Security & Trust

Your salon's data, protected.

We handle real bookings, payments and client details every day - so security isn't an afterthought. Here's how we keep your salon and your clients safe.

Your data stays in the UK/EU

Salon and client data is stored on secure servers in the UK/EU, with strict tenant isolation so one salon can never see another's data.

Encrypted in transit and at rest

All connections use TLS, and sensitive credentials (mailbox passwords, API keys) are encrypted with AES-256 at rest.

PCI-compliant payments

Card payments run through a PCI Level 1 provider. Card numbers are never seen or stored by Rivo - they go straight to the provider's secure vault.

GDPR by design

You're the data controller; we're your processor. We offer a Data Processing Agreement, data export, and deletion on request.

Your own email & website

Your salon email runs on infrastructure we manage for you with modern anti-spam (SPF, DKIM, DMARC) - no third-party mailbox required.

Access control

Staff permissions and PIN re-authentication protect sensitive actions and client contact details inside the app.

Backups & resilience

Regular encrypted backups mean your data is recoverable. Payments and payouts are handled by our regulated payment provider.

Your data is yours

No lock-in. Export your clients, appointments and sales whenever you like, and we'll delete your data on request when you leave.

The detail

Read our Privacy Policy, Data Processing Agreement and Terms of Service. Reporting a vulnerability? Email security@rivosalon.com - we take it seriously and will respond quickly.