BarberPlace logo BarberPlace
← Back to Home

Privacy Policy

Last updated: 25 June 2026

Your Privacy Matters: This Privacy Policy explains how BarberPlace collects, uses, and protects your personal data. We are committed to full transparency and compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

πŸ“‹ Contents

  1. Introduction
  2. Who We Are (Data Controller)
  3. Data We Collect
  4. How We Use Your Data
  5. Legal Basis for Processing
  6. Data Sharing
  7. Data Retention
  8. Your Rights Under UK GDPR
  9. Data Security
  10. Cookies
  11. International Transfers
  12. Children's Privacy
  13. Changes to This Policy
  14. Contact Us

1. Introduction

BarberPlace ("we", "us", "our") operates BarberPlace (barberplace.co.uk). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.

By using BarberPlace, you consent to the data practices described in this policy. If you do not agree, please do not use our platform.

2. Who We Are (Data Controller)

BarberPlace is the Data Controller for personal data collected through BarberPlace. If you have any questions about this policy or how we handle your data, please contact us:

Company: BarberPlace

Email: privacy@barberplace.co.uk

Website: barberplace.co.uk

3. Data We Collect

3.1 Information You Provide

For Barbers:

  • Full name and email address
  • Password (encrypted β€” we cannot see this)
  • UK postcode and derived location (district, region, coordinates)
  • Profile information (bio, availability dates, portfolio photos)
  • Login activity (count and timestamps)

For Salons:

  • Contact name and email address
  • Business name, phone number, and website
  • UK postcode and derived location
  • Login activity (count and timestamps)

For Admins:

  • Email address and password (encrypted)
  • Multi-factor authentication credentials (TOTP secret β€” stored encrypted)
  • Audit log of admin actions

3.2 Information Collected Automatically

  • IP addresses (for security and rate limiting)
  • Session data (to keep you logged in)
  • Login timestamps and frequency
  • Basic browser and device information (security logging only)

3.3 Information from Third Parties

  • Google (Sign in with Google): If you choose to sign in using your Google account, we receive your name and email address from Google. We do not receive your Google password or any other Google account data. Your Google sign-in is governed by Google's Privacy Policy.
  • Postcodes.io: We send only your postcode to convert it to geographic coordinates. No personal identifiers are shared with this service.
  • Cloudinary: Profile and offer photos are stored on Cloudinary's servers. Their privacy policy applies to stored images.

4. How We Use Your Data

Service Delivery (Contract Performance)

  • To create and manage your account
  • To match barbers with salons based on availability and location
  • To enable direct messaging between barbers and salons
  • To display barber profiles in search results
  • To show distance-based search results to salons

Security and Fraud Prevention (Legitimate Interest)

  • To protect against unauthorised account access
  • To enforce rate limiting and prevent abuse
  • To maintain audit logs of admin actions
  • To require email verification for new accounts

Communications (Legitimate Interest)

  • To send account verification emails
  • To notify salons of application approval or rejection
  • To notify admins of new salon applications and offer interest
  • To send password reset emails when requested

5. Legal Basis for Processing

Under UK GDPR, we rely on the following legal bases:

  • Contract Performance: Processing necessary to provide our services (account creation, matching, messaging)
  • Legitimate Interests: Security logging, fraud prevention, platform improvement, and business communications
  • Consent: If we introduce marketing communications in future, we will seek explicit consent first
  • Legal Obligation: Complying with applicable UK laws and regulations

6. Data Sharing

We do not sell your personal data. We share data only in these circumstances:

Within the Platform

  • Barber profiles (name, location, availability, bio, photos) are visible to approved salons
  • Salon contact details are shared with admins when a salon expresses interest in an offer

Third-Party Service Providers

  • Render.com: Our hosting provider β€” all application data is stored on their servers
  • Cloudinary: Stores profile photos and offer images
  • Brevo: Sends transactional emails (only name and email are shared)
  • Postcodes.io: Receives postcodes for geocoding (no personal identifiers shared)

