Privacy Policy
Summary
This policy explains how NetGuards LLC (DBA PrettyCRM) (“PrettyCRM”, “we”, “us”) handles personal information on prettycrm.com, in the studio app at app.prettycrm.com and when you contact us. Effective 2026-10-08.
- We do not sell personal information for money.
- Client information that a studio keeps in PrettyCRM belongs to that studio. We process it only to provide the service and never use it for advertising.
- PrettyCRM asks for no health information and is not a medical records system.
- Our website uses analytics or advertising technologies only if you allow them, and we honor Global Privacy Control.
Who this policy covers
Website visitors and account users (studio owners and team members): PrettyCRM decides how their information is used (we are the controller or “business”).
A studio’s clients: the studio decides what it keeps in PrettyCRM and is the controller. PrettyCRM acts as its processor or “service provider” under the Data Processing Addendum. If you are a client of a studio, please send requests to the studio; we will help it respond.
Information we collect
Information you give us
- Account: name, email, password (we store only an Argon2id hash), studio name, language, team role.
- Verification: a mobile number when you sign up with a free email provider (verified by Google Identity Platform; afterwards we keep only a keyed fingerprint to prevent duplicate trials), your authenticator secret (encrypted) and hashes of your recovery codes.
- Billing: Stripe collects card details; we receive a customer ID, plan, subscription status, billing country or postal code and invoices. We never see full card numbers.
- Communications: messages you send through Feedback or by email.
Customer Data
What a studio enters about its clients: names, contact details, language preferences, beauty profile (skin type and tone, undertone, eye colour, notes), looks, schedules, events and any fields the studio chooses to add. All of it is encrypted with the studio’s key.
Information collected automatically
- Security and logs: IP address, browser, sign-in times and failed attempts, to protect accounts and investigate abuse.
- Bot protection: Cloudflare Turnstile evaluates browser signals at sign-up and sign-in.
- Website, only with your permission: Google tags (Analytics/Ads) and the Meta Pixel, which may collect online identifiers, pages viewed and interactions. See the Cookie Policy.
How we use information
- Provide, maintain and secure the service, including two-step verification, duplicate-trial prevention and fraud prevention.
- Process payments and invoices and meet tax and legal obligations.
- Send service messages: codes, invitations, billing notices and important changes.
- Answer feedback and support requests.
- Improve the service using aggregated statistics.
- On our website, and only if you allow it, measure campaigns and show PrettyCRM ads on Google and Meta.
Customer Data is used only to provide the service to the studio. We do not use it for advertising, to train artificial-intelligence models, or to build profiles.
Legal bases (EEA, UK and Switzerland)
Contract (providing the service), legitimate interests (security, fraud prevention, improving the service), consent (analytics and advertising cookies, which you can withdraw at any time) and legal obligation (tax, accounting).
Who we share information with
With providers that help us run the service and are contractually required to protect the data:
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud (Google LLC) | Application hosting, database, encryption keys (Cloud KMS / HSM), backups, phone-number verification (Identity Platform) | United States (us-west2, Los Angeles) |
| Stripe, Inc. | Subscription payments, invoices, tax calculation | United States |
| Resend (Plus Five Five, Inc.) | Transactional email (verification codes, invitations, feedback delivery) | United States |
| Cloudflare, Inc. | Bot protection on sign-up and sign-in (Turnstile) | Global network |
| Vercel Inc. | Hosting of the marketing website and documentation (no Customer Data) | Global network |
If you allow advertising cookies on our website, Google and Meta receive online identifiers and browsing information to measure and personalize ads. Under California law this may be “sharing” for cross-context behavioral advertising. You can opt out at any time (see Your choices). We may also disclose information when the law requires it, to protect rights and safety, or in a merger or acquisition, with notice.
Your choices: Do Not Sell or Share
Use the Do Not Sell or Share My Personal Information link at the bottom of every page, or the button below, to turn off advertising cookies. If your browser sends a Global Privacy Control signal, we treat it as a valid opt-out request and do not load advertising tags. You do not need an account.
Your rights
Depending on where you live, you can ask to access, correct, delete or port your information, opt out of sale, sharing and targeted advertising, and appeal our decision. We will not discriminate against you for using these rights. Write to concierge@prettycrm.com or use Feedback in the app with the topic “Privacy”. We will verify your identity in a reasonable way and respond within 45 days (one month in the EEA and UK). You may use an authorized agent. In the EEA and UK you may also complain to your data protection authority.
Retention
- Account data and Customer Data: while the studio is active. When a trial or subscription ends, the studio becomes read-only and we keep the data for up to 180 days; after that we may delete it with prior notice. A studio can ask for earlier deletion.
- Deletion destroys the studio’s encryption key, which makes any remaining copies unreadable, including backups, which expire within 35 days.
- Security logs: up to 13 months. Billing records: as long as tax law requires (usually 7 years).
Security
Field-level encryption with a per-studio key protected in a hardware security module (Google Cloud KMS), per-studio isolation enforced by the database, TLS on every connection, mandatory two-step verification, short-lived download links and least-privilege access for our staff. No system is perfect; if an incident affects you, we will notify you as the law requires.
International transfers
PrettyCRM operates in the United States. If you use it from another country, your information is processed in the United States. Where the law requires it we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
Children
PrettyCRM is a business service and is not directed to children under 16. We do not knowingly collect children’s information for our own purposes, and we do not sell or share it. Studios that serve minors must have a parent’s or guardian’s permission.
Notice for California residents
In the past 12 months we collected: identifiers (name, email, IP address), commercial information (plan, invoices), internet activity (security logs; website browsing only with permission) and professional information (studio name, role). Sources: you, your studio, your browser and our providers. Purposes: as described above. We do not sell personal information for money. If you allow advertising on our website, we may share identifiers and internet activity with Google and Meta for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics.
Changes and contact
If we change this policy in a material way, we will tell you in the app or by email before the change takes effect. Contact: NetGuards LLC (DBA PrettyCRM), HONOLULU, HI · concierge@prettycrm.com.