Skip to content
LUO Business
CapabilitiesHow it worksWho it is forPricing
Try LUO free →
HomeHow it worksPricingPrivacyРусский

LUO Business data protection

Privacy
policy.

Last updated: August 24, 2026.

In short

LUO does not sell personal data. Salon data is used to provide selected product functions, while optional website analytics is enabled only after consent.

1. Who processes data and in what role

During beta, LUO Business is responsible for account, security, support and product-development data. When a salon enters client or employee information, the salon determines the purpose and lawful basis and LUO acts as its processor. Full operator and seller details will be published in the legal notice before payments are accepted.

2. Categories of data

We may process user names and contact details, salon and team data, roles and permissions, clients, services, schedules, appointments, messages, inventory and financial operations, AI settings, support requests, consent records and security logs. Full payment-card details should be processed by the payment provider and not stored by LUO.

3. Purposes and lawful grounds

Data is used to create accounts, perform the contract and requested functions, secure and support the service, meet legal obligations and improve the product. Marketing messages and optional analytics rely on separate consent that may be withdrawn. Each salon must establish its own lawful basis for client and team data.

4. AI functions

The minimum relevant part of a request may be sent to a configured AI provider to answer or prepare an action. LUO limits context to the feature’s purpose and does not use salon operational data to train public models without separate permission. Users should review sensitive actions before confirming them.

5. Recipients and international transfers

Infrastructure, communications, AI and support providers receive only what is needed for their function; the current list is on the Subprocessors page. Before commercial launch in each market, LUO documents storage locations, transfer mechanisms and applicable localisation requirements.

6. Retention

Account and salon data is retained while the service is used. After termination, a salon has up to 30 days to request an export, after which operational data is deleted or anonymised unless law requires otherwise. Backups expire through rotation; security and consent records may be retained longer to protect legal rights and investigate incidents. Website attribution is retained for up to 90 days and cookie choice for up to 12 months.

7. Your rights

You may request access, correction, export, deletion or restriction, object to processing, and withdraw consent. We may need to verify identity and authority. A salon client should usually contact the salon first; LUO assists the salon in fulfilling the request.

8. Security and incidents

Controls include HTTPS, password hashing, server-side permission checks, rate limits and critical-action logging. Current safeguards and limitations are described on the Security page. Confirmed incidents are communicated to affected parties without undue delay as applicable law requires.

9. Cookies and analytics

Essential technologies support login, security and chosen settings. First-party funnel analytics does not accept IP addresses, user agents or free-form text and starts only after consent. External measurement scripts are not loaded without consent. Choices can be changed on the Cookies and analytics page.

10. Children, changes and contact

The service is built for businesses and is not directed to children acting independently. Material policy changes are published with a new effective date and are not applied retroactively. Contact support@luoapp.space; never send passwords, login codes or unnecessary client data.

Back to home →View pricing →
LUOSalon automation and operating CRM
TermsPrivacyCookiesDPASecurityLegal noticeРусский

© 2026 Luo

Policy version: 2026-08-24