Privacy Policy
Effective Date: February 21, 2026
Last Updated: February 21, 2026
Table of Contents
1Introduction
Tri Styles LLC (“we,” “us,” or “Loci”) operates the Loci platform at locibooking.com. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Platform.
This policy applies to all users of the Platform, including Business Owners who subscribe to manage their businesses, their staff members, and Clients who book appointments. By using Loci, you consent to the data practices described in this policy.
2Information We Collect
2a. Information You Provide
Business Owners: First and last name, email address, phone number, password (hashed with bcrypt — never stored in plaintext), business name, business type, team size, location count, location name, address, phone number, timezone, and billing information (processed by Stripe — we do not store credit card numbers).
Clients: First and last name, email address, phone number, date of birth, gender, physical address, referral source, appointment notes, service preferences, preferred stylist, contact preferences, and marketing consent.
Staff: Name, email address, phone number, role, assigned locations, and profile photos.
2b. Information Collected Automatically
- IP address, browser type and version, device type, and operating system
- Pages visited, time spent on pages, and referring URLs
- Cookies and similar technologies (session cookies for authentication)
2c. Information from Third Parties
If you choose to sign in with Google, we receive your name and email address from your Google account profile. We do not receive your Google password.
3How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Platform
- Process payments and manage subscriptions
- Send transactional communications, including appointment confirmations, reminders, status updates, and cancellation notices
- Provide customer support
- Ensure platform security and prevent fraud
- Comply with legal obligations
- Generate aggregated, anonymized analytics to improve the service
4SMS/Text Messaging
We send transactional SMS messages on behalf of businesses using the Platform. These messages are delivered via Twilio and include:
- Appointment confirmations
- Booking reminders
- Schedule changes
- Cancellation notices
- Status updates (e.g., “Your stylist is ready!”)
Message frequency varies based on appointment activity. Message and data rates may apply.
No mobile information, including phone numbers and mobile opt-in data, will be shared with third parties or affiliates for marketing or promotional purposes.
Phone numbers are shared only with Twilio solely for the purpose of delivering transactional messages.
Opt out: You may opt out at any time by replying STOP to any message. We honor STOP, END, CANCEL, UNSUBSCRIBE, and QUIT keywords. After opting out, you will receive one confirmation message; no further messages will be sent.
Help: For help, reply HELP to any message or contact support@locibooking.com.
Consent to receive messages is not a condition of any purchase or booking.
5Third-Party Service Providers
We work with the following third-party service providers to operate the Platform:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing (PCI-DSS compliant) | Payment method, billing info, transaction history |
| Twilio | SMS delivery | Phone number, message content |
| Resend | Email delivery | Email address, message content |
| Supabase | Database hosting (encrypted at rest) | All platform data |
| Vercel | Application hosting | Application logs, IP addresses |
| OAuth authentication (optional) | Email, name (only if user chooses Google sign-in) | |
| Anthropic | AI intake sessions (optional) | Intake responses, client profile info (only when AI feature is used) |
| AWS S3 | File and image storage | Uploaded photos, profile images, invoice PDFs |
We require all service providers to maintain appropriate security measures. We do not sell personal information to any third party.
6Data Sharing & Disclosure
- We do not sell, rent, or trade your personal information.
- We share data only with the service providers listed above, solely for operational purposes.
- We may disclose information if required by law, subpoena, court order, or government request.
- We may share aggregated, de-identified data that cannot reasonably identify you.
- In the event of a merger, acquisition, or asset sale, user data may be transferred. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.
7Data Retention
- Account data is retained while your account is active.
- After account deletion, data is soft-deleted and retained for up to 90 days for recovery purposes, then permanently deleted.
- Financial transaction records are retained as required by law (typically 7 years) and are immutable — they cannot be modified after creation.
- Audit logs are retained for compliance and security purposes.
- You may request immediate permanent deletion of your data by contacting support@locibooking.com.
8Data Security
We implement industry-standard security measures to protect your data:
- All data transmitted via TLS/HTTPS encryption
- Database encrypted at rest (Supabase)
- Passwords hashed using bcrypt (never stored in plaintext)
- JWT-based session management with permission versioning
- Multi-tenant architecture with strict organizational data isolation
- Role-based access control with permission overrides
- Regular security reviews and audit logging
9Your Privacy Rights
All users have the following rights:
- Access — Request a copy of your personal data
- Correction — Request correction of inaccurate data
- Deletion — Request deletion of your data (subject to legal retention requirements)
- Data Export — Request a portable copy of your data
- Opt-Out — Opt out of marketing communications; opt out of SMS by replying STOP
- Withdraw Consent — Withdraw consent at any time without affecting the lawfulness of prior processing
To exercise these rights: Email support@locibooking.com. We will respond within 45 days. We may need to verify your identity before processing requests.
Account deletion: Available through in-app settings or by emailing support@locibooking.com. Web-based deletion is also available for users who have uninstalled the app.
10California Privacy Rights (CCPA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know — Request the categories and specific pieces of personal information we have collected about you
- Right to Delete — Request deletion of your personal information
- Right to Correct — Request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing — We do not sell or share personal information for cross-context behavioral advertising
- Right to Limit Use of Sensitive Personal Information — We use sensitive personal information only as necessary to provide the services
- Right to Non-Discrimination — We will not discriminate against you for exercising your CCPA rights
Categories of Personal Information Collected in the Past 12 Months
- Identifiers (name, email, phone number, address)
- Commercial information (appointment history, services booked, purchase history)
- Internet/electronic network activity (usage logs, IP address, browser information)
- Geolocation data (business location addresses)
- Professional information (staff roles, employment status)
- Sensitive personal information (financial account details via Stripe, date of birth)
Categories sold or shared: None. We do not sell or share personal information.
To exercise California rights: Email support@locibooking.com. We will verify your identity and respond within 45 days (extendable by 45 days with notice). You may designate an authorized agent to submit requests on your behalf.
11Business Owners & Client Data
- Business Owners are data controllers for the client data they collect through Loci.
- Loci acts as a data processor on behalf of Business Owners.
- Clients with questions about how a specific business uses their data should contact that business directly.
- Business Owners are responsible for obtaining appropriate consent from their clients, as described in our Terms of Service.
- Loci provides tools for Business Owners to manage and delete client data.
12AI-Powered Features
Loci offers optional AI-powered intake features using Anthropic Claude.
- When used, intake session responses and relevant client profile information are sent to Anthropic for processing.
- You will be informed before any personal data is sent to AI services.
- AI features can be disabled entirely by the Business Owner.
- AI-processed data is used only to generate intake assessments and is not used to train AI models.
For more information about AI features and your responsibilities, see our Terms of Service.
- We use essential cookies for authentication and session management only.
- We do not use advertising or cross-site tracking cookies.
- We do not participate in cross-app tracking.
- We honor Global Privacy Control (GPC) browser signals.
14Children's Privacy
Loci is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe we have collected information from a child under 13, please contact us at support@locibooking.com.
15International Users
Loci is operated from the United States. If you access the Platform from outside the United States, you consent to the transfer of your information to the United States and its processing in the United States. We comply with applicable data protection laws.
16Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email and/or platform notification at least 30 days before the changes take effect. The date of the last update will always be displayed at the top of this page.
Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the revised policy. If you do not agree to the revised policy, you must stop using the Platform.
17Contact Us
If you have any questions about this Privacy Policy, please contact us:
Email: support@locibooking.com
Business Entity: Tri Styles LLC
Location: United States
For privacy-specific inquiries, please include “Privacy” in the subject line.