Cuts by Amber Data Policy
This Data Policy explains how Cuts by Amber, a DBA of Red River Prairie Group LLC, uses, processes, stores, and protects data when using Square APIs, Apple platform tools, and related internal systems.
Quick Data Security Summary
Here is the short version of how data is protected for booking and website operations:
- We only process data needed for booking, communication, and support.
- Website and API traffic uses encrypted transport where supported (HTTPS/TLS).
- Access to customer data is limited and monitored for misuse or unauthorized access.
- If a security incident affects customer information, we investigate and notify as required by law.
1. Scope
This policy applies to data processed through:
- Cuts by Amber application and backend services.
- Cuts by Amber website pages and booking forms at cutsbyamber.com.
- Square APIs (booking, availability, customer records, and related transaction workflows).
- Google Places API, used to display a limited selection of publicly available Google Reviews on our website.
- Meta Graph API, used to retrieve a limited selection of publicly available Facebook Page reviews or recommendations for display on our website, when configured.
- Google Analytics 4, if enabled for website usage and reliability measurement.
- Apple platform tools and services used by the app.
- Internal business tools used for operations and customer support.
2. Data Categories Processed
Data categories may include:
- Customer identifiers: name, phone number, email address, birthdate (if provided).
- Appointment data: selected services, schedule, booking notes, history.
- Profile verification data: lookup contact details, one-time verification codes/challenges, failed-attempt counters, short-lived verification sessions, and necessary session cookies or opaque browser-session tokens.
- Operational metadata: request timestamps, service IDs, location IDs, and basic diagnostics.
- Website request metadata: page requests, browser/device context, and referral context where available.
- Analytics event and device/browser data, if Google Analytics 4 is enabled.
- Consent and communication preferences selected during booking flows.
- Marketing/communication preferences where provided.
- Push-notification data, when enabled: an APNs device token, associated Square customer record identifier, token-registration status, and registration timestamp.
We do not intentionally store full payment card numbers in app-managed storage.
3. Square API Data Use
Square API usage is limited to legitimate business operations, including:
- Availability lookups.
- Booking creation and management.
- Customer profile creation/association for bookings.
- Operational reconciliation and support.
Booking and customer personal data used by the scheduling workflow is stored and managed in Square systems. Our PHP API endpoints act as an integration layer to push and pull required booking and customer data to and from Square.
Depending on the workflow, Square API requests may include selected service IDs, location IDs, appointment dates and times, customer name, email address, phone number, booking notes, and communication or marketing preferences. Availability searches use service and scheduling data; booking and customer endpoints use the contact and appointment information needed to create, associate, confirm, and manage appointments.
Data sent to Square is limited to the minimum required fields for those functions.
3B. Profile Verification and Appointment Access
The website can look up an existing Square customer profile using an email address or phone number supplied by the customer. Before showing profile details or appointment history, the website sends a one-time verification code through the selected SMS or email delivery provider. Verification challenges expire after a short period, are limited to a small number of attempts, and short-lived verified sessions are used only to authorize profile viewing, preference updates, and eligible appointment viewing, cancellation, or changes. Necessary secure session controls may operate across Cuts by Amber subdomains solely to maintain this verified account access.
The website does not create a separate username-and-password account through this profile feature. Contact information and appointment data remain subject to Square’s systems and retention practices as described in this policy.
3A. Meta Graph API and Facebook Reviews
When Facebook review integration is enabled, our server uses the Meta Graph API to request selected publicly available reviews or recommendations from the configured Cuts by Amber Facebook Page. The website may display a limited number of eligible review excerpts, source labels, ratings, dates, and links back to Facebook.
We do not send booking information or customer contact information to Meta for this review display. Meta credentials, including any Page access token, are kept server-side and are not exposed in the website page. Review requests are made when the review panel loads; the site displays a limited selection and does not intentionally retain a separate long-term review archive. Review content remains subject to Facebook and Meta policies, and users should manage changes or deletions through Facebook. You may also contact Cuts by Amber to request that copied review content be removed from this website. See the Meta Privacy Policy and Meta Platform Terms.
4. Apple Tools and Platform Data
Apple tools and services may process limited diagnostics, platform telemetry, and app operation data according to Apple policies and user device settings.
Cuts by Amber uses Apple platform features to support:
- App functionality and reliability.
- User experience and accessibility.
- Security and fraud-prevention controls.
- Optional delivery of transactional appointment confirmations, cancellations, rescheduling updates, and reminders through Apple Push Notification service (APNs).
When a verified app user enables appointment notifications, the app obtains an APNs device token from Apple and sends it over encrypted transport to our API. The API associates the token with the verified customer record, stores it in a protected server-side registry, and uses it only to address transactional appointment notifications. Notification contents are limited to the appointment update and do not include payment-card information.
APNs tokens are retained for up to one year after the latest registration. The app requests removal when the user disables appointment notifications, and invalid tokens are removed when identified. APNs credentials are stored outside public web directories and are not delivered to the app.
5. Purpose Limitation
Collected and processed data is used only for:
- Service delivery and booking operations.
- Customer communications and support.
- Promotions/marketing where allowed by law and user choices.
- Internal operations and app administration.
- Legal and compliance obligations.
6. Data Minimization and Retention
We limit data collection and API payloads to what is reasonably necessary. Retention follows business and legal requirements and may vary by record type.
