Smidi
Privacy Policy
Last updated: August 2026 · Nidaros Koding
Smidi is operated by Nidaros Koding. This Privacy Policy describes how we process personal data when you use the Smidi platform website at getsmidi.com and related platform services. It does not replace the privacy practices of individual salons that use Smidi to run their own websites and booking flows.
Who is responsible for your data
Nidaros Koding operates the Smidi software platform and processes data needed to provide platform services, operate accounts, and maintain security.
Salons and other businesses that use Smidi are separate controllers for the customer and booking data they collect through their own public sites, admin tools, and communications. When you book with a salon, contact that salon directly for questions about how they use your information.
Data we process on the platform
Depending on how you interact with Smidi, we may process:
Account and profile information such as name, email address, phone number, and authentication credentials for platform users (salon owners, staff, and client accounts where applicable).
Business and operational data entered by salon operators, including services, availability, appointments, client records, and website content.
Technical and usage data such as IP address, browser type, device information, and log data needed to operate, secure, and improve the service.
Communications you send to us, including messages submitted through the platform contact form on getsmidi.com.
Why we process data
We process personal data to provide and operate the Smidi platform, authenticate users, deliver transactional notifications, maintain security and tenant isolation, respond to support and sales enquiries, and improve reliability and performance.
We do not sell personal data.
Legal bases (EEA/UK)
Where GDPR applies, we rely on appropriate legal bases including contract (providing the service you or your salon signed up for), legitimate interests (operating, securing, and improving the platform, and responding to enquiries), and consent where required (for example, where a salon configures optional marketing communications to its own customers).
Service providers
We use trusted infrastructure and service providers to operate Smidi. Depending on configuration and feature use, these may include:
Supabase — database, authentication, and backend infrastructure.
Resend — transactional email delivery for platform and salon notifications.
Twilio — SMS delivery when SMS notifications are enabled and configured.
Vercel — application hosting, deployment, and platform performance/analytics tooling.
Google — Google Places API for optional live review cards on salon websites (server-side requests when configured by a salon); Google Fonts may be loaded on salon public websites when selected in salon branding.
Kartverket / Geonorge — Norwegian address search for salon address autocomplete (server-side).
Providers process data on our instructions and under appropriate agreements. This list reflects current implementation and may evolve as the product develops.
Cookies and similar technologies
Smidi uses cookies and similar storage primarily to keep you signed in. Supabase authentication session cookies are host-scoped and are not shared across unrelated domains.
On platform and tenant sites, Vercel Analytics and Vercel Speed Insights may collect aggregated page-view and performance data to help us understand usage and improve the service. We do not operate a marketing cookie consent platform in v0.19.2; this disclosure describes actual behaviour at a baseline level.
Internal platform preview tooling may set short-lived HttpOnly cookies on approved staging/preview environments for operator QA. These cookies are not used on public production marketing pages for end customers.
Some admin interfaces may use browser local storage for non-sensitive UI preferences.
Retention
We retain personal data for as long as needed to provide the service, meet legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type and salon configuration.
Detailed data-export and self-service deletion product flows are not part of this release; contact us if you have a privacy request related to platform operations.
Security and tenant isolation
Smidi is designed as a multi-tenant platform. Salon data is isolated at the application and database access layers using tenant-scoped authorization (including row-level security). We apply technical and organizational measures appropriate to the nature of the service.
International transfers
Our service providers may process data in the European Economic Area and in other countries. Where required, we use appropriate safeguards for international transfers.
Your rights
Depending on applicable law, you may have rights to access, rectify, erase, restrict, or object to processing of your personal data, and to data portability where applicable. You may also lodge a complaint with a supervisory authority.
For platform-related privacy requests, use the contact form at getsmidi.com/contact and select Privacy as the topic.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected on this page with an updated date. Continued use of the platform after changes constitutes acceptance where permitted by law.
Contact
For privacy questions about Smidi platform operations, contact Nidaros Koding via getsmidi.com/contact.