Legal
Privacy Policy
Version 2.0 · Last updated: 17 August 2026 · Effective: 17 August 2026
This Privacy Policy sets out how RCS (FZE) collects, uses, discloses and protects personal data in connection with the Flit application, the flitapp.ai website and the public booking pages the Service generates. It addresses in particular two categories requiring heightened protection: the client records held by a subscribing lash professional, which may include health-related information, and the facial measurement performed by the virtual try-on. In summary: application data is hosted in the European Union; personal data is neither sold nor shared for advertising; no personal data is used to train artificial-intelligence models; and no facial measurement is retained.
Contents
- Who we are
- Who this policy is for, and the two roles
- What we collect
- What your device is asked for
- Why we use it, and our legal bases
- Client health information
- Biometric information and the try-on
- Google Calendar
- Who we work with
- Where your data is, and transfers
- How long we keep it
- How we protect it
- Your rights, and how to use them
- If you are in California
- Consumer health data (Washington and Nevada)
- Other United States privacy laws
- If you are in Canada
- Cookies and storage on your device
- Children
- No automated decisions about you
- Changes to this policy
- Contact, and how to complain
1. Who we are
Flit is a product of RCS (FZE), a free zone establishment registered in Sharjah under licence No. 9943 ("RCS", "we", "us"), and is the controller of the data described in clause 2.2. Its registered address and contact details are set out in clause 22. Requests concerning personal data are handled by RCS directly, at support@flitapp.ai.
2. Who this policy is for, and the two roles
2.1 It covers our website (flitapp.ai), the Flit application in every form, the public booking pages Flit generates, and the emails the Service sends.
2.2 Two distinct relationships arise within Flit, and they determine to whom a request should be addressed:
| Whose data | Who decides what happens to it | Our role |
|---|---|---|
| The lash artist's own data: name, email, business details, subscription, support messages, usage | We do | Controller. This policy governs it |
| Their clients' data: contact details, intake and health answers, photographs, lash maps, notes, appointments, payments | The lash artist does | Processor. We act on their instructions, under our Data Processing Terms |
2.3 Clients of a lash professional. A request to access, correct or delete a client record must be addressed to the lash professional who holds it, who can act on it within the app. Where they are unable to do so, we will assist them on request. RCS does not amend or delete such a record on its own initiative, as it is not ours to determine.
3. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account | First and last name, email, password (stored only as a hash), country, currency, business name, studio addresses, working hours | You, at sign-up and in Settings |
| Subscription | Plan, status, renewal and trial dates | Our payment provider tells us whether your subscription is active. No card number, and no part of one, ever reaches Flit: the payment happens entirely on their side |
| Your business content | Clients, appointments, treatment records, prices, expenses, photographs, lash maps, notes, booking page text and images | You, and the clients who book with you |
| Client contact and intake | Name, phone, email, date of birth, emergency contact, intake answers | You, or your client through your booking page or an intake form |
| Client health answers | Allergies, medication, pregnancy, eye conditions, contact lenses, patch-test result | Your client, with their consent. See clause 6 |
| Consent records | Signature image, name, date, and the exact text signed | Your client, on the device |
| Try-on measurement | The geometry of the eyes, in the moment | The camera, on the device only. Never stored, never sent. See clause 7 |
| Calendar | Busy time ranges from your Google calendar, and the Flit appointments we write to it | Google, only if you connect it. See clause 8 |
| Technical | Device type, browser, language, time zone, app version, IP address, error reports, sync timestamps | Automatically, when you use Flit |
| Website | Aggregate page views, and your email if you join the waitlist | Cookieless measurement. See clause 18 |
| Support | What you write to us, and our replies | You |
3.1 We do not collect location beyond the country you set and the time zone your device reports, we do not buy data about you from anyone, and we do not build a profile of you for advertising.
4. What your device is asked for
Each permission is requested at the point it is needed, and refusing one disables only the feature concerned:
- Camera, to run the try-on and to take a picture you choose to keep. The video is processed live on the device and is not recorded or transmitted.
- Photo library, only when you add an image to a client's file or to your booking page. Flit reads the image you pick, never the library.
- Notifications. Flit does not ask for these today: a new booking request shows as a badge inside the app. If we add them, they will be asked for at that point, and only to tell you about your own bookings.
- Storage on the device, so Flit works offline and keeps you signed in. This is how the app functions, not a tracker.
