Skip to content
Back to home

Privacy Policy

Last updated: June 2026

Controller

The controller for the processing of personal data in connection with the Coiffly website and the Coiffly app is Gordion Software Solutions GmbH, [ERFORDERLICH: Strasse Nr., PLZ Ort], Switzerland. For privacy questions or to exercise your rights: support@coiffly.ch.

Principle and applicable law

We process personal data in accordance with the Swiss Data Protection Act (revDSG) and, where applicable, the EU GDPR. We only collect data necessary to operate the website, provide the app and intermediate hairdressing services. This policy applies both to customers and to the independent hairdressers operating via the platform ("providers").

Notify-me sign-up (website)

If you sign up for the launch notification on the website, we store your email address to inform you about the Coiffly app launch. The legal basis is your consent. You may request deletion at any time by email.

Server log files (website)

When you visit the site, the hosting provider automatically stores access data in log files (e.g. IP address, date/time, page requested, browser type). This data serves technical security and stable operation and is deleted after a short period.

Cookies & tracking (website)

One strictly necessary cookie stores your language choice (DE/EN); it is required to operate the site and needs no consent. Fonts are served locally from our own server; no connection is made to Google Fonts.

For audience measurement we use Google Analytics 4 (Google Ireland Ltd.) — but only if you explicitly consent via the cookie banner. We use Google Consent Mode: until you opt in, no analytics cookies are set and no analytics storage takes place. Only after your consent does Google Analytics set cookies (including _ga) and process pseudonymised usage data (e.g. pages visited, approximate location, device/browser data). Data may be transferred to Google and processed in the USA, safeguarded by Standard Contractual Clauses. The legal basis is your consent. You can withdraw it at any time with effect for the future by choosing "Decline" in the cookie banner or clearing the stored choice in your browser.

What data the app processes

Within the Coiffly app we process the following categories of data, depending on use:

  • Account and profile data (name, email address, phone number, password/credentials, customer/provider role). Account authentication and management is handled by our identity service Keycloak.
  • Booking data (selected service, appointment, location/address of the service, status, booking-related communication, ratings).
  • Location data (geolocation) – see the dedicated section below.
  • Payment data – processed via Stripe; see the dedicated section below.
  • Image uploads: verification photos (selfie and official ID of providers) and portfolio/profile images.
  • Usage and diagnostic data via Firebase (Analytics and Crashlytics) and device tokens for push notifications.

Account and authentication (Keycloak)

For registration, login and account management we use Keycloak, an identity and access management system operated within our own infrastructure. This processes your credentials and basic profile data. The legal basis is performance of the user contract (Art. 6(1)(b) GDPR / the corresponding basis under revDSG).

Bookings and intermediation

To process a booking we share the data necessary for service delivery (name, contact details, location/address, selected service, time) with the selected independent provider, or – where a provider initiates the request – with the customer. This is necessary to carry out the intermediated service (contract performance). Coiffly acts solely as an intermediary platform; the service contract is concluded between the customer and the provider.

Location data / geolocation

With your consent we process your device location in order to (a) find suitable nearby providers or jobs ("matching") and (b) enable live location tracking of the approaching provider during an ongoing mobile appointment. You can withdraw location access at any time in your device settings; without it, location-based features may be unavailable. The legal basis is your consent and contract performance.

Payments (Stripe & Stripe Connect)

Payments in the app are handled by the payment service provider Stripe. Stripe processes payment data (e.g. card/payment-method details, amount, transaction metadata) both as an independent controller and as our processor. We do not store full card details ourselves. Payouts to the independent providers are made via Stripe Connect; providers enter into their own account/contract relationship with Stripe and transmit the required identification and bank details to Stripe. Stripe may transfer data to countries outside Switzerland/the EU, safeguarded by Standard Contractual Clauses. More information: stripe.com/privacy.

Image uploads & provider verification (MinIO)

To verify providers we process a selfie and a photo of an official identity document; in addition, portfolio and profile images may be uploaded. These image files are stored in our self-operated object storage MinIO. ID data is used exclusively for identity and eligibility checks and is deleted once that purpose ceases. The legal basis is contract performance and our legitimate interest in a safe, trustworthy platform.

Diagnostics & usage analytics (Firebase Analytics & Crashlytics)

We use Firebase Analytics (usage statistics) and Firebase Crashlytics (crash and error diagnostics) from Google to keep the app stable and to improve it. This processes pseudonymised device and usage data (e.g. device/app version, events, crash reports, instance identifier). Where such processing requires consent, we obtain it in the app; otherwise we rely on our legitimate interest in operational security and product improvement. Provider: Google; transfer to the USA may occur (safeguarded by Standard Contractual Clauses).

Push notifications (Firebase Cloud Messaging)

For push notifications (e.g. booking confirmations, status updates) we use Firebase Cloud Messaging (FCM). A device token is processed for this. You can disable push notifications at any time in your device settings.

Processors & recipients

We use carefully selected service providers as processors, with whom data-processing agreements are in place:

  • Stripe (payment processing, Stripe Connect payouts)
  • Google / Firebase (Analytics, Crashlytics, push via FCM)
  • Keycloak (authentication, operated within our infrastructure)
  • MinIO (object storage for image uploads, operated within our infrastructure)
  • Hosting/infrastructure providers for the website and backend

We also share data with the customer or provider involved in a given booking, to the extent necessary for service delivery, and with authorities where legally required.

Retention

We retain personal data only for as long as necessary for the relevant purposes or as required by statutory retention obligations. Account and booking data are stored for the duration of account use; payment and invoice records are subject to statutory (generally ten-year) retention periods. Verification images are deleted once the verification purpose ceases, and diagnostic data after a short period. Following account deletion, data is deleted or anonymised unless a statutory retention obligation applies.

Your rights

You have the right to information, rectification, deletion and restriction of processing of your personal data, to object, and to data portability. You may withdraw any consent given at any time with effect for the future. You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or – where the GDPR applies – with a competent supervisory authority. Contact support@coiffly.ch.

Delete your account

You can delete your account and the associated data at any time: in the app under Settings → "Delete account" or by email to support@coiffly.ch. For details on the process and timelines, see the Delete account page.