Legal

Privacy Policy

Version 2.0 · Last updated: 17 August 2026 · Effective: 17 August 2026

This Privacy Policy sets out how RCS (FZE) collects, uses, discloses and protects personal data in connection with the Flit application, the flitapp.ai website and the public booking pages the Service generates. It addresses in particular two categories requiring heightened protection: the client records held by a subscribing lash professional, which may include health-related information, and the facial measurement performed by the virtual try-on. In summary: application data is hosted in the European Union; personal data is neither sold nor shared for advertising; no personal data is used to train artificial-intelligence models; and no facial measurement is retained.

Contents

  1. Who we are
  2. Who this policy is for, and the two roles
  3. What we collect
  4. What your device is asked for
  5. Why we use it, and our legal bases
  6. Client health information
  7. Biometric information and the try-on
  8. Google Calendar
  9. Who we work with
  10. Where your data is, and transfers
  11. How long we keep it
  12. How we protect it
  13. Your rights, and how to use them
  14. If you are in California
  15. Consumer health data (Washington and Nevada)
  16. Other United States privacy laws
  17. If you are in Canada
  18. Cookies and storage on your device
  19. Children
  20. No automated decisions about you
  21. Changes to this policy
  22. Contact, and how to complain

1. Who we are

Flit is a product of RCS (FZE), a free zone establishment registered in Sharjah under licence No. 9943 ("RCS", "we", "us"), and is the controller of the data described in clause 2.2. Its registered address and contact details are set out in clause 22. Requests concerning personal data are handled by RCS directly, at support@flitapp.ai.

2. Who this policy is for, and the two roles

2.1 It covers our website (flitapp.ai), the Flit application in every form, the public booking pages Flit generates, and the emails the Service sends.

2.2 Two distinct relationships arise within Flit, and they determine to whom a request should be addressed:

Whose dataWho decides what happens to itOur role
The lash artist's own data: name, email, business details, subscription, support messages, usage We do Controller. This policy governs it
Their clients' data: contact details, intake and health answers, photographs, lash maps, notes, appointments, payments The lash artist does Processor. We act on their instructions, under our Data Processing Terms

2.3 Clients of a lash professional. A request to access, correct or delete a client record must be addressed to the lash professional who holds it, who can act on it within the app. Where they are unable to do so, we will assist them on request. RCS does not amend or delete such a record on its own initiative, as it is not ours to determine.

3. What we collect

CategoryExamplesWhere it comes from
AccountFirst and last name, email, password (stored only as a hash), country, currency, business name, studio addresses, working hoursYou, at sign-up and in Settings
SubscriptionPlan, status, renewal and trial datesOur payment provider tells us whether your subscription is active. No card number, and no part of one, ever reaches Flit: the payment happens entirely on their side
Your business contentClients, appointments, treatment records, prices, expenses, photographs, lash maps, notes, booking page text and imagesYou, and the clients who book with you
Client contact and intakeName, phone, email, date of birth, emergency contact, intake answersYou, or your client through your booking page or an intake form
Client health answersAllergies, medication, pregnancy, eye conditions, contact lenses, patch-test resultYour client, with their consent. See clause 6
Consent recordsSignature image, name, date, and the exact text signed Your client, on the device
Try-on measurementThe geometry of the eyes, in the momentThe camera, on the device only. Never stored, never sent. See clause 7
CalendarBusy time ranges from your Google calendar, and the Flit appointments we write to itGoogle, only if you connect it. See clause 8
TechnicalDevice type, browser, language, time zone, app version, IP address, error reports, sync timestampsAutomatically, when you use Flit
WebsiteAggregate page views, and your email if you join the waitlist Cookieless measurement. See clause 18
SupportWhat you write to us, and our repliesYou

3.1 We do not collect location beyond the country you set and the time zone your device reports, we do not buy data about you from anyone, and we do not build a profile of you for advertising.

