Privacy Policy

Last updated: 22 April 2026 · Effective: 22 April 2026

1. Who We Are

SAY ("we", "us", "our") is a salon and wellness management platform operated by Servicesforyou Ltd, a company registered in England and Wales (No. 11636155).

Data Controller: Servicesforyou Ltd

Trading as: SAY-OS

Data Protection Officer: Servicesforyou Ltd (privacy@say-salon.com)

ICO Registration: ZC121398 (Information Commissioner's Office, United Kingdom)

Registered Address: 7 Auckland Road, 203 Wigeon Heights, London E10 5ZB

Contact: privacy@say-salon.com

Website: app.say-salon.com

2. What Data We Collect

We collect different categories of personal data depending on whether you use SAY as a client (booking services) or a salon professional (managing your business).

2.1 Account Data

Name, email address, phone number, profile photo, authentication credentials (via Google or Apple sign-in, or email/password). We store a hashed user ID linked to your Supabase authentication account.

2.2 Booking & Service Data

Appointment history, service preferences, rebooking patterns, preferred staff members, service routines and frequencies, and reliability scores (calculated from booking history to optimise scheduling).

2.3 Health & Safety Data GDPR Art. 9

SAY collects health-related data to ensure your safety during beauty and wellness treatments. This is special category data under UK GDPR Article 9 and requires your explicit consent before collection. This data includes:

Each health data item has granular privacy controls — you choose Always share, Share when relevant, or Hidden per condition in your Health Profile. These controls determine what salon professionals can see when they access your Beauty Passport or consultation record.

2.4 Style & Appearance Data

Hair, nail, and style preferences, reference photos you upload, manual service history entries, and your Beauty Passport profile for communicating preferences to salons when travelling.

2.5 Professional Profile Data

If you create a professional profile: specialisations, experience, portfolio, ratings, and view analytics.

2.6 Communication Data

Messages sent via WhatsApp or SMS through our platform, notification preferences (push, email, SMS), and voice commands processed through our voice assistant.

2.7 Payment Data

We do not store credit card numbers or bank details. All payment processing is handled by Stripe, which acts as an independent data controller for payment data. We store only your subscription status, plan type, and transaction references.

2.8 Technical Data

Device type, browser, IP address (hashed for passport view audit logs), app version, and usage analytics.

3. Lawful Basis for Processing

Data CategoryLawful BasisGDPR Article
Account dataContract performanceArt. 6(1)(b)
Booking & service dataContract performanceArt. 6(1)(b)
Health & safety dataExplicit consentArt. 9(2)(a)
Style & appearance dataContract performanceArt. 6(1)(b)
Communication dataLegitimate interestArt. 6(1)(f)
Payment dataContract performanceArt. 6(1)(b)
Technical dataLegitimate interestArt. 6(1)(f)

Health data consent: Before any health-related data is collected, we present a clear consent screen explaining what data will be stored, how it will be used, and who can see it. You can withdraw consent at any time through your Health Profile's Data Controls section. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

4. How We Use Your Data

We do not sell your personal data. We do not use your health data for marketing purposes. We do not use your data for automated decision-making that produces legal effects.

5. Who We Share Data With

5.1 Salon Professionals

When you book with a salon, they may see a summary of your active health conditions, allergies, and patch test status — but only data you have set to "always share" or "share when relevant" in your privacy controls. They cannot see data you have marked as "hidden".

When a salon professional scans your Beauty Passport QR code, they must provide their name and the treatment they intend to perform before viewing your health data. This access is logged and visible to you under "Who viewed your passport" (GDPR Article 15 right of access).

5.2 Third-Party Processors

We use the following services to operate SAY. Each acts as a data processor under a Data Processing Agreement:

ServicePurposeData ProcessedLocation
SupabaseDatabase & authenticationAll account and application dataEU (Frankfurt)
StripePayment processingPayment details, subscription statusEU/US
VercelApp hostingTechnical data, IP addressesEU/US
TwilioSMS & WhatsApp messagingPhone numbers, message contentUS
BrevoTransactional emailEmail addresses, notification contentEU (France)
Google (Gemini)AI voice processing fallbackVoice command text (no health data)US
Firebase (FCM/APNs)Push notificationsDevice tokensUS

Voice commands processed on-device (native app) use Apple's Speech framework or Android's SpeechRecognizer and do not leave your device. Only the Gemini fallback route transmits command text to a server, and it never includes health data.

6. International Data Transfers

Some of our processors are based in the United States. Where data is transferred outside the UK, we rely on:

7. Data Retention

DataRetention Period
Account dataDuration of account + 30 days after deletion
Booking historyDuration of account (needed for rebooking engine)
Health & safety dataUntil you withdraw consent or delete your account
Patch test recordsUntil expiry + 12 months, or account deletion
Voice command textNot stored — processed in real-time and discarded
Consultation exports12 months (salon regulatory requirement)
Passport view logsDuration of account (GDPR Art. 15 audit trail)
Payment records6 years (UK tax/accounting obligations)

When you delete your account, all personal data is permanently deleted within 30 days except where we are legally required to retain it (e.g. payment records for tax purposes).

8. Your Rights

Under UK GDPR, you have the following rights:

How to Exercise Your Rights

Self-service: You can export your data as JSON and delete all health data directly from your Health Profile > Data Controls section in the app. You can also delete your entire account from Settings.

Email request: For formal Data Subject Access Requests (DSARs) or any rights request, email privacy@say-salon.com. We will respond within 30 days.

Complaint: If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

9. Data Security

We implement appropriate technical and organisational measures to protect your data:

10. Cookies & Local Storage

SAY uses minimal cookies and local storage:

We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

11. Children

SAY is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@say-salon.com and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notification. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact Us

Data Controller: Servicesforyou Ltd (No. 11636155)

Data Protection Officer: Servicesforyou Ltd (privacy@say-salon.com)

Privacy enquiries: privacy@say-salon.com

ICO Registration: ZC121398

ICO Complaints: ico.org.uk/make-a-complaint