User privacy data protection method for beauty and hairdressing
Through data collection modules, encryption technology, access control and monitoring mechanisms, the data protection problem in the beauty and hairdressing industry has been solved, and the security of user privacy data and the standardized development of the industry have been achieved.
Patent Information
- Application Number
- CN202510728823.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-10-28
AI Technical Summary
The beauty and hairdressing industry has weak data protection awareness and irregular data management, which leads to the leakage of user privacy data and unauthorized data sharing or use, infringing on user privacy rights.
By following the principle of minimization through data collection modules, using data encryption technologies such as the Serpent algorithm and the Diff-Hellman key exchange algorithm, setting access control and authority allocation, implementing data sharing authorization, and combining active and passive monitoring, we can ensure the consistency and security of data use.
Effectively protect user privacy data, reduce the risk of leakage, enhance user trust, improve consumer experience, avoid legal disputes, and promote standardized development of the industry.
Smart Images

Figure CN120850331A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of security and privacy protection technology, specifically a method for protecting user privacy data in the beauty and hairdressing industry. Background Technology
[0002] With the digital development of the beauty and hairdressing industry, businesses collect users' personal information through various online and offline channels, including but not limited to name, contact information, physical characteristics, and consumption preferences.
[0003] However, the industry currently suffers from weak awareness of data protection and non-standard data management. For example, some businesses collect excessive amounts of user privacy data without proper encryption and security measures, which can easily lead to data leaks. At the same time, in the process of data use and sharing, there are frequent cases where data is used for commercial promotion or shared with third parties without the user's consent, which seriously infringes on the user's privacy rights.
[0004] Therefore, it is necessary to propose a method for protecting user privacy data in the beauty and hairdressing industry. Summary of the Invention
[0005] To address the shortcomings of existing technologies, this invention provides a method for protecting user privacy data in the beauty and hairdressing industry. This method has the advantages of standardized collection of user information while protecting privacy, thus solving the problems mentioned in the background technology.
[0006] This invention provides the following technical solution: a method for protecting user privacy data in the beauty and hairdressing industry, comprising the following steps: Step 1: Collect customer information through the data collection module. The information includes: name, contact information, hairstyle preference, and skin type, etc., and follows the principle of minimizing data collection. Step 2: Through the data storage module, data encryption is used to encrypt and store user data. Step 3: Through the data usage module, check the data usage operations to ensure consistency in data usage; Step 4: Provide user-side and merchant-side pages or apps for merchants to register customer information and for users to manage their data permissions and view data usage records.
[0007] Preferably, step one further includes an information notification unit and a data acquisition unit. In the information notification unit, the merchant pushes a notification link to the user's terminal via a webpage. The user views the link, which details the collected data content, collection purpose, usage method, and data protection measures. After obtaining the user's consent, the user inputs the required information.
[0008] Preferably, in step two, the user's sensitive data (such as contact information, allergy history, scalp test report, etc.) is encrypted using the Serpent algorithm and the Diff-Hellman key exchange algorithm.
[0009] Preferably, step two further includes an access control unit and a data backup unit. The access control unit is used to set access ports with different permission levels. According to the employee's job requirements, the access control system assigns corresponding access permissions to each port. Only employees who have been authenticated and authorized can access the data through the corresponding port. The data backup unit backs up the encrypted data to a secure storage device or cloud storage system through a data transmission channel according to a preset backup cycle.
[0010] Preferably, the method further includes a data sharing module, which includes a sharing authorization unit. When it is necessary to share data with a third party, the unit obtains the user's explicit consent through a user authorization confirmation interface and signs a data protection agreement with the third party.
[0011] Preferably, the system also includes a security monitoring unit, which employs active detection and passive monitoring methods. Active detection is used to perform vulnerability scanning on servers, databases, network devices, and applications, while passive monitoring is used to monitor abnormal data access and suspicious login behavior.
[0012] Preferably, the data access permissions specifically mean that only authorized specific employees can access user data. Access levels are precisely allocated according to the employee's job function. For example, front desk employees may only be able to view appointment information, while beauticians and hairdressers may only be able to view user preference data related to services.
[0013] Preferably, in step four, on the user's page or app, the user logs in using a key and can view their basic information, haircut records, appointment services, payment and deposit records. On the merchant's page or app, the merchant logs in using a key and can view the number of users, the appointment time information, the required haircut type, and the basic information of the hairdresser.
