Privacy Policy
Last updated: March 2026
1. Who We Are
Pivot Parlor (“we”, “us”