Privacy Policy
Last updated: 22 June 2026
SharpCuts (“we”, “us”) operates the SharpCuts mobile app, the SharpAdmin web dashboard, and the related backend services (collectively, the “Service”). This policy explains what personal information we collect, why we collect it, and what choices you have. We aim for plain English over legalese.
1. Who is the controller
Northern Tech LTD is the data controller for personal information processed through the Service. Contact: support@northerntechltd.com.
2. Information we collect
- Account data. When you sign in with Google or Apple, we receive your name, email address, and (if you provide it) profile photo.
- Phone number. Required before booking. We send a one-time SMS verification code via Twilio.
- Addresses. Addresses you save for haircuts. We geocode them (via Google Maps) to match you with barbers whose service radius covers your location.
- Device location.If you grant permission, we use your current device location to surface nearby barbers. We don't store it server-side.
- Booking history. Service booked, barber, time, address, status, price, ratings you leave.
- Payment data. Payment card details are entered directly into Stripe and are never seen by our servers. We store a Stripe customer ID and the last four digits.
- Barber data (if you sign up as a barber). Display name, bio, photos, home base coordinates (kept private), service radius, hours, services and prices, ratings received, Stripe Connect account ID.
- Device + log data. Standard diagnostics: app version, OS version, crash reports, IP address, push notification token (if you opt in).
3. How we use it
- To match customers with nearby barbers.
- To process bookings, payments, and payouts.
- To send transactional SMS and push notifications (booking accepted, reminders, “on the way”).
- To prevent fraud and resolve disputes.
- To comply with legal obligations.
4. Third parties we share data with
We use a small number of trusted processors. They only see what they need to do their job, and they're bound by data-protection agreements.
- Supabase — hosting, database, authentication.
- Stripe — payment processing and payouts to barbers (Stripe Connect Express). Stripe sees full payment details.
- Twilio — SMS for phone verification, booking notifications, and proxy-masked communication between you and your barber.
- Google — sign-in (OAuth), Maps geocoding, Places autocomplete.
- Apple — sign-in (Apple ID).
- Expo / Vercel — application hosting, push notification delivery.
We don't sell personal information. We don't share it with advertisers.
5. Visibility between users
Barbers see your first name, masked phone number (via Twilio Proxy), the address for that booking, and the door code shown to both of you. They do not see your email, payment details, or other addresses.
Customers see a barber's display name, photo, bio, distance, and ratings. They do not see the barber's exact home address (only the distance derived from it).
6. How long we keep data
- Account data: until you delete your account.
- Booking records: 7 years (tax + dispute requirements).
- Diagnostics + logs: 90 days.
- Payment data with Stripe: governed by Stripe's policies.
7. Your choices
- Access + export. Email support@northerntechltd.com and we'll send your data within 30 days.
- Correction. Edit name and phone from the Profile tab. For anything else, email us.
- Account deletion. In the app: Profile → Delete account. This permanently removes your profile, addresses, and push tokens. Booking history is retained for tax purposes (anonymised where legally possible). Or email us.
- Push and SMS. Disable push in iOS/Android settings; reply STOP to any SMS to opt out of further messages.
- Location. Revoke in iOS/Android settings any time. The app still works — you just type an address manually.
8. International transfers
Our processors operate primarily in the US and EU. Where data is transferred between regions, we rely on the standard contractual clauses or equivalent safeguards.
9. Children
The Service is for users 16+ (or older where required by local law). We do not knowingly collect data from children under 16. If you believe a child has used the Service, email us and we'll delete the account.
10. Security
Data is encrypted in transit (TLS) and at rest. Authentication tokens live in the device's secure keychain. Database row-level security enforces that you only see your own data. We can't guarantee absolute security, but we treat your data with the same care we'd want for our own.
11. Changes
If we make material changes, we'll notify you in the app and update the date at the top of this page.
12. Contact
All enquiries: support@northerntechltd.com