Legal

Privacy Policy

Last updated: August 19, 2026

This Privacy Policy describes how Extelia collects, uses, discloses, and safeguards personal data in connection with our website and the Extelia platform. Please read it carefully. Capitalized terms not defined here have the meaning given in our Terms of Service.

1. Overview

Extelia ("Extelia," "we," "us," or "our") provides a business management platform for hair extension professionals and salons, including client records, the Hair Passport, formulas, appointments, inventory, reporting, and an AI assistant (the "Service"). This Privacy Policy explains what personal data we collect, how we use and share it, the choices you have, and how to contact us.

This Policy applies to visitors of our marketing website, prospective and current customers who register an organization account ("Customers," "you"), and the individual users within a Customer's organization ("Staff Users"). It also explains, separately, how we handle information that Customers enter into the Service about their own clients ("End-Client Data"), because that data is not ours — it belongs to the Customer.

If you are an end client of a salon or stylist who uses Extelia and you have questions about your own personal data, please see Section 12 ("If You Are an End Client of an Extelia Customer") below.

2. Our Role: Controller vs. Processor

Extelia acts in two distinct legal capacities, and the rules that apply depend on which category of data is involved:

  • As a data controller, for the information we collect directly to operate our business relationship with you: account and billing details, marketing site interactions, support communications, and platform usage/analytics data.
  • As a data processor (or "service provider"), for End-Client Data that Customers input, upload, or generate within the Service — such as a salon's records about its own clients. For that data, the Customer (the salon or business) is the controller, and we process it strictly on the Customer's behalf and documented instructions, as governed by our Terms of Service and, where applicable, a Data Processing Addendum ("DPA") entered into with the Customer.

If you are a salon or business using Extelia, you are responsible for ensuring you have a lawful basis (including, where required, explicit consent) to collect and store your clients' personal data — including any health-related information — in the Service. See Section 6 and Section 14 for more detail.

3. Information We Collect

3.1 Account & Business Information

When you create an Extelia account or organization, we collect information such as your name, email address, phone number, business name, business address, role, and authentication data. If you sign in via a third-party identity provider, we receive the profile information that provider shares with us.

3.2 Payment & Billing Information

Subscription payments are processed by Stripe, Inc. ("Stripe"). We do not store full payment card numbers on our servers. We receive limited billing metadata from Stripe — such as subscription plan, billing status, invoice history, trial status, and the last four digits of a payment method — to manage your subscription. Stripe's use of your payment information is governed by Stripe's own privacy policy.

3.3 End-Client Data You Enter Into the Service

The Service is designed for Customers to record detailed professional information about their own clients. Depending on how you use Extelia, this may include:

  • Client contact details (name, phone, email, notes);
  • Hair Passport records: install history, formulas, batch/lot numbers, methods, and maintenance schedules;
  • Hair and scalp health assessments, notes, allergy records, and contraindication flags (for example, patch-test results and known sensitivities);
  • Before/after and progress photographs uploaded during a visit;
  • Client documents (e.g., signed consent forms, intake forms) uploaded to the Service;
  • Appointment history, visit notes, and retail purchase history; and
  • Any other information a Customer chooses to record about a client.

Some of this information — particularly allergy, contraindication, and hair/scalp health data — may be considered sensitive or "special category" personal data under laws like the EU/UK GDPR. Extelia does not decide what End-Client Data is collected — Customers control this and are solely responsible for obtaining any consent or authorization required from their own clients before entering it into the Service. See Section 6.

3.4 Usage, Device & Log Data

We automatically collect technical information when you use the Service, including IP address, browser and device type, operating system, pages viewed, features used, timestamps, referring URLs, and crash/error diagnostics. If you enable push notifications, we store a device-specific push subscription token so we can deliver alerts (for example, low-inventory or appointment reminders).

3.5 Cookies & Similar Technologies

Our marketing website and application use cookies and similar technologies (such as local storage) to keep you signed in, remember preferences, understand aggregate usage of our site, and measure the performance of our marketing pages. We use essential cookies required for the Service to function and, where applicable, analytics cookies. You can control non-essential cookies through your browser settings; blocking essential cookies may prevent parts of the Service from working.

3.6 Marketing, Leads & Referrals

If you use tools on our marketing site — such as the inventory-loss calculator, an enterprise sales inquiry form, or our referral program — we collect the information you submit (e.g., name, email, business details, and referral codes) so we can respond to you, track referral credits, and improve our marketing.

4. How We Use Information

We use personal data to:

  • Provide, maintain, secure, and improve the Service;
  • Create and administer accounts, organizations, and staff permissions;
  • Process payments, manage subscriptions, trials, and billing;
  • Enable core features Customers configure, including client records, the Hair Passport, formulas, appointments, inventory tracking, reporting, and reminders (such as patch-test or maintenance reminders);
  • Send transactional communications (billing, security, service, and support notices);
  • Send push notifications and alerts you or your organization have enabled;
  • Respond to support requests and enterprise inquiries;
  • Detect, investigate, and prevent fraud, abuse, and security incidents;
  • Analyze aggregated, de-identified usage trends to improve the Service; and
  • Comply with legal obligations and enforce our Terms of Service.

We do not sell personal data, and we do not use End-Client Data to serve third-party advertising.

