Ensure to check our Booking Policy before making any bookings on the website

Legal

Privacy Policy

How we collect, use, and protect your personal data — in plain English.

1. Who We Are

Savage Beauty Luxe is a private beauty studio operating in Salford Quays, Manchester, England. We are the data controller for all personal information collected through this website and during the provision of our services.

For any data-related enquiries or to exercise your rights, please contact us via our Contact page.

2. What Personal Data We Collect

We collect the following personal data when you use our website or book a service:

  • Identity data: first name and last name
  • Contact data: email address and phone number
  • Booking data: selected service, preferred date and time, appointment notes
  • Payment data: deposit amount paid — we do not store card or bank details
  • Communications: messages sent via our contact form
  • Technical data: a session cookie used solely to maintain your booking session

3. How We Use Your Data

We use your personal data only for the following purposes:

  • To process and manage your appointment booking
  • To send booking confirmations, reminders, and aftercare information by email
  • To respond to enquiries submitted via our contact form
  • To manage cancellations, rescheduling, and deposit payments
  • To meet our legal and record-keeping obligations

We do not use your data for automated decision-making or profiling. We do not send marketing emails unless you have explicitly requested them.

4. Legal Basis for Processing

We process your personal data under the following lawful bases:

  • Contract performance: processing your booking and delivering the service you have requested
  • Legitimate interests: managing our business operations, responding to enquiries, and maintaining records
  • Legal obligation: where we are required to retain records under applicable law

5. Data Retention

We keep your personal data only for as long as necessary:

  • Confirmed booking records: retained for 90 days after your appointment, then automatically deleted
  • Pending bookings (unpaid): retained for 7 days from creation
  • Contact form enquiries: retained for 6 months from the date of submission

6. Third Parties We Share Data With

We share your data only with the following trusted service providers, solely to operate our service:

  • Vercel Inc. — website hosting (servers in the EU and US)
  • Upstash Inc. — booking data storage (encrypted Redis database)
  • Resend Inc. — transactional email delivery (confirmations and notifications)

We do not sell, rent, or trade your personal data with any third party for marketing purposes.

7. Your Rights Under UK GDPR

As a UK resident, you have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you
  • Rectification: request correction of inaccurate or incomplete data
  • Erasure: request deletion of your data where there is no legitimate reason to retain it
  • Restriction: request that we limit how we process your data in certain circumstances
  • Portability: receive your data in a structured, machine-readable format
  • Objection: object to processing where we rely on legitimate interests

To exercise any of these rights, contact us via our Contact page. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Cookies

This website uses a single functional session cookie to maintain the admin login session. This cookie is httpOnly (not accessible to JavaScript) and expires after 8 hours. No advertising, tracking, or third-party cookies are set by us.

Vercel Analytics may collect anonymised, aggregated page-view data without identifying individual users. No personal information is linked to analytics data.

9. Data Security

We take reasonable technical and organisational measures to protect your personal data, including HTTPS-only access, encrypted data storage, and cryptographically signed admin sessions. However, no internet transmission is entirely secure.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated effective date. Continued use of our website after changes constitutes acceptance of the revised policy.

Last updated: March 2026

For any questions about this policy, please get in touch via our Contact page.

You may also wish to read our Terms & Conditions and Booking Policy.