5. Why we use it, and our legal bases
Where the GDPR, the UK GDPR or an equivalent law applies, we rely on the following:
| What we do | Why | Legal basis |
|---|---|---|
| Create your account, keep you signed in, sync your devices, store your content | To give you what you subscribed to | Performance of our contract with you |
| Send booking requests, confirmations, reminders and deposit instructions | The Service cannot work without them | Contract, and our legitimate interest in running the Service for the artist |
| Take payment, and prevent fraudulent chargebacks | To be paid, and to comply with tax and accounting rules | Contract, and legal obligation |
| Support, security monitoring, fixing faults | To keep the Service safe and working | Legitimate interests |
| Aggregate product measurement | To see which screens are used, never who used them | Legitimate interests |
| Process client health answers and consent records | To hold the file the artist keeps | Processed on the artist's instructions, on the explicit consent they obtain from the client |
| Run the try-on | To show a style on a face | The explicit consent of the person in front of the camera, taken on the device before it runs |
| Keep records, answer a lawful request | Because we must | Legal obligation |
5.1 Where we rely on legitimate interests, we have weighed them against your rights and concluded they do not override them. The assessment carried out for any given use is available on request.
5.2 Where we rely on consent, you can withdraw it at any time, and doing so does not undo what was lawful before.
6. Client health information
6.1 An intake form can capture allergies, medication, pregnancy, eye conditions and patch-test results. Most privacy laws treat this as special-category or sensitive data, and the strictest rules apply to it.
6.2 The lash artist decides to collect it and obtains the client's explicit consent. We process it only to store and display it in that client's file, on the artist's instructions.
6.3 We do not use health information for advertising, we do not sell or share it, we do not use it to train any model, we do not disclose it to a data broker, an insurer or an employer, and we do not use it to build a profile. It is stored in the European Union, encrypted in transit, and reachable only through the artist's own account.
6.4 Flit is not a healthcare provider and is not covered by HIPAA. The information is a beauty-professional record, and it is protected here as sensitive personal data, including under the laws described in clause 15.
7. Biometric information and the try-on
7.1 What happens technically. To place a lash style on a face, the try-on measures where the eyes are and how they are shaped, image by image, as the camera runs. The measurement is computed on the device, used for that single frame, and discarded when the next frame arrives. It is never written to storage, never transmitted to us or to anyone else, and never used to identify, verify or recognise a person.
7.2 Consent before the camera. The person shown in the try-on is asked to consent on the device, in their own name, before the camera starts. That consent is recorded and kept with any photograph it produced.
7.3 A photograph is not a face template. If the client chooses to keep an image, what is stored is an ordinary photograph in their file. It can be deleted at any time, and it is only ever published or shared with their separate agreement.
7.4 Written retention and destruction schedule. This clause is our public policy for biometric identifiers and biometric information, as required by laws including the Illinois Biometric Information Privacy Act and the Texas Capture or Use of Biometric Identifier Act.
(a) We do not collect, capture, store, transmit, sell, lease, trade or otherwise profit from any biometric identifier or biometric information. The facial measurement described in clause 7.1 exists only in device memory, for the duration of a single video frame.
(b) Because nothing is retained, there is no retention period: destruction is immediate and automatic, and in every case occurs before the purpose of the measurement is satisfied, and well within one year of the person's last interaction.
(c) We disclose no such information to any third party, and no third-party service receives it, because it never leaves the device.
(d) Photographs kept in a client's file are photographs, not biometric identifiers. They are deleted when the client deletes them, when the client record is deleted, or when the account is deleted, as set out in clause 11.
8. Google Calendar
8.1 Connecting your Google account is optional, and reversible at any time. When you do, Flit asks for the narrowest permissions that let a calendar work, and no others:
- A calendar of its own (calendar.app.created). Flit creates a separate "Flit" calendar in your Google account and writes only the appointments it manages there. It cannot see, read or change any other calendar in your account.
- When you are busy (calendar.freebusy). Flit reads only the busy time ranges of your main calendar, so it never offers a slot you have already taken. This returns intervals of time and nothing else: Flit never receives the title, description, guests, location or attachments of any event.
- Your email address (openid, email), only to show you which Google account is connected.
8.2 This information is used for one purpose: keeping your Flit calendar and your Google calendar in step, and keeping your availability honest on your booking page. It is never used for advertising, never sold, never transferred to anyone else, and no human at RCS reads it. The keys to your calendar are held server-side, in storage encrypted at rest and reachable only by our own server: they never reach the browser, and no page you open can read them.
8.3 Disconnect at any time in Settings, or revoke access at myaccount.google.com/permissions. Either stops the sync immediately, and we delete the tokens and the map of synced events.
8.4 Flit's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9. Who we work with
9.1 RCS relies on a limited number of specialist providers: hosting and database, transactional email, subscription payments, website measurement, and, only where you choose to import a paper client book, a document-reading service. Each is bound by a written contract, may use the data solely to perform its service for us, must protect it to a standard no lower than ours, and may not use it for its own purposes.
