Skip to content

Legal

Sub-processors

The third parties that handle data for BeautyZilla salons — Schedule 3 of the Data Processing Agreement, compiled from the integrations the software actually uses.

Sub-processorsv1.0effective

What this list is

A sub-processor is a third party BeautyZilla engages to process personal data on a salon's behalf in order to provide the Service. Under clause "Sub-processors" of our Data Processing Agreement every salon gives general authorisation for the sub-processors on this page, and this page is Schedule 3 of that agreement.

The list is compiled from the integrations the BeautyZilla software actually makes calls to — not from a list of vendors we might one day use. It was last reviewed on 28 August 2026. Two rows (Meilisearch and MinIO) are software we run on our own server rather than companies that receive your data; they are included so that the full path your data takes is visible in one place.

The current sub-processors

Sub-processors
Sub-processorPurposeData categoriesRegionUsed by
Stripe Payments Europe Ltd / Stripe, Inc.Card payments, deposits and no-show charges taken through BeautyZilla, and billing for salon subscriptions. Stripe holds card numbers; BeautyZilla never sees them.
  • Name
  • Email address
  • Payment amount and status
  • Card details (held by Stripe only)
Ireland (EU) and United StatesOnline booking, point of sale, subscription billing
Postmark (ActiveCampaign, LLC)Transactional email delivery: sign-in codes and account emails sent from BeautyZilla.
  • Email address
  • Sign-in code
  • Message content
United StatesSign-in, account notices
Twilio Inc.SMS delivery, and WhatsApp delivery as a Meta Business Solution Provider: appointment reminders, marketplace listing-claim codes and enquiry relay messages.
  • Mobile number
  • Message content (appointment details, codes, replies)
United States (EU/Ireland data residency where enabled)Reminders, WhatsApp, marketplace listing claims
Sentry (Functional Software, Inc.)Error monitoring for the API and background worker so faults are found and fixed quickly. Enabled only when configured for a deployment.
  • Error traces
  • Account and tenant identifiers
  • IP address
United States (EU region available)API and background worker
Hostinger International Ltd (virtual private server)Hosts the whole platform: the application servers, the PostgreSQL database, the Redis queue, and the self-hosted search and media stores listed below.
  • All data stored in BeautyZilla
UK/EU regionEvery surface
Meilisearch (self-hosted on our server)The marketplace search index, rebuilt from published salon listings. Runs on our own server; Meilisearch the company receives nothing.
  • Salon listing data (business name, address, services)
UK/EU region (on our server)Marketplace search
MinIO (self-hosted S3-compatible object storage on our server)Stores uploaded media: salon photos, staff photos and logos. Runs on our own server; MinIO the company receives nothing.
  • Uploaded images and their file names
UK/EU region (on our server)Salon sites, marketplace listings, console
Google (Tag Manager, Analytics), Meta (Pixel), TikTok (Pixel)Traffic measurement and advertising attribution for beautyzilla.co and for a salon's own site where that salon has entered its tag IDs. Loaded only after the visitor accepts analytics or marketing cookies.
  • Device and browser identifiers
  • Pages visited
  • IP address
United States and EUMarketing site and salon sites, after consent only

Integrations you connect yourself

Some services receive data only because a salon has chosen to connect its own account to them — for example two-way sync with a staff member's Google Calendar, or the Google, Meta and TikTok tags a salon enters for its own website. In those cases the salon has its own relationship with that provider, the provider acts on the salon's authorisation rather than ours, and BeautyZilla simply carries out the connection you configured. You can disconnect any of them from the console at any time.

How changes are notified

  • When we intend to add a sub-processor, or to change what an existing one does with salon data, we add it to the table above at least 30 days before it first handles any salon's data, together with the date the change takes effect.
  • The "last reviewed" date in the introduction is updated on every change, and the change is recorded in the Data Processing Agreement's changelog.
  • Salon account owners who would like to be told by email as well can ask for that by writing to the address below; we keep a list and email it on every change.
  • Removing a sub-processor, or narrowing what one does, is not a change you need notice of; we simply update the table.

How to object

If you have reasonable data-protection grounds to object to a new or changed sub-processor, email info.beautyzilla@gmail.com within 30 days of the change appearing on this page, from your account owner's address, saying which sub-processor you object to and why. We will reply within ten working days with a proposed alternative. If we cannot offer one that reasonably addresses your objection, you may end the affected part of the Service under the Data Processing Agreement's sub-processor clause, with a refund of any fees paid in advance for the period after termination.

Version history

  1. Version 1.0First register: Stripe, Postmark, Twilio, Sentry, Hostinger, Meilisearch, MinIO, consent-gated tags.

Choose which optional cookies this site may set. Strictly necessary cookies are always on — the site does not work without them.

Cookie policy v1.0 · Cookie policy