Skip to content
Solmé

Solmé · policies

Privacy policy

Effective August 23, 2026

This explains what [YOUR LEGAL BUSINESS NAME] ("Solmé", "we") collects when you use solmehair.com, why, and what you can make us do about it. It is written to be read, not to be survived.

Two things worth knowing up front, because they are unusual enough to matter:


What we collect

When you buy something Your name, email address, shipping address, what you ordered, and what you paid. If you called or wrote to us about the order, the correspondence.

When you create an account Your email and a password. The password is stored only as a cryptographic hash by our authentication provider — we cannot read it, and neither can anyone who steals the database.

When you apply for a wholesale account Your business name, contact details, cosmetology licence and resale certificate, and the state and expiry of that certificate. Licence and certificate documents are held in private storage, readable only by authorised staff, and never public.

When you work here Staff and sales representatives generate an activity record: who shipped what, who counted what, who approved what, and when. This is an audit trail, it is deliberate, and it cannot be edited or deleted by anyone — including us.

Automatically, from being on the internet Our hosting and network providers log IP addresses, browser type, and request times for security and reliability. We do not build profiles from these logs.

What we deliberately do not collect Card numbers, bank details, government ID, race, health information, precise location, or biometric data. We do not buy data about you from anyone else.


Cookies

Only the ones that make the site function:

Cookie What it does
Basket Remembers what is in your basket between pages
Discount code Holds a code you entered until checkout
Order confirmation Shows you your order once, after you pay
Sign-in session Keeps you signed in to your account

All four are strictly necessary. None of them track you across other websites, and we do not sell or share what they contain.


Why we use it

We do not send marketing email. If that ever changes, it will be something you opt into, and every message will carry an unsubscribe link.


Who else touches your data

Five companies, each doing one job, none of them permitted to use your data for their own purposes:

Who What they do
Stripe Takes the payment. Holds the card details we never see.
Supabase Runs the database where orders and accounts live.
Vercel Hosts and serves the website.
Resend Delivers our email — order confirmations, invoices, reminders.
Cloudflare Runs the domain's DNS and protects the site from attack.

We may also share information with an accountant, a lawyer, or a shipping carrier where the work requires it, and with authorities where the law compels it and we have satisfied ourselves that it does.

We do not sell your personal information, and we never have. We do not share it for cross-context behavioural advertising. Under California law those phrases have specific meanings, and our answer to both is no.


How long we keep it


Your rights

Wherever you live, you can ask us to:

You will never be charged, refused service, or given a worse price for asking.

How to ask: email privacy@solmehair.com from the address on your account, or write to us at the address below. We will verify it is really you — usually by matching details of a recent order — and answer within 45 days. If a request is genuinely complex we may take another 45 days, and we will tell you before we do. You may use an authorised agent; we will ask for proof of that authority.

California residents: the rights above are your CCPA/CPRA rights to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of, and we do not offer financial incentives in exchange for data.

Where we ship: we currently sell and ship within the United States only, and your data is processed in the United States.


Keeping it safe

Every table in our database enforces row-level security, so an account can only ever reach its own records — the rule is applied by the database itself, not by a screen that could be bypassed. Traffic is encrypted in transit. Payment card data never reaches us. Staff access is limited by role, and privileged actions are written to an audit trail nobody can quietly rewrite.

No system is perfect. If personal data is ever exposed, we will notify affected people and the relevant authorities as the law requires, and we will say plainly what happened.


Children

Solmé is for adults. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, write to privacy@solmehair.com and we will delete it.


Changes

If we change this policy we will update the date at the top and, for anything that materially affects you, say so on the site. Continuing to use Solmé after a change means you accept it.


Contact

privacy@solmehair.com

[YOUR LEGAL BUSINESS NAME] [YOUR MAILING ADDRESS]