Privacy Policy
how Pinsot collects, uses, shares, retains, and protects personal information
Introduction and scope
Pinsot is a product operated by Dakoli LLC, a California limited liability company. This document explains the rules, rights, procedures, and responsibilities that apply to how pinsot collects, uses, shares, retains, and protects personal information
Pinsot provides subscription software and technology for nail salon operations in a global market. Salons are independent businesses that provide nail, beauty, wellness, and related services to their clients. Unless a document expressly says otherwise for a specific transaction, the salon—not Pinsot—is responsible for its services, prices, technicians, schedules, employment relationships, commissions, taxes, refunds, client care, licensing, sanitation, and regulatory compliance.
The English version is the controlling version unless applicable law requires otherwise. The Vietnamese translation is provided for meaningful access and convenience and is intended to preserve the same substance.
Who controls information
Dakoli LLC generally acts as a controller for Pinsot account administration, website operation, subscriptions, direct support, security, product analytics that Pinsot determines, legal compliance, and direct communications. For personal information a salon submits or manages about its clients, technicians, and operations, Pinsot generally processes that information for the salon under the salon's instructions. The exact role depends on the context and applicable law.
Salons are responsible for their notices, lawful bases, consents, permissions, retention choices, client communications, workforce practices, and responses where they control personal information. Clients should contact the salon first about salon-controlled records. Pinsot will assist the salon as required by contract and law and will route direct requests to the appropriate controller when necessary.
Information we may collect
Depending on enabled features and the user's relationship with a salon, information may include identity and contact details; account, authentication, salon, organization, location, role, and permission records; technician profile, skills, availability, turn, compensation-input, and work records; client profiles, preferences, appointment, visit, service, nail-record, communication, consent, and feedback information; and transaction, billing, price, discount, tip, commission-estimate, and report data.
We may also process support requests, uploaded content, integration data, AI prompts and outputs, device and browser information, notification tokens, approximate location when a user enables a relevant feature, usage events, diagnostic information, audit history, logs, cookies, and local-storage preferences. We ask users not to submit government identifiers, full payment credentials, unnecessary health information, or other sensitive data unless a verified feature and lawful purpose specifically require it.
Sources of information
We receive information directly from account holders, salon administrators, team members, clients, support requesters, and website visitors. Salons may provide information about authorized users, technicians, clients, services, and transactions. Other users may provide information when booking, communicating, giving feedback, requesting support, or using an enabled application.
We may receive technical or transaction information from a user's device, browser, a configured integration, authentication component, hosting environment, notification service, payment provider, or other service provider. We do not assume an integration is active merely because code supports it; public provider disclosures are limited to services verified in the repository and deployment records.
Purposes and lawful bases
We use information to create and secure accounts; provide salon workflows; maintain tenant, role, and location boundaries; process subscriptions; support users; communicate operational notices; detect abuse; investigate incidents; maintain audit records; improve reliability and usability; develop enabled features; comply with law; establish or defend rights; and complete corporate transactions. We do not use salon-controlled data for unrelated purposes contrary to customer instructions.
For EEA and UK users, processing may rely on performance of a contract, steps requested before a contract, legitimate interests such as securing and improving the service, consent where required, and legal obligations. We balance legitimate interests against individual rights. A person may withdraw consent prospectively where consent applies, but withdrawal does not make earlier lawful processing unlawful. A salon must identify its own lawful bases for salon-controlled data.
Sensitive information and minors
Pinsot is not a medical service and users must not use it to diagnose nail or health conditions. Salons should avoid recording health, disability, biometric, government-identifier, financial-account, precise-location, immigration, or other sensitive information unless a verified workflow, lawful basis, clear necessity, access control, and appropriate notice support the use. Free-text fields should not become a repository for unnecessary personal details.
Pinsot business accounts are not directed to children. Client records may concern minors when a salon lawfully serves them, but the salon must obtain any required parent or guardian permission and minimize the information. Pinsot does not knowingly invite children to create independent business accounts. Contact us if you believe a child's information was collected improperly.
