International Data Transfers
This page shows, for each provider, which data flows to it, in which role it acts and where the data is processed.
For none of the providers listed below have the processing country and the transfer mechanism been conclusively confirmed yet. We therefore neither claim that your data never leaves Switzerland nor name a country or safeguard that has not been checked.
Overview
The platform is operated in Switzerland: application servers, database, file storage and backups run on Infomaniak Public Cloud.
Data is processed outside Switzerland by Resend (email delivery, USA) and Stripe (payments, USA and other countries). The map and the address search load Google Maps Platform services directly in your browser.
Expo (push notifications) is only involved when you use the Stylingcorner app and allow notifications.
Changes
If a provider or a processing location changes, we update this page and record the change in the change history.
Overview by provider
Infomaniak (Infomaniak Network SA, Genf)
Role: Processor (hosting on our behalf)
What data flows: All data stored by the platform: accounts, bookings, business, staff and customer data, and uploaded files
Processing location: Switzerland — application servers, database, file storage and backups run on Infomaniak Public Cloud. Backups are encrypted before they leave the server and kept for 14 days on the server and 30 days in object storage
Resend
Role: Processor (email delivery on our behalf), under Resend's data processing agreement
What data flows: Recipient email address, subject and message content — e.g. one-time codes, name, salon name, appointment date/time and services, billing status
Processing location: USA — Resend stores customer data, including message content and delivery logs, in the United States. Logs are kept for 30 days and backups for 7 days
Stripe
Role: Payment service provider acting partly as a processor and partly as an independent controller (for example for fraud prevention and its regulatory duties), as set out in Stripe's data processing agreement; for Connect payments the contractual relationship is primarily between Stripe and the business
What data flows: Billing: company name, billing email, internal company/plan identifiers; Stripe returns card brand/last 4 digits/expiry for display. Connect: amount, currency and internal booking identifiers (company, checkout session, appointment); card/TWINT details are entered directly in Stripe's payment form — Stylingcorner never receives full card data
Processing location: Stripe processes data in the United States and other countries
Expo (Expo Push Service)
Role: Processor (push relay on our behalf). Only involved when you use the Stylingcorner app and allow notifications; Apple and Google operate their push services under their own terms
What data flows: Device push token and the notification itself: title and text (e.g. salon name, appointment weekday/time) plus a data payload with the notification ID, notification type and the related appointment or review ID
Google Maps Platform (Google Ireland Limited / Google LLC)
Role: Receives the browser's request directly, under Google's own Maps Platform terms
What data flows: Visitor IP address, browser user agent, the map area viewed, address search terms typed in PRO, and — only where the visitor has granted the browser's location permission — their approximate coordinates
Apple and Google platform services (mobile app)
These services are not processors engaged by Stylingcorner; they receive data because the app runs on Apple's or Google's platforms. Processing country and transfer basis follow their own terms.
- Apple (iOS) / Google (Android) — push delivery: Push notifications relayed by Expo are delivered through Apple Push Notification service (iOS) or Firebase Cloud Messaging (Android), including the notification title, text and data payload described above.
- Apple Maps (iOS) / Google Maps SDK (Android) — in-app map: The app's map uses the platform's default map provider (react-native-maps without an explicitly selected provider): Apple Maps on iOS and the Google Maps SDK on Android. The map provider receives the device's network requests (e.g. IP address) and the map area displayed.
- Apple / Google — reverse geocoding on the device: When you use your current location in the app, it converts your coordinates into a place name with the operating system's geocoder (Apple on iOS; the Android geocoder, typically provided by Google). Only the city name is used, as a display label.
- Google Maps (link) — directions: The directions link in the app opens google.com/maps with the salon's address in your browser or maps app — only when you tap it.