[0014] Compared with the prior art, the present invention has the following beneficial effects: This method for protecting user privacy data in the beauty and hairdressing industry provides comprehensive security for user information, reduces the risk of data leakage, enhances user trust in businesses, improves user experience and satisfaction, and helps establish a positive image, enhance competitiveness, avoid legal disputes and economic losses caused by data leakage, and ensure the sustainable development of businesses. Its widespread application will help standardize data management practices in the beauty and hairdressing industry, promote the overall improvement of data protection levels in the industry, create a healthy and orderly market environment, and facilitate the digital and standardized development of the beauty and hairdressing industry. Attached Figure Description
[0015] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0016] Figure 1 This is a schematic diagram of the privacy data protection method of the present invention; Figure 2 This is a schematic diagram of the user and merchant data connection process structure of the present invention. Detailed Implementation
[0017] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0018] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0019] The beauty and hairdressing industry is an industry that creates and appreciates beauty. After decades of development, the beauty and hairdressing industry has evolved from simple haircuts and skincare into an industry that involves a wide range of fields such as hairdressing, beauty, cosmetics, and beauty equipment. The end of the industry is the beauty and hairdressing service industry, which is the humanized embodiment of various material means. The beauty and hairdressing service industry has become the locomotive and barometer of the entire industry, driving the beauty, hairdressing, cosmetics and related industries to survive in exploration and develop in competition.
[0020] With the development of digitalization, businesses are acquiring more users and collecting their personal information through various online and offline channels in order to bring more users and revenue. However, businesses are not doing enough to protect users' personal information.
[0021] There is a widespread problem of weak data protection awareness and irregular data management within the industry. Some businesses collect excessive amounts of user privacy data at will, and lack effective encryption and security measures for data storage, which can easily lead to data leaks. At the same time, in the process of data use and sharing, there are frequent cases of using data for commercial promotion or sharing it with third parties without the user's consent, which seriously infringes on the user's privacy rights.
[0022] Please see Figure 1 and Figure 2 A method for protecting user privacy data in the beauty and hairdressing industry includes the following steps: Step 1: Collect customer information through the data collection module. The information includes: name, contact information, hairstyle preference, and skin type, etc., and follows the principle of minimizing data collection. Step 2: Through the data storage module, data encryption is used to encrypt and store user data. Step 3: Through the data usage module, check the data usage operations to ensure consistency in data usage; Step 4: Provide user-side and merchant-side pages or apps for merchants to register customer information and for users to manage their data permissions and view data usage records.
[0023] Step three specifically involves: strictly using the data in accordance with the purpose informed to the user when the data was collected; without the user's explicit authorization, the user data shall not be used for other purposes, such as marketing, advertising, or other commercial uses. At the same time, anonymization technology shall be used to remove information that can identify the user (such as name, ID number, etc.) to ensure that the user's personal privacy is not leaked while using the data for business analysis.
[0024] As a preferred technical solution of the present invention, step one further includes an information notification unit and a data acquisition unit. In the information notification unit, the merchant pushes a notification link to the user's terminal via a terminal page. The user views the link, which details the collected data content, collection purpose, usage method, and data protection measures. After obtaining the user's consent, the user inputs the required information.
[0025] As a preferred technical solution of the present invention, in step two, the user's sensitive data (such as contact information, allergy history, scalp test report, etc.) is encrypted using the Serpent algorithm and the Diff-Hellman key exchange algorithm.
[0026] In the key exchange phase: the user equipment and the merchant server each generate their own private parameters; both parties calculate a public value using the public parameters and their own private parameters, and send the public value to each other; both parties calculate the same symmetric key based on the public value received from each other and their own private parameters. Data encryption stage: Users enter personal information (such as name, contact information, hairstyle preference, etc.) on the device. The device uses a symmetric key obtained through the Diff-Hellman algorithm and the Serpent algorithm to encrypt the data. The encrypted data is then sent to the merchant through the network. Data decryption stage: After receiving the encrypted data, the merchant uses the same symmetric key to decrypt the data using the Serpent algorithm, thereby obtaining the user's original information.
[0027] As a preferred technical solution of the present invention, step two further includes an access control unit and a data backup unit. The access control unit is used to set access ports with different permission levels. According to the employee's job requirements, the access control system assigns corresponding access permissions to each port. Only employees who have been authenticated and authorized can access the data through the corresponding port. The data backup unit backs up the encrypted data to a secure storage device or cloud storage system through a data transmission channel according to a preset backup cycle.
[0028] As a preferred embodiment of the present invention, the method further includes a data sharing module, which includes a sharing authorization unit. When it is necessary to share data with a third party, the unit obtains the user's explicit consent through a user authorization confirmation interface and signs a data protection agreement with the third party.
[0029] Establish a data sharing supervision mechanism to regularly check the use of data shared with third parties, ensuring that third parties use the data in accordance with the agreement and do not engage in any illegal operations. If any illegal behavior by a third party is discovered, data sharing should be terminated immediately.