5. AI Features

Extelia includes AI-assisted features (for example, an in-app assistant and formula or inventory recommendations). These features process the relevant data already stored in your organization's account — such as client, formula, or inventory records — through a third-party AI infrastructure provider acting as our sub-processor, in order to generate responses and suggestions.

  • We do not permit our AI sub-processors to use Customer or End-Client Data to train models for other customers.
  • AI outputs are generated automatically and may be inaccurate or incomplete. AI-derived suggestions are professional aids only — see the AI disclaimer in our Terms of Service.
  • Where required by law, we will identify our AI sub-processor(s) in our Data Processing Addendum or sub-processor list made available to Customers on request.
  • No automated decision-making with legal or similarly significant effects. AI features generate draft text and suggestions for a human (the Customer or their staff) to review, edit, and decide whether to use. We do not use these features to make decisions about End Clients — such as denying service, altering pricing, or making clinical determinations — without a human in the loop, and they do not produce any automated decision that produces legal or similarly significant effects within the meaning of Article 22 GDPR.

7. How We Share Information

We do not sell personal data. We share personal data only in the following circumstances:

  • Within your organization — data entered by one Staff User is visible to other authorized Staff Users of the same organization, according to the permissions your organization configures;
  • Sub-processors and service providers who host, secure, or support the Service under contractual confidentiality and data-protection obligations, including:
    • Cloud database, authentication, and file-storage infrastructure (Supabase);
    • Payment processing (Stripe);
    • AI inference infrastructure (see Section 5);
    • Web push notification delivery;
    • Email delivery and customer support tooling; and
    • Error monitoring and reliability tooling.
  • Legal & safety — where required to comply with law, legal process, or governmental request, or to protect the rights, property, or safety of Extelia, our Customers, or others;
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections; and
  • With your direction — where you or your organization affirmatively direct us to share data (for example, exporting a client-facing Hair Passport PDF).

A current list of sub-processors is available to Customers on request at support@extelia.app.

8. International Data Transfers

We and our sub-processors may process and store data in countries other than your own, including the United States. Where personal data originating in the EEA, UK, or Switzerland is transferred internationally, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and, where relevant, the UK International Data Transfer Addendum), or other lawful transfer mechanisms.

9. Data Retention

We retain personal data for as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. In general:

  • Account and End-Client Data is retained for the duration of an active subscription and for a limited period afterward to allow reactivation, unless the Customer requests earlier deletion or exports/deletes records itself;
  • Billing records are retained as required by applicable tax and accounting law;
  • Upon account cancellation, Customer and End-Client Data is deleted or anonymized within a commercially reasonable period, as further described in our Terms of Service, except where retention is required by law or for legitimate backup/security purposes; and
  • Marketing leads and enterprise inquiries are retained until you unsubscribe or request deletion, or for a reasonable period of inactivity.

10. How We Protect Information

We use administrative, technical, and physical safeguards designed to protect personal data, including encryption of data in transit, database-level access controls and row-level security scoped to each organization, authentication safeguards, and staff access limited on a need-to-know basis. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal data, we will notify affected Customers and applicable authorities as required by law.

11. Your Rights & Choices

Subject to applicable law, you may have the right to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for certain processing. California residents may have additional rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of certain sharing (we do not sell or "share" as defined by the CPRA for cross-context behavioral advertising).

To exercise these rights:

  • Account & End-Client Data — Customers can access, export, correct, or delete most records directly from within the Service (Settings → Data), including CSV export/import of clients, appointments, inventory, and reports.
  • Requests we handle directly — for anything not self-serviceable, or if you are a Staff User without administrator access, contact us at support@extelia.app. We will verify the request and respond within the timeframe required by applicable law.

You also have the right to lodge a complaint with your local data protection authority.

Non-discrimination. We will not deny you goods or services, charge different prices, or provide a different level of service because you exercised a privacy right under the CCPA/CPRA or similar law.

Do Not Track. Our systems do not currently respond to browser "Do Not Track" signals, though you can still control cookies as described in Section 3.5.

12. If You Are an End Client of an Extelia Customer

If a salon or stylist uses Extelia to store information about you as their client, that business — not Extelia — is the controller of your personal data and is responsible for responding to your privacy requests, including access, correction, or deletion. Please contact the salon or professional directly. We assist our Customers in fulfilling those requests but do not independently manage relationships with end clients we do not have a direct relationship with.

13. Children's Privacy

The Service is intended for business use by professionals and is not directed to children. We do not knowingly collect personal data directly from children under 13 (consistent with the U.S. Children's Online Privacy Protection Act, "COPPA") or under 16 for account registration purposes more generally. If we learn that a child has provided us personal data through account registration in violation of this Policy, we will delete it. End-Client Data entered by a Customer about a minor client is the Customer's responsibility to collect lawfully, including any required parental or guardian consent under applicable law.

14. Data Processing Addendum for Business Customers

If your organization is subject to the GDPR, UK GDPR, or similar data protection laws with respect to End-Client Data, we offer a Data Processing Addendum governing our processing of that data as your processor, including sub-processing, security commitments, breach notification, and audit rights. To request a copy or execute a DPA, contact support@extelia.app.

15. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify Customers by email or through an in-app notice before the changes take effect. The "Last updated" date above reflects the most recent revision. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

16. Contact Us

Questions about this Privacy Policy or our data practices can be sent to support@extelia.app.