9.2 Annex III of our Data Processing Terms sets out, for each of them, what it does, what it can access and where it operates, and we tell account holders 30 days before adding a new one. We describe them by the role they perform rather than by name; if you need the name of the company behind a role, ask us and we will give it to you.
9.3 We may also disclose data where the law genuinely requires it, to establish or defend a legal claim, or to protect someone's safety. If we receive a demand for your data, we will tell you unless we are legally forbidden from doing so.
9.4 If our business is ever sold or merged, your data may transfer with it. The buyer would be bound by this policy, and we would tell you before anything changed.
9.5 We do not sell personal data, and we never have. We do not share it for cross-context behavioural advertising. We do not use your content, your clients' records or their photographs to train artificial-intelligence models, and our providers are contractually barred from doing so with data we send them.
10. Where your data is, and transfers
10.1 Your app data, including every client record and photograph, is stored in the European Union.
10.2 Some providers necessarily process limited data elsewhere: an email address to deliver a message, a billing detail to take a payment, a page you upload if you choose the optional import. Where data leaves the European Economic Area or the United Kingdom, we rely on an adequacy decision where one exists, or on the European Commission's standard contractual clauses with the UK addendum where it does not, together with technical measures such as encryption in transit.
10.3 RCS is established outside the European Economic Area, at the address in clause 22. Our own access to data from there is subject to the same contractual protections, and to this policy.
11. How long we keep it
| What | How long |
|---|---|
| Your account and everything in it | While your account is open |
| After you delete your account | Removed from live systems immediately, and from any backup copy we hold within 30 days |
| After a subscription lapses without deletion | 90 days, so you can come back or export, then deleted after a warning |
| A client record or photograph you delete | Immediately from live systems, and within 30 days from any backup copy |
| Facial measurement from the try-on | Not retained at all (clause 7.4) |
| Google tokens and the map of synced events | Deleted when you disconnect |
| Billing and tax records | As long as tax law requires, typically 5 to 7 years |
| Support messages | 3 years, so we can follow a history |
| Security and error logs | Up to 12 months |
12. How we protect it
- Encrypted in transit, and encrypted at rest by our hosting provider.
- Every account is isolated at the database level, so one account cannot read another's rows. This is enforced by the database itself, not only by the app.
- Passwords are never stored in a readable form.
- Access by us is limited to the few people who need it to run or support the Service.
- Flit loads everything it needs from its own servers, so opening a booking page does not expose a client to an outside tracker.
- Our offline-first sync rules are designed so that a device coming back online cannot silently overwrite or erase data held elsewhere.
- If a breach affects your data, we will tell you without undue delay, and the regulator where the law requires it, with what we know and what we are doing about it.
12.1 No system is entirely secure, and the security of the device on which you use Flit, including who is able to unlock it, is outside our control.
13. Your rights, and how to use them
13.1 Depending on where you live, you may have the right to: know what we hold and get a copy; correct it; delete it; take it elsewhere in a portable format; restrict or object to a use; withdraw a consent; and not be treated worse for exercising any of these.
13.2 Most of these you can exercise yourself, immediately, inside the app: edit any record, export your data, delete a client, delete a photograph, or delete your whole account from Manage account.
13.3 For anything else, write to support@flitapp.ai from the address on your account. We answer within 30 days, and tell you if a request genuinely needs longer. We do not charge for this, unless a request is manifestly unfounded or repetitive. We may need to verify who you are, and we will ask for no more than is necessary to do so.
13.4 If you are the client of a lash artist, see clause 2.3: the record belongs to them, and they can act on it faster than we can.
14. If you are in California
14.1 This clause supplements the rest for California residents, under the CCPA as amended by the CPRA.
14.2 Categories collected in the last 12 months, using the statutory names: identifiers (name, email, phone, IP address); customer records (business details, payment status); commercial information (subscription, and the transactions you record); internet activity (aggregate page views, error logs); geolocation limited to country and time zone; audio and visual information (photographs you or your clients store); professional information (your business); and sensitive personal information, being health-related intake answers and, for the try-on, a transient facial measurement that is never retained.
14.3 Sources and purposes are set out in clauses 3 and 5. Disclosures are limited to the service providers described in clause 9, each under a contract that forbids using the data for their own purposes.
14.4 We do not sell personal information, and we do not share it for cross-context behavioural advertising, including that of anyone under 16. We do not use or disclose sensitive personal information for any purpose other than performing the Service, so no right to limit its use arises; such a request would nonetheless be honoured.
