Legal

Privacy, in plain language.

This is the notice the Protection of Personal Information Act requires - written the way we would say it across the chair, because a policy nobody reads protects nobody.

Effective 30 July 2026 · Version 1.0

1.The short version

  • Your client book belongs to you. For your clients’ information, you are the responsible party and we are your operator - we process it only to run Strand for you.
  • Nothing is stored without consent. Client photos save only with the client’s recorded consent; marketing needs your opt-in, per channel.
  • No ads, nothing sold. Your data and your clients’ data are never sold and never used to target advertising.
  • Delete everything, any time, from inside the app - here is how.
  • Analytics only on de-identified data. Anything used to improve Strand is stripped of identity first, and only where you have consented.

2.Who is responsible

Strand Hair and Beauty (Pty) Ltd (Reg. 2026/555939/07), of Durbanville, Cape Town, South Africa, operates Strand and this website. Where Strand decides why and how personal information is processed - your account, the waitlist, this website - we are the responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA). Our information officer is the chief executive officer, reachable at data@strand.style; rights requests go to privacy@strand.style. Section 12 lists the Information Regulator’s details if we ever let you down.

3.Two kinds of data, two sets of duties

Strand holds two very different kinds of personal information, and POPIA treats them differently on purpose.

Your data - your account, profile, subscription, settings, identity verification and messages with us. For this, Strand is the responsible party, and this policy is our notice to you.

Your clients’ data - the names, contact details, formulas, visit notes and photos in your client book. Your clients are your data subjects: you are the responsible party and Strand is your operator, processing that information only on your instructions, under the written undertaking in section 6 of the terms. We never use your client book for our own purposes in identifiable form, and a client’s identity is never correlated across the different stylists who serve them.

4.What we collect

CategoryWhatWhy
Account and profileName, email, phone, sign-in identity (Apple, Google or Instagram), salon membership and role, settingsTo provide the app - contract
Client book (as your operator)Client names, contact details, services, formulas, prices, notes, photos with recorded client consentYour studio memory, on your instructions
Voice notesAudio you record and its transcription; audio is processed to text and structured into the client cardCapture - the core of the product
MessagesWhatsApp and Instagram conversations you connect: content, sender, timestampsLanding conversations in your studio memory; replies you switch on
Identity verificationVerification tier and outcome from our verification partner; see section 5Account assurance and legal obligations
WaitlistName, email, city, role, your answer to the memory question, Instagram handle if you share itConsent - to contact you about early access
Website demosQuestions you type or say to demos on this site, where offered, rate-limited by IP; demos answer from a fictional sample client, never from real recordsRunning the demo you asked for
TechnicalLogs, device and app diagnostics, IP address for rate limiting and abuse preventionSecurity and reliability - legitimate interest

5.Identity verification and special personal information

Some account tiers require identity verification through our verification partner, Didit. Depending on tier this can include an age and liveness check or a government identity document - biometric information POPIA classes as special personal information, processed only with your explicit consent at the moment of verification. The decisive fact: Strand never stores the selfie or the document. Those artefacts stay with the verification partner under its own safeguards; Strand stores only the tier, the outcome and a reference code. Where you provide a South African ID number, it is held only as long as the verification it supports remains live, is never used for analytics, and is deleted with your account.

6.Why we process, and on what basis

PurposeLawful basisYour control
Running Strand for youContract - section 11(1)(b)Cancel any time; export and delete on the way out
Identity verificationExplicit consent, plus legal obligationsChoose a tier that does not require it, where offered
Marketing email or SMSConsent - section 11(1)(a), per channelOpt in per channel; every message carries an opt-out
Product analytics and improving StrandConsent, on de-identified data onlyWithdraw in the app; you are removed from the next build
Fraud and abuse preventionLegitimate interest - section 11(1)(f)Object under section 11(3); we stop unless the law requires otherwise

Consent in Strand is scoped, versioned and recorded - every grant and withdrawal is kept as an ordered, timestamped record, so we can always show what you agreed to and when. Withdrawing is as easy as granting, from the app’s privacy settings.

7.How AI processing works

Strand’s intelligence - transcribing voice notes, structuring client cards, drafting captions and quotes, answering your questions - runs on AI models operated by the providers listed in section 8, each bound as an operator. Your content is sent to them only to produce the result you asked for. Your identifiable data is never used to train shared models. Where we improve Strand’s own intelligence, we use only de-identified, consent-gated data from which names, contacts, identifiers and anything that could re-identify a person have been removed, with small groups suppressed entirely. Data from connected WhatsApp conversations is never used to train or improve AI models at all, in any form - Meta’s platform terms prohibit it and we honour that categorically. When Strand replies automatically in a connected messaging channel, the first automated reply discloses that it is automated, and you or your client can always ask for a human.

