Privacy Policy
Jai Austin Barfoot, sole trader, ABN 87 274 343 489, trading as Taper by Aiandi ("we", "us", "Taper") provides software that helps barbershops manage their walk-in queue, client cards, and AI haircut previews. This policy explains how we collect, use, and protect personal information when you use the Taper website (taper.style), the Taper application (app.taper.style), and any other service we provide (together, the "Service").
We operate the Service with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth), the Spam Act 2003 (Cth), and applicable Australian Consumer Law requirements in mind. Customers operating outside Australia must tell us before onboarding so any additional local requirements, including the GDPR or UK GDPR where applicable, can be assessed and documented. By using the Service you acknowledge this Policy and our Terms of Service.
1. Who controls your data
If you are a barbershop owner or staff member using Taper to run your shop, Taper is the controller of your account information (email, login, billing).
If you are a customer of a barbershop using a Taper iPad or queue link, the barbershop normally determines the immediate purpose of collecting your client details and is responsible for giving you an appropriate collection notice and using the information lawfully. Taper processes the information to deliver the requested Service and also makes limited decisions needed to secure, maintain, support, bill, prevent abuse, and comply with law. The exact legal role of each party can depend on the activity and applicable law; calling Taper a processor does not remove duties that the law places directly on us. Requests to see, correct, or delete shop client data should first be directed to the barbershop. If the shop does not respond, email privacy@taper.style and we will assist where legally and technically able.
2. What we collect
From shop owners and staff
- Name, email, phone, business name, ABN if you provide one
- Hashed password (we never store the plain text)
- Subscription and billing metadata from Stripe (we never see your card number)
- Server logs: IP address, browser type, pages visited, basic activity timestamps
From customers using a barbershop's Taper iPad or queue link
- Name, mobile, email (only if you provide them)
- Selected haircut
- Front-facing photo (if you choose to use the AI preview)
- The AI preview image generated from that photo
- Marketing/contact consent flags
- Time you joined the queue, IP address (for abuse prevention only)
Photos of faces are personal information and may reveal sensitive information such as appearance, ethnicity, health, or religious dress. Taper does not use facial recognition, biometric verification, biometric identification, face matching, or biometric templates. We still handle face photos with a higher level of care because misuse could be harmful.
3. How we use it
- To run the service: show you the queue, save cut cards, generate AI previews, send the shop your selected style.
- To improve the product: aggregate, de-identified usage analytics. We do not train AI models on customer photos.
- To bill and support: manage subscriptions, respond to support requests.
- To comply with the law: respond to legal process, enforce our Terms.
We do not sell or rent personal information. We do not use your photo or any information you give a barbershop to advertise other products to you.
4. AI haircut previews
If you (or the shop on your behalf) request an AI preview, your front photo and the chosen haircut style are sent to OpenAI via OpenAI's API to generate a preview image. OpenAI processes the image under its API and business data terms and returns the generated image to Taper. OpenAI says API data is not used to train or improve models by default unless the API customer explicitly opts in. OpenAI may still process inputs for safety, abuse monitoring, legal compliance, and service operation. Taper does not opt in to OpenAI model training with customer photos.
Taper does not use the AI preview to make legal, financial, employment, credit, insurance, access, or other decisions that significantly affect a person's rights or interests. It is a visual aid for a haircut conversation only.
AI previews are illustrative only. They are not a guarantee of how a haircut will actually look on you. Variations in lighting, hair growth pattern, scalp visibility, and barber technique mean the real-world result will differ. The preview is a visualisation aid, not a contractual outcome.
The shop owner can delete a saved preview from their dashboard at any time. If you want yours deleted immediately, ask the shop, or email us at privacy@taper.style.
5. Marketing & SMS / email contact
Taper's customer-marketing and follow-up tools are currently disabled while central unsubscribe and suppression controls are completed. A shop must not use Taper client details for SMS or email marketing unless it has separately obtained valid consent and uses a compliant external provider. Any marketing message must accurately identify the sender, include a functional unsubscribe method, and honour unsubscribe requests within 5 business days. Taper itself only emails account holders about their Taper account, security alerts, support, billing, and changes to this Policy or our Terms.
6. How long we keep things
- Unsaved customer photos and AI previews: temporary queue, upload, and preview copies are automatically purged within 24 hours.
- Saved cut-card photos and previews: retained only where separate storage consent was recorded. They remain available while the shop account is active unless the shop or customer deletes them sooner.
- Cut cards and client records: retained while the shop account is active. After an owner schedules closure, Taper provides a 30-day export and cancellation window and then deletes active account data, subject to legally required records and restricted backup ageing.
- Account & billing records: generally kept for at least 5 years after the relevant record or transaction, or longer where a specific law, dispute, fraud-prevention need, or extended assessment period requires it.
- Server logs: 90 days.
- Restricted backups: deleted production data may remain in access-restricted disaster-recovery backups for up to 30 days, after which those snapshots age out. Backups are not used for ordinary processing. If a backup is restored after an incident, valid deletion requests are reapplied.
Shop owners can export their data, delete individual client photos or records, and schedule account closure from the app. Account closure has a 30-day cancellation window; active subscriptions must be cancelled first. Some billing, tax, fraud-prevention, and security records may be retained where the law requires it.
7. Where it's stored
Taper hosts the application on DigitalOcean infrastructure in Sydney, Australia. We use subprocessors only where needed to provide the Service, currently including DigitalOcean for hosting, Stripe for payments, Resend/SMTP providers for transactional email, and OpenAI for AI previews. Stripe, Resend, and OpenAI may process data outside Australia, including in the United States. Where data is sent overseas, we take reasonable steps to ensure it is handled consistently with the APPs, including contractual controls, provider security reviews, minimising the data sent, and using providers' business/API data protection settings where available.
8. Security
We use HTTPS for all connections, hash passwords with bcrypt, apply role-based access controls, keep API keys server-side only, run service monitoring and access-restricted backups, and require authenticated plan entitlements plus server-side quotas for every live AI preview. No system is perfectly secure. We maintain an incident response process, assess a suspected eligible breach expeditiously and within the period required by law, and notify affected individuals and the OAIC where the Notifiable Data Breaches scheme requires it.
9. Your rights
You can ask us to:
- See the personal information we hold about you
- Correct anything that's wrong
- Delete data where deletion is legally and technically available
- Export a copy of your data
- Stop marketing contact
Email privacy@taper.style from the address linked to your account, or contact your barbershop. If that address does not respond, email jai@aiandi.com.au. We aim to respond within 30 days. If you're not satisfied, you can complain to the Office of the Australian Information Commissioner.
10. Cookies
Taper uses only the minimum cookies needed to keep you logged in and to remember your shop. We don't run third-party advertising trackers. The marketing site at taper.style does not set tracking cookies for visitors who don't sign in.
11. Children
Taper isn't designed for independent use by children under 16. Before a photo can be processed, the flow requires an age assurance that the person is 16+ or that a parent or guardian is present and consents. For the guardian path, the guardian's name must be recorded; staff-assisted flows also record the acting staff account. Shops must not collect or process a minor's photo where that assurance cannot truthfully be given.
12. Changes
We'll post material changes here, notify shop owners by email and in the app at least 14 days before they take effect where practicable, and record account-owner acceptance of the current legal version. Urgent security or legal updates may take effect sooner with as much notice as reasonably practicable.
13. Contact
Privacy questions: privacy@taper.style or jai@aiandi.com.au
General contact: hello@taper.style or jai@aiandi.com.au
Operator: Jai Austin Barfoot, sole trader, ABN 87 274 343 489, trading as Taper by Aiandi, Melbourne, Australia.