Trust & Security Center

Your data is yours. Nobody else can reach it.

Grumming holds real personal information — home addresses, phone numbers and appointment history. This page explains, in plain language, exactly how that information is protected, and how you can verify it.

TLS 1.3 encryption

Every page and request

Row-level data isolation

Enforced in the database

No plain-text secrets

Keys held in a vault

Azure cloud, India region

Data stays in-country

Four layers of protection

Each person sees only their own data

A customer can open, change or cancel only their own appointments. Another customer's bookings, address, phone number and notes are not reachable from any account, page or link.

  • Booking records are locked to the account that created them
  • Salon owners see only their own salon's bookings and client list
  • Stylists see only the appointments assigned to them
  • Rules live in the database itself, not just in the website code

Keys and passwords stay hidden

Passwords are never stored as readable text — they are converted into an irreversible cryptographic fingerprint. Service keys and database credentials live in an encrypted vault and are never sent to the browser.

  • Passwords hashed with industry-standard algorithms
  • Sign-up codes delivered through a verified email sender
  • Credentials write-only: they can be replaced, never read back
  • No secret ever ships inside the public website files

Enterprise cloud infrastructure

Grumming runs on Microsoft Azure with a managed PostgreSQL database hosted in the Central India region, with automated backups and platform-level protection against traffic attacks.

  • Managed Azure PostgreSQL with automated daily backups
  • Encrypted connections required for every database session
  • Separate roles for customers, stylists, salons and administrators
  • Continuous automated scanning of code and dependencies

Safety during the actual appointment

Digital security is only half the promise. Every stylist is checked before they can accept a booking, and customers have a direct safety channel during a visit.

  • Background and identity checks before a stylist goes live
  • Hygiene standards and in-person skill assessment
  • Emergency alert channel during an in-progress visit
  • Reviews tied to real completed bookings only

How this is checked, continuously

Security is not a one-time claim. Automated checks run against the platform on an ongoing basis, covering three areas: the database access rules that keep accounts separated, the application interfaces that handle bookings and profiles, and the third-party software libraries the platform is built on. Findings are triaged and resolved, and results are available to partners on request.

Database access rules

Every table storing personal data is checked for correct per-account restrictions.

Application interfaces

Booking, profile and admin endpoints are scanned for exposure and missing checks.

Software supply chain

Dependencies are monitored against public vulnerability advisories and patched.

Questions people ask us

Responsible disclosure

Found something? Tell us and we will fix it.

We welcome reports from customers, salon partners and independent researchers. Send the details to our security inbox — we acknowledge every genuine report and will never take action against someone who discloses responsibly.