8.Operators and third parties we use

These providers process personal information on our behalf under written contracts, each limited to its purpose. We never sell personal information to anyone.

ProviderWhat forWhere
ClerkSign-in and account securityUnited States
DiditIdentity verification; holds verification artefactsEU
Meta PlatformsWhatsApp Business Platform and Instagram messaging, when you connect themUnited States / Ireland
TwilioMessaging infrastructure, where used as our WhatsApp providerUnited States
ElevenLabsVoice transcription and the voice assistantUnited States
AnthropicAI answers and drafting (Claude models)United States
Google CloudHosting and infrastructure, South African region preferred for identity dataSouth Africa / global
ResendWaitlist and transactional emailUnited States

A note on WhatsApp, stated honestly: messages on the WhatsApp Business Platform are encrypted in transit between your client’s device and the platform, but Meta decrypts them to deliver them to the business - this is not the end-to-end encryption of a personal WhatsApp chat, and Meta and any messaging provider handle content in order to deliver it. Meta retains message data for up to 30 days for delivery; Strand’s own retention is in section 11.

Data we receive from Meta’s platforms when you connect Instagram or WhatsApp is used only to run your connected conversations. We do not use it to build profiles beyond your own studio memory, do not use it in any eligibility decision, and do not sell, license or buy platform data - and when you disconnect a channel or delete your account, we delete the platform data that came with it.

We also disclose information where the law compels it - and we will tell you, unless the law forbids that too.

9.When data leaves South Africa

Some operators above process data outside South Africa. Section 72 of POPIA allows this only under protection comparable to POPIA, and that is how we transfer: written operator contracts binding each provider to equivalent safeguards, explicit consent where the transfer rides on it (identity verification), and a standing preference to keep the identity plane - the systems that know who you are - hosted in South Africa. De-identified analytics data is outside section 72 because it is no longer personal information, and we treat keeping it that way as an engineering guarantee, not an assumption.

10.How we secure it

Section 19 of POPIA requires appropriate, generally accepted safeguards; ours are engineering decisions, not paperwork. Access to personal information is bound to purpose in code, so a system component can only reach data its purpose entitles it to. Identity data and analytics data live in separate systems that share no keys. Traffic is encrypted in transit; secrets are held in a managed vault, not in code; and every access to the audit trail is itself audited. If a breach ever compromises your information, we notify the Information Regulator and you as section 22 requires.

11.How long we keep things

DataKept for
Your account and client bookWhile your account is active; deleted on request
Connected message history24 months, then deleted on a rolling basis
Identity verification referenceWhile the verification it supports is live
Waitlist entriesUntil launch in your area, or until you ask us to remove you
Financial records5 years, as tax and company law require
Consent and deletion recordsKept as proof of compliance, personal content minimised

12.Your rights, and how to use them

POPIA gives you the right to know what we hold about you, to correct it, to delete it, to object to processing, and to complain. In Strand these are buttons, not letters: export my records and delete my data live in the app’s privacy settings, and POPIA and your data walks through each right. For anything else, email privacy@strand.style - we respond within 30 days.

If you are not satisfied, you may complain to the Information Regulator (South Africa): Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191; telephone 010 023 5200 (toll free 0800 017 160); complaints email POPIAComplaints@inforegulator.org.za; general enquiries enquiries@inforegulator.org.za; https://inforegulator.org.za.

13.Direct marketing

We market by electronic means only with your consent, or - if you are already a customer - only for similar services, with an opt-out in every message, as section 69 of POPIA requires. This applies to email, SMS and messaging channels such as WhatsApp alike - they are all electronic communication under POPIA. We will ask for marketing consent at most once; declining is final unless you change your mind, and we keep a record of every refusal and objection so you are never asked again.

14.Children

Strand is a professional tool for people 18 and older. POPIA prohibits processing a child’s personal information outright unless a competent person - usually a parent or guardian - consents first, and we honour that strictly: a stylist recording a minor client’s details or photos must obtain the guardian’s prior consent, and the app’s consent flow is built to record it.

15.Cookies

This website sets no advertising cookies and no third-party analytics cookies. Rate limiting for any demos uses your IP address server-side and stores nothing in your browser beyond what the site needs to function. If that ever changes, we will ask first and update this policy.

16.Changes to this policy

When we change this policy materially - a new purpose, a new category of data, a new operator with access to identifiable data - we notify you in the app or by email before the change takes effect, and where the change needs your consent we ask for it rather than assume it. The effective date at the top always tells you which version you are reading.