1 Introduction
ArtBizDesk ("we," "our," "us") is a business management platform for beauty professionals in India. This Privacy Policy explains what data the platform collects, how it is used and stored, and who else it is shared with.
This policy applies to registered artists (account holders), to visitors who use the contact form on our website, and to the people whose details an artist enters into the platform (their clients and team members).
Roles. For your own account data — your name, business name, email, phone, address and subscription details — we decide how the data is used. For the business records you enter into your workspace — your clients, bookings, payments and team members — you decide what is collected and why; we store and process it on your behalf, to provide the Service to you. You are responsible for having a lawful basis to enter another person's details into the platform.
The Digital Personal Data Protection Act, 2023 (DPDP Act) gives individuals in India certain rights over their personal data. Section 7 explains how to exercise those rights with us. We do not hold any privacy or security certification (such as ISO 27001, SOC 2, PCI DSS) and we make no claim of certified compliance with GDPR or any other framework.
2 Information We Collect
A. Account information you give us when you register:
- Your name, business name, email address, phone number, and WhatsApp number.
- Your address, city, state, pincode, and country.
- The plan you selected.
- Where a subscription payment is arranged with us, the record we keep of it: the amount received, the payment method, and any reference or note you give us. We do not collect card numbers or bank account credentials (see part E).
B. Business data you enter into your workspace:
- Clients: name, contact number, address, city, and any notes you write.
- Bookings: dates and times, location, an optional map link, prices, discounts, status, and your internal notes.
- Services: service names, categories, prices, durations, and descriptions.
- Payments: amounts, payment method, payment date, and notes.
- Team members: name, contact number, WhatsApp number, speciality, daily rate, and the payments you record against them.
C. Files you upload:
- Service photos. These are stored as ordinary files on the web server. Anyone who has the direct link to a service photo can open it without logging in, so please do not upload anything private as a service photo.
- Payment receipt images. These are stored outside the public web folder and are served only to the account that uploaded them, after an ownership check. They are not publicly reachable by URL.
D. Information the platform records automatically:
- Security and account data: your hashed password, your count of failed login attempts and any temporary lockout time, and — only if you switch on two-factor authentication — your 2FA secret (stored encrypted) and your backup codes (stored hashed).
- Activity timeline: a record of actions you take in your own workspace (for example a booking created, a payment recorded, a client updated), visible to you in the app.
- Notification data: if you allow browser notifications, we store the push token your browser issues and basic information about the device/browser it came from. We also store your reminder preferences and a log of reminders sent to you.
- Contact form submissions: if you use the "Contact Us" form on our website, we store your name, email, mobile number, subject, message, and — for anti-spam and security purposes — your IP address and browser user-agent.
- Administrative logs: when an ArtBizDesk administrator changes an account (for example approves it, changes its status, or updates its licence dates), we log the action, what changed, and the administrator's IP address.
- Session data: a server-side session that keeps you logged in (see Section 9).
- Server logs: like any web application, our server and hosting provider generate technical logs, which can include IP addresses, timestamps, and error details. These are used for security and debugging.
We do not run analytics software and we do not track which pages you visit inside the app for profiling or marketing purposes.
E. Information we do NOT collect:
- Credit or debit card numbers, CVVs, or bank account credentials. There is no payment gateway in the platform — subscription payments are arranged manually, outside the Service.
- Government IDs, Aadhaar numbers, or PAN.
- Biometric data, health data, or location tracking.
If you type sensitive information into a free-text field (for example a client note) or upload it as an image, it will be stored as you entered it. Please don't put anything there that you would not want stored.
3 How We Use Your Information
We use the information described above for the following purposes, and no others:
- Account creation & management: to review and approve your registration, set your plan and licence period, and manage renewals and account status.
- Service delivery: to run the features you use — clients, bookings, services, payments, team members, reports, calendar, and reminders.
- Communication: to send you account activation details and your temporary password, password-reset emails, licence and subscription information, and important service messages, at your registered email address.
- Reminders and notifications: to show you in-app notifications and, if you allow it, browser push notifications about your upcoming bookings (see Section 5).
- Customer support: to respond to your queries and troubleshoot problems you report.
- Security and abuse prevention: to rate-limit requests, block automated spam on the contact form, lock accounts after repeated failed logins, and investigate suspected misuse.
4 Data Storage & Security
These are the protections that are actually implemented in the platform:
- Passwords are never stored in plain text. They are stored as a one-way hash using PHP's standard password hashing (currently bcrypt).
- HTTPS. Traffic to the live site is redirected to HTTPS, so data in transit is encrypted.
- Separation between accounts. Every record is tied to the account that owns it, and every query is restricted to the logged-in account, so one artist cannot read or change another artist's records.
- Optional two-factor authentication using an authenticator app, with one-time backup codes. Your 2FA secret is stored encrypted and your backup codes are stored hashed.
- Account lockout after 5 consecutive failed login attempts (15 minutes), and rate limiting on login, password-reset, and contact-form requests.
- Protection against cross-site request forgery (CSRF) on every form, and a Content Security Policy to reduce the risk of script injection.
- Payment receipt images are stored outside the public web folder and are released only to the account that owns them, after an ownership check.
- Backups. We take compressed backups of the platform database for operational recovery. Backups are kept for a short rolling window (currently about 15 days) and are then deleted. Backups can be created and downloaded only by ArtBizDesk administrators.
To be clear about what we do not have: we do not encrypt the database itself at rest, we do not operate a 24/7 security monitoring service, we do not carry out formal third-party security audits or penetration tests, and we hold no security certification.
