Legal

Privacy policy

How spamanagement.co handles the data of spas, their teams and their clients.

Who we are

spamanagement.co is business software for massage spas in the United Arab Emirates, operated by 1997labs (Dubai, United Arab Emirates). Questions about this policy: ask@spamanagement.co.

Our role

For the data a spa keeps about its own clients (bookings, visit history, notes, sales), the spa is the controller and we act as its processor: we store and process that data only to provide the service to the spa, on its instructions. For the accounts of spa owners and staff, and for visitors to this website, we are the controller.

What data we process

  • Account data: name, email, password (stored hashed), role, two-step verification settings, sign-in times.
  • Spa data: business details, branches, services, prices, staff schedules, inventory, sales and accounting records.
  • Spa clients’ data entered by the spa or by a client booking online: name, phone, email (optional), bookings, preferences and notes, purchases, packages and gift cards.
  • Website visits on spa sites and this site: pages viewed and clicks, counted without cookies (see below).
  • Billing: invoices for the subscription and how they were paid.

Instagram, Facebook (Meta) and Google Business Profile

A spa can connect its own Instagram professional account or Google Business Profile. When it does, we use the access it grants only to:

  • read messages, comments and reviews so the spa can see them and reply;
  • draft replies and posts (with AI) for the spa to review;
  • publish replies and posts that the spa has approved;
  • show basic insights about the spa’s own account.

We do not sell this data, use it for advertising, or share it with anyone other than the service providers listed below. Access tokens are stored encrypted. A spa can disconnect at any time in its settings, or revoke access directly in Instagram/Facebook settings or its Google account; we then stop using the token and delete it. Our use of data received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.

AI processing

AI features (drafting replies, posts, website copy and suggestions) send the text needed for that task to BytePlus ModelArk, our AI provider. We send only what the task needs, and we do not allow the data to be used to train models where the provider offers that choice. AI output is a draft: the spa decides what is sent or published.

WhatsApp

We never send WhatsApp messages automatically. Message buttons open WhatsApp with a pre-filled text on the spa’s own phone or computer; a person at the spa chooses to send it. We do not connect to WhatsApp accounts.

Where data is stored and for how long

  • Data is stored on servers at DigitalOcean (currently in their Bangalore, India data centre) and delivered through Cloudflare. Data may therefore be transferred outside the UAE, with safeguards as required by law.
  • We keep spa data while the subscription is active. After it ends, the spa can export its data for 30 days; we then delete it. Encrypted backups roll off within a further 30 days.
  • Website visit statistics are kept for 90 days in detail and then only as totals.
  • Billing records are kept as long as UAE tax law requires.

Backups and security

Data is encrypted in transit (HTTPS). Each spa’s data is separated in the database so one spa can never see another’s. We take regular encrypted backups kept off the main server. Access is limited to people who need it to run the service; staff accounts support two-step verification, and sign-ins and sensitive actions are logged.

Service providers

DigitalOcean (hosting), Cloudflare (network and security), BytePlus ModelArk (AI), an email provider for account emails (such as sign-in and password reset), and Stripe if a spa chooses to pay a platform invoice by card. Meta and Google receive only what a spa chooses to publish or reply through them.

Cookies and analytics

We use only first-party cookies needed to keep you signed in and secure. Visit statistics are counted without cookies and without third-party trackers.

Your rights

Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and other laws that apply, you can ask to access, correct or delete your personal data, to restrict or object to processing, and to receive a copy. If you are a client of a spa, please contact the spa first — it controls your data — or write to us and we will pass your request on. See how to request deletion.

Changes

We may update this policy. We will post the new version here and tell spas by email or in the dashboard before an important change takes effect.

Contact

1997labs, Dubai, United Arab Emirates — ask@spamanagement.co.

Last updated 9 October 2026. 1997labs, Dubai, United Arab Emirates. See also Terms · Data deletion.