1. Who We Are
Stockwise Software is a software company based in Scotland, United Kingdom. We operate two software-as-a-service products:
- BeautyOS — salon management software available at beautyos.co.uk
- StockWise IMS — inventory management software launching at stockwiseims.co.uk
For data protection purposes, Stockwise Software is the Data Controller for account holder data across both products. Where salon owners or business operators store third-party data within our products, we act as a Data Processor and the account holder is the Data Controller for that third-party data.
BeautyOS enquiries: support@beautyos.co.uk
StockWise IMS enquiries: support@stockwiseims.co.uk
2. Scope of This Policy
This Privacy Policy applies to this company website, the BeautyOS platform, and the StockWise IMS platform and all associated services.
3. What Data We Collect
Account and registration data:
- Full name, business name, email address, and telephone number
- Business address and postcode
- IP address and browser information collected at registration for fraud prevention
- Login history and session activity
Payment and billing data:
- Subscription plan and billing history
- Card payment information is handled entirely by Stripe — we do not store your card details at any point
BeautyOS — data processed on behalf of salon operators:
- Client names, email addresses, and phone numbers entered by the salon
- Appointment records, treatment history, and notes
- GDPR consent records and SMS/email delivery logs
StockWise IMS — data processed on behalf of business operators:
- Staff account details (names, email addresses, roles)
- Stock and inventory records
- Audit log entries recording stock movements and administrative actions
Website usage data:
- Server access logs only — we do not use Google Analytics or any third-party analytics
- Contact form submissions
4. How We Use Your Data
- To create and manage your account and provide access to the service you have subscribed to
- To process subscription payments and manage billing through Stripe
- To send transactional emails and appointment reminder SMS via Brevo (BeautyOS)
- To send low-stock email alerts and system notifications (StockWise IMS)
- To provide customer support and respond to enquiries
- To detect and prevent fraudulent registrations or abuse
- To improve and develop our products
- To comply with legal and regulatory obligations
We do not use your data to serve advertising. We do not sell your data to any third party.
5. Legal Basis for Processing
- Contract performance: Processing necessary to provide the service you have subscribed to
- Legitimate interests: Fraud prevention, platform security, and service improvement
- Legal obligation: Compliance with applicable law, including tax and accounting requirements
- Consent: Where applicable; you may withdraw consent at any time
6. Data Retention
We retain account data for the duration of your active subscription and for up to 12 months following account closure, after which it is permanently deleted. Billing records are retained for 7 years as required by UK tax law.
For BeautyOS: client data is retained for as long as the salon account remains active and deleted immediately upon permanent account closure. Salon operators may delete individual client records at any time.
For StockWise IMS: audit log entries are retained indefinitely as an append-only security record. Stock records are deleted upon account closure.
7. Third-Party Services
- Stripe — payment processing. PCI-DSS Level 1 certified and UK GDPR compliant. Stripe Privacy Policy →
- Brevo — transactional email and SMS delivery. EU GDPR compliant. Brevo Privacy Policy →
- Render.com — cloud hosting. Render Privacy Policy →
We do not share your data with any other third parties. We do not use third-party advertising networks, tracking pixels, or behavioural analytics tools.
8. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Rectification: Ask us to correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data, subject to legal retention obligations
- Portability: Request your data in a structured, machine-readable format
- Restriction: Ask us to restrict processing in certain circumstances
- Objection: Object to processing based on legitimate interests
To exercise any of these rights, email us at the relevant address in section 12. We will respond within 30 days. You also have the right to complain to the ICO at ico.org.uk or by calling 0303 123 1113.
9. Cookies
This company website does not use cookies. Our individual products use only strictly necessary session cookies required for authentication and security (CSRF protection). We do not use tracking, advertising, or analytics cookies. No cookie consent banner is required.
10. Data Security
We implement appropriate technical and organisational measures including HTTPS encryption, PBKDF2 password hashing, HttpOnly session cookies, brute-force login protection, server-side role-based access control, and regular OWASP-aligned security reviews. In the event of a data breach affecting your rights and freedoms, we will notify you and the ICO within 72 hours as required by law.
11. Changes to This Policy
We may update this policy from time to time. We will notify existing account holders of significant changes by email or via a notice within the relevant application. Continued use after the effective date constitutes acceptance.
12. Contact
For privacy-related questions or to exercise your rights:
- BeautyOS: support@beautyos.co.uk
- StockWise IMS: support@stockwiseims.co.uk