Privacy policy
Last updated 13 September 2026
How Instant Booking handles personal data — for the salons that use it, and for the clients who book with them.
Who we are
Instant Booking’s operator and registered details will be listed here once finalised.
Two different roles
For salon accounts — owners and staff who sign up — Instant Booking is the data controller. We decide how that account data is used, and this policy covers it.
For a salon’s clients — people who book an appointment — the salon is the controller and Instant Booking processes the data on the salon’s behalf, under our data processing terms. If you booked with a salon, contact the salon first about your data; we will help them respond.
What we collect
- Salon accounts: name, email address, password (stored only as a secure hash by our authentication provider), business name, address, phone, and the services, prices, staff names and working hours you add.
- Bookings: the client’s name, email, phone number, the appointment, and any notes they or the salon add.
- Patch test records: the date and result of a skin test and any notes the salon adds. A recorded reaction can be health information, so salons should keep notes to what they genuinely need.
- Technical data: sign-in cookies, and IP addresses and request logs that our hosting keeps for security and to stop abuse of the booking form.
How we use it, and why we’re allowed to
- To run the service you signed up for — taking bookings, sending confirmations and reminders, and letting clients change their booking (contract).
- To keep Instant Booking secure, prevent fraud and spam, and fix problems (legitimate interests).
- To meet legal, tax and accounting obligations (legal obligation).
We don’t sell personal data, we don’t run a marketplace, and we never use a salon’s client list to market other businesses to those clients.
Who we share it with
Only the providers that make Instant Booking work, each under a data processing agreement:
- Supabase — our database and sign-in. Booking data is stored in London, United Kingdom.
- Vercel — hosting. Requests are handled in London but Vercel may process limited data, such as logs, elsewhere.
- Resend — delivers confirmation and reminder emails, and processes email addresses and message content in the United States.
Where data leaves the UK we rely on UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, or the UK International Data Transfer Addendum, as applicable.
How long we keep it
Salon account data is kept while the account is open. Booking and client data is kept for as long as the salon keeps it in Instant Booking. When a salon closes its account, we delete its data within 90 days, except where the law requires us to keep something longer.
Your rights
Under UK data protection law you can ask for a copy of your data, ask us to correct or delete it, restrict or object to how it’s used, and receive it in a portable format. If you booked with a salon, the salon handles these requests, and we support them.
If you’re unhappy with how your data is handled, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We’d appreciate the chance to put it right first.
Security
Data is encrypted in transit. Each salon’s data is isolated at the database level, so one salon’s account cannot read another’s. Public booking pages expose only what a client needs to book — never staff contact details or other clients.
Changes
If we make a material change to this policy we’ll tell salon account holders by email before it takes effect.