Legal
Privacy policy
What personal data PETAL handles, why, on what lawful basis, and the rights people have — for the salons who use PETAL and the individuals whose data flows through it.
Current as of 23/09/2026— working draft, not yet reviewed by a solicitor.
PETAL is a software-as-a-service platform that helps independent UK hairdressers and salons run their business — bookings and calendar, client profiles, and related tools. This policy explains, in plain and compliant terms, how we handle personal data.
1. About this policy and who we are
This policy is published by:
- Legal entity: Petal UK Ltd
- Company number: to be issued on incorporation (registration pending)
- Registered address: 59 Brockmans Close, Minster, Ramsgate, CT12 4ET (current correspondence address; registered office to be confirmed on incorporation)
- Trading name / brand:PETAL is the product and trading name of Petal UK Ltd — “Where Elegance Meets Efficiency.”
- Contact for privacy matters: petalbookingsystem@gmail.com
- ICO registration:registration pending (we intend to register with the ICO’s data protection fee scheme)
Throughout this policy, “we”, “us”, “our” and “PETAL” mean the entity above. “You”means whoever is reading it — a salon owner, a member of salon staff, a salon’s client, or a visitor to our website. We comply with the UK GDPR, the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), and the Privacy and Electronic Communications Regulations 2003 (PECR). Our supervisory authority is the Information Commissioner’s Office (ICO).
2. The two roles PETAL plays — this is important
Data protection law distinguishes between a data controller (who decides why and how personal data is used) and a data processor(who handles data on a controller’s behalf). PETAL wears two hats, depending on whose data it is.
2a. PETAL as a processor (for a salon’s client data)
When a salon uses PETAL to manage its own clients— their names, contact details, appointment history, consultation notes and similar — the salon is the data controller and PETAL is the data processor. Our handling of this data is governed by a Data Processing Agreement (DPA) we enter into with every salon (Article 28 UK GDPR). If you are a client of a salon and want to exercise your data rights, your first point of contact is the salon, as controller.
2b. PETAL as a controller (for our own data)
PETAL is the data controller for:
- Salon account and staff/user data— the details we hold to create, bill, secure and support your PETAL account.
- Marketing contacts and prospects— people who ask to hear from PETAL or enquire about the product.
- Website visitors— people who browse our public website, including analytics and cookie data.
Each salon should provide its own privacy notice to its clients explaining how it, as controller, uses their data.
3. What personal data we collect, and why
3a. Salon account & staff data (PETAL is controller)
Owner/staff name, work email and phone; login credentials and 2FA details; role and permissions; subscription, plan and billing records; support correspondence; and product usage/audit logs. Lawful bases: contract (Art. 6(1)(b)), legitimate interests (Art. 6(1)(f)) for security and support, and legal obligation for tax/accounting and security.
3b. Salon client data (the salon is controller; PETAL is processor)
Client name and contact details; booking and calendar data; consultation and profile information the salon records; deposit records (amount, status and refunds); and no-show tracking data. Where a hairdresser asks for a deposit, the client pays it by card through Stripe; PETAL never sees or stores card numbers and never charges a client’s card automatically for a no-show. Special category (health) data (for example allergies, scalp or skin conditions) may be recorded where necessary for a safe service; extra Article 9 protections apply and the salon, as controller, is responsible for the lawful basis. PETAL supports this with strict per-salon isolation, access controls, encryption in transit and audit logging.
3c. Payment data (shared responsibility with Stripe)
Payments are handled by Stripe. Card details are entered directly with Stripe. PETAL does not store full card numbers — Stripe holds card data under PCI-DSS. Strong Customer Authentication (SCA) under the Payment Services Regulations 2017 applies to relevant payments. Stripe processes both PETAL’s own billing and the deposits clients pay to hairdressers. A hairdresser who takes deposits connects their own account with Stripe (Stripe Connect): Stripe collects and holds their identity-verification and bank details under its own terms and privacy policy, and PETAL keeps only a reference to that Stripe account and a record of each deposit.
3d. Marketing contacts (PETAL is controller)
Name and email of people who opt in to hear from PETAL, plus their preferences and engagement, used to send PETAL’s own updates. Lawful basis: consent (and, where applicable, the soft opt-in).
