Your salon data stays permission-scoped and approval-controlled.
Last updated: July 31, 2026
This notice applies to Noiva Connect at https://noiva.io/api/mcp and the public connection guide at https://noiva.io/connect. It supplements Noiva's general privacy notice for the Noiva platform.
Connection and account data
When you connect a supported assistant, Noiva processes the signed-in Noiva user, salon, location, role, live permissions, requested OAuth scopes, and connector client details needed to complete the connection. Authorization codes, access tokens, and refresh tokens are stored only as one-way hashes; expiry, rotation, and revocation records are retained for security. Noiva never asks for your ChatGPT, Codex, Claude, or Grok password or API key.
Salon data used by tools
A tool may read only the minimum salon data needed for the request and allowed by the signed-in user's role, location, and permissions. Results can include privacy-minimized salon operations, appointment, service, inventory, staff, customer, report, payroll, approval, or settings data. Each tool description states important omissions and limits.
Setup proposals and approval records
A salon setup proposal may contain business and location details, hours, services, staff contact details, customer contact details, and upcoming appointments supplied for setup. Noiva stores the exact proposal as a pending approval record. It is not applied until the active salon Owner reviews the complete proposal inside Noiva with MFA. A rejected or failed proposal does not change salon records.
Audit and security records
Noiva records security evidence such as the salon and user, connection identifier, tool name, permission decision, result, counts, reasons, and timestamps. Tool-call audit metadata does not store provider passwords, raw OAuth tokens, or the provider's full conversation. Proposed content that must be reviewed, such as a setup bundle or customer-note request, is stored in its approval record rather than copied into tool-call audit metadata.
What your chosen provider receives
When you ask a connected provider to use Noiva, that provider receives the tool inputs and results needed to answer your request. ChatGPT and Codex, Claude, and Grok each operate under their own terms and privacy practices. Noiva does not control how a provider stores or uses conversation content after Noiva returns it. Connect only a provider and workspace you trust.
How Noiva uses this data
Noiva uses the data to authenticate the connection, enforce salon and location boundaries, answer requested tools, prepare previews, create approval requests, apply an Owner-approved setup, prevent duplicate requests, investigate security events, provide support, and maintain the service. Noiva Connect does not activate payment or messaging providers, send invitations or marketing, change consent, or move money.
Retention and your choices
You can revoke a Noiva Connect connection in Noiva settings. Revocation makes its access and refresh-token family unusable. Noiva retains active salon records under the salon's account and legal obligations, and retains connection, approval, audit, and security records only as needed to operate, secure, document, and meet legal obligations for the service. Contact the salon for requests about salon records and Noiva for platform or connection requests.
Contact
For Noiva Connect privacy or security questions, email [email protected]. Never send passwords, access tokens, refresh tokens, or provider credentials by email or support ticket.