Privacy Policy – Spring Hair Ladies Salon
Effective date: 04-03-2026
1. Introduction
This Privacy Policy explains how Spring Hair Ladies Salon ("Spring Hair Ladies Salon",
"we", "us", or "our") collects, uses, discloses, and protects personal data in
connection with our website www.springhairladiessalon.com
(the "Website") and our home beauty salon services in Abu Dhabi.
It applies to visitors to our Website and to customers and prospective customers who
contact us or use our services.
This Privacy Policy is designed to meet the requirements of Federal Decree-Law No. (45)
of 2021 Concerning the Protection of Personal Data in the United Arab Emirates (the
"UAE PDPL") and similar data-protection principles applicable to our operations.
For the purposes of the UAE PDPL, Spring Hair Ladies Salon is the "Controller" of your
personal data in relation to the processing activities described in this Privacy Policy,
and our third-party service providers generally act as "Processors" on our behalf.
2. Information We Collect
We may collect the following categories of personal data, depending on how you interact with us:
-
Contact information
- Name.
- Mobile or other phone number.
- Email address.
- Physical address or service location for home services.
-
Identifiers and basic profile data
- Customer or booking reference numbers (if assigned in our internal systems or third-party booking tools).
- Social media usernames or profile information you choose to share when contacting us via TikTok, Facebook, or Instagram.
-
Payment data
- Method of payment and transaction details (amount, date, payment reference), processed via our payment providers or collected at the time of service.
-
Booking details
- Preferred appointment date and time.
- Type of service requested (for example, waxing, hair care, nails, massage).
- Special instructions or preferences you provide.
-
Communications
- Content of messages you send to us by phone, WhatsApp, email, or social media.
- Feedback, questions, or complaints you choose to share.
-
Usage data
- Information about how you access and use the Website, such as pages visited, time and date of visit, device and browser information, and basic diagnostic data generated by server logs.
-
Cookies and tracking data
- Information collected through cookies and similar tracking technologies that may be used to operate the Website, remember your preferences, and understand usage patterns.
-
Photos and reviews
- Photographs and images of your hair, nails, lashes, or other treatments that you consent for us to capture and publish in our galleries or on our social media accounts.
- Testimonials or reviews that you choose to provide to us on social media or via third-party platforms.
-
Employment applicant data
- Name, contact details, CV/resume information, work history, and any other information you provide when you contact us about job opportunities.
3. How We Collect Information
-
Directly from you
- When you call us using the phone number shown on the Website.
- When you message us via WhatsApp using the link provided on the Website.
- When you email us using the email address shown on the Website.
- When you interact with us via our social media pages (TikTok, Facebook, Instagram) linked from the Website.
-
Automatically when you use the Website
- Through server logs that record basic technical information about visits to the Website (for example, IP address, timestamps, and visited URLs).
-
From third parties
- From booking or scheduling platforms that you may use to book our services.
- From payment service providers that process your payments for our services.
- From social media platforms when you interact with us on those platforms.
4. Use of Your Information
We use the categories of personal data described above for the following purposes:
-
To provide our services and manage bookings
- Data used: Contact information, identifiers and profile data, booking details, communications, payment data.
- For example, to schedule and confirm home salon appointments, manage changes or cancellations, and deliver treatments at your chosen location.
-
To process payments and manage billing
- Data used: Payment data, contact information, booking details.
- For example, to issue receipts and maintain records of purchases for accounting and tax purposes.
-
To communicate with you
- Data used: Contact information, booking details, communications.
- For example, to respond to your questions, confirm appointments, send service updates, or respond to complaints via phone, WhatsApp, email, or social media.
-
To operate, maintain, and improve the Website and services
- Data used: Usage data, cookies and tracking data, communications.
- For example, to understand how visitors use the Website, address technical issues, and improve our services and customer experience.
-
For marketing and promotional purposes
- Data used: Contact information, photos and reviews, identifiers and profile data, communications.
- For example, to feature before-and-after photos (with your consent), share testimonials, and inform you about offers or new services through channels you have chosen.
- We will only use your contact details for direct electronic marketing where permitted under UAE law and, where required, with your consent and a simple way to opt out.
