Veladuno Beauty Privacy Policy
Effective date: 10 August 2026 Version: 1.0
Who is responsible
Veladuno Beauty is the commercial brand operated by Costaru Marius Constantin, an individual / sole trader in Romania.
Address: Strada Mihai Popescu nr. 5, Bloc 29, Scara D, Apartament 8, Etaj 2, Târgoviște, Dâmbovița, Romania. Privacy contact: privacy@veladuno.com
The operator is the controller for account administration, service security, support and its own commercial records. Each salon is normally the controller for the customer, appointment, service and team information it enters, while the operator processes that information to provide the service to the salon.
Information processed
Veladuno Beauty processes information entered or generated through use of the service, including:
- account email address, Firebase Authentication identifier and sign-in
- salon and membership information, including role and access status;
- customer records such as name, phone number, email address and notes;
- appointment records including date, time, duration, service, price, deposit,
- service, team, settings, import and other operational records;
- support communications and technical security/error records; and
- trial, subscription status and Paddle billing identifiers held server-side.
security information;
status and notes;
Veladuno Beauty does not store payment-card details. Paddle collects and processes payment information in its checkout as merchant of record.
The application has no configured advertising analytics, behavioural advertising or cross-site profiling.
Purposes and legal bases
Information is processed to:
- create and administer accounts and provide the salon-management service,
- store and display salon operational records under the salon's instructions,
- secure accounts, enforce roles, isolate tenants, prevent abuse and diagnose
- administer trials, subscriptions, customer support and billing, based on the
- comply with legal obligations or establish, exercise or defend legal claims.
based on performance of the service contract;
based on the service contract between the operator and salon;
failures, based on contractual necessity and legitimate interests in operating a secure service;
contract and applicable accounting/legal obligations; and
Where a salon enters personal data about its customers or staff, that salon is responsible for identifying its own lawful basis and giving required notices.
Service providers
The following providers support the Production service:
- Google Firebase / Google Cloud — Firebase Authentication and Cloud
- Vercel — application hosting, serverless billing endpoints, delivery and
- Paddle — merchant of record, checkout, subscription administration,
Firestore. Google generally acts as processor for customer data under its applicable data-processing terms. The Production Firestore database is in europe-west2.
operational logs under Vercel's applicable terms and data-processing arrangements.
payment handling, receipts, refunds and related fraud/compliance processing. Paddle acts under its own buyer terms and privacy notice for transaction data.
These providers may use subprocessors and process information in countries outside Romania. Their applicable contractual transfer safeguards, including standard contractual clauses where relevant, govern such transfers. Current provider information is available from their official privacy and data-processing pages.
Information may also be disclosed when required by law, a competent authority or to establish, exercise or defend legal claims. It is not shared with advertising networks by the application.
Browser storage
The application uses local storage and session storage for requested-service functions, including language and theme choices, onboarding/interface hints, selected salon context, local caches, notification preferences and snapshots. Local cached data can include salon operational records. Firebase Authentication uses browser-managed persistence for the signed-in session.
The application clears its salon context on logout and revalidates membership when the session is restored or the salon changes. Browser storage is not a source of authority for permissions, plan, subscription or membership.
Retention
Account and salon information is retained while needed to provide the service. Operational records remain until deleted through the service, removed on a verified request, or no longer required after the service relationship ends. Support, security and billing records may be retained for as long as necessary to resolve issues, prevent abuse, meet accounting/legal obligations and handle legal claims. Provider backups and logs follow the providers' applicable retention cycles.
No fixed retention period is promised where the period depends on a salon's instructions, an unresolved transaction, security need or legal obligation. Data is deleted or anonymised when it is no longer reasonably required for the applicable purpose.
Security
The service uses authenticated access, active membership checks, role-based permissions, Firestore Rules, server-side entitlement enforcement and tenant isolation. Sensitive server credentials are not included in the public application. No security measure can guarantee absolute security.
Rights and requests
Depending on applicable law, individuals may have rights of access, correction, deletion, restriction, objection and portability, and the right to withdraw consent where consent is the basis for processing.
Requests may be sent to privacy@veladuno.com. Identity and authority may need to be verified before a request is fulfilled. For customer or appointment data entered by a salon, the request should normally be made to that salon as controller; Veladuno Beauty will assist the salon where required.
Individuals may lodge a complaint with the Romanian supervisory authority, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), at https://www.dataprotection.ro/, or with another competent supervisory authority where applicable.
Updates
This policy will be updated before a material new processing purpose, analytics or advertising system, new provider or materially different billing flow is introduced. The effective date above identifies the current version.