TERNO PRIVACY POLICY
Effective Date: 1 August 2026
1. INTRODUCTION
This Privacy Policy explains how Terno (Gulf) FZ-LLC and its regional Affiliates ("Terno," "we," "us," or "our") collect, use, disclose, and protect personal data when you use the Terno booking and appointment management platform (the "Services" or "Platform"), as described in our Terms of Service.
This Policy uses the same defined terms as our Terms of Service, including "Merchant" (the business using Terno), "Customer" (an individual who books an appointment with a Merchant through Terno), "User" (a Merchant's staff or authorized representative), and "Business" (the Merchant's salon, barbershop, or other service business).
Terno's collection, use, and protection of personal data referenced in Section 8.2 of our Terms of Service is governed by this Policy. By using the Services, you consent to the practices described here.
2. WHO THIS POLICY APPLIES TO
This Policy applies to personal data we process about:
- Merchants and Users — business owners, managers, and staff who create a Terno account, subscribe to the Services, and manage their Business through the Platform.
- Customers — individuals who book, reschedule, or cancel appointments with a Merchant through Terno, including via WhatsApp, our booking pages, or a Merchant's own website.
- Website visitors — anyone who visits terno.io or a Merchant's Terno-hosted booking page, whether or not they book an appointment.
Where Terno processes Customer data on a Merchant's behalf, the Merchant — not Terno — is generally the data controller for that data, and Terno acts as a data processor under our Data Processing Agreement. See Section 12 (Controller and Processor Roles) below for what this means in practice.
3. INFORMATION WE COLLECT
3.1 Information Merchants Provide Directly
When a Merchant registers for and uses the Services, we collect:
- Account and contact information — name, email address, phone number, business role, and login credentials.
- Business information — Business name, address, opening hours, service menu, pricing, staff list, and business type.
- Verification information — business license or registration details a Merchant provides to us directly. Identity verification for payouts (e.g., ID documents) is collected and held by Stripe as part of Stripe Connect onboarding, not by Terno — we only receive a verification status back from Stripe.
- Payment and payout information — full card and bank details are entered directly into Stripe's own secure systems (via Stripe Connect and Stripe.js) and never touch Terno's servers or database. Terno stores only a Stripe customer/account reference ID and transaction status — never a full card number, CVV, or bank account number.
- AI feature usage — how many AI-assisted actions (e.g., Terno Receptionist replies, AI website generation) a Merchant's account has used, for billing and credit-balance purposes. This is usage/billing metadata, not new personal data beyond what is already described in Section 3.4 and 3.5.
- Communications — messages Merchants send to Terno support, and content submitted through the Platform (e.g., knowledge base entries, message templates, staff schedules).
We do not, and are not able to, collect Social Security Numbers, passport numbers, or other government ID numbers directly. Where identity verification is required to enable payouts, this is handled entirely within Stripe Connect's own onboarding flow — Terno never receives or stores the underlying documents.
3.2 Information About Customers (Collected on Behalf of Merchants)
When a Customer books an appointment with a Merchant through Terno, we collect, on the Merchant's behalf:
Contact and identity information — name, phone number, and email address.
Appointment details — service selected, staff preference, date and time, notes, and booking history.
Payment information — where a deposit or payment is collected, processed via Stripe; Terno does not store full payment card details.
Communication content — messages exchanged with the Merchant or with Terno's automated booking assistant ("Terno Receptionist") via WhatsApp or other supported channels.
Service preference and suitability details (optional, Customer-declared) — where a Merchant enables this feature and a Customer chooses to provide them: hair pattern, porosity and density; scalp condition; Fitzpatrick skin type; and any cultural or accessibility needs the Customer wishes to record (for example, head-covering practice, a preference for a same-gender stylist, mobility accommodation, or sensory accommodation).
These details are optional. A Customer can book, and receive every service, without providing any of them. Some of them may reveal, or be treated as revealing, racial or ethnic origin or religious or philosophical belief, and we therefore treat all of them as sensitive (special category) personal data and collect them only with the Customer's separate, explicit, opt-in consent, recorded against a versioned consent text.
