KAIZER Booking ← Help center
Help center › Step-by-step setup

Privacy and data security

What protects your data, how to answer a customer who asks “where is the guarantee?”, and what the owner should switch on.

What is already protected

  • A separate database per business. Your clients, sales and bank live in their own file; another salon or store cannot see them.
  • Encryption. All traffic runs over HTTPS. Bank data and the Stripe, Square and Twilio keys are encrypted on disk with a key kept outside the database.
  • Cards never pass through the program. Card payments are taken by Stripe and Square (PCI DSS Level 1); card numbers are stored nowhere.
  • Bank without a password. The feed comes through Plaid: you sign in on the bank's page, the program gets read-only transactions.
  • Passwords are not stored, only their hash. Five wrong attempts lock sign-in for 15 minutes.
  • Two-step sign-in by email code and remembered devices — Settings → Sign-in security.
  • Staff permissions per section and action are enforced by the server; a removed employee loses access at once.
  • Client photos are visible only to signed-in users of your business; signed agreements keep a trail — time, IP, device.
  • Backups of every database are taken daily and kept 30 days.

If a customer asks “where is the guarantee?”

Answer like this: “Your data is stored in the KAIZER Store program by Kaizer Inc. (USA). It belongs to our salon; the platform does not sell it or use it for advertising. Card payments go through Stripe/Square, we do not keep your card number. You can ask us at any time to show, correct or delete your data.” For those who want details there are four documents in three languages: Security & Privacy, Privacy Policy, Terms of Service and the Data Processing Addendum with the list of every service the data goes to. They live at /legal/store/ on the program's site; you can put the link on your store page or in a signature.

Who is responsible for customer data

By law the owner of your customers' data is you (the controller) and the platform is the processor: it acts only on your instructions and never writes to your customers on its own behalf. So customer requests are handled by you: to show data, open the card; to export, Clients → Excel; to delete, the “Delete client” button in the card (cannot be undone); to unsubscribe, the mark in the card. If a customer writes to the platform's support, the request is forwarded to you.

What the owner should switch on

  • Two-step sign-in and a quarterly review of remembered devices — Settings → Sign-in security.
  • A personal login for every employee with only the sections they need — Settings → Users. When someone leaves, delete the login the same day.
  • Retention of the Email and SMS journals — Settings → Journals: the shorter, the less personal data sits idle.
  • A password longer than 12 characters, not the same as your mailbox.

If something happens

You suspect someone else signed in, lost a phone with the program open, got a strange email “from the program” — change the password at once and write to Support (button in the menu). If the platform confirms a breach affecting your data, you will be told by email within 72 hours: what happened, which data and what was done.

Inside the program the same article is under Help.

Справка › Пошаговая настройка

Конфиденциальность и безопасность данных

Что защищает ваши данные, как ответить клиенту на вопрос «где гарантия?» и что включить владельцу.

Что уже защищено

  • Отдельная база на каждый бизнес. Ваши клиенты, продажи и банк лежат в своём файле; другой салон или магазин их увидеть не может.
  • Шифрование. Весь обмен идёт по HTTPS. Банковские данные и ключи Stripe, Square и Twilio зашифрованы на диске ключом, который хранится отдельно от базы.
  • Карты не проходят через программу. Оплату картой принимают Stripe и Square (сертификат PCI DSS Level 1); номера карт нигде не хранятся.
  • Банк без пароля. Выписка приходит через Plaid: вы входите на странице банка, программа получает операции только для чтения.
  • Пароли не хранятся — только их хеш. Пять неверных попыток блокируют вход на 15 минут.
  • Двухэтапный вход по коду на email и запомненные устройства — Настройки → Безопасность входа.
  • Права сотрудников по разделам и действиям проверяет сервер; удалённый сотрудник теряет доступ сразу.
  • Фото клиентов видны только вошедшим пользователям вашего бизнеса; у подписанных договоров есть след — время, IP, устройство.
  • Резервные копии всех баз делаются каждый день и хранятся 30 дней.

Если клиент спрашивает «где гарантия?»

Ответьте так: «Ваши данные хранятся в программе KAIZER Store компании Kaizer Inc. (США). Они принадлежат нашему салону, платформа их не продаёт и не использует для рекламы. Оплата картой идёт через Stripe/Square, номер карты у нас не хранится. Вы можете в любой момент попросить нас показать, исправить или удалить ваши данные». Для тех, кто хочет подробностей, есть четыре документа на трёх языках: Безопасность и конфиденциальность, Политика конфиденциальности, Условия использования и Соглашение об обработке данных со списком всех сервисов, куда уходят данные. Они лежат по адресу /legal/store/ на сайте программы; ссылку можно поставить на витрину или в подпись.