International transfers and retention
Pinsot serves a global market, so information may be processed outside the country where it was collected. Where required, Dakoli LLC will use an approved transfer mechanism, contractual protection, adequacy decision, or another lawful basis. Displaying a DPA or transfer annex does not by itself execute Standard Contractual Clauses; customers should request the applicable signed documentation.
We retain information for the period reasonably needed to provide and secure the service, follow salon instructions, maintain business and audit records, resolve disputes, enforce agreements, and comply with law. Retention depends on the data type, relationship, account status, legal duties, security needs, and customer instructions. Deletion from active systems may not immediately remove limited disaster-recovery copies, which remain protected and expire under the applicable cycle once verified.
Security and incident handling
Pinsot uses verified practices including authenticated accounts, server-side authorization, tenant and location boundaries, role-based access, session controls, audit records, redacted diagnostics, and secure-development review. We do not claim a certification, encryption implementation, backup capability, data location, or employee-access control unless verified. No safeguards eliminate all risk, and users must protect devices and credentials and report concerns promptly.
Report suspected security issues to security@pinsot.com. Do not publicly disclose exploit details that create unnecessary risk and do not include live credentials or unrelated personal information. We will assess reports, take proportionate containment and remediation steps, and provide legally required notices to affected controllers or individuals.
AI and automated decision-making
AI features may process prompts, relevant salon context, generated output, feedback, safety signals, and audit information needed to provide and review the feature. Inputs should be minimized and must not include prohibited secrets or unnecessary sensitive data. Provider use is disclosed only when verified and enabled.
Pinsot AI is assistive and review-first. Pinsot does not intend AI to make solely automated decisions that produce legal or similarly significant effects for a person. Salons must keep humans responsible for employment, pay, discipline, safety, legal, medical, financial, and account-termination decisions, explain material use where appropriate, and provide a route for review or correction.
Cookies, messages, and choices
Pinsot uses necessary storage for core site, language, session, and security functions as described in the Cookie Policy. Optional analytics or marketing technologies must not be treated as active unless verified and, where required, consented to. Users can use available cookie settings, browser controls, Global Privacy Control where applicable, device notification settings, and in-message opt-out methods.
Operational email, SMS, push, or in-app messages may support verification, appointments, waitlists, security, and service administration. Optional promotional communication requires the salon or Pinsot, as applicable, to have appropriate permission and honor opt-outs. A person can withdraw optional consent without losing essential service messages where law permits the distinction.
Privacy rights and procedures
Depending on location and context, a person may have rights to access, know, correct, delete, export or port, restrict, object, withdraw consent, appeal a decision, or complain to a regulator. Authorized agents may submit requests where law permits. We may verify identity, authority, account relationship, and request scope using proportionate information and may deny or limit a request where an exception applies, explaining the basis and appeal route when required.
Submit a request through /privacy-request or email privacy@pinsot.com. Identify the request type and account or salon relationship without sending unnecessary identification. We will acknowledge, verify, route, and respond within the period required by applicable law. If the salon controls the record, we may refer the request to the salon or assist it in responding.
Regional disclosures
California and other US state residents may have rights to know, access, correct, delete, obtain a portable copy, opt out of sale, sharing, or targeted advertising, limit certain sensitive-information uses, and appeal, subject to scope and exceptions. Pinsot does not currently represent that it sells personal information or uses cross-context behavioral advertising. Legal definitions vary, so we will evaluate opt-out requests under applicable law and honor recognized preference signals where required.
EEA and UK individuals may also have rights to restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority. Canadian and other jurisdictions may provide comparable rights and complaint routes. Florida residents receive rights available under applicable Florida or federal law. The law that applies depends on the person, processing context, and mandatory jurisdictional rules; Dakoli LLC remains a California limited liability company.
Changes, language, and contact
This document is version 2026.07.20, effective and last updated July 20, 2026. We may update it to reflect product, legal, safety, or operational changes. Material changes will be communicated through an appropriate public or in-product notice when reasonably required. Continued use after an effective change is governed by applicable law and any notice or consent that law requires.
Questions and requests concerning this document may be sent to privacy@pinsot.com. Contact addresses are centralized and require owner verification before production. Do not email passwords, verification codes, full payment credentials, government identification, health details, or unrelated client records.