We do not derive these details from photographs, video, facial scans, or any biometric process. They are typed by the Customer, or recorded by salon staff from what the Customer tells them. We do not collect biometric identifiers or biometric information.
These details are shared across every branch in the Merchant's business group, not only the branch where they were recorded.
3.3 Information Collected Automatically
When anyone uses our Services or visits a Terno-hosted page, we automatically collect:
- Technical information — IP address, browser type and version, device identifiers, operating system, and time zone.
- Usage information — pages viewed, features used, session duration, and referring URLs.
- Approximate location — inferred from IP address, used for currency/timezone defaults and fraud prevention (we do not collect precise device GPS location).
3.4 Information Collected via WhatsApp and Other Communication Channels
Terno uses the WhatsApp Business Platform (operated by Meta Platforms, Inc.) to send booking confirmations, reminders, and to power the Terno Receptionist automated booking assistant. When a Customer messages a Merchant's connected WhatsApp number:
- We receive the message content, sender phone number, and message metadata (timestamp, delivery status) via Meta's WhatsApp Business API.
- Message content is processed by our AI booking assistant (built on Google Cloud Vertex AI, Gemini models) to understand booking requests and generate replies. This processing happens automatically and message content is not used to train third-party foundation models beyond the processing needed to generate a reply.
- Where WhatsApp delivery fails, we may fall back to SMS via Twilio for time-sensitive messages such as verification codes.
We only use WhatsApp messaging for the purposes a Customer would reasonably expect from booking or communicating with a Merchant — we do not use WhatsApp contact information for unrelated marketing without consent.
Automated decision-making. The Terno Receptionist can independently confirm, reschedule, or cancel a Booking based on a Customer's message, without a human reviewing that specific exchange before it happens. A Customer can ask to speak with a staff member at any point in the conversation; this triggers a handoff notification to the Merchant's staff, who can take over the conversation directly. Merchants (and Terno, for quality and safety purposes) may review flagged or escalated conversations after the fact to correct mistakes and improve the assistant's accuracy — this internal review uses conversation content already collected under this Policy and is not a separate collection of new data. By messaging a Merchant's WhatsApp number, a Customer consents to their message being processed by the Terno Receptionist and, where relevant, reviewed internally for the quality and safety purposes described above.
Who can see this content. Conversation transcripts are visible to the Merchant whose number was messaged (through their inbox) and to a limited set of trained Terno personnel who need access to operate, support, or improve the Service. Access is role-restricted and logged, consistent with Section 8 (Data Security).
Transactional vs. marketing messages. Booking confirmations, reminders, and replies needed to complete a booking are operational messages a Customer cannot opt out of while keeping an active booking, since they are necessary to provide the Service. Optional marketing messages (e.g., promotions from a Merchant) require opt-in consent and can be opted out of at any time.
3.5 Website Content and AI-Assisted Generation
Terno lets Merchants build and publish a business website and booking page. In connection with this feature:
- A Merchant may submit a description of their Business, brand preferences, and existing content to our AI provider (Google Cloud Vertex AI) to generate suggested website copy, layouts, or page templates.
- Anything a Merchant publishes to their website or booking page — business descriptions, staff names or photos, service listings, and Customer reviews — is intentionally public and visible to anyone who visits that page or finds it via search. Merchants are responsible for having the right to publish any personal data (for example, staff or Customer photos) included in their website content.
- Website-generation prompts and published website content are not used to train third-party AI models beyond producing the requested output.
4. HOW WE USE INFORMATION
We use the information described above to:
- Provide, operate, and maintain the Services, including account management, booking scheduling, and payment processing;
- Send booking confirmations, reminders, rescheduling and cancellation notices, and respond to Customer messages via WhatsApp, SMS, or email;
- Power the Terno Receptionist automated booking assistant;
- Provide customer support and troubleshoot technical issues;
- Detect, prevent, and investigate fraud, abuse, and security incidents;
- Generate aggregated analytics and reporting for Merchants about their own Business;
- Comply with our legal obligations, including tax, anti-money-laundering, and consumer protection requirements; and
- Improve and develop the Services.
