Skip to content
Estylr
Sign in

Last updated September 2026

Security

Booking an appointment means handing over your name, your number, sometimes your address. Here is what we do with it.

  • Your card details never reach us

    Online payments go through a UPI app or a checkout page hosted by our payment provider. Your card number, CVV and UPI PIN are entered there, not on Estylr.

    We keep the amount and a reference from the provider. Nothing that could be used to charge you again.

  • Signing in

    You can sign in with a one-time code sent to your phone, so you do not need a password at all.

    If your account does have a password, it is stored as a bcrypt hash. We cannot read it, we cannot recover it, and a copy of our database would not reveal it.

  • Sessions you control

    Every device gets its own session, and ending one from your account cuts that device off. Sign-in tokens are short-lived and rotate as you use the site.

  • Where your data lives

    Encrypted in transit, encrypted at rest, and backed up automatically. Our database is in India and our servers are in Singapore, the nearest region to it.

  • Who can see it

    Access follows role. A professional sees their own bookings and nothing about anyone else's. Administrative access is limited to the people who need it, and what they do is recorded.

  • What we have not done yet

    We would rather say this than leave it implied. Estylr holds no formal security certification and has not commissioned an external penetration test.

    We publish this page so you can judge what is here on its merits rather than on a badge.

  • Found a problem?

    Tell us before you tell anyone else and we will work with you on it. We will not pursue anyone who reports a genuine issue in good faith.

Questions about any of this?

If something here is unclear, or you have found a problem, we would rather hear it than not.

Get in touch
Browse professionals