Your client list is the most personal thing you own.
What RoxRox Salon does with it, in plain terms — and, just as importantly, where the responsibility stays with you.
Encrypted, not just stored
Client notes, phone numbers and dates of birth are encrypted in the database rather than sitting in plain text, and each account's data is encrypted under its own owner. A salon record is a phone number, a home address, a date of birth and sometimes a health note about one person — that is not the kind of thing to keep in a spreadsheet on a laptop by the till.
Consent per channel, kept as a history
A client can accept reminders and refuse marketing, take texts and not WhatsApp. Those are separate permissions, and the changes are kept as a history rather than a single current flag — so if somebody asks what they agreed to and when, there is an answer rather than a shrug.
Access and erasure are workflows, not favours
When a client asks for their data or asks to be deleted, there is a request to open, a verification step, an export or an erasure to run, and a record that it was completed. Downstream processors that also have to act are tracked as part of the same request, and a legal hold can stop an erasure that would destroy something you are required to keep.
Data that ages out on a schedule
Nothing is kept forever by default. Confirmation codes are cleared at expiry, expired booking requests and password resets go after thirty days, soft-deleted client profiles are fully erased after ninety, and allergy and other sensitive free-text values clear on a schedule while the basic profile remains. Financial records are deliberately excluded from automatic deletion, because tax law in your jurisdiction — not us — decides how long those live.
Who is responsible for what
For your client records, you are the data controller and RoxRox is your processor. That is not a technicality: it means the decisions about why you hold client data, what lawful basis you rely on, and what you tell clients are yours, and no software can make them for you. What we can do is give you the tooling to act on them and not lose the record.
About allergy and health notes
Allergy information is health data, and health data is treated differently from a phone number almost everywhere. RoxRox provides an explicit authority-and-consent record for sensitive data, retention that clears those values on a schedule, and encryption underneath — but a salon has to establish and record its own lawful basis before relying on the field. We will not tell you that buying a booking system settles that question, because it does not.
This page is not legal advice
It describes what the software does. Privacy law differs by country and sometimes by state, and wording that satisfies one regime is not automatically enough for another — our own internal assessments treat GDPR, the Australian Privacy Act and CCPA/CPRA separately for exactly that reason. If your obligations are unclear, ask someone qualified in your jurisdiction.
Questions about data
Can another salon see my clients?
No. Data is scoped to the account and encrypted under it. Salons on RoxRox do not share a client list, and there is no cross-salon directory of clients.
Can I get my data out?
A client's record can be exported as a file through the subject-access workflow, which is also how you answer a client who asks for their data. A one-click export of the entire salon is not in the product yet; ask us and we will run it. We would rather tell you that than imply a button that is not there.
What happens to client data if I stop paying?
Accounts that go unused without a subscription are warned at thirty days, seven days and one day before their data is erased. The warning sequence exists so nothing disappears without somebody being told first.
Do you use my client data to train anything?
No. Your client records are processed to run your salon, on your instructions.
See it on your own diary.
Start a 30-day free trial. No card, no installer — your booking link can be live this afternoon.