Last updated: 9 September 2026 · Effective: 9 September 2026
This policy applies to both of our products: SAY, our client app, and SAY-OS, our salon and professional platform. Both are operated by Servicesforyou Ltd ("we", "us", "our"), a company registered in England and Wales (No. 11636155).
Data Controller: Servicesforyou Ltd
Trading as: SAY and SAY-OS
Privacy contact: privacy@say-salon.com
ICO Registration: ZC121398 (Information Commissioner's Office, United Kingdom)
Registered Address: 7 Auckland Road, 203 Wigeon Heights, London E10 5ZB
Contact: privacy@say-salon.com
Website: app.say-salon.com
Our role under UK GDPR depends on how the platform is used:
We collect different categories of personal data depending on whether you use SAY as a client (booking services) or a salon professional (managing your business).
Name, email address, phone number, profile photo, authentication credentials (via Google or Apple sign-in, or email/password). We store a hashed user ID linked to your Supabase authentication account.
Appointment history, service preferences, rebooking patterns, preferred staff members, service routines and frequencies, and reliability scores (calculated from booking history to optimise scheduling).
SAY collects health-related data to ensure your safety during beauty and wellness treatments. This is special category data under UK GDPR Article 9 and requires your explicit consent before collection. This data includes:
Each health data item has granular privacy controls — you choose Always share, Share when relevant, or Hidden per condition in your Health Profile. These controls determine what salon professionals can see when they access your Beauty Passport or consultation record. Where a salon creates or records health data about its own clients, the salon is the controller for those records (see 1.1).
Hair, nail, and style preferences, reference photos you upload, manual service history entries, and your Beauty Passport profile for communicating preferences to salons when travelling.
If you create a professional profile: specialisations, experience, portfolio, ratings, and view analytics.
Messages sent via WhatsApp or SMS through our platform, notification preferences (push, email, SMS), and voice commands processed through our voice assistant.
We do not store credit card numbers or bank details. All payment processing is handled by Stripe, which acts as an independent data controller for payment data. We store only your subscription status, plan type, and transaction references.
Device type, browser, IP address (hashed for passport view audit logs), app version, and usage analytics.
| Data Category | Lawful Basis | GDPR Article |
|---|---|---|
| Account data | Contract performance | Art. 6(1)(b) |
| Booking & service data | Contract performance | Art. 6(1)(b) |
| Reliability scoring (profiling) | Legitimate interest | Art. 6(1)(f) |
| Health & safety data | Explicit consent | Art. 9(2)(a) |
| Style & appearance data | Contract performance | Art. 6(1)(b) |
| Communication data | Legitimate interest | Art. 6(1)(f) |
| Payment data | Contract performance | Art. 6(1)(b) |
| Technical data | Legitimate interest | Art. 6(1)(f) |
Health data consent: Before any health-related data is collected, we present a clear consent screen explaining what data will be stored, how it will be used, and who can see it. You can withdraw consent at any time through your Health Profile's Data Controls section. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
We do not sell your personal data. We do not use your health data for marketing purposes. We do not use your data for automated decision-making that produces legal effects.
We calculate a reliability score from your booking history (to optimise scheduling) and Skin Intelligence metrics — your Barrier Load Index and Pigmentation Risk — from your skin type, routine, and conditions. This is profiling under UK GDPR. It produces no legal or similarly significant effects and is never used to make automated decisions about you. You may object to this profiling at any time under Article 21 (email privacy@say-salon.com or use your in-app Data Controls). Reliability scoring relies on our legitimate interest (Art. 6(1)(f)); Skin Intelligence metrics are derived from health data and rely on your explicit consent (Art. 9(2)(a)).
We do not currently send marketing communications, but we may in future. If we do, marketing is sent only to users who have opted in. You are asked to accept or decline marketing at sign-up, and the default is declined. The lawful basis is your consent (Art. 6(1)(a) and PECR reg. 22). Every marketing message includes an unsubscribe link, and you can change your preference at any time in your notification settings. We never use your health data for marketing.
When you book with a salon, they may see a summary of your active health conditions, allergies, and patch test status — but only data you have set to "always share" or "share when relevant" in your privacy controls. They cannot see data you have marked as "hidden".
When a salon professional scans your Beauty Passport QR code, they must provide their name and the treatment they intend to perform before viewing your health data. This access is logged and visible to you under "Who viewed your passport" (GDPR Article 15 right of access).
Salons are independent controllers for the client records, consultation notes, and health data they create in SAY-OS; Servicesforyou Ltd processes that data on their behalf under the Data Processing Agreement in our Terms of Service (see 1.1).
We use the following services to operate SAY. Each acts as a data processor under a Data Processing Agreement:
| Service | Purpose | Data Processed | Location |
|---|---|---|---|
| Supabase | Database & authentication | All account and application data | EU (Frankfurt) |
| Stripe | Payment processing | Payment details, subscription status | EU/US |
| Vercel | App hosting | Technical data, IP addresses | EU/US |
| Twilio | SMS & WhatsApp messaging | Phone numbers, message content | US |
| Brevo | Transactional email | Email addresses, notification content | EU (France) |
| Google (Gemini) | AI voice processing fallback | Voice command text (not stored) | US |
| Firebase (FCM/APNs) | Push notifications | Device tokens | US |
Voice commands processed on-device (native app) use Apple's Speech framework or Android's SpeechRecognizer and do not leave your device. Only the Gemini fallback route transmits command text to a server. We do not intentionally transmit health data, and voice commands are not stored.
Some of our processors are based in the United States. Where data is transferred outside the UK, we rely on:
| Data | Retention Period |
|---|---|
| Account data | Duration of account + 30 days after deletion |
| Booking history | Duration of account (needed for rebooking engine) |
| Health & safety data | Deleted from SAY on consent withdrawal or account deletion; salon-created records retained by the salon as controller (see 1.1) |
| Patch test records | Until expiry + 12 months, or account deletion |
| Voice command text | Not stored — processed in real-time and discarded |
| Consultation exports | Retained by the salon as controller for as long as its insurance and regulatory obligations require |
| Passport view logs | Duration of account (GDPR Art. 15 audit trail) |
| Payment records | 6 years (UK tax/accounting obligations) |
When you delete your account, all personal data is permanently deleted within 30 days except where we are legally required to retain it (e.g. payment records for tax purposes). Where a salon is the controller for records it created (see 1.1), the salon determines their retention in line with its own insurance and regulatory obligations; SAY deletes its own copy of your health data on consent withdrawal or account deletion.
Under UK GDPR, you have the following rights:
Self-service: You can export your data as JSON and delete all health data directly from your Health Profile > Data Controls section in the app. You can also delete your entire account from Settings.
Email request: For formal Data Subject Access Requests (DSARs) or any rights request, email privacy@say-salon.com. We will respond within 30 days.
Complaint: If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
We implement appropriate technical and organisational measures to protect your data:
SAY uses minimal cookies and local storage:
We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
SAY (the client app) is not directed at children under 16, and we do not knowingly collect personal data directly from under-16s. Where a salon using SAY-OS records data about a client under 18 — for example, a consultation record for a minor — the salon is the controller for that record and is responsible for obtaining verifiable parental or guardian consent before treatment. If you believe a child has provided us with personal data directly, contact privacy@say-salon.com and we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notification. The "Last updated" date at the top of this page reflects the most recent revision.
Data Controller: Servicesforyou Ltd (No. 11636155)
Privacy contact: privacy@say-salon.com
ICO Registration: ZC121398
ICO Complaints: ico.org.uk/make-a-complaint