5 Sharing of Information & Third-Party Services
We do not sell, rent, or trade your personal data or your clients' data. Data leaves our systems only in the following ways:
A. Third-party services the platform depends on:
- Google Firebase Cloud Messaging (push notifications). If you allow browser notifications, reminder notifications are delivered through Google's Firebase Cloud Messaging service. The content of those notifications can include the name of a client or a team member and the time of a booking (for example, "Tomorrow: [client name]"). This means that data is transmitted to Google, whose servers may be located outside India. If you do not want this, do not allow browser notifications — you will still see notifications inside the app.
- Email delivery. Account, password-reset, and notification emails are sent through an email service, which necessarily receives your email address and the content of the email.
- Hosting. Our hosting provider stores the servers and database on which the platform runs.
- Content delivery networks. Our pages load fonts, styles, and scripts from public CDNs (Google Fonts, cdnjs/Cloudflare, and jsDelivr). As with any website that loads external resources, your browser contacts those services directly, and they can see your IP address and browser information. They do not receive your business data.
B. WhatsApp — what actually happens. The WhatsApp feature in ArtBizDesk only prepares message text for you. The platform does not connect to WhatsApp, does not use the WhatsApp/Meta API, and does not send anything to WhatsApp or to your clients. Nothing is shared with WhatsApp or Meta by ArtBizDesk. If you choose to send a message yourself from your own WhatsApp account, that is between you, WhatsApp, and your recipient.
C. Other limited circumstances:
- Legal compliance: when required by law, court order, or a lawful demand from a government authority in India.
- Business transfer: in the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you if your data becomes subject to a different privacy policy.
- With your consent: in any other case, only with your explicit prior consent.
6 Who Can See Your Data
- You — you see everything in your own workspace, and nothing from any other account.
- Your team members — they do not get a login. They cannot access the platform at all. A team member is only a record inside your workspace.
- Your clients — they do not get a login and cannot access the platform.
- ArtBizDesk administrators — they approve registrations, assign plans, set licence dates, change account status, and read registration and contact-form submissions. Administrators and the technical personnel who run the platform have access to the production database and to database backups, which contain all accounts' data. They access it for operating, supporting, securing, and maintaining the Service, or where required by law.
7 Your Rights
You may ask us to do the following in relation to your personal data. There is no self-service tool for these in the app today; every request is handled manually by our team, by email.
- Access: ask for a summary of the personal data we hold about you.
- Correction: ask us to correct data that is wrong or incomplete. You can already edit most of your own profile and all of your business records directly in the app.
- Deletion: ask us to delete your account and its data. Please read Section 8 first — it explains what deletion does and does not remove.
- Withdraw consent: withdraw your consent to our processing. Because we need this data to run your account, withdrawing consent generally means closing your account.
- Grievance: if you believe your data rights have been affected, write to us at the address in Section 11. If you are not satisfied with our response, you may approach the Data Protection Board of India under the DPDP Act, 2023.
Write to us at info@artbizdesk.in. We aim to respond within 30 days.
If you are a client or team member of an artist and you want your details removed from that artist's records, please contact the artist directly — the records are theirs, they entered them, and they control them. If you cannot reach them, you may write to us and we will try to help.
8 Data Retention & What Deletion Really Does
We keep your data for as long as your account exists. We do not automatically delete accounts or business data, including after a licence expires — your data is kept so that you can renew and pick up where you left off.
Please understand how removal works in the platform, so that nothing here misleads you:
- Deleting a record in the app hides it, it does not erase it. When you delete a client, service, team member, booking, or service category, the record is marked as deleted and disappears from your screens, but the row remains in our database.
- Account deletion is manual. If you ask us to delete your account, our team carries this out; there is no automated process, so it is not instantaneous.
- Backups. Even after data is removed from the live database, it can still exist in database backups until those backups age out of the rolling retention window (currently about 15 days), after which they are deleted.
We may also retain certain information for longer where we are required to do so by law, or where it is needed to resolve a dispute or enforce our agreements.
9 Cookies & Browser Storage
ArtBizDesk uses only what it needs to function. There is no cookie consent banner because we do not use any optional, advertising, or tracking cookies.
- Session cookie (essential): a single cookie that identifies your session so you stay logged in. The cookie itself is cleared when you close your browser; the session it points to is stored on our server and expires after a period of inactivity (currently 7 days) or when you log out. This cookie is strictly necessary and cannot be disabled.
- Security tokens: the anti-CSRF token that protects your forms is held in your server-side session, not in a separate tracking cookie.
- Browser storage for push notifications: if you allow notifications, your browser registers a service worker for Firebase Cloud Messaging, which stores data locally in your browser to receive push messages. Blocking or removing notification permission stops this.
We do not use advertising cookies, cross-site tracking cookies, or analytics cookies. Note that the external CDNs described in Section 5 are contacted by your browser when a page loads.
10 Children's Privacy
ArtBizDesk is intended for use by individuals who are 18 years of age or older. We do not knowingly collect personal information from minors as account holders. If you believe that a minor has registered an account, please contact us and we will take steps to remove the information.
11 Changes to This Policy
We may update this Privacy Policy as our practices, our legal obligations, or the features of the platform change. When we do, we will update the "Last updated" date shown on this page, and where the change is material we will also aim to notify active users by email.
Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.
12 Contact Us
For any question about this Privacy Policy, to exercise your data rights, or to raise a grievance:
- Email: info@artbizdesk.in
- WhatsApp: use the WhatsApp button on this page.
- Response time: we aim to respond to privacy requests within 30 days.
If we cannot resolve your grievance, you may approach the Data Protection Board of India as constituted under the Digital Personal Data Protection Act, 2023.