We do not sell personal data, and we do not use Customer data collected on a Merchant's behalf for our own independent marketing purposes.
5. LEGAL BASES FOR PROCESSING
For users in the UK, EU, and other regions with similar requirements, we rely on the following legal bases:
- Contract — processing necessary to provide the Services under our Terms of Service or a Merchant's booking with a Customer.
- Legitimate interests — improving and securing the Services, preventing fraud, and administering our business, provided these interests are not outweighed by your rights.
- Consent — for optional marketing communications and non-essential cookies, which you may withdraw at any time.
- Explicit consent for special category data — where a Customer chooses to provide the optional service preference and suitability details described in Section 3.2, we and the Merchant rely on the Customer's explicit consent (GDPR / UK GDPR Article 9(2)(a), and the equivalent express or explicit-consent standard under UAE, Saudi, Brazilian, Australian, Canadian and Japanese law). This consent is requested separately from any booking or terms acceptance, is never a condition of making a booking, and can be withdrawn at any time by the same means it was given.
- Legal obligation — compliance with tax, financial services, anti-money-laundering, and know-your-customer requirements.
6. HOW WE SHARE INFORMATION
We share personal data only as necessary to provide the Services, and with the following categories of recipients:
Sub-processors and service providers:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database hosting, storage, and backups | EU region |
| Stripe, Inc. | Payment processing and payouts (Stripe Connect) | Multiple (see Stripe's privacy policy) |
| Meta Platforms, Inc. | WhatsApp Business Platform messaging | Multiple (see Meta's privacy policy) |
| 360dialog GmbH | WhatsApp message transmission (legacy/alternate integration) | EU region (Germany) |
| Twilio Inc. | SMS fallback for time-sensitive notifications | Multiple (see Twilio's privacy policy) |
| Google LLC (Google Cloud / Vertex AI, Google Gemini API) | AI processing for the Terno Receptionist booking assistant; AI-assisted generation of website, service and marketing content; AI-assisted summarisation of the Merchant's own analytics; calendar sync; Maps/Places autocomplete | Multiple (see Google's privacy policy); for the details in Section 3.2, see the AI processing table below |
| Vercel Inc. | Application hosting and content delivery | Multiple (see Vercel's privacy policy) |
| Google Ads (Google LLC) | Optional: Merchant-initiated Customer Match audience uploads for the Merchant's own ad campaigns | Multiple (see Google's privacy policy) |
| Meta Platforms, Inc. (Meta Ads) | Optional: Merchant-initiated Custom Audience uploads, and server-side booking conversion events (Meta Conversions API), for the Merchant's own ad campaigns | Multiple (see Meta's privacy policy) |
Where the Terno Receptionist's AI processing happens. For most Merchants, requests are processed in Google Cloud's data centre for the Merchant's own region (for example, an EU Merchant's requests are processed in the Netherlands). For some EU-region Merchants, this processing may instead take place in the United Kingdom (London), when doing so lets us run an improved version of the underlying AI model that is not yet available in an EU data centre. This transfer is made under the European Commission's adequacy decision for the UK (renewed 19 December 2025, in force until 27 December 2031), which finds that the UK provides a level of data protection equivalent to the EU's — the strongest available basis for this kind of transfer under EU law, and the reason no separate contractual safeguard (such as the Standard Contractual Clauses referenced in Section 7) is needed for it. This does not change where the sensitive service-preference details described in Section 3.2 are processed — those follow the separate table below.
AI providers that may process service preference and suitability details (Section 3.2):
| Sub-processor | Entity and role | Purpose | Where processing happens |
|---|---|---|---|
| Google Cloud Vertex AI (Google LLC / Google Cloud EMEA Ltd.) | Processor, under Google Cloud's Data Processing Addendum | Generating treatment and product suggestions for salon staff from hair and skin details | Routed by the Merchant's data region: Gulf → Netherlands · EU → Netherlands · UK → London · North America → Iowa, USA · Latin America → São Paulo, Brazil · Asia-Pacific → Singapore · Australia/NZ → Sydney · Africa → Belgium |
| Anthropic PBC | Processor, under Anthropic's commercial terms | Same purpose | United States |
| OpenAI, L.L.C. | Processor, under OpenAI's business terms | Same purpose | United States |
What is and is not sent to these providers. Only hair and skin details (hair pattern, porosity, density, scalp condition, Fitzpatrick skin type) are sent. Cultural and accessibility answers are never sent to any AI provider, in any form — this is enforced in our systems, not only by policy. Suggestions are shown to salon staff, who decide; no booking, price, or service is decided automatically on the basis of these details.