[0030] As a preferred technical solution of the present invention, the method further includes a security monitoring unit, which adopts active detection and passive monitoring methods. The active detection is used to perform vulnerability scanning on servers, databases, network devices and applications, while the passive monitoring is used to monitor abnormal data access and suspicious login behavior.
[0031] Specifically, it is necessary to deploy appropriate security protection equipment such as firewalls, intrusion detection systems, and antivirus software to prevent external attacks and malicious software intrusions.
[0032] As a preferred technical solution of the present invention, the data access permission specifically means that only authorized specific employees can access user data. The access level is precisely allocated according to the employee's job function. For example, front desk employees may only be able to view appointment information, while beauticians and hairdressers may only be able to view user preference data related to services.
[0033] As a preferred technical solution of the present invention, in step four, on the user's page or app, the user logs in using a key and can view their basic information, haircut records, appointment services, payment and deposit records. On the merchant's page or app, the merchant logs in using a key and can view the number of users, the appointment time information of users, the required haircut type and the basic information of the hairdresser, etc.
[0034] The user can browse the hairdressers employed by the corresponding merchants and select the appropriate hairdresser when making an appointment based on their own needs. The user can set one or two hairdressers in the backup list. After the user confirms the appointment information, the merchant receives the information, reviews the user's appointment information, determines the final hairdresser selection based on the actual situation, and sends it to the user for confirmation. After the user confirms, the information is fed back to the merchant for final confirmation. Once the merchant determines the amount based on the user's haircut, it is sent to the user. After the user confirms the amount, the system automatically deducts the amount from the user's account and sends a copy of the payment list to the user, which is then saved in the storage system. Users can also rate the hairdresser based on their own experience, thus enhancing the functionality of the programs on both the user and merchant sides.
[0035] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A method for protecting user privacy data in the beauty and hairdressing industry, characterized in that: Includes the following steps: Step 1: Collect customer information through the data collection module. The information includes: name, contact information, hairstyle preference, and skin type, etc., and follows the principle of minimizing data collection. Step 2: Through the data storage module, data encryption is used to encrypt and store user data. Step 3: Through the data usage module, check the data usage operations to ensure consistency in data usage; Step 4: Provide user-side and merchant-side pages or apps for merchants to register customer information and for users to manage their data permissions and view data usage records.
2. The method for protecting user privacy data in the beauty and hairdressing industry according to claim 1, characterized in that: Step one further includes an information notification unit and a data acquisition unit. In the information notification unit, the merchant pushes a notification link to the user's terminal via a webpage. The user views the link, which details the collected data content, collection purpose, usage method, and data protection measures. After obtaining the user's consent, the user inputs the required information.
3. The method for protecting user privacy data in the beauty and hairdressing industry according to claim 1, characterized in that: In step two, the user's sensitive data (such as contact information, allergy history, scalp test report, etc.) is encrypted using the Serpent algorithm and the Diff-Hellman key exchange algorithm.
4. The method for protecting user privacy data in the beauty and hairdressing industry according to claim 1, characterized in that: Step two also includes an access control unit and a data backup unit. The access control unit is used to set access ports with different permission levels. According to the employee's job requirements, the permission allocation management system assigns corresponding access permissions to each port. Only employees who have been authenticated and authorized can access the data through the corresponding port. The data backup unit backs up the encrypted data to a secure storage device or cloud storage system through the data transmission channel according to a preset backup cycle.
5. A method for protecting user privacy data in the beauty and hairdressing industry according to claim 1, characterized in that: The system also includes a data sharing module, which includes a sharing authorization unit. When it is necessary to share data with a third party, the module obtains the user's explicit consent through a user authorization confirmation interface and signs a data protection agreement with the third party.
6. A method for protecting user privacy data in the beauty and hairdressing industry according to claim 1, characterized in that: The system also includes a security monitoring unit that employs both active detection and passive monitoring. Active detection is used to scan servers, databases, network devices, and applications for vulnerabilities, while passive monitoring is used to monitor abnormal data access and suspicious login behavior.
7. A method for protecting user privacy data in the beauty and hairdressing industry according to claim 4, characterized in that: The data access permissions specifically mean that only authorized employees can access user data. Access levels are precisely assigned based on the employee's job function. For example, a front desk employee may only be able to view appointment information, while a beautician or hairdresser may only be able to view data such as user preferences related to the service.
8. A method for protecting user privacy data in the beauty and hairdressing industry according to claim 4, characterized in that: In step four, on the user's page or app, the user logs in using a key. The user can view their basic information, haircut records, appointment services, payment and deposit records. On the merchant's page or app, the merchant logs in using a key. The merchant can view the number of users, the appointment time information, the required haircut type, and the basic information of the hairdresser.