How Belcome protects client data
Salons and med spas trust us with their clients. This page says plainly what Belcome does to protect that trust, and what is still your part.
Belcome is in private build. This page describes how the service is built for launch.
Encrypted in transit and at rest.
Every connection uses HTTPS. The database and file storage are encrypted on disk.
Health data stays on HIPAA-eligible services.
Client data for med spas lives on Amazon Web Services, under the AWS Business Associate Addendum, and is not sent to tools that do not sign one.
An audit log that only grows.
Opening, changing and moving a client file leaves an entry. Entries can only be added, never edited or erased, including by us.
Two-step sign-in.
Owners and team members can turn on an authenticator app code with single-use recovery codes.
Each person sees what their role allows.
Owner, manager, front desk and provider each get the access they need, and each business only ever sees its own data.
Texts never name the treatment.
A reminder says when and where. The service someone booked never goes into a text message.
Error reports without personal details.
Names, emails and phone numbers are removed before an error report leaves our servers.
HIPAA, in plain words
Belcome is built to support HIPAA requirements for med spas and clinics: we sign a Business Associate Agreement with every business that needs one, and the safeguards above are part of it. Software alone does not make a business compliant. Your policies, your team's training and how you use the app are your part.
Questions about security, or something to report? Write to info@designmastersolutions.com.