Qcut Privacy Policy

Version prepared: 15 September 2026

1. Who operates Qcut

Qcut is a barber discovery and appointment service operated from Palestine by محمد ايهاب وتد and عمر ارسلان مقالدة. Qcut is the project name; it is not currently a registered company. The service is intended for users in Palestine.

Operating location: Palestine. Electronic contact: qcut.barbers@gmail.com. For privacy questions and requests, email qcut.barbers@gmail.com.

2. Information we collect and why

Accounts and authentication. We process your name, phone number, account identifier and role, password and verification information to register you, authenticate access and recover or secure your account. Barbers may also provide an email address. Passwords are stored using one-way hashing rather than as readable passwords.

Profiles and barber businesses. We process profile pictures and, for barbers, shop names, descriptions, city, address/location description, shop coordinates, cover and gallery pictures, social links, services, prices and working hours to display profiles and manage availability.

Appointments and service records. We process the customer and barber linked to a booking, selected services, date and time, party size, price, payment method and booking status, including cancellation or non-attendance information where recorded. Booking, bill and salon-report records help manage appointments and business activity. Haircut payments currently take place at the shop; Qcut does not provide an online haircut-payment checkout.

Location. With the relevant device permission, we use device coordinates to find nearby barbers and identify a city or address. We also process locations selected manually and store barber shop coordinates. Coordinates used for nearby searches are sent to Qcut's servers. Mapping/address features send coordinates to Google and may use OpenStreetMap Nominatim as a fallback. Search coordinates may also appear in request logs; they should not be treated as information that always stays on the device.

Photos and support. We process the photos you choose to upload for profiles, galleries or support, and the text and attachments you send to Qcut support. Uploaded files are stored using Firebase Storage. We also process complaints and account-related requests, including any deletion reason you provide.

Notifications and operational records. We use device notification tokens and installation identifiers to deliver account, appointment and support notifications. We process connection and security information, including IP addresses and request/error records, to operate and protect the service. Such records may include request paths and parameters, status codes, times, account identifiers and contact information recorded during message delivery. This operational logging is separate from advertising or audience analytics.

3. Who can receive your information

The relevant barber can see your name, phone number, profile picture if provided, and appointment details to manage your booking. Barber business profiles, shop locations, services and gallery pictures are visible to people browsing them. Support messages are intended for Qcut support and the account involved, rather than public display.

Service providers process information needed to operate Qcut:

External navigation and social services you open handle the information they receive under their own policies. We may disclose relevant information to comply with applicable law or lawful requests, or to address a legal claim, subject to applicable requirements.

4. Advertising and communications

We do not sell personal information or share it for advertising purposes. We do not use advertising or user-behavior analytics tools. Messages and notifications are for appointments, accounts and support, not promotional campaigns. These statements do not mean that service providers receive no data or keep no technical records.

5. Permissions and your choices

You can manage location, camera, photo and notification permissions in your device settings. Refusing a permission can limit the associated feature. You may choose a location manually where supported. Providing a photo means selecting or taking an image to upload; it does not mean publishing your entire photo library.

Turning off notifications or uninstalling Qcut does not delete your account or previously transmitted information. Avoid placing sensitive details in support attachments. A person who obtains a file's access link may be able to view that file; do not assume that possession of a link is restricted to a signed-in recipient.

6. Retention and account deletion

Customer accounts. Open Settings → Advanced Settings → Delete account and confirm. Customer account deletion is permanent. The account database record and associated appointments, appointment-change requests, customer bills, support-message records and notifications are deleted. Removing a message or profile record does not by itself establish that its separately stored media file or a backup copy has been removed.

Barber accounts. The current in-app procedure archives a barber account and allows it to be restored. It does not permanently erase the barber's profile, gallery, past bookings, business records, messages or notification information. Barbers can contact qcut.barbers@gmail.com to request erasure or enquire about retained information. Sending a request is not itself confirmation that erasure has been completed.

Separately stored information. Customer profile and support-media files are not currently included in the automatic database-deletion process. Removing the account does not establish removal of those files, provider records, operational logs or backup copies. Requests concerning these records can be sent to our privacy contact. We do not represent the existing procedure as automatic erasure of every copy.

Retention. Account and service information is maintained to operate accounts, appointments, support and business records. The current system has no established time-based expiry for archived barber data or customer media left outside the database-deletion process. Operational logs and backups depend on provider and system settings; a single verified retention period for them has not yet been established. Consequently, we cannot state a fixed deadline for erasure of these remaining categories in this version. Temporary verification and rate-limit records expire according to their technical validity periods. Any retention required by law remains subject to the applicable requirement; this is not a general authorization to keep all information indefinitely.

You can contact qcut.barbers@gmail.com about deletion or another privacy request, including if you cannot access your account. We may need to verify that the request relates to you. Do not send your password or a sign-in verification code by email. You can send an account or data-deletion request by email without reinstalling the app. Include the account phone number and whether the account is a customer or barber account, and describe the request. Do not include passwords or sign-in codes. A dedicated public deletion-request webpage is not yet available.

7. Processing outside Palestine

Service providers may process information outside Palestine. Launching Qcut only in Palestine does not keep all information in Palestine. The providers named above use infrastructure in different locations. We have not yet verified the specific hosting regions for every service, and do not represent the data as stored exclusively in Palestine or in any other particular country. You may contact us for available information about processing locations. Applicable legal requirements continue to apply to international processing.

8. Young users

You must be at least 13 to create your own Qcut account. Users aged 13–17 must meet any parental-permission requirements that apply to them. Children under 13 must not create their own accounts. A parent or guardian may book a haircut for a child using the adult's account, the adult's name and the number of people, without supplying the child's personal details.

If you believe a child has supplied personal information contrary to these rules, contact us so we can investigate and address it. This eligibility rule does not override applicable protections for minors.

9. Security and privacy requests

We use account authentication, role-based access controls and password hashing. The app is configured to connect to Qcut's API using HTTPS. No system can guarantee absolute security. Access controls and retention also depend on the systems operated by our providers.

You can contact us to request access to, correction of or deletion of your information. Additional rights and any necessary exceptions depend on applicable law. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. We handle requests and any required breach notifications under applicable law.

10. Changes and contact

Updated versions of this policy will identify their version date. You can request the current policy at qcut.barbers@gmail.com. Material changes will be communicated as required by applicable law.

Privacy and support: qcut.barbers@gmail.com. Operators: محمد ايهاب وتد and عمر ارسلان مقالدة. Operating location: Palestine.