3e. Website & analytics data (PETAL is controller)
IP address, device/browser information and pages viewed, collected via cookies. See section 8. Lawful basis: consent for non-essential cookies; legitimate interests for strictly necessary operation and security.
4. Lawful bases (UK GDPR Article 6)
- Contract— to provide the PETAL service.
- Legitimate interests— to secure our systems, prevent fraud, support customers and improve the product.
- Legal obligation— to keep accounting records, meet security duties and respond to lawful requests.
- Consent— for marketing to prospects and for non-essential cookies; you can withdraw it at any time.
5. How we use email — two very different types
Transactional email(booking confirmations, reminders, password resets, billing notices) is not marketing — it is necessary to deliver the service and is not subject to marketing consent. Marketing email is governed by PECR and the UK GDPR: we only send it with clear opt-in consent, or under the limited soft opt-in to existing customers, and every marketing email has a one-click unsubscribe.
6. Who we share your data with
We do not sell your personal data. We share it only with sub-processors who act under contract and on our instructions:
- Stripe— payment processing, client deposits, hairdressers’ connected payout accounts and subscription billing (holds card data under PCI-DSS).
- Supabase— application database, authentication, file storage and real-time backend, hosted in the UK region (London / eu-west-2).
- Google (Gmail)— sending transactional and marketing email (current interim provider; we intend to migrate to a dedicated email service).
We may also share data with professional advisers under confidentiality, where required by law, or in connection with a business sale or restructuring.
7. International data transfers
Where a provider stores or processes data outside the UK, we ensure an appropriate Chapter V safeguard (UK adequacy, the UK–US Data Bridge, or an IDTA / SCCs with the UK Addendum). Supabase hosts our database in the UK; Stripe and Google (Gmail) may process data outside the UK under their own safeguards, which we review.
8. Cookies and analytics
Our public website uses strictly necessary cookies without consent (as PECR permits) and sets analytics and other non-essential cookies only with your consent, gathered through our cookie banner. At launch we use no third-party website analytics, so we set only strictly necessary cookies. You can accept, reject or change your choices at any time — see our cookie policy.
9. How long we keep data (retention)
- Active salon account & staff data — for the life of the account.
- Cancelled/lapsed accounts — locked but retained ~90 days so you can export or return, then deleted.
- Salon client data (as processor) — kept per the salon’s instructions; on account closure, retained 90 days then deleted.
- Billing/accounting records — 6 years (legal obligation).
- Marketing contacts — until you unsubscribe or after 24 months of inactivity.
- Audit/security logs — 12 months.
10. Your rights
Under the UK GDPR you have the right to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object (including to direct marketing at any time), and rights around automated decision-making. We do not currently make solely automated decisions with legal or similarly significant effects. To exercise your rights, contact petalbookingsystem@gmail.com— we respond within one month. If you are a salon’s client, please contact the salon first, as it is the controller.
11. Children’s data
PETAL is a business tool for salons and is not directed at children. We do not knowingly collect personal data from anyone under 18 through our own accounts. A salon may, as controller, record details for a client who is a minor and is responsible for any required consent.
12. How we keep data secure
We protect personal data with measures appropriate to the risk: strict per-salon isolation enforced at the database level (Row-Level Security on salon_id); secure authentication with two-factor authentication required for salon Owners; encryption in transit, access controls and role-based permissions; an audit log; and card data held by Stripe under PCI-DSS. If a personal data breach is likely to risk people’s rights, we report it to the ICO within 72 hours and notify affected individuals where the law requires.
13. Complaints and the regulator
Please contact us first at petalbookingsystem@gmail.com. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk; helpline 0303 123 1113; Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF).
14. How to contact us
Privacy and general enquiries: petalbookingsystem@gmail.com. Post: Petal UK Ltd, 59 Brockmans Close, Minster, Ramsgate, CT12 4ET. We have not appointed a Data Protection Officer (not required given our current size).
15. Changes to this policy
We may update this policy as PETAL evolves or the law changes. We will post the updated version here with a new version number and date, and tell account holders directly about material changes.