-
To manage recruitment
- Data used: Employment applicant data, contact information, identifiers.
- For example, to process applications, evaluate candidates, and maintain a talent pool.
-
To comply with legal obligations and protect our rights
- Data used: All relevant categories, especially payment data, booking details, usage data, and communications.
- For example, to meet tax and accounting obligations, respond to lawful requests from authorities, enforce our legal rights, and detect or prevent fraud or misuse of our services.
5. Legal Bases and Data Protection Principles (UAE PDPL)
Under the UAE PDPL, we process your personal data in accordance with the following principles:
- Lawfulness, fairness, and transparency – we process personal data lawfully, fairly, and in a transparent manner, including by providing this Privacy Policy.
- Purpose limitation – we collect personal data for specified, explicit, and legitimate purposes and do not further process it in ways that are incompatible with those purposes.
- Data minimisation – we collect only the personal data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
- Accuracy – we take reasonable steps to keep personal data accurate and, where necessary, up to date.
- Storage limitation – we keep personal data in a form which permits identification of data subjects for no longer than is necessary for the purposes described in this Privacy Policy, subject to applicable legal retention requirements.
- Integrity and confidentiality – we use appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage.
We rely on the following legal bases to process your personal data under the UAE PDPL:
- Contractual necessity – to provide our services, manage bookings, process payments, and communicate with you about your appointments and any related issues.
- Consent – when you agree to certain processing activities, for example, receiving promotional communications or allowing us to use your photos or testimonials for marketing.
Where UAE law requires consent for the use of certain cookies or similar technologies, we will obtain your consent before placing such cookies on your device, and you may withdraw your consent at any time.
- Legal obligations – to comply with applicable laws and regulations, such as tax, accounting, and reporting requirements, and to respond to lawful requests from public authorities.
- Legitimate interests – to operate, secure, and improve our Website and services, to respond to your enquiries, to manage customer relationships, and to prevent fraud or misuse, provided that these interests are not overridden by your rights and freedoms.
6. Cookies and Tracking Technologies
Cookies are small data files stored on your device when you visit a website, and similar technologies (such as pixels and local storage) may also be used to recognize your browser and device over time.
We may use the following categories of cookies and trackers:
- Necessary cookies – required for the Website to function correctly (for example, basic security, page navigation).
- Preferences cookies – used to remember your settings and choices.
- Statistics/analytics cookies – used to understand how visitors use the Website and to improve performance.
- Marketing cookies – used to track visitors across sites to deliver relevant advertising.
No specific analytics, advertising pixels, or cookie management tools are installed on the public pages of the Website at this time. If we implement such tools in future, this section will be updated and, where required by UAE law, a cookie banner or similar consent mechanism will be provided.
Where UAE law requires consent for the use of certain cookies or similar technologies, we will obtain your consent before placing such cookies on your device. You can manage cookies through your browser settings (for example, blocking or deleting cookies). If you block certain cookies, some parts of the Website may not function properly. We do not currently respond to "Do Not Track" signals because there is no consistent industry standard for doing so.
7. Sharing Your Information
We may share your personal data with the following categories of recipients, only to the extent necessary for the purposes described in this Privacy Policy:
-
Service providers and contractors
- Companies and individuals who provide services to us, such as IT support, website hosting, maintenance, and customer support.
-
Booking and scheduling platforms
- Third-party booking providers that facilitate appointment scheduling and management.
-
Payment providers
- Banks or payment processors that handle your payments for our services.
-
Marketing and social media platforms
- Social networks such as TikTok, Facebook, and Instagram, where we maintain pages and share content, and where you may interact with us or where your photos/testimonials may be published with your consent.
-
Professional advisers and legal authorities
- Lawyers, accountants, insurers, and other professional advisers as needed.
- Public authorities, regulators, law enforcement, or courts when required by law or to protect our rights, privacy, safety, or property.
-
Business transfers
- In connection with any merger, sale of business assets, financing, or acquisition of all or a portion of our business, personal data may be transferred as part of that transaction, subject to appropriate safeguards.
We do not sell your personal data, and we do not share personal data for cross-context behavioural advertising.
