Stylingcorner

Data Retention & Deletion

Version v2.0In force since 23 September 2026Last updated 23 September 2026

This page describes how our systems actually handle deleting and retaining data today. Retention periods are stated where they are defined and technically implemented.

How a deletion request for a customer account works today

1. Request: signed-in customers submit the request in their account settings under Privacy; without signing in, a request can be sent by email to legal@stylingcorner.ch. There is no one-click self-service deletion.

2. Identity verification: the privacy team manually checks whether the requester is the account holder and records the result in the request. Nothing is executed without a confirmed identity.

3. Execution: an authorised administrator (only the Super Admin and Platform Admin roles) executes the de-identification with a stated reason and explicit confirmation. The execution is recorded in the audit log without personal data (only the number of revoked sessions/devices), and the request is closed.

What de-identification does — and what it does not

In the customer account, identifying details are replaced or removed: the email address is replaced by an undeliverable placeholder address, the name by "Anonymisiertes Konto", phone number and profile picture are removed and the password is made unusable. The account is locked, all marketing preferences are switched off and this withdrawal is recorded in the consent log. All sessions are deleted, remembered devices and push devices are revoked and open sign-in codes are invalidated.

This is not an irreversible anonymisation of the whole dataset. The internal account ID remains, as do language, creation date and the timestamps of email confirmation and terms confirmation. Linked records remain attached to this ID (see next section). Anyone with access to those linked records can still attribute them to the same — now de-identified — account.

Remaining copies and who is responsible for them

At Stylingcorner (responsible: Stylingcorner): favourites, recently viewed salons, reviews written (text remains public, shown pseudonymised), in-app notifications, support cases, earlier privacy requests (with the email address and name given at the time) and any earlier data exports containing the original contact details. De-identification does not currently change these. Reason: there is no decision yet and no function for deleting them; some records (e.g. reviews, privacy requests) also serve platform integrity and evidence of how a request was handled.

Bookings and payment flows (responsible: the salon for the appointment and the payment; Stylingcorner for the booking and checkout flow): appointments, checkout sessions and the cancellation terms captured at booking remain, because they are the basis of the contract between customer and salon and of any refunds.

The salon's customer file (responsible: the salon; Stylingcorner is its processor): the customer record a salon keeps in its customer management (name, contact details, birthday, consents, notes, appointment history) is not changed by the account de-identification. Deleting it there is the salon's responsibility; we forward such requests to the salon.

Payment data at Stripe (responsible: Stripe or the salon as payee): Stripe retains payment data under its own terms. Accounting-relevant records (sales, payments, refunds, subscription invoices) are not hard-deleted on our side; business books and accounting vouchers are subject to the statutory retention duty under Art. 958f of the Swiss Code of Obligations (ten years) — this concerns accounting records only, not other data.

Audit logs (responsible: Stylingcorner): append-only, never overwritten, used for security and as evidence of administrative actions. No period has been decided.

Messages: there is no chat or messaging feature. Emails are delivered through the email service Resend; Resend keeps delivery logs for 30 days and backups for 7 days.

Backups (responsible: Stylingcorner, hosting at Infomaniak): the database and uploaded files are backed up daily, encrypted before they leave the server and stored in Switzerland; the encrypted copies are deleted after 30 days. De-identified data can remain in a backup until it expires.

Businesses (PRO) after the contract ends

For business accounts there is currently no automated deletion or anonymisation process after the contract ends. A business's data (appointments, customer file, sales, team) remains stored until it is handled manually on request. Return and deletion happen on request to legal@stylingcorner.ch, unless a statutory retention duty prevents it.

Defined retention periods

Periods are stated where they are defined and implemented in the system: PRO in-app notifications are deleted after 90 days, server logs after 14 days and backups after 30 days. For all other categories there is no fixed period: the data is kept until deletion is requested (process described above).

It is based on a review of the database schema and background jobs from 2026-09-16 and of the production servers from 2026-09-23.

CategoryCurrent technical behaviourResponsibleDefined period
Marketplace customer accountOn a verified deletion request, de-identification by an admin: email, name, phone, profile picture and password replaced or removed, account locked, sessions deleted, devices revoked. Account ID, language and timestamps remain.Stylingcorner
Records linked to the account (favourites, recently viewed, reviews, in-app notifications, support cases, earlier privacy requests and data exports)Remain after de-identification, linked via the account ID; earlier requests and exports contain the original contact details.Stylingcorner
Appointments, checkout sessions, captured cancellation termsRetained; basis of the treatment contract and of any refunds.Salon (appointment, payment) / Stylingcorner (booking flow)
The salon's customer file (CRM customer record, notes, appointment remarks)Only an active/inactive flag, no automatic deletion; not affected by the account de-identification. Free text can incidentally contain sensitive information.Salon (Stylingcorner as processor)
Sales, payments, refunds, vouchers, subscription invoicesAppend-only, never hard-deleted. Art. 958f CO (ten years) applies to business books and accounting vouchers — accounting records only.Salon (customer payments) / Stylingcorner (PRO subscription)
Card brand/last 4 digits/expiry of the PRO payment methodStored in the application database for display.Stylingcorner
Verification and ID documents (claims, verification)Private, non-public storage; no retention or deletion function.Stylingcorner
Employee sick-leave time blocks (with optional note)No expiry or deletion field.Salon (Stylingcorner as processor)
Consents (marketing preferences)Current state as yes/no. Changes made in the account's privacy area and during a de-identification are additionally logged with a timestamp (append-only); changes via the general profile settings and older settings have no timestamp yet.Stylingcorner, or the salon (its own customers' consents)
First-party usage statistics (website)Events without account, name or IP reference; no automatic deletion.Stylingcorner
PRO in-app notificationsDeleted automatically by a daily background job.Stylingcorner
90 days (implemented in code)
Sign-in codes and sessionsExpired customer sessions are deleted when next used; there is no automatic clean-up for sign-in codes and PRO sessions.Stylingcorner
Audit logs and internal admin notesAppend-only, no expiry field.Stylingcorner
Imported business listings and raw import dataA listing can be taken offline; the listing and the original import record remain stored.Stylingcorner (until claimed)
API server logsRequest method, URL (incl. search parameters, e.g. coordinates for app searches), status and duration. Application and web-server logs are rotated daily and then deleted.Stylingcorner
14 days
BackupsDaily backups of the database and of uploaded files. They are encrypted before they leave the server and stored in Switzerland (Infomaniak). On the server, database backups are kept for 14 days and file backups for 3 days.Stylingcorner (hosting: Infomaniak)
30 days (encrypted copy)
Data Retention & Deletion | Stylingcorner Marketplace