4. What your device is asked for

Each permission is requested at the point it is needed, and refusing one disables only the feature concerned:

5. Why we use it, and our legal bases

Where the GDPR, the UK GDPR or an equivalent law applies, we rely on the following:

What we doWhyLegal basis
Create your account, keep you signed in, sync your devices, store your content To give you what you subscribed toPerformance of our contract with you
Send booking requests, confirmations, reminders and deposit instructions The Service cannot work without themContract, and our legitimate interest in running the Service for the artist
Take payment, and prevent fraudulent chargebacksTo be paid, and to comply with tax and accounting rulesContract, and legal obligation
Support, security monitoring, fixing faultsTo keep the Service safe and workingLegitimate interests
Aggregate product measurementTo see which screens are used, never who used themLegitimate interests
Process client health answers and consent recordsTo hold the file the artist keepsProcessed on the artist's instructions, on the explicit consent they obtain from the client
Run the try-onTo show a style on a faceThe explicit consent of the person in front of the camera, taken on the device before it runs
Keep records, answer a lawful requestBecause we mustLegal obligation

5.1 Where we rely on legitimate interests, we have weighed them against your rights and concluded they do not override them. The assessment carried out for any given use is available on request.

5.2 Where we rely on consent, you can withdraw it at any time, and doing so does not undo what was lawful before.

6. Client health information

6.1 An intake form can capture allergies, medication, pregnancy, eye conditions and patch-test results. Most privacy laws treat this as special-category or sensitive data, and the strictest rules apply to it.

6.2 The lash artist decides to collect it and obtains the client's explicit consent. We process it only to store and display it in that client's file, on the artist's instructions.

6.3 We do not use health information for advertising, we do not sell or share it, we do not use it to train any model, we do not disclose it to a data broker, an insurer or an employer, and we do not use it to build a profile. It is stored in the European Union, encrypted in transit, and reachable only through the artist's own account.

6.4 Flit is not a healthcare provider and is not covered by HIPAA. The information is a beauty-professional record, and it is protected here as sensitive personal data, including under the laws described in clause 15.

7. Biometric information and the try-on

7.1 What happens technically. To place a lash style on a face, the try-on measures where the eyes are and how they are shaped, image by image, as the camera runs. The measurement is computed on the device, used for that single frame, and discarded when the next frame arrives. It is never written to storage, never transmitted to us or to anyone else, and never used to identify, verify or recognise a person.

7.2 Consent before the camera. The person shown in the try-on is asked to consent on the device, in their own name, before the camera starts. That consent is recorded and kept with any photograph it produced.

7.3 A photograph is not a face template. If the client chooses to keep an image, what is stored is an ordinary photograph in their file. It can be deleted at any time, and it is only ever published or shared with their separate agreement.

7.4 Written retention and destruction schedule. This clause is our public policy for biometric identifiers and biometric information, as required by laws including the Illinois Biometric Information Privacy Act and the Texas Capture or Use of Biometric Identifier Act.

(a) We do not collect, capture, store, transmit, sell, lease, trade or otherwise profit from any biometric identifier or biometric information. The facial measurement described in clause 7.1 exists only in device memory, for the duration of a single video frame.

(b) Because nothing is retained, there is no retention period: destruction is immediate and automatic, and in every case occurs before the purpose of the measurement is satisfied, and well within one year of the person's last interaction.

(c) We disclose no such information to any third party, and no third-party service receives it, because it never leaves the device.

(d) Photographs kept in a client's file are photographs, not biometric identifiers. They are deleted when the client deletes them, when the client record is deleted, or when the account is deleted, as set out in clause 11.

8. Google Calendar

8.1 Connecting your Google account is optional, and reversible at any time. When you do, Flit asks for the narrowest permissions that let a calendar work, and no others:

8.2 This information is used for one purpose: keeping your Flit calendar and your Google calendar in step, and keeping your availability honest on your booking page. It is never used for advertising, never sold, never transferred to anyone else, and no human at RCS reads it. The keys to your calendar are held server-side, in storage encrypted at rest and reachable only by our own server: they never reach the browser, and no page you open can read them.

8.3 Disconnect at any time in Settings, or revoke access at myaccount.google.com/permissions. Either stops the sync immediately, and we delete the tokens and the map of synced events.

8.4 Flit's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

9. Who we work with

9.1 RCS relies on a limited number of specialist providers: hosting and database, transactional email, subscription payments, website measurement, and, only where you choose to import a paper client book, a document-reading service. Each is bound by a written contract, may use the data solely to perform its service for us, must protect it to a standard no lower than ours, and may not use it for its own purposes.