8. Third-Party Links
The Website may contain links to third-party websites, applications, or services, including social media platforms.
We are not responsible for the privacy practices or the content of those third-party sites, and this Privacy Policy does not apply to them.
We encourage you to review the privacy policies of any third-party sites you visit.
9. Data Retention
We determine retention periods in line with the UAE PDPL and other applicable UAE laws (including accounting and tax requirements),
and we do not keep personal data longer than necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
- Booking and service records – typically retained for approximately 6–7 years for tax, accounting, and legal compliance.
- Payment and billing records – retained for the period required under applicable tax and financial laws (often 6–7 years).
- Customer enquiries and communications – retained for about 2–3 years after the last interaction, depending on the nature of the correspondence and any ongoing issues.
- Marketing and promotional data – retained for as long as you remain subscribed or engaged with our marketing, or until you object or withdraw consent.
- Photos and testimonials – retained for as long as they are used for marketing purposes or until you withdraw your consent or request deletion, subject to our legitimate interests and any legal obligations.
- Employment applicant data – retained for about 6–12 months after the hiring process unless longer retention is legally permitted or required.
10. Data Subject Rights and How to Exercise Them
Depending on your location and applicable law, including the UAE PDPL, you may have the following rights regarding your personal data:
- Right of access – to request information about the personal data we hold about you.
- Right to rectification – to ask us to correct inaccurate or incomplete information.
- Right to deletion (erasure) – to request deletion of your personal data in certain circumstances.
- Right to restriction of processing – to request that we limit the processing of your information in certain cases.
- Right to data portability – to receive a copy of your personal data in a structured, commonly used format and to transmit it to another controller where technically feasible.
- Right to object – to object to certain processing, including where we rely on legitimate interests or for direct marketing.
- Right to withdraw consent – where processing is based on your consent, you can withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.
If you believe your rights under the UAE PDPL have been infringed, you may have the right to lodge a complaint with the UAE Data Office or other competent regulator, without prejudice to any other administrative or judicial remedies available to you.
To exercise your rights or to ask any question about this Privacy Policy or our data practices, you can contact us using the details in the "Contact Information" section below.
We will respond to your request within the timeframe required under the UAE PDPL, typically within 30 days, and may request additional information to verify your identity before acting on your request.
11. Security Measures
We take appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
These measures may include:
- Encryption of data in transit through standard HTTPS protocols provided by our hosting environment (where implemented).
- Access controls and restrictions so that only authorised personnel and service providers have access to personal data on a need-to-know basis.
- Use of reputable hosting and service providers that implement industry-standard security practices.
- Regular backups and basic system monitoring to help ensure availability and integrity of data.
- Training and guidance for staff on handling customer information and maintaining confidentiality.
We also maintain internal records of our personal data processing activities and periodically review our security and privacy measures in line with the UAE PDPL and relevant guidance.
However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.
12. Children's Privacy
Our Website and services are intended for adults and are not directed to children under the age of 16.
We do not knowingly collect personal data from children under 16 without appropriate parental or guardian consent.
If we become aware that we have collected personal data from a child without such consent, we will take steps to delete that information as soon as reasonably practicable.
Parents or guardians who believe their child has provided us with personal data may contact us using the details in the "Contact Information" section.
13. International Transfers
As a business based in Abu Dhabi, United Arab Emirates, personal data may be processed and stored in the UAE and in other countries where our service providers or partners are located.
This may involve transferring your information to jurisdictions that may not provide the same level of data protection as your home country.
Where your personal data is transferred outside the UAE, we will only do so in accordance with the UAE PDPL, including by relying on decisions that a destination country provides an adequate level of protection, or by using data-transfer agreements or other safeguards approved under UAE law.
The specific safeguards in place may depend on the third-party provider and should be reviewed and confirmed by the business.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons.
When we make changes, we will update the "Effective date" at the top of this Privacy Policy and may provide additional notice on the Website where appropriate.
Your continued use of the Website or our services after any update constitutes your acceptance of the revised Privacy Policy.
15. Contact Information
If you have any questions about this Privacy Policy or our handling of your personal data, please contact us at: