Legal
Privacy notice
This explains what Who Cares does with your personal information, in plain terms. It applies to this website and to bookings made through it.
What is collected
- Your account — name and email address, so an appointment can be attached to you and confirmations can be sent.
- Your bookings — the treatments chosen, the date and time, any notes you add, and what was charged.
- Optional consultation details — allergies, skin sensitivities, relevant medical information and treatment preferences. This is entirely optional, it is never required to make a booking, and you can delete it at any time.
- Patch test records — the date a tinting patch test was carried out, so it can be confirmed as in date.
- Payment records — the amount, the date, and a reference from our payment processor. Card numbers are never seen or stored by Who Cares.
Health-related information, such as allergies, is treated as special category data under UK GDPR. It is only collected with your explicit consent, only used to carry out your treatment safely, and is never used for marketing.
Why it is collected
- To provide the treatment you booked — this is the performance of a contract with you.
- To keep you safe during treatment, and to meet insurance requirements around patch testing — this relies on your explicit consent.
- To keep accurate financial records — this is a legal obligation.
- To send you marketing, but only if you have specifically opted in. You can opt out at any time, and every marketing email carries an unsubscribe link. Booking confirmations and reminders are not marketing and will still be sent.
Who else is involved
Running the booking system involves a small number of service providers. Each one only receives what it needs:
- Supabase — stores the booking database and account logins.
- Stripe — takes deposit payments. Stripe handles your card details directly; they are never sent to Who Cares.
- Resend — sends confirmation and reminder emails. Some of this processing takes place in the United States, under the safeguards those providers have in place.
- Vercel — hosts the website itself.
Your information is never sold, and never shared with anyone for their own marketing.
How long it is kept
- Booking and payment records are kept for six years, which is the period HMRC requires for business records.
- Consultation and patch test records are kept while you remain a client and for a reasonable period afterwards, in case you return.
- If you ask for your account to be deleted, personal details are removed and the financial record is reduced to what the law requires us to keep.
Your rights
Under UK GDPR you can ask to:
- see a copy of the information held about you;
- have anything inaccurate corrected;
- have your information deleted, subject to the record-keeping above;
- withdraw a consent you previously gave, at any time;
- object to how your information is being used.
You can download a copy of your data and request deletion yourself from your account. If you are unhappy with how a request was handled, you can complain to the Information Commissioner's Office at ico.org.uk.
Cookies
This site sets only the cookies needed to keep you signed in and to keep your booking safe while you complete it. There is no advertising tracking and no third-party analytics, which is why you are not being asked to accept anything.
Contact
Contact details for data protection queries will be published here.