This list is exhaustive for this category of data. We do not send service preference or suitability details to any AI provider not named in this table. If we add one, we will update this Policy and notify affected Merchants and Customers before the change takes effect, not after.
No training. These providers process this information solely to return a suggestion to us. They do not use it to train or fine-tune their models.
Other disclosures:
- Between Merchant and Customer — Customer booking and contact information is shared with the Merchant a Customer books with, so the Merchant can fulfill the appointment.
- Merchant advertising tools — audience uploads (optional) — if a Merchant chooses to use Terno's marketing tools to run their own Google or Meta ad campaigns, we upload a cryptographically hashed (SHA-256) version of that Merchant's Customers' phone numbers and email addresses to Google Ads Customer Match and/or Meta Custom Audiences, for retargeting or exclusion in the Merchant's own campaigns. Only Customers who have given marketing consent to that Merchant are included. Terno does not use this data for its own advertising, and a Customer can be excluded from future syncs by withdrawing marketing consent through the Merchant or by contacting us at privacy@terno.io.
- Merchant advertising tools — conversion reporting (optional) — if a Merchant has connected Meta Ads, we send Meta a cryptographically hashed (SHA-256) version of the Customer's phone number each time that Customer completes a booking with that Merchant, via Meta's Conversions API, so the Merchant can measure whether their ad spend led to a booking. This conversion event is sent for every booking made with a Merchant who has connected Meta Ads — unlike the audience uploads above, it is not limited to Customers who have given marketing consent, because it is used only to measure ad performance and is never used to contact the Customer. A Customer can ask us to stop this by contacting privacy@terno.io, or by asking the Merchant to disconnect their Meta Ads integration.
- Affiliates — Terno's regional Affiliates may access data as necessary to operate the Services in their region.
- Professional advisors — our accountants, auditors, and legal counsel, where necessary to obtain advice or manage our business.
- Legal and regulatory disclosures — where required by law, court order, or a valid regulatory or law enforcement request.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to the same protections described in this Policy.
- Aggregated or de-identified data — which cannot reasonably be used to re-identify you, may be shared or published without restriction (e.g., anonymized usage statistics).
We update this Policy when our sub-processors change materially.
7. INTERNATIONAL DATA TRANSFERS
Terno operates globally, and your data may be transferred to and processed in countries other than your own. The specific destinations for each sub-processor are stated in the tables in Section 6.
Where we transfer personal data outside the UK/EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum (as referenced in our Data Processing Agreement). You may request a copy of the safeguards applying to any transfer by emailing privacy@terno.io.
For the EU-to-UK transfer described in Section 6 (Terno Receptionist processing that may take place in London), the applicable safeguard is different: the European Commission's own adequacy decision for the UK, rather than the Standard Contractual Clauses. An adequacy decision is a formal finding, published by the European Commission, that a country's data protection law is equivalent to the EU's — it is a public legal instrument, not a private contract, so there is no separate document to request a copy of; you can read the decision itself at the European Commission's website.
For the service preference and suitability details described in Section 3.2, which we treat as sensitive personal data, the destinations are limited to those in the AI processing table in Section 6 and are, for Google Cloud Vertex AI, routed to the region shown there for the Merchant's data region.
Where you are in a country with additional transfer requirements — including Saudi Arabia, Brazil, Québec (Canada), Japan or Australia — additional safeguards, assessments or consents may apply before we transfer sensitive personal data outside your country, and we will not make such a transfer until they are in place.
