Plain-language summary
The short version
Glammy applies or plans safeguards proportionate to the current pre-launch website and will expand them before product accounts and integrations launch. This page does not claim a certification, independent audit, guaranteed uptime or absolute security.
- Effective
- Last updated
Security is an ongoing operating responsibility. This statement describes the controls designed for Glammy’s public website and the principles intended for the future salon platform.
The current site primarily handles waitlist, contact and deletion-request information. It does not currently hold salon appointment databases or connect to Meta accounts.
1. Public website safeguards
- HTTPS in production and transport-security headers where deployment supports them.
- A restrictive content security policy, frame protection, content-type protection, referrer limits and permissions policy.
- Server-side input validation, request-size limits, same-origin checks and spam-resistance measures for forms.
- Restricted administrative access to deployment and email-delivery systems.
- Privacy-conscious logging that avoids intentionally recording form message bodies, passwords or access tokens.
- Dependency review, secure configuration and remediation of relevant reported vulnerabilities.
Infrastructure protections and production rate limits may be provided partly by the hosting platform. Final deployment settings must be verified before launch rather than assumed from source code alone.
2. Future product safeguards
Before salon accounts or connected-platform data are processed, Glammy intends to document and test authentication, role-based access, credential and secret handling, tenant separation, encryption, backup and recovery, auditability, secure development, incident response, vendor review, retention and deletion controls.
Any future Meta integration must use authorised connections, least-necessary permissions, protected tokens, customer-directed actions, controlled disconnection and applicable platform requirements. A roadmap entry is not evidence that these controls are live.
3. People and access
Access to production systems and submitted information should be limited to people who need it for an authorised role. Access should be reviewed, protected with strong authentication where available and removed promptly when no longer required. Confidentiality expectations and security responsibilities should be documented for people with access.
4. Security incident response
Glammy will assess credible security events, take steps to contain and remediate them, preserve appropriate records and notify affected parties or authorities when applicable law or contractual commitments require it. Public updates will be factual and will not disclose information that would create additional risk.
5. Your security responsibilities
- Do not submit passwords, access tokens, payment-card credentials or unnecessary sensitive information through public forms.
- Use a current browser and protect the email account used for correspondence.
- Verify that messages requesting credentials or urgent payment genuinely come from an authorised Glammy channel.
- For future product accounts, use unique credentials, strong available authentication and prompt access removal for former team members.
6. Reporting a security concern
Email contact@glammyapp.in with a concise description, affected URL or feature, steps to reproduce and potential impact. Do not access data that is not yours, disrupt service, use social engineering, publicly disclose an unresolved issue or include live secrets in the initial report.
Glammy does not currently publish a bug-bounty reward or safe-harbour programme. Good-faith reports will be reviewed, but no payment or response time is promised by this statement.
7. Accurate assurance language
Glammy does not claim ISO certification, SOC reporting, penetration-test results, a service-level agreement, guaranteed availability or immunity from security incidents on this website. This statement will be updated only when an assurance can be supported by current evidence.
Keep exploring
References and related pages
Related Glammy policies
Direct contact
Contact Glammy
Report a security concern to contact@glammyapp.in without including live credentials or unnecessary personal data.
This document is a carefully prepared product draft and does not constitute legal advice. Glammy should obtain review from qualified counsel before production publication and whenever its services, vendors, data uses or applicable obligations change.