9.2 Annex III of our Data Processing Terms sets out, for each of them, what it does, what it can access and where it operates, and we tell account holders 30 days before adding a new one. We describe them by the role they perform rather than by name; if you need the name of the company behind a role, ask us and we will give it to you.

9.3 We may also disclose data where the law genuinely requires it, to establish or defend a legal claim, or to protect someone's safety. If we receive a demand for your data, we will tell you unless we are legally forbidden from doing so.

9.4 If our business is ever sold or merged, your data may transfer with it. The buyer would be bound by this policy, and we would tell you before anything changed.

9.5 We do not sell personal data, and we never have. We do not share it for cross-context behavioural advertising. We do not use your content, your clients' records or their photographs to train artificial-intelligence models, and our providers are contractually barred from doing so with data we send them.

10. Where your data is, and transfers

10.1 Your app data, including every client record and photograph, is stored in the European Union.

10.2 Some providers necessarily process limited data elsewhere: an email address to deliver a message, a billing detail to take a payment, a page you upload if you choose the optional import. Where data leaves the European Economic Area or the United Kingdom, we rely on an adequacy decision where one exists, or on the European Commission's standard contractual clauses with the UK addendum where it does not, together with technical measures such as encryption in transit.

10.3 RCS is established outside the European Economic Area, at the address in clause 22. Our own access to data from there is subject to the same contractual protections, and to this policy.

11. How long we keep it

WhatHow long
Your account and everything in itWhile your account is open
After you delete your accountRemoved from live systems immediately, and from any backup copy we hold within 30 days
After a subscription lapses without deletion90 days, so you can come back or export, then deleted after a warning
A client record or photograph you deleteImmediately from live systems, and within 30 days from any backup copy
Facial measurement from the try-onNot retained at all (clause 7.4)
Google tokens and the map of synced eventsDeleted when you disconnect
Billing and tax recordsAs long as tax law requires, typically 5 to 7 years
Support messages3 years, so we can follow a history
Security and error logsUp to 12 months

12. How we protect it

12.1 No system is entirely secure, and the security of the device on which you use Flit, including who is able to unlock it, is outside our control.

13. Your rights, and how to use them

13.1 Depending on where you live, you may have the right to: know what we hold and get a copy; correct it; delete it; take it elsewhere in a portable format; restrict or object to a use; withdraw a consent; and not be treated worse for exercising any of these.

13.2 Most of these you can exercise yourself, immediately, inside the app: edit any record, export your data, delete a client, delete a photograph, or delete your whole account from Manage account.

13.3 For anything else, write to support@flitapp.ai from the address on your account. We answer within 30 days, and tell you if a request genuinely needs longer. We do not charge for this, unless a request is manifestly unfounded or repetitive. We may need to verify who you are, and we will ask for no more than is necessary to do so.

13.4 If you are the client of a lash artist, see clause 2.3: the record belongs to them, and they can act on it faster than we can.

14. If you are in California

14.1 This clause supplements the rest for California residents, under the CCPA as amended by the CPRA.

14.2 Categories collected in the last 12 months, using the statutory names: identifiers (name, email, phone, IP address); customer records (business details, payment status); commercial information (subscription, and the transactions you record); internet activity (aggregate page views, error logs); geolocation limited to country and time zone; audio and visual information (photographs you or your clients store); professional information (your business); and sensitive personal information, being health-related intake answers and, for the try-on, a transient facial measurement that is never retained.

14.3 Sources and purposes are set out in clauses 3 and 5. Disclosures are limited to the service providers described in clause 9, each under a contract that forbids using the data for their own purposes.

14.4 We do not sell personal information, and we do not share it for cross-context behavioural advertising, including that of anyone under 16. We do not use or disclose sensitive personal information for any purpose other than performing the Service, so no right to limit its use arises; such a request would nonetheless be honoured.

14.5 Your rights: to know, to access a copy, to correct, to delete, to opt out of sale or sharing (there is none), to limit the use of sensitive information, and not to be discriminated against for asking. We do not offer financial incentives for data.

14.6 To exercise them, write to support@flitapp.ai. We confirm within 10 business days and answer within 45 days, extendable once by a further 45 where we tell you why. An authorised agent may act for you with written permission we can verify.

