data
- To provide, operate, and maintain the Flo∞ platform and its features.
- To power AI-assisted booking, messaging, reordering, and the phone receptionist.
- To process subscriptions and payments and to manage your account.
- Service and transactional messages: booking confirmations, appointment reminders, changes to a booking you already have, offers of a slot you asked to be waitlisted for, one-time codes, and support replies.
- Marketing messages sent by a business to its own customers through Flo∞ — a separate purpose from the transactional messages above, and one you can opt out of. See Marketing messages and how to stop them below.
- To monitor, secure, debug, and improve the service.
- To comply with legal obligations and enforce our terms.
We do not sell personal data. We do not use end-customer data to train our own models, and we do not use it for advertising.
Marketing messages and how to stop them
Some of what a business sends through Flo∞ is marketing rather than a message about an appointment you have already made. Today that means: birthday gifts and seasonal greetings, holiday campaigns a business sends to its customer list, and — only where the business has deliberately switched them on, one setting at a time — a follow-up after a missed appointment, a win-back for a customer who has not visited in a while, and a request for a review. These go out by SMS, WhatsApp, or email, depending on how the business is able to reach you.
Lawful basis. The business you booked with decides whether to send these messages and is the controller of your record (see section 2). It is responsible for having a lawful basis to market to you, including obtaining your consent where the applicable law or the messaging channel requires it — an obligation also set out in our Terms of Service. Flo∞ acts as that business’s processor: we send on its instruction, and we suppress every business-initiated marketing message, on every channel, for anyone recorded as opted out.
How to opt out. Either of these works, at any time and at no cost:
- Reply STOP. Send STOP (or UNSUBSCRIBE, or توقف in Arabic) as a reply on SMS, WhatsApp, or Instagram DM. We confirm it back to you and it takes effect straight away. Reply START to opt back in. Every marketing message Flo∞ sends automatically carries this opt-out line.
- Ask the business directly. Staff can switch marketing off for your record from their Flo∞ console. This is the route for email, where a “STOP” reply is not automatically detected, and for anyone who would rather ask a person.
Opting out stops marketing only — it does not stop booking confirmations or reminders. You will still receive confirmations, reminders, changes to a booking you have, offers for a slot you asked to be waitlisted for, and one-time codes. That is deliberate: those are messages about an appointment you yourself made, and switching them off would mean missing it. If you do not want a business to hold or contact your details at all, ask that business to delete your record (see section 9).
Quiet hours. Marketing sent automatically is also time-limited. The missed-appointment, win-back, and review-request messages are only sent between 09:00 and 20:00 in the business’s own local time by default — a business can configure a different window — and anything falling due outside it waits rather than being dropped. Birthday gifts, seasonal greetings, and campaigns are sent on a single daily run rather than the moment they come due.
5. Sub-processors
We rely on the following third-party service providers to operate Flo∞. Each processes personal data only as needed to provide its part of the service, under its own terms and security commitments:
| Provider | Purpose |
|---|---|
| Supabase | Managed Postgres database, authentication, and file storage: the primary store for tenant and end-customer records. |
| Stripe | Subscription billing and payment processing for business accounts. Stripe handles card data directly; we do not store full card numbers. |
| Twilio | Sending and receiving SMS, WhatsApp, and voice communications (e.g. appointment confirmations and the phone line). |
| Retell AI | Powers the AI phone receptionist: speech recognition and voice responses for inbound calls (Premium feature). |
| Anthropic | Large-language-model processing behind the AI assistant (booking, messaging, and operations actions). |
| Resend | Transactional email delivery (e.g. notifications, support, and demo-request alerts). |
| Sentry | Application error monitoring and performance diagnostics, to keep the service reliable. |
Some of these providers process data outside the UAE/MENA region (for example in the EU or US). TODO (owner): confirm with counsel the appropriate safeguards and cross-border transfer disclosures for your jurisdiction(s).
6. Data retention
We keep personal data for as long as a business account is active and for as long as needed to provide the service. When a business closes its account, we delete or anonymise its data within a reasonable period, except where we must retain certain records to meet legal, tax, accounting, or security obligations.
TODO (owner): set and state specific retention periods (e.g. days to delete after account closure, billing-record retention) once confirmed.
7. Security
We use technical and organisational measures to protect personal data, including encryption in transit, access controls, tenant isolation, and error monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to notify affected parties of a material breach as required by applicable law.
8. Cookies
Flo∞ uses a small number of strictly necessary cookies, primarily to keep you signed in (Supabase authentication) and to keep the app secure. These are essential to provide the service and cannot be switched off through the app.
We do not currently set advertising, analytics, or other non-essential tracking cookies, so no cookie-consent banner is shown. If that changes, we will update this policy and add a consent mechanism where required.
9. Your rights
Subject to applicable law, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. To exercise these rights:
- Business accounts: contact us at info@flo8.io.
- End customers: contact the business you booked with (the controller of your record). We will support that business in fulfilling your request.
- Marketing messages: you can stop them yourself at any time by replying STOP on SMS, WhatsApp, or Instagram DM, or by asking the business to switch them off — no need to contact us. Section 4 explains what this does and does not stop.
TODO (owner): confirm with counsel which data-protection regime(s) apply (e.g. UAE PDPL, DIFC DPL, or others by customer location) and add any region-specific rights and complaint/contact details.
10. Children
Flo∞ is a business tool and is not directed to children. We do not knowingly collect personal data directly from children. Businesses that record minors’ details (e.g. for appointments) are responsible for having a lawful basis to do so.
11. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “last updated” date above and, where appropriate, notify account holders. Continued use of Flo∞ after an update means you accept the revised policy.
Questions about this policy?
Reach our team at info@flo8.io. We're a UAE-established company serving businesses across the MENA region.