Last updated: 22 April 2026 · Effective: 22 April 2026
SAY ("we", "us", "our") is a salon and wellness management platform operated by Servicesforyou Ltd, a company registered in England and Wales (No. 11636155).
Data Controller: Servicesforyou Ltd
Trading as: SAY-OS
Data Protection Officer: Servicesforyou Ltd (privacy@say-salon.com)
ICO Registration: ZC121398 (Information Commissioner's Office, United Kingdom)
Registered Address: 7 Auckland Road, 203 Wigeon Heights, London E10 5ZB
Contact: privacy@say-salon.com
Website: app.say-salon.com
We collect different categories of personal data depending on whether you use SAY as a client (booking services) or a salon professional (managing your business).
Name, email address, phone number, profile photo, authentication credentials (via Google or Apple sign-in, or email/password). We store a hashed user ID linked to your Supabase authentication account.
Appointment history, service preferences, rebooking patterns, preferred staff members, service routines and frequencies, and reliability scores (calculated from booking history to optimise scheduling).
SAY collects health-related data to ensure your safety during beauty and wellness treatments. This is special category data under UK GDPR Article 9 and requires your explicit consent before collection. This data includes:
Each health data item has granular privacy controls — you choose Always share, Share when relevant, or Hidden per condition in your Health Profile. These controls determine what salon professionals can see when they access your Beauty Passport or consultation record.
Hair, nail, and style preferences, reference photos you upload, manual service history entries, and your Beauty Passport profile for communicating preferences to salons when travelling.
If you create a professional profile: specialisations, experience, portfolio, ratings, and view analytics.
Messages sent via WhatsApp or SMS through our platform, notification preferences (push, email, SMS), and voice commands processed through our voice assistant.
We do not store credit card numbers or bank details. All payment processing is handled by Stripe, which acts as an independent data controller for payment data. We store only your subscription status, plan type, and transaction references.
Device type, browser, IP address (hashed for passport view audit logs), app version, and usage analytics.
| Data Category | Lawful Basis | GDPR Article |
|---|---|---|
| Account data | Contract performance | Art. 6(1)(b) |
| Booking & service data | Contract performance | Art. 6(1)(b) |
| Health & safety data | Explicit consent | Art. 9(2)(a) |
| Style & appearance data | Contract performance | Art. 6(1)(b) |
| Communication data | Legitimate interest | Art. 6(1)(f) |
| Payment data | Contract performance | Art. 6(1)(b) |
| Technical data | Legitimate interest | Art. 6(1)(f) |
Health data consent: Before any health-related data is collected, we present a clear consent screen explaining what data will be stored, how it will be used, and who can see it. You can withdraw consent at any time through your Health Profile's Data Controls section. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
We do not sell your personal data. We do not use your health data for marketing purposes. We do not use your data for automated decision-making that produces legal effects.
When you book with a salon, they may see a summary of your active health conditions, allergies, and patch test status — but only data you have set to "always share" or "share when relevant" in your privacy controls. They cannot see data you have marked as "hidden".
When a salon professional scans your Beauty Passport QR code, they must provide their name and the treatment they intend to perform before viewing your health data. This access is logged and visible to you under "Who viewed your passport" (GDPR Article 15 right of access).
We use the following services to operate SAY. Each acts as a data processor under a Data Processing Agreement:
| Service | Purpose | Data Processed | Location |
|---|---|---|---|
| Supabase | Database & authentication | All account and application data | EU (Frankfurt) |
| Stripe | Payment processing | Payment details, subscription status | EU/US |
| Vercel | App hosting | Technical data, IP addresses | EU/US |
| Twilio | SMS & WhatsApp messaging | Phone numbers, message content | US |
| Brevo | Transactional email | Email addresses, notification content | EU (France) |
| Google (Gemini) | AI voice processing fallback | Voice command text (no health data) | US |
| Firebase (FCM/APNs) | Push notifications | Device tokens | US |
Voice commands processed on-device (native app) use Apple's Speech framework or Android's SpeechRecognizer and do not leave your device. Only the Gemini fallback route transmits command text to a server, and it never includes health data.
Some of our processors are based in the United States. Where data is transferred outside the UK, we rely on:
| Data | Retention Period |
|---|---|
| Account data | Duration of account + 30 days after deletion |
| Booking history | Duration of account (needed for rebooking engine) |
| Health & safety data | Until you withdraw consent or delete your account |
| Patch test records | Until expiry + 12 months, or account deletion |
| Voice command text | Not stored — processed in real-time and discarded |
| Consultation exports | 12 months (salon regulatory requirement) |
| Passport view logs | Duration of account (GDPR Art. 15 audit trail) |
| Payment records | 6 years (UK tax/accounting obligations) |
When you delete your account, all personal data is permanently deleted within 30 days except where we are legally required to retain it (e.g. payment records for tax purposes).
Under UK GDPR, you have the following rights:
Self-service: You can export your data as JSON and delete all health data directly from your Health Profile > Data Controls section in the app. You can also delete your entire account from Settings.
Email request: For formal Data Subject Access Requests (DSARs) or any rights request, email privacy@say-salon.com. We will respond within 30 days.
Complaint: If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
We implement appropriate technical and organisational measures to protect your data:
SAY uses minimal cookies and local storage:
We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
SAY is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@say-salon.com and we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notification. The "Last updated" date at the top of this page reflects the most recent revision.
Data Controller: Servicesforyou Ltd (No. 11636155)
Data Protection Officer: Servicesforyou Ltd (privacy@say-salon.com)
Privacy enquiries: privacy@say-salon.com
ICO Registration: ZC121398
ICO Complaints: ico.org.uk/make-a-complaint