14.7 Under California's "Shine the Light" law, we disclose no personal information to third parties for their own direct marketing.

15. Consumer health data (Washington and Nevada)

15.1 This clause is our Consumer Health Data Privacy Policy for the purposes of the Washington My Health My Data Act and Nevada SB 370, and it applies to consumers in those states.

15.2 What is collected. Intake answers a lash artist records about a client that relate to health: allergies, medication, pregnancy, eye conditions, contact lens use, and patch-test results. It is collected from the client, by the artist, in the app.

15.3 Why. Solely to store and display it in that client's file so the artist can perform a treatment safely. It is used for no other purpose, and it is processed on the artist's instructions.

15.4 Who it goes to. No one, beyond the hosting provider that stores it on our behalf under contract, listed on our Annex III of our Data Processing Terms. We do not disclose it to affiliates, advertisers, data brokers or anyone else.

15.5 We do not sell consumer health data. It has never been sold and will not be sold, and no authorisation to sell will be sought, as no sale occurs. It is not used to target advertising, and Flit contains no advertising.

15.6 Your rights are to confirm whether we hold such data, to access it including a list of who received it, to withdraw consent to its collection and sharing, and to have it deleted. Write to support@flitapp.ai; we answer within 45 days, extendable once by 45 days with an explanation. If we deny a request you may appeal to the same address, and we will answer the appeal within 45 days; if we deny the appeal, you may complain to the Washington Attorney General.

15.7 The transient facial measurement described in clause 7 is not retained, shared or sold, and no biometric data is collected within the meaning of these laws.

16. Other United States privacy laws

If you live in a state with a comprehensive privacy law, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others as they take effect, you have broadly the rights in clause 13: to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, or profiling with legal effects. We do none of those three things. Sensitive data, including health information, is processed only with consent obtained by the lash artist. Where your state allows an appeal against a refusal, write to support@flitapp.ai and we will answer within 45 days and tell you how to reach your Attorney General.

17. If you are in Canada

Under PIPEDA and, in Quebec, the Act respecting the protection of personal information in the private sector (Law 25), you may access and correct your personal information, withdraw consent, and complain to the Office of the Privacy Commissioner of Canada or to the Commission d'accès à l'information du Québec. Your data is stored outside Canada, in the European Union, and is therefore subject to the laws of that jurisdiction; clause 10 sets out the safeguards. We do not use automated decision-making, and we do not profile you.

18. Cookies and storage on your device

18.1 Our website sets no advertising or tracking cookies. Our traffic measurement is cookieless, does not follow you across sites, and reports only aggregates such as how many people viewed a page. No cookie banner is therefore displayed.

18.2 The app uses storage on your device for what it cannot work without: keeping you signed in, and holding your data locally so Flit keeps working when the network does not. Clearing it signs you out and removes the local copy; the synced copy is unaffected.

19. Children

Flit is for professionals aged 18 or over, and is not directed at children. We do not knowingly collect data from a child. A lash artist who treats a minor is responsible for obtaining a parent's or guardian's consent for the record they keep, and we will help delete such a record on request.

20. No automated decisions about you

We do not make decisions about you by automated means that produce legal or similarly significant effects. The optional import feature uses a document-reading service to turn a photographed page into text that you then review and correct yourself; nothing it produces is saved without your confirmation. That service is contractually barred from using your pages to train its models, and it keeps them only as long as it needs to answer, plus any short period its own abuse-monitoring requires. We keep no copy of the page.

21. Changes to this policy

We may update this policy as Flit and the law change. The version and date at the top tell you which text is current. For a change that materially affects your rights, we give at least 30 days notice by email or in the app, and where the law requires consent for a new use, we ask for it rather than assume it.

22. Contact, and how to complain

22.1 RCS (FZE), licence No. 9943. Block B, Office B50-030, SRTI Park, Sharjah, United Arab Emirates. support@flitapp.ai.

22.2 Any complaint concerning the handling of personal data may be addressed to us, and will be investigated. You also have the right to complain to your local data protection authority. In the European Union that is the authority of the country where you live or work; in the United Kingdom, the Information Commissioner's Office; in Canada, the Office of the Privacy Commissioner; in the United States, your state Attorney General.