Trimelo beta applications are open

Privacy Policy

Last updated 2 August 2026. How Trimelo collects, uses, and protects personal information under the Australian Privacy Principles (Privacy Act 1988).

Who we are

Trimelo (“we”, “us”) provides booking, calendar, payments, messaging, and related software for Australian hair salons and barbershops. Privacy requests: admin@trimelo.io. Our Australian Business Number (ABN) will be published here when registered.

This policy covers the Trimelo platform (staff dashboard, public booking pages, mobile staff app, and related services). When a salon collects your information to book or serve you, that salon is typically the organisation responsible for that client record; Trimelo processes it on their behalf to run the product.

What we collect

Depending on how you use Trimelo, we may hold:

  • Salon and staff details — names, work emails, roles, photos, working hours, salon profile (address, phone, ABN), and identity data via Auth0 for staff sign-in.
  • Client CRM data entered by the salon or at booking — name, phone, email, notes/allergies/tags, visit and no-show history, marketing consent and unsubscribe status.
  • Booking data — appointment times, services, assigned staff, location (if multi-site), party/guest attendee names, and manage-booking tokens.
  • Payment metadata — amounts, status, Stripe identifiers, and card brand/last4/expiry only. We never store full card numbers (PANs); Stripe handles card data.
  • Messaging records — SMS/email destinations and snapshotted message bodies for confirmations, reminders, waitlist offers, and related notices; OTP challenges (codes stored hashed); STOP/unsubscribe suppressions.
  • Waitlist and commercial-SMS consent text/source where a client joins a waitlist or opts in to marketing.
  • Import files — client/service data a salon uploads from Fresha, Timely, Square, or similar CSV exports.
  • Technical and security logs — IP/device signals, access and error logs needed to operate and secure the service.

Why we collect it

We use personal information to:

  • Provide booking, calendar, CRM, POS, deposits, fees, reminders, waitlist backfill, reporting, and subscription billing.
  • Send transactional SMS/email (confirmations, reminders, staff-triggered cancellation notices) and, where consent exists, commercial SMS such as waitlist offers or win-back messages.
  • Process payments through Stripe Connect (client → salon) and platform subscription billing (salon → Trimelo).
  • Personalise AI-assisted messaging (for example classifying SMS replies and drafting backfill offers) without inventing booking facts the salon has not authorised.
  • Suggest CSV column mappings for client imports from headers and a small redacted sample only — the full import file stays in Trimelo and is applied by deterministic code, not by the model.
  • Support, security, fraud prevention, and product improvement.

SMS and email (Spam Act 2003)

Transactional messages about a booking do not require marketing consent. Commercial messages (waitlist offers, win-back) are sent only where consent or another Spam Act exception applies. Recipients can opt out by replying STOP (or equivalent); we suppress that number platform-wide for commercial SMS.

SMS is sent from a shared Trimelo Australian number, not a per-salon sender ID. Message content identifies the salon where relevant.

Payments

Client card payments are direct charges on the salon’s Stripe connected account. Trimelo is not in the client→salon money path and does not add a client-facing platform fee. Subscription fees from the salon to Trimelo are billed separately on Trimelo’s own Stripe account.

No-show and late-cancellation fees are charged only against the fee terms the client agreed at booking time (a consent snapshot), never against a later fee amount the salon may have changed.

Who we share with

We use service providers to operate Trimelo. They only receive what they need to perform their role:

  • Stripe — payments and Connect KYC.
  • Mobile Message — SMS delivery and inbound replies.
  • Resend — email delivery (when messaging is enabled).
  • Auth0 — staff authentication only (end clients do not create Auth0 accounts).
  • Railway (and related infrastructure) — hosting of the app, worker, AI agent, and database.
  • Google (Gemini API) and OpenRouter — LLM inference in the AI agent for SMS classification/personalisation and for suggesting client CSV column mappings from headers plus a bounded redacted sample (not the full file). Google is the primary provider; OpenRouter is the fallback used when Google is unavailable. OpenRouter is a routing service and forwards the request to an underlying inference provider on our behalf.
  • Object storage providers — salon and staff images.

Some providers may process data outside Australia. Where that occurs, we take steps appropriate under the APPs (including contractual and technical safeguards) and disclose it here. We do not sell personal information.

Security and retention

We use encryption in transit and at rest, tenant isolation (including salon-scoped access controls), and PCI scope minimisation via Stripe. We retain information only as long as needed for the purposes above, legal obligations, dispute resolution, and backup integrity, then delete or de-identify it.

Your rights

Under the Australian Privacy Principles you may request access to, correction of, or deletion of personal information we hold, subject to legal exceptions. Salons can export their client data from the product; individuals can also contact admin@trimelo.io.

If you are unhappy with how we handle a privacy matter, contact us first. You may also complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Changes

We may update this policy as the product or law changes. The “Last updated” date at the top will change when we do. Material changes will be communicated through the product or by email where appropriate. Questions: admin@trimelo.io.

This summary reflects how Trimelo works today. It is not a substitute for legal advice. ABN and registered entity details will be added when available.