Privacy for shops

Last updated September 22, 2026

This is for the owner and staff of a business that runs on Thrivari, whether a barbershop, a salon, a studio, or any other business that takes appointments: the dashboard, the booking site we run under your name, and anything you connect to them. If you booked an appointment at a shop, this page is yours instead. Questions go to hello@thrivari.com.

The short version

What we hold about your shop

Your business name, address, hours, services and prices, the people on your team, the owner's contact details, and the settings you choose. Each person who signs in to the dashboard has their own PIN, which we store scrambled so that nobody, including us, can read it back.

What we hold for your shop

Your clients' names, phone numbers, and email addresses; the family members they book for; every appointment, past and future, with the staff member and the service; notes your team writes; memberships and credit; the payment records that come across from Square; and the texts and emails the service has sent them.

This is your data, not ours. We use it only to run your dashboard and booking site, to send the appointment texts and emails you have switched on, and to show you your reports. Staff see what their role allows, and you set the roles. We do not read it for any purpose of our own, and we never sell it, share it for advertising, or use it to train software.

When you connect Square

Only the owner can connect Square, and only by pressing Connect and saying yes on Square's own sign-in page. We ask Square for read access to your bookings, customers, payments, refunds, orders, team members, services, and business profile. We do not ask for permission to change anything in your Square account, and we cannot.

We read your history once, then Square tells us about each new booking, change, or payment as it happens, and we check in once an hour in case anything was missed. The key Square gives us is stored encrypted with a separate key that lives outside the database.

Press Disconnect on the Connections page and the key is deleted at once, and Square stops sending us anything. The bookings and payments that already came across stay, because they are your books, until you ask us to delete them.

When a staff member connects Google Calendar

Each staff member connects their own calendar, by pressing Connect beside their name and saying yes on Google's sign-in page. We ask Google for one permission: to see the calendar, read-only.

We use it for one thing. Every 15 minutes we ask Google which stretches of the next 60 days are busy, and we keep only those start and end times. We never receive, store, or show what an event is called, who is in it, where it is, or what it says. Each refresh replaces the last one. The booking site shows those times as unavailable for that person; nobody, including the owner, sees why.

The connection key is stored encrypted, the same way as Square's. The staff member or the owner can press Disconnect at any time, which deletes the key and the busy times immediately. Nobody else ever receives anything read from the calendar, and no other use is made of it.

Thrivari's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Payments and cards

Thrivari never sees or stores a card number. Cards your clients save live with Square, and we hold only a reference that Square will honor for your shop alone. Payments taken in person go through your own Square account and its terms.

Who else touches it

Each of these does one job for you and receives only what that job needs.

No advertising networks, no analytics companies, no data brokers. We hand information to anyone else only if the law requires it, and we will tell you when we are allowed to.

How your booking site sees visitors

Your booking site sees the same basics as any website: a rough location from the connection, the kind of device, and how the visitor arrived. It records what gets pressed, so you can see where people stop partway through booking. It keeps a small random ID in the browser to keep a client signed in. No third-party cookies, no trackers, and we never store IP addresses.

Keeping it, and getting rid of it

We keep your shop's data for as long as you use Thrivari. If you leave, we keep it for 90 days in case you come back, then delete it, apart from payment records the tax rules make us keep for 7 years.

At any time you can ask for a copy of everything, in a file you can open elsewhere, or ask us to delete your shop or any one client. Email hello@thrivari.com and it is done within 30 days. If one of your clients asks to see or delete their record, you can send that to us too.

Keeping it safe

Everything travels and rests encrypted. Connection keys are encrypted again under a separate key. PINs are scrambled. Each staff member sees only what their role allows. If we ever learn that your data has been exposed, we tell you within 72 hours of finding out, with what happened and what we are doing about it.

Where it lives

In the United States, on Cloudflare's network. If you are outside the United States, using Thrivari means your data comes here.

Children

Children appear only as family members under a parent's or guardian's account, with a first name and the haircut. We never collect anything from a child directly.

Changes

We update the date at the top when this changes. If a change affects data you have already given us, we email the owner first.