8. DATA SECURITY
We implement technical and organizational measures to protect personal data, including:
- Encryption — TLS 1.2+ in transit; AES-256 encryption at rest for sensitive fields; passwords hashed with bcrypt or equivalent.
- Access controls — role-based access control, multi-factor authentication support, and audit logging of access to personal data (logs retained 90 days).
- Redundancy and backups — daily encrypted backups, replicated storage, and quarterly recovery testing.
- Incident response — a documented process for detecting, containing, and notifying affected parties of any data security incident as required by applicable law.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to protect your information using the measures above.
9. DATA RETENTION
We retain personal data for as long as necessary to provide the Services and for the purpose it was collected, and generally:
- Account and Business data — for the duration of a Merchant's Subscription, plus up to 30 days after termination to permit data export, after which it is deleted (per our Data Processing Agreement, Section 3.6).
- Customer booking data — retained on the Merchant's behalf for as long as the Merchant's account remains active, or as instructed by the Merchant.
- WhatsApp and AI conversation transcripts — retained for as long as the related Merchant account is active (so conversation history remains available to the Merchant and the Receptionist), or for up to 6 years after a flagged/escalated conversation for quality, safety, and dispute-resolution purposes, whichever applies.
- Service preference and suitability details (Section 3.2) — a Customer's Fitzpatrick skin type and their cultural and accessibility answers are deleted automatically 3 years after their last completed booking with the Merchant's business group, and immediately if the Customer withdraws consent. Hair pattern, porosity, density and scalp condition are retained as part of the Customer's service record for as long as that record exists, and are deleted on request or when the Customer's record is deleted.
- Backups — deleted within 90 days of the underlying data being deleted.
- Records required by law — such as transaction and tax records, retained for the period required by applicable financial or tax regulations, which may exceed the periods above.
We may retain data longer where necessary to resolve disputes, enforce our agreements, or comply with a legal obligation.
10. YOUR RIGHTS
Depending on your location, you may have the right to:
- Access a copy of the personal data we hold about you;
- Correct inaccurate or incomplete personal data;
- Delete your personal data, subject to legal retention requirements;
- Restrict or object to certain processing, including direct marketing;
- Port your data to another provider in a machine-readable format; and
- Withdraw consent at any time, where processing is based on consent.
To exercise these rights, contact us at privacy@terno.io. If you are a Customer and your request relates to a specific Merchant's records, we may direct you to that Merchant, who is generally the data controller for your booking information.
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (for example, the UAE's Data Office, a EU/EEA supervisory authority, the UK Information Commissioner's Office, or South Africa's Information Regulator, as applicable to your location).
11. ADDITIONAL RIGHTS FOR U.S. RESIDENTS
If you are a resident of a U.S. state with a consumer privacy law (such as California, Colorado, or Virginia), the following additional disclosures apply:
- Categories collected — identifiers (name, email, phone), commercial information (booking and transaction history), internet/network activity (device and usage data described in Section 3.3), geolocation (approximate, as described in Section 3.3), and professional information (for Merchants and Users).
- Sensitive personal information collected — where a Customer chooses to provide the optional details described in Section 3.2, we collect personal information that may reveal racial or ethnic origin and religious or philosophical beliefs. We collect and use this information only to perform the services the Customer has asked for, and disclose it only to the service providers listed in Section 6 for that purpose. We do not use it to infer characteristics about a consumer, and we do not sell or share it. Because our use is limited to these purposes, the right to limit the use of sensitive personal information under Civil Code section 1798.121 does not apply to it; if that ever changes, we will post a "Limit the Use of My Sensitive Personal Information" link and notify you before the change takes effect. We retain it for the periods stated in Section 9.
- No biometric information — we do not collect biometric identifiers or biometric information, and we do not derive any of the details in Section 3.2 from photographs, video, or facial scans.
- We do not sell personal data.
- Limited sharing for targeted advertising — as described in Section 6 ("Merchant advertising tools"), if a Merchant opts in to syncing Customer contact information (hashed, consent-gated) to Google Ads or Meta Ads for that Merchant's own campaigns, this may be considered "sharing" for "cross-context behavioral advertising" under some State Privacy Laws. Outside of this specific, opt-in, Merchant-controlled feature, we do not disclose personal data for targeted advertising.