Legal Requirements

  • We may disclose data if required by law, court order, or to protect the rights and safety of users

7. Data Retention

  • Active accounts: Data retained for the duration of your account
  • Deleted accounts: When you request account deletion via Settings, your account is immediately deactivated and permanently deleted after a 7-day grace period. You will receive a confirmation email with a cancellation link. After 7 days, all personal data is permanently erased.
  • Messages β€” one party deletes: If you delete your account, your messages are anonymised (your name is replaced with "Account deleted") but the conversation is preserved for the other party. Your identity is no longer linked to those messages.
  • Messages β€” both parties delete: When both parties in a conversation have deleted their accounts, the conversation is retained for 12 months to allow for any legal or law enforcement requests, then permanently deleted.
  • Reported messages: Conversations containing a report are retained until the report is resolved plus 6 months, regardless of account deletion status.
  • Audit logs: Retained for 6 years as required under UK law for compliance and legal obligation purposes. These logs are anonymised if your account is deleted (user ID set to null β€” no link to you personally).
  • Security logs: Retained for 12 months
  • Email logs: Retained for 90 days
  • Database backups: Retained for 7 days (Render PostgreSQL policy)

You can delete your account at any time via Settings β†’ Delete Account. You do not need to contact us β€” deletion is fully self-service.

8. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

πŸ“‹ Right of Access Request a copy of your personal data we hold
✏️ Right to Rectification Correct inaccurate or incomplete data
πŸ—‘οΈ Right to Erasure Request deletion of your personal data ("right to be forgotten")
⏸️ Right to Restriction Request we limit how we process your data
πŸ“¦ Right to Portability Receive your data in a structured, machine-readable format
🚫 Right to Object Object to processing based on legitimate interests

To exercise any of these rights, contact us at privacy@barberplace.co.uk. We will respond within 30 days.

βš–οΈ Right to Complain: You also have the right to lodge a complaint with the UK supervisory authority if you believe your rights have been violated:

Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113

9. Data Security

We implement appropriate technical and organisational measures to protect your data:

  • Passwords: Hashed using bcrypt β€” we cannot see your password
  • HTTPS: All data transmitted over encrypted connections
  • Admin access: Mandatory two-factor authentication (TOTP) for all admin accounts
  • Rate limiting: Protection against brute force attacks
  • Session security: Secure, HttpOnly cookies
  • Input validation: All user inputs sanitised to prevent injection attacks
  • Bot protection: Cloudflare Turnstile on registration and login

Despite these measures, no internet transmission is 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the ICO within 72 hours.

10. Cookies & Local Storage

We use the following cookies and browser storage:

  • Session cookie: Keeps you logged in during your visit. Stored server-side in our secure database.
  • Security cookies: Used for CSRF protection and rate limiting
  • Cookie consent (localStorage): Remembers that you have acknowledged our cookie notice, so we don't show it on every visit

We do not use advertising cookies, analytics cookies, or third-party tracking cookies. We do not use Google Analytics or any other tracking services.

11. International Transfers

Your data is primarily processed and stored in the UK and EU. Our service providers (Render, Cloudinary, Brevo) may process data in other countries. Where data is transferred outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.

12. Children's Privacy

BarberPlace is not intended for use by persons under the age of 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us immediately at privacy@barberplace.co.uk.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of significant changes by email. The "Last updated" date at the top of this policy indicates when it was last revised. Continued use of the platform after changes constitutes acceptance of the updated policy.

14. Contact Us

For any privacy-related questions, requests, or complaints:

Email: privacy@barberplace.co.uk

Company: BarberPlace

Website: barberplace.co.uk

πŸ›οΈ UK Supervisory Authority:

Information Commissioner's Office (ICO)
ico.org.uk | 0303 123 1113

© 2026 BarberPlace Β· BarberPlace Β· Terms of Service