Palette

Privacy Policy

Effective 2026-07-06. We’ll update this page when the policy changes and post the date here.

Who we are

Palette is a colour-bar management app for hair salons. The salon team uses it to record colour formulas, weigh products live during a service, and track inventory. It is a B2B product: the people who sign in are the salon’s colourists and managers, not their clients.

Palette is operated by Palette Scale Pty Ltd, ABN 12 701 601 505. When a salon uses Palette, the salon collects its clients’ information to deliver its services, and Palette stores and processes that information on the salon’s behalf. This policy explains how Palette handles it. Each salon should also give its own clients a short privacy notice; Palette provides a template salons can adapt.

Where your data lives

All Palette colour data is stored in Supabase, in the ap-southeast-2 region (Sydney, Australia). Row-level security policies isolate each salon’s data from every other salon on the same database. Your client and formula records stay at rest in Australia.

Disclosure to overseas providers

Palette keeps client and formula records in Australia. Some supporting services are run by companies based overseas (mainly the United States):

  • Hosting and content delivery (Supabase and Vercel) run the Australian-region infrastructure that stores and serves the app. Client colour data stays at rest in the Sydney region.
  • Sign-in email (Resend) sends the one-time sign-in codes to salon managers. To do that it processes the recipient’s email address.
  • AI insights (Anthropic) power the optional weekly summary and analytics. They receive aggregated salon operating data (sales totals, inventory levels, and stylist performance figures) and no client names or client records.

Where personal information is handled by an overseas provider, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles (APP 8). We do not sell personal information, and there is no advertising or tracking in the app.

What we collect

The minimum we need to do the job. For each client a salon works on:

  • Name, so the colourist can find the client’s formula history at the bowl.
  • Booking-platform client ID, an opaque identifier from the salon’s booking platform (for example Fresha) that lets Palette link a client to the salon’s existing booking record. We don’t store the underlying booking-platform data ourselves.
  • Formula history, the colour products and amounts used per visit. This is the product itself; it makes the next visit faster.

For each colourist working at a salon we store their display name, role, and a hashed PIN. Stylist activity (which formulas they ran, which excesses they captured) is attributed to the stylist ID for the salon’s reporting.

What we don’t collect

  • Phone numbers, email addresses, postal addresses, dates of birth
  • Photographs, video, or before/after images of clients
  • Patch tests of any kind, including reactions, dates, or any other medical detail
  • Payment information: payments are handled outside Palette by the salon’s POS
  • Free-text notes about clients beyond the formula itself
  • Location data
  • Device contacts, browsing history, or advertising identifiers

Bluetooth and the scale

On platforms that support it, Palette pairs with an Acaia Pearl S kitchen-style scale via Bluetooth Low Energy. The only data exchanged is weight readings while a colourist is mixing a formula. Nothing else on your device is accessed.

Security

  • Stylist PINs are hashed before storage and never logged.
  • Row-level security policies enforce per-salon isolation at the database layer, not just the application layer.
  • All network traffic uses HTTPS / TLS. The mobile app shell uses Apple’s WKWebView with App Transport Security enabled.
  • Logs never contain client names, formulas, or PINs, only identifiers.

Your rights

Under the Australian Privacy Act and equivalent legislation:

  • APP 12, Access. A salon can request a complete export of their Palette data at any time. We deliver it as a single JSON file containing every record in every table the salon owns.
  • APP 13, Correction. Inaccurate data is correctable via the Manager surface inside the app. If you can’t reach the data through the app, email us.
  • APP 11.2, Right to Erasure. A salon can request hard deletion of all their data. We archive first (reversible window), then hard-delete after a 30-day appeal period unless the request is withdrawn.

To exercise any of the above, email us (details below).

Data breach response

If a notifiable data breach occurs under the Notifiable Data Breaches scheme, we will notify the affected salon and the Office of the Australian Information Commissioner within the required timeframe, and follow up with what happened and what we’ve done about it.

Retention

Salon data is retained for as long as the salon’s account is active. On account closure the data follows the deletion workflow above. Audit and debugging logs are retained for 90 days then aggregated or dropped.

Children

Palette is a workplace tool used by professional colourists. It is not designed for, or directed at, anyone under 16.

Changes to this policy

If we change what we collect or how we handle it, we will update this page and the effective date at the top. For material changes we will notify each salon’s primary contact through the app.

Contact

Questions, access requests, deletion requests, or anything else: email support@palettescale.com. We aim to acknowledge within two business days. For a complaint we can’t resolve, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.