Your data is yours. Nobody else can reach it.
Grumming holds real personal information — home addresses, phone numbers and appointment history. This page explains, in plain language, exactly how that information is protected, and how you can verify it.
TLS 1.3 encryption
Every page and request
Row-level data isolation
Enforced in the database
No plain-text secrets
Keys held in a vault
Azure cloud, India region
Data stays in-country
Four layers of protection
Each person sees only their own data
A customer can open, change or cancel only their own appointments. Another customer's bookings, address, phone number and notes are not reachable from any account, page or link.
- Booking records are locked to the account that created them
- Salon owners see only their own salon's bookings and client list
- Stylists see only the appointments assigned to them
- Rules live in the database itself, not just in the website code
Keys and passwords stay hidden
Passwords are never stored as readable text — they are converted into an irreversible cryptographic fingerprint. Service keys and database credentials live in an encrypted vault and are never sent to the browser.
- Passwords hashed with industry-standard algorithms
- Sign-up codes delivered through a verified email sender
- Credentials write-only: they can be replaced, never read back
- No secret ever ships inside the public website files
Enterprise cloud infrastructure
Grumming runs on Microsoft Azure with a managed PostgreSQL database hosted in the Central India region, with automated backups and platform-level protection against traffic attacks.
- Managed Azure PostgreSQL with automated daily backups
- Encrypted connections required for every database session
- Separate roles for customers, stylists, salons and administrators
- Continuous automated scanning of code and dependencies
Safety during the actual appointment
Digital security is only half the promise. Every stylist is checked before they can accept a booking, and customers have a direct safety channel during a visit.
- Background and identity checks before a stylist goes live
- Hygiene standards and in-person skill assessment
- Emergency alert channel during an in-progress visit
- Reviews tied to real completed bookings only
How this is checked, continuously
Security is not a one-time claim. Automated checks run against the platform on an ongoing basis, covering three areas: the database access rules that keep accounts separated, the application interfaces that handle bookings and profiles, and the third-party software libraries the platform is built on. Findings are triaged and resolved, and results are available to partners on request.
Database access rules
Every table storing personal data is checked for correct per-account restrictions.
Application interfaces
Booking, profile and admin endpoints are scanned for exposure and missing checks.
Software supply chain
Dependencies are monitored against public vulnerability advisories and patched.
Questions people ask us
Responsible disclosure
Found something? Tell us and we will fix it.
We welcome reports from customers, salon partners and independent researchers. Send the details to our security inbox — we acknowledge every genuine report and will never take action against someone who discloses responsibly.