Legal

Privacy policy

Effective 14 September 2026 · last updated 14 September 2026

This policy explains how MiSuite Pty Ltd, a company based in Sydney, New South Wales, handles personal information in connection with MiSuite — the point-of-sale, booking and customer-management software used by beauty and nail salons in Australia, comprising the Mi POS, Mi Beauty, Mi Staff and Mi Check-In apps, the salon booking pages and the manager dashboard.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Two roles, and which one applies to you

We hold personal information in two distinct capacities. Which parts of this policy apply to you depends on which one you fall under.

  • As a service provider to a salon. When a salon uses MiSuite, the salon collects information about its own customers and staff, and we store and process that information on the salon’s instructions. The salon decides what to collect and why, and the salon is responsible for its own privacy notice to its customers. If you are a customer of a salon, your first point of contact about your information is that salon.
  • On our own account. When you create a MiSuite account through the Mi Beauty app or a salon’s booking page, we hold that account. When a salon subscribes to MiSuite, we hold its business and billing details.

What we collect

If you are a salon’s customer

Collected by the salon at the desk, at the check-in kiosk, on its booking page, or through the Mi Beauty app:

  • Contact details — your name, mobile number (stored in international format), email address if you give one, and date of birth if the salon records it.
  • Bookings and visits — your appointments, the services you had, which technician performed them, when you arrived, and whether an appointment was missed or cancelled.
  • Purchases — what you bought, how much you paid and by what method (cash, card, gift card, voucher), gift cards you bought or received, packages, memberships and loyalty points.
  • Notes the salon writes about your visits — for example a nail shape you prefer, or a product that irritated your skin.
  • Messages between you and the salon (SMS and the in-app inbox), reviews you leave, and your consent choices, including any withdrawal of consent.

Health information and photographs — sensitive information

Some of what a salon may record about you is “sensitive information” under the Privacy Act, which carries a higher standard of protection than ordinary personal information.

Specifically, MiSuite is capable of storing: allergies and product sensitivities you disclose, recorded as free text; whether you are pregnant, where a salon asks because a treatment is contraindicated; and photographs of you or of treatment areas — for example nails before and after, or a reaction to a product.

We collect this only where the salon has recorded it because you told them. A salon cannot add a photograph to your record at all unless photo consent has first been marked on that record, and the software refuses the upload otherwise. You can ask the salon to remove any of it at any time.

Photographs are processed on our servers when uploaded: they are re-encoded, resized, and location and camera metadata (EXIF) is stripped, so no GPS coordinates leave the salon. They are stored in a private container and can only be retrieved through the application under a signed-in staff account — never from a public web address.

If you have a MiSuite account (Mi Beauty or a salon’s booking page)

  • Your mobile number, which is your sign-in — we text you a one-time code — and the key that links your bookings across the salons you visit.
  • A PIN if you set one, and a passkey or Face ID setting if you use one. A passkey’s private key never leaves your device.
  • A record of each device you sign in on (a name you can recognise, the platform, when it was last used) so that you or we can sign a lost phone out, and push notification tokens if you allow notifications.
  • Saved payment cards are held by Stripe, not by us. We store only the card brand, its last four digits, and a Stripe reference.
  • Salons you have favourited, referrals you have made, and Wallet passes you have added.

If you work at a salon

Entered by the salon’s owner or manager: your name and preferred name, sign-in email, mobile number, role, the shops you work at, your roster and hours worked, your commission rate, pay basis and earnings, and — where the salon records them — your date of birth, home address, personal email address, start date, employment type and an emergency contact. Your password and your manager PIN are stored only as salted hashes and cannot be read back by anyone, including us. If you use Mi Staff, we keep a record of each phone you sign in on.

If you run a salon

Your business name, ABN, trading names, addresses, opening hours, and your banking and card details (held by Stripe, not by us), together with the records we keep about your account — support notes, and an audit trail of any change we make on your behalf.

Collected automatically

Server logs, which include the request path, timing and the IP address the request came from; crash reports from the apps, sent through Sentry with phone numbers and email addresses removed before they leave your device; and service health metrics.

We use no advertising trackers and no analytics SDKs. There is no advertising identifier, no cross-site tracking, and nothing on this website or in any of the apps that profiles you.