Кто отвечает за данные клиентов

По закону владелец данных ваших клиентов — вы (контролёр), а платформа — обработчик: она действует только по вашим указаниям и не пишет вашим клиентам от своего имени. Поэтому запросы клиентов исполняете вы: показать данные — откройте карточку; выгрузить — Клиенты → Excel; удалить — кнопка «Удалить клиента» в карточке (отменить нельзя); отписать от рассылок — отметка в карточке. Если клиент напишет в поддержку платформы, запрос перешлют вам.

Что включить владельцу

  • Двухэтапный вход и проверка запомненных устройств раз в квартал — Настройки → Безопасность входа.
  • Личный логин каждому сотруднику и только нужные разделы — Настройки → Пользователи. Ушёл сотрудник — удалите логин в тот же день.
  • Срок хранения журналов Email и SMS — Настройки → Журналы: чем короче, тем меньше личных данных лежит без дела.
  • Пароль длиннее 12 символов, не тот же, что в почте.

Если что-то случилось

Подозреваете чужой вход, потеряли телефон с открытой программой, получили странное письмо «от программы» — сразу смените пароль и напишите в Поддержку (кнопка в меню). Если платформа подтвердит утечку, затронувшую ваши данные, вам сообщат по email не позднее 72 часов: что произошло, какие данные и что сделано.

В программе эта же статья — в разделе «Справка».

Centro de ayuda › Configuración paso a paso

Privacidad y seguridad de los datos

Qué protege sus datos, cómo responder a un cliente que pregunta «¿dónde está la garantía?» y qué debe activar el propietario.

Qué está ya protegido

  • Una base de datos separada por negocio. Sus clientes, ventas y banco están en su propio archivo; otro salón o tienda no puede verlos.
  • Cifrado. Todo el tráfico va por HTTPS. Los datos bancarios y las claves de Stripe, Square y Twilio se cifran en disco con una clave guardada fuera de la base de datos.
  • Las tarjetas nunca pasan por el programa. Los pagos con tarjeta los cobran Stripe y Square (PCI DSS Nivel 1); los números de tarjeta no se guardan en ningún sitio.
  • Banco sin contraseña. El extracto llega por Plaid: usted inicia sesión en la página del banco y el programa recibe movimientos de solo lectura.
  • Las contraseñas no se guardan, solo su hash. Cinco intentos erróneos bloquean el acceso 15 minutos.
  • Inicio de sesión en dos pasos con código por email y dispositivos recordados — Ajustes → Seguridad de acceso.
  • Los permisos del personal por sección y acción los aplica el servidor; un empleado eliminado pierde el acceso de inmediato.
  • Las fotos de clientes solo las ven los usuarios con sesión de su negocio; los acuerdos firmados guardan un rastro: hora, IP, dispositivo.
  • Copias de seguridad de todas las bases cada día, conservadas 30 días.

Si un cliente pregunta «¿dónde está la garantía?»

Responda así: «Sus datos se guardan en el programa KAIZER Store de Kaizer Inc. (EE. UU.). Pertenecen a nuestro salón; la plataforma no los vende ni los usa para publicidad. Los pagos con tarjeta van por Stripe/Square, no guardamos su número de tarjeta. Puede pedirnos en cualquier momento ver, corregir o borrar sus datos». Para quien quiera detalles hay cuatro documentos en tres idiomas: Seguridad y privacidad, Política de privacidad, Términos del servicio y el Acuerdo de tratamiento de datos con la lista de todos los servicios a los que van los datos. Están en /legal/store/ en el sitio del programa; puede poner el enlace en su tienda o en una firma.

Quién responde de los datos de los clientes

Por ley, el titular de los datos de sus clientes es usted (responsable) y la plataforma es el encargado: actúa solo según sus instrucciones y nunca escribe a sus clientes en su propio nombre. Por eso las solicitudes de los clientes las atiende usted: para mostrar datos, abra la ficha; para exportar, Clientes → Excel; para borrar, el botón «Eliminar cliente» en la ficha (no se puede deshacer); para dar de baja de envíos, la marca en la ficha. Si un cliente escribe al soporte de la plataforma, la solicitud se le reenvía a usted.

Qué debe activar el propietario

  • Inicio de sesión en dos pasos y revisión trimestral de los dispositivos recordados — Ajustes → Seguridad de acceso.
  • Un acceso personal para cada empleado con solo las secciones que necesita — Ajustes → Usuarios. Si alguien se va, elimine el acceso el mismo día.
  • Conservación de los diarios de Email y SMS — Ajustes → Diarios: cuanto más corta, menos datos personales quedan sin uso.
  • Una contraseña de más de 12 caracteres, distinta de la del correo.

Si ocurre algo

Sospecha que alguien más entró, perdió un teléfono con el programa abierto, recibió un email extraño «del programa»: cambie la contraseña de inmediato y escriba a Soporte (botón del menú). Si la plataforma confirma una brecha que afecte a sus datos, se lo comunicará por email en un plazo de 72 horas: qué pasó, qué datos y qué se hizo.

Dentro del programa, el mismo artículo está en «Ayuda».