Legal
Privacy Policy
Last updated: July 28, 2026
This Privacy Policy explains how ReadyPedi (“we,” “us”) collects, uses, and protects information when you use our service (the “Service”). By using the Service, you agree to the practices described here.
1. Information we collect
- Account information. The shop name, license and address details, admin email, and the technician names you add to run the cleaning log.
- Cleaning records. The entries your team logs (chair, technician, date, time, and cleaning type), which the Service stamps onto the TDLR form.
- Billing information. Your subscription status and plan. Card details are collected and stored by our payment processor, Stripe. We never receive or store your full card number.
- Technical information. Basic logs and diagnostics generated when you use the Service, used to keep it secure and working.
2. How we use information
We use the information we collect to:
- provide the Service: store your cleaning records and generate the TDLR form;
- manage your account, subscription, and billing;
- send transactional email (for example, your welcome message and payment receipts); and
- maintain the security, integrity, and reliability of the Service.
We do not sell your personal information.
3. Service providers
We share information with trusted third parties only as needed to run the Service. These include:
- Supabase for database and authentication (stores your account and cleaning records);
- Stripe for payment processing and subscription billing;
- Vercel for application hosting;
- GitHub for encrypted off-site backups. A nightly job copies your account, your technician names and your cleaning records to a private repository so the Service can be restored if the database is lost. Those copies are kept for 30 days and then deleted;
- Resend for delivery of transactional email;
- Fastmail for the mailbox behind our contact address. If you write to us, or reply to one of our emails, your message and your email address are stored there;
- Have I Been Pwned to check, when you choose a password, whether that password appears in a known public data breach. Your password is never sent. We hash it and transmit only the first five characters of that hash — a fragment shared by many hundreds of thousands of different passwords — then do the comparison on our own server. The service cannot learn your password or identify you from it; and
- Sentry for error monitoring. It receives diagnostic details about failures — the error, the page or job it happened in, and the browser or server it happened on — so we can find and fix them. It is configured not to collect personal information automatically, and email addresses are removed from error text before it is sent.
Each provider processes information only to perform services for us.
4. Data retention
We retain your account information for as long as your account is active. Cleaning records are different, and the difference matters: your plan sets how far back your history goes, and older entries are deleted automatically and permanently.
- Boutique. Cleaning records are kept for 90 days.
- Standard. Cleaning records are kept for 1 year.
- Mega Lounge. Cleaning records are kept for 1 year.
- Enterprise / Large Salon. Cleaning records are kept for as long as your account is active.
A daily job removes entries older than your plan’s period, counted in calendar days in your shop’s own time zone. This deletion is permanent: entries cannot be edited or restored once removed, and we cannot recover them for you from the live service. Copies may persist in our encrypted backups for up to 30 days after that, after which they are removed from those too. Changing plans applies from that point forward — upgrading does not bring back records that have already been deleted. Your plan’s period is shown on your Logs and Inspection screens, and the Inspection screen names the oldest date still available whenever you select a range reaching past it.
You remain responsible for your own record-keeping obligations. Texas requires foot-spa cleaning records to be kept and made available to TDLR, and the required period may be longer than the period your plan keeps. If you need records for longer than your plan retains them, print or export them before they age out, or move to a plan with a longer period.
You can request deletion of your account and associated data as described below. As with the automatic deletion above, copies may remain in our encrypted backups for up to 30 days before they are removed from those as well. Some information may be retained for longer where required for legal, tax, or security reasons.
5. Security
We use reasonable technical and organizational measures to protect your information, including tenant isolation so one shop’s data is not accessible to another. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Your choices
You may access and update your shop information from your admin settings. To request a copy of your data or its deletion, contact us at info@readypedi.com. We will respond within a reasonable time.
7. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected in the “Last updated” date above.
8. Contact
Questions about this Policy or your data? Email us at info@readypedi.com.