- Right to opt out of sharing — you can opt out of the sharing described above at any time by withdrawing marketing consent through the relevant Merchant, or by contacting privacy@terno.io.
- Sharing for business purposes — we disclose the categories above to the sub-processors listed in Section 6, for the purposes described in Section 4. Outside of the advertising-sync feature, this is a "disclosure for a business purpose," not a sale or share.
- Your rights — in addition to Section 10 above, you may have the right to know, delete, correct, and limit use of sensitive personal information, and the right to non-discrimination for exercising these rights.
- Exercising your rights — contact privacy@terno.io. You may use an authorized agent to submit a request on your behalf, subject to verification. We will not discriminate against you for exercising any of these rights.
12. CONTROLLER AND PROCESSOR ROLES
Terno acts in different capacities depending on the data involved:
- As a data controller — for Merchant account data, billing information, and our own marketing communications to Merchants, Terno determines the purposes and means of processing and is the controller.
- As a data processor — for Customer data that a Merchant collects and stores through the Platform (bookings, contact details, messages), Terno processes this data only on the Merchant's documented instructions, under the terms of our Data Processing Agreement. The Merchant is the data controller for this information; if you are a Customer with questions about how your data is used, please contact the Merchant you booked with directly.
13. CHILDREN'S PRIVACY
The Services are intended for business use by Merchants and their staff, who must be at least 18 years old. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us at privacy@terno.io and we will take steps to delete it.
14. COOKIES & TRACKING TECHNOLOGIES
We and our service providers use cookies and similar technologies (such as pixels and device identifiers) on our website and Merchant booking pages to:
- Keep you signed in and remember your preferences;
- Understand how our Services are used, so we can improve them; and
- Measure the effectiveness of our own marketing of the Terno platform itself to Merchants.
Separately from cookies, a Merchant may choose to sync their own Customers' contact information to Google Ads or Meta Ads for that Merchant's advertising — see Section 6 ("Merchant advertising tools") for how that works and how to opt out.
You can control cookies through your browser settings. Disabling cookies may affect the functionality of the Services.
15. TERNO 3RD PARTY CALENDAR SYNC BROWSER EXTENSION
Some Merchants who already use a supported booking platform connect that account to Terno so we can synchronise bookings between the two platforms. As of the effective date of this Policy, the only supported platform is Fresha; more may be added over time. Where a Merchant is signed in to a supported platform in their own browser, they may optionally install the Terno 3rd Party Calendar Sync Chrome extension to complete that connection without re-entering their login on Terno's website.
What the extension does. After a Merchant has signed in to Fresha themselves, on Fresha's own login page, the extension reads the session cookies Fresha's website has already set in that browser (using Chrome's cookies permission, scoped only to fresha.com) and sends them once, over HTTPS, to Terno's own servers to complete the connection described above.
What the extension does not do. It never displays, requests, stores, or has access to a Merchant's Fresha password. It does not run on, or request permission for, any website other than fresha.com and Terno's own domain. It does not track browsing activity, and it makes no use of the captured session data beyond the one-time connection handshake.
This feature is optional. A Merchant who prefers not to install the extension can complete the same Fresha connection through Terno's standard, password-based sign-in flow instead.
The extension's full source code, along with a plain-language explanation of exactly what data it reads and where it sends it, is published alongside its listing.
16. THIRD-PARTY LINKS
Our Services may contain links to third-party websites or services (including payment providers and WhatsApp itself). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal data.
17. CHANGES TO THIS POLICY
We may update this Policy from time to time to reflect changes in our practices or legal requirements. We will post the updated Policy on this page and update the "Effective Date" above. If we make a material change, we will notify Merchants by email or through the Platform.
18. CONTACT US
If you have questions about this Privacy Policy or how we handle personal data, contact us at:
Terno (Gulf) FZ-LLC Email: privacy@terno.io Data Protection queries: dpo@terno.io
This Privacy Policy should be read together with our Terms of Service and Data Processing Agreement.