Legal
Effective 14 September 2026 · last updated 14 September 2026
This policy explains how MiSuite Pty Ltd, a company based in Sydney, New South Wales, handles personal information in connection with MiSuite — the point-of-sale, booking and customer-management software used by beauty and nail salons in Australia, comprising the Mi POS, Mi Beauty, Mi Staff and Mi Check-In apps, the salon booking pages and the manager dashboard.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
We hold personal information in two distinct capacities. Which parts of this policy apply to you depends on which one you fall under.
Collected by the salon at the desk, at the check-in kiosk, on its booking page, or through the Mi Beauty app:
Some of what a salon may record about you is “sensitive information” under the Privacy Act, which carries a higher standard of protection than ordinary personal information.
Specifically, MiSuite is capable of storing: allergies and product sensitivities you disclose, recorded as free text; whether you are pregnant, where a salon asks because a treatment is contraindicated; and photographs of you or of treatment areas — for example nails before and after, or a reaction to a product.
We collect this only where the salon has recorded it because you told them. A salon cannot add a photograph to your record at all unless photo consent has first been marked on that record, and the software refuses the upload otherwise. You can ask the salon to remove any of it at any time.
Photographs are processed on our servers when uploaded: they are re-encoded, resized, and location and camera metadata (EXIF) is stripped, so no GPS coordinates leave the salon. They are stored in a private container and can only be retrieved through the application under a signed-in staff account — never from a public web address.
Entered by the salon’s owner or manager: your name and preferred name, sign-in email, mobile number, role, the shops you work at, your roster and hours worked, your commission rate, pay basis and earnings, and — where the salon records them — your date of birth, home address, personal email address, start date, employment type and an emergency contact. Your password and your manager PIN are stored only as salted hashes and cannot be read back by anyone, including us. If you use Mi Staff, we keep a record of each phone you sign in on.
Your business name, ABN, trading names, addresses, opening hours, and your banking and card details (held by Stripe, not by us), together with the records we keep about your account — support notes, and an audit trail of any change we make on your behalf.
Server logs, which include the request path, timing and the IP address the request came from; crash reports from the apps, sent through Sentry with phone numbers and email addresses removed before they leave your device; and service health metrics.
We use no advertising trackers and no analytics SDKs. There is no advertising identifier, no cross-site tracking, and nothing on this website or in any of the apps that profiles you.
We do not sell personal information, and we do not use it to train machine-learning models.
| Recipient | What | Why |
|---|---|---|
| The salon you visit | Everything it collected about you, and your account’s name and mobile so it can recognise you | It is their customer relationship |
| Other salons | Nothing. A salon sees only its own records. Where a gift card is valid at several salons in one group, those salons can see the card — not your history | — |
| Stripe | Card details, which go directly to Stripe and never through our servers; your name, email and the amount | Online deposits, gift cards, no-show fees and salon subscriptions |
| ClickSend | Your mobile number and the text of the message | Sending SMS |
| Microsoft Azure | Everything, encrypted at rest, in the Australia East (Sydney) region — including email delivery and push notifications | Hosting |
| Sentry | Crash reports with phone numbers and email addresses removed | Finding and fixing defects |
| Apple and Google | Push notification tokens and Wallet passes | Delivering notifications and passes to your phone |
Our own systems and your data are hosted in Australia. Some of the providers listed above are located overseas or may store or process data overseas — Stripe, ClickSend, Sentry, Apple and Google. Where we disclose information to them we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, and each is bound by its own published privacy terms.
You can ask us, or the salon, to erase you. When we do, we anonymise your account and every salon’s record of you: your name, mobile number, email, notes, allergy and pregnancy records, photographs, saved cards, devices, favourites and the text of any review are deleted or replaced, and every session and notification is revoked. Photograph files themselves are deleted from storage, not merely hidden.
The sale, appointment and gift-card records remain, attached to the anonymised record and no longer identifying you, because the law requires those transaction records to be kept. This cannot be undone.
To ask, email privacy@misuite.com.au or speak to the salon.
Data is encrypted in transit and at rest. Passwords and PINs are stored only as hashes. Card numbers never touch our servers. Each salon’s data is separated at the database level rather than only in application code, so one salon’s records cannot be reached from another’s account. Access by our own staff is recorded with who, when and from where, and a salon can sign a lost tablet or phone out immediately.
If a data breach is likely to result in serious harm, we will assess it and, where required, notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.
You can ask to see the information we hold about you, to correct it, or to have it erased. If you are a salon’s customer, ask the salon first — most requests are theirs to action directly. Otherwise contact us at privacy@misuite.com.au. We will respond within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
A salon can send you marketing only with your consent, which you give at the desk, in the app or on the booking page, and which you can withdraw at any time — by replying STOP to any marketing text, in the app’s settings, or by asking the salon. Consent is recorded separately for text, email and push, so agreeing to one does not opt you into the others.
Appointment reminders, queue calls and messages about a booking you have made are service messages rather than marketing, and are sent so that you are not left waiting or charged a fee you did not see coming. You can turn service messages off in the Mi Beauty app; if you do, a salon cannot charge you a no-show fee, because the warning could not reach you.
MiSuite is not directed at children and we do not knowingly create accounts for them. A salon may record an appointment for a child under a parent’s or guardian’s account.
We will post any change on this page and update the date at the top. Where a change is material, we will also notify the salons that use MiSuite.
MiSuite Pty Ltd · Sydney, NSW, Australia
Privacy enquiries: privacy@misuite.com.au
General support: support@misuite.com.au