- Only fields needed for booking, communication, and support are collected in normal workflows.
- Security and operational logs are retained for a limited period for diagnostics and threat monitoring.
- Records are deleted or de-identified when no longer required, where reasonably feasible.
7. Security Controls
Reasonable safeguards are applied, including:
- Controlled access to systems and records.
- Network and infrastructure protections where available.
- Separation of payment credential handling via Square.
- Administrative controls for staff access and workflow boundaries.
- Encryption in transit where supported (for example, HTTPS/TLS for website and API communication).
- Monitoring and review processes to identify misuse, abnormal traffic, and unauthorized access attempts.
8. Sharing and Disclosure
We do not sell personal information.
Where digital advertising or analytics tools are used, data sharing is limited to lawful business purposes and user choice controls where applicable.
Google Places API is used to display a limited selection of publicly available Google Reviews ratings and reviews on our website. Our server requests review data when the review panel loads and does not intentionally retain a separate long-term review archive. Our server sends Google the configured place ID and requested review fields; no personal customer data is sent to Google for this purpose. See the Google Privacy Policy and Google Maps Platform Terms.
When enabled, the Meta Graph API is used to retrieve selected publicly available Facebook Page reviews or recommendations for display on this website. Our server sends Meta the configured Page identifier and authorized review request parameters; booking information and customer contact information are not sent to Meta for this purpose.
If Google Analytics 4 is enabled, Google may process website usage and device/browser data for analytics and reliability measurement. The current server configuration sends the anonymize_ip setting when GA4 is initialized. GA4 data retention and any consent controls are managed in the applicable Google Analytics property settings. Cuts by Amber does not use it for cross-app or cross-website advertising tracking.
Data may be shared with:
- Square and required service providers.
- Google, where Google Places API or optional Google Analytics 4 processing is enabled for the purposes described above.
- Meta, where the Meta Graph API integration is enabled for the limited Facebook review display described above.
- Apple platform services where relevant to app operation.
- Apple Push Notification service, when an app user enables appointment notifications, for device-token processing and notification delivery.
- Business marketing channels, including website placements, social media, other online media, and print media, for pictures, videos, testimonials, comments, reviews, and similar content where permitted by law.
- Authorities where legally required.
9. User Rights and Requests
Users may request access, correction, or applicable opt-out choices by contacting Cuts by Amber. In the iOS app, a verified customer can delete the customer profile through Account > Account deletion. This removes the active customer profile and registered appointment-notification devices. Appointment, transaction, and other records may be retained where required for legal, tax, fraud-prevention, or transaction recordkeeping purposes. The website profile feature does not create a separate username-and-password account.
When a user books an appointment and provides a phone number, appointment-related communications, including confirmations, scheduling updates, and reminders, may be sent by email and/or SMS from Cuts by Amber and/or Square, our booking platform, to the provided contact details. We may also send one-time non-promotional operational notices, such as a location or closure update, when reasonably needed to support existing customers.
Cuts by Amber may also place service-related calls to confirm, update, or discuss appointments using the provided phone number. Cuts by Amber does not place marketing or telemarketing phone calls.
Marketing emails are managed separately from transactional service notices and include unsubscribe instructions. Opt-out requests are processed according to applicable law and platform requirements.
Appointment push notifications are optional and separate from SMS and marketing consent. Enabling them authorizes transactional appointment notifications to the registered device only; it does not enroll a user in marketing messages.
Marketing messages are processed separately and are sent only when a user affirmatively opts in. Marketing texts may include loyalty messages, coupons, discounts, promotions, and service announcements. This opt-in also triggers enrollment or phone-number mapping in our Square Loyalty program. Loyalty enrollment is separate from appointment booking and is subject to Square’s terms and privacy policy.
Users can opt out of SMS messages by replying STOP (or HELP for help) and can opt out of marketing emails through unsubscribe instructions or by contacting Cuts by Amber. Message and data rates may apply. Joining a marketing text program is not a condition of purchase.
For review content sourced from third-party platforms such as Google and Facebook, users should manage edits or deletions through the originating platform account. Upon request, Cuts by Amber can remove or stop displaying copied/highlighted review content on this website, but cannot directly remove content from third-party platforms unless platform tools permit it.
10. Minors
We offer a Kids Cut for children 12 and under. A parent or legal guardian must make and manage any Kids Cut booking. The booking name, contact details, and consent choices must belong to the parent or legal guardian; the child name is collected only when needed to identify the appointment. We do not knowingly create online accounts for children or send marketing messages directly to children, and we do not knowingly collect personal information from minors in violation of applicable law. If discovered, appropriate deletion or remediation steps are taken.
11. Compliance Alignment
This Data Policy is intended to align with:
- Square developer and platform data handling expectations.
- Apple App Store and Apple platform privacy expectations.
- Applicable Texas and U.S. legal requirements.
12. Security Incident Response
If a security event affects customer information, we will investigate, contain, and remediate the issue according to applicable requirements.
- We coordinate incident response with relevant providers when third-party systems are involved.
- Where required by law, notifications are provided to affected users and authorities.
13. Contact
Cuts by Amber
DBA of Red River Prairie Group LLC
Email: amberlirette@cutsbyamber.com
Phone: (806) 640-7702
Address: 350 NW Parkway St. Suite 500, Azle, TX 76020