Privacy policy
Effective from:
This is a translation. If it differs from the Ukrainian text, the Ukrainian text prevails.
1. Who we are
The Perukar service ("Perukar", "we"). Perukar is software for beauty salons: bookings, clients, cash desk, stock, payroll, reports. It runs at app.perukar.org, the online booking and review pages at book.perukar.org, this site at perukar.org.
For any question about personal data, write to admin@perukar.org.
This policy follows the Law of Ukraine "On Personal Data Protection" and, for visitors from the European Union, the General Data Protection Regulation (GDPR).
2. Who is responsible for what
- A salon that uses Perukar is the controller of its clients' and employees' personal data: it decides what data to enter and why. Perukar processes that data only on the salon's behalf and on its instructions (as a processor); the terms of that processing are in the "Processing personal data" section of the Terms of service.
- Perukar is the controller of the employee account data needed for sign-in and security: the login, passkeys, the sign-in log.
- This site (perukar.org) collects no personal data: it has no forms, no cookies and no analytics.
If you are a salon's client, ask your salon first about your data; we help it answer.
3. What data we process and why
| Category | Source | Purpose | Legal basis |
|---|---|---|---|
| Employee accounts: name, login, role, interface language, e-mail (if given) | The salon or the employee | Access to the program, permissions | Contract with the salon; legitimate interest |
| Sign-in security: passkey public keys, password hashes (argon2id), one-time code secrets (when enabled), sessions, a log of sign-in events with IP address and browser type | The employee, their browser | Protecting accounts, investigating incidents | Legitimate interest; the duty to protect data |
| Salon clients: name, phone, e-mail, birthday, visits, the master's notes and photos, message consents, reviews | The salon; the client during online booking | Bookings, service, visit history, reminders | Decided by the salon (contract with the client, consent, legitimate interest) |
| Online booking: phone number and a one-time SMS code | The client | Confirming the booking, preventing abuse | Decided by the salon; legitimate interest |
| Payments and fiscal receipts: amounts, payment method, products and services, receipt data | The salon | Sales records, fiscalisation | The salon's legal obligation |
| Messages sent: the recipient's number or identifier, text, delivery status | The salon | Reminders, service messages, review requests | Decided by the salon (the client's consent for marketing messages) |
We do not sell personal data and do not use it for advertising.
4. Google user data
Google sign-in. When an employee signs in with Google, we receive from Google the account identifier, the e-mail address and a flag saying the address is verified. We keep the link between the Google account and the Perukar account; we do not store any Google token for sign-in.
Google Calendar. When a master connects her Google Calendar, Perukar creates one calendar of its own, "Perukar — <salon>", in her account and writes into it her visits (the client's first and last name, the service, the time), shifts, vacations and blocked time. Only if she allows it, Perukar reads the busy and free times of her primary calendar so that the salon does not book clients into her private appointments; we never read or store event titles, places or attendees. We do not read or change any other calendar of hers.
The Google refresh token is stored encrypted; access tokens exist only in the server's memory. When the master disconnects the calendar (or leaves the salon), we delete the calendar we created and revoke access; if Google is unreachable at that moment, we delete our record of the connection anyway. Access can also be removed at any time in the Google account settings (myaccount.google.com → Security → Third-party apps).
Perukar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The policy: https://developers.google.com/terms/api-services-user-data-policy.
We do not sell Google user data, do not use it for advertising or to train artificial intelligence models, and people do not read it — except with your consent, for security (investigating abuse), or as the law requires.
5. Who receives data
Only those the service needs, and only as much as they need:
- The hosting provider whose servers run Perukar. The servers are rented from a hosting provider; we name the country where they stand on request.
- TurboSMS — sending SMS (online booking codes, reminders) on the salon's behalf.
- Telegram and Viber — only when the salon has enabled these channels and the client has agreed.
- Zoho Mail — sending e-mail from the perukar.org address (invitations, access recovery).
- Checkbox — the software cash register for the salon's fiscal receipts.
- Google — Google sign-in and Google Calendar, only for those who turned them on.
- Backup storage at a different provider — copies are encrypted before they are sent, and the provider cannot read them.
Authorities receive data only on a lawful basis.
6. Transfers abroad
Some of these recipients (Google, Telegram, Viber, Zoho, the hosting and backup storage providers) process data outside Ukraine, including in the European Union and the United States. We choose providers that ensure adequate protection (including standard contractual clauses) and send only what the service cannot work without.
7. Cookies and browser storage
The Perukar app uses only the cookies sign-in needs:
| Name | Purpose | Lifetime |
|---|---|---|
| bpro_session | The employee's session after sign-in | Up to 30 days (ends after 12 hours of inactivity) |
| __Host-bpro_oidc | Protects Google sign-in | 10 minutes |
| __Host-bpro_gcal | Protects connecting Google Calendar | 10 minutes |
The theme chosen in the app (light or dark) is kept by the browser in its local storage on the device. This site (perukar.org) sets no cookies and loads no analytics and no third-party scripts.
8. How long data is kept
- Sessions — up to 30 days.
- A salon's data — while the contract with the salon lasts; after it ends, deleted within 30 days (before that the salon can get a copy).
- Backups — daily ones for 14 days and weekly ones for 8 weeks, after which they are deleted automatically.
- Voice dictation audio of notes — 30 days; visit photos are kept until the salon deletes them.
- The security event log — 3 years.
9. Your rights
Under Article 8 of the Law of Ukraine "On Personal Data Protection" and Articles 15–22 of the GDPR, you have the right to know what data about you is processed, to get a copy, to have it corrected or erased, to restrict or object to processing, to withdraw consent and to receive your data in a portable format.
A salon's clients should contact their salon first — it is the controller of their data; we help it. Employees and everyone else can write to us at admin@perukar.org. We answer within 30 days.
You may complain to the Ukrainian Parliament Commissioner for Human Rights or, in the European Union, to the data protection supervisory authority of your country.
10. How we protect data
- Each salon has a separate database.
- Sign-in with passkeys; passwords are stored only as argon2id hashes.
- Encrypted connections only (HTTPS); the session cookie is out of reach of scripts.
- Connection secrets (Google, message channels) are stored encrypted.
- Backups are encrypted before they leave the server.
- Every sign-in event is logged; employees' access is limited by their role.
If a breach threatens your rights, we notify the salon and, where the law requires, the supervisory authority.
11. Children
Perukar is not meant for users under 16. A salon enters data of its minor clients on its own responsibility and with their parents' consent where the law requires it.
12. Changes to this policy
We notify salons of material changes in advance. The date the current version takes effect is shown at the top of the page.
13. Contact
Questions, requests and complaints about personal data: admin@perukar.org.