14.5 Your rights: to know, to access a copy, to correct, to delete, to opt out of sale or sharing (there is none), to limit the use of sensitive information, and not to be discriminated against for asking. We do not offer financial incentives for data.
14.6 To exercise them, write to support@flitapp.ai. We confirm within 10 business days and answer within 45 days, extendable once by a further 45 where we tell you why. An authorised agent may act for you with written permission we can verify.
14.7 Under California's "Shine the Light" law, we disclose no personal information to third parties for their own direct marketing.
15. Consumer health data (Washington and Nevada)
15.1 This clause is our Consumer Health Data Privacy Policy for the purposes of the Washington My Health My Data Act and Nevada SB 370, and it applies to consumers in those states.
15.2 What is collected. Intake answers a lash artist records about a client that relate to health: allergies, medication, pregnancy, eye conditions, contact lens use, and patch-test results. It is collected from the client, by the artist, in the app.
15.3 Why. Solely to store and display it in that client's file so the artist can perform a treatment safely. It is used for no other purpose, and it is processed on the artist's instructions.
15.4 Who it goes to. No one, beyond the hosting provider that stores it on our behalf under contract, listed on our Annex III of our Data Processing Terms. We do not disclose it to affiliates, advertisers, data brokers or anyone else.
15.5 We do not sell consumer health data. It has never been sold and will not be sold, and no authorisation to sell will be sought, as no sale occurs. It is not used to target advertising, and Flit contains no advertising.
15.6 Your rights are to confirm whether we hold such data, to access it including a list of who received it, to withdraw consent to its collection and sharing, and to have it deleted. Write to support@flitapp.ai; we answer within 45 days, extendable once by 45 days with an explanation. If we deny a request you may appeal to the same address, and we will answer the appeal within 45 days; if we deny the appeal, you may complain to the Washington Attorney General.
15.7 The transient facial measurement described in clause 7 is not retained, shared or sold, and no biometric data is collected within the meaning of these laws.
16. Other United States privacy laws
If you live in a state with a comprehensive privacy law, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others as they take effect, you have broadly the rights in clause 13: to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, or profiling with legal effects. We do none of those three things. Sensitive data, including health information, is processed only with consent obtained by the lash artist. Where your state allows an appeal against a refusal, write to support@flitapp.ai and we will answer within 45 days and tell you how to reach your Attorney General.
17. If you are in Canada
Under PIPEDA and, in Quebec, the Act respecting the protection of personal information in the private sector (Law 25), you may access and correct your personal information, withdraw consent, and complain to the Office of the Privacy Commissioner of Canada or to the Commission d'accès à l'information du Québec. Your data is stored outside Canada, in the European Union, and is therefore subject to the laws of that jurisdiction; clause 10 sets out the safeguards. We do not use automated decision-making, and we do not profile you.
18. Cookies and storage on your device
18.1 Our website sets no advertising or tracking cookies. Our traffic measurement is cookieless, does not follow you across sites, and reports only aggregates such as how many people viewed a page. No cookie banner is therefore displayed.
18.2 The app uses storage on your device for what it cannot work without: keeping you signed in, and holding your data locally so Flit keeps working when the network does not. Clearing it signs you out and removes the local copy; the synced copy is unaffected.
19. Children
Flit is for professionals aged 18 or over, and is not directed at children. We do not knowingly collect data from a child. A lash artist who treats a minor is responsible for obtaining a parent's or guardian's consent for the record they keep, and we will help delete such a record on request.
20. No automated decisions about you
We do not make decisions about you by automated means that produce legal or similarly significant effects. The optional import feature uses a document-reading service to turn a photographed page into text that you then review and correct yourself; nothing it produces is saved without your confirmation. That service is contractually barred from using your pages to train its models, and it keeps them only as long as it needs to answer, plus any short period its own abuse-monitoring requires. We keep no copy of the page.
21. Changes to this policy
We may update this policy as Flit and the law change. The version and date at the top tell you which text is current. For a change that materially affects your rights, we give at least 30 days notice by email or in the app, and where the law requires consent for a new use, we ask for it rather than assume it.
22. Contact, and how to complain
22.1 RCS (FZE), licence No. 9943. Block B, Office B50-030, SRTI Park, Sharjah, United Arab Emirates. support@flitapp.ai.
22.2 Any complaint concerning the handling of personal data may be addressed to us, and will be investigated. You also have the right to complain to your local data protection authority. In the European Union that is the authority of the country where you live or work; in the United Kingdom, the Information Commissioner's Office; in Canada, the Office of the Privacy Commissioner; in the United States, your state Attorney General.