Why we collect it

  • To run the salon’s business — take bookings, sell and redeem services, products and gift cards, roster staff, calculate commission and pay, send appointment reminders, and manage a walk-in queue.
  • To let you sign in, and to keep accounts secure: one-time codes, session revocation, rate limiting, and checks on payments made from a device we have not seen before.
  • To send you messages you have agreed to. You can reply STOP to any marketing text and it stops immediately.
  • To charge you for something you bought online, and — where a salon operates a no-show policy that you agreed to at the time of booking — to charge that fee. We keep a copy of the exact wording you agreed to, and a fee is never charged unless the reminder was actually delivered.
  • To meet legal obligations, including tax records and the three-year minimum term the Australian Consumer Law requires for gift cards.
  • To support salons. Our staff can view a salon’s data when the salon asks for help, and every such access is recorded.

We do not sell personal information, and we do not use it to train machine-learning models.

Who we share it with

RecipientWhatWhy
The salon you visitEverything it collected about you, and your account’s name and mobile so it can recognise youIt is their customer relationship
Other salonsNothing. A salon sees only its own records. Where a gift card is valid at several salons in one group, those salons can see the card — not your history
StripeCard details, which go directly to Stripe and never through our servers; your name, email and the amountOnline deposits, gift cards, no-show fees and salon subscriptions
ClickSendYour mobile number and the text of the messageSending SMS
Microsoft AzureEverything, encrypted at rest, in the Australia East (Sydney) region — including email delivery and push notificationsHosting
SentryCrash reports with phone numbers and email addresses removedFinding and fixing defects
Apple and GooglePush notification tokens and Wallet passesDelivering notifications and passes to your phone

Our own systems and your data are hosted in Australia. Some of the providers listed above are located overseas or may store or process data overseas — Stripe, ClickSend, Sentry, Apple and Google. Where we disclose information to them we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, and each is bound by its own published privacy terms.

How long we keep it

  • Sales, appointment and gift-card records — at least seven years, to meet tax record-keeping obligations, and at least three years for gift cards under the Australian Consumer Law, whichever is longer.
  • Your MiSuite account — until you ask us to delete it.
  • Server logs — 30 days.
  • Backups — a continuous seven-day point-in-time window, plus weekly copies retained for four weeks. A record deleted from the live system persists in backups until those windows pass.
  • One-time codes and sign-in sessions — minutes to hours.

Deleting your information — what actually happens

You can ask us, or the salon, to erase you. When we do, we anonymise your account and every salon’s record of you: your name, mobile number, email, notes, allergy and pregnancy records, photographs, saved cards, devices, favourites and the text of any review are deleted or replaced, and every session and notification is revoked. Photograph files themselves are deleted from storage, not merely hidden.

The sale, appointment and gift-card records remain, attached to the anonymised record and no longer identifying you, because the law requires those transaction records to be kept. This cannot be undone.

To ask, email privacy@misuite.com.au or speak to the salon.

Security

Data is encrypted in transit and at rest. Passwords and PINs are stored only as hashes. Card numbers never touch our servers. Each salon’s data is separated at the database level rather than only in application code, so one salon’s records cannot be reached from another’s account. Access by our own staff is recorded with who, when and from where, and a salon can sign a lost tablet or phone out immediately.

If a data breach is likely to result in serious harm, we will assess it and, where required, notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.

Your rights

You can ask to see the information we hold about you, to correct it, or to have it erased. If you are a salon’s customer, ask the salon first — most requests are theirs to action directly. Otherwise contact us at privacy@misuite.com.au. We will respond within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

Marketing and messages

A salon can send you marketing only with your consent, which you give at the desk, in the app or on the booking page, and which you can withdraw at any time — by replying STOP to any marketing text, in the app’s settings, or by asking the salon. Consent is recorded separately for text, email and push, so agreeing to one does not opt you into the others.

Appointment reminders, queue calls and messages about a booking you have made are service messages rather than marketing, and are sent so that you are not left waiting or charged a fee you did not see coming. You can turn service messages off in the Mi Beauty app; if you do, a salon cannot charge you a no-show fee, because the warning could not reach you.

Children

MiSuite is not directed at children and we do not knowingly create accounts for them. A salon may record an appointment for a child under a parent’s or guardian’s account.

Changes to this policy

We will post any change on this page and update the date at the top. Where a change is material, we will also notify the salons that use MiSuite.

Contact us

MiSuite Pty Ltd · Sydney, NSW, Australia
Privacy enquiries: privacy@misuite.com.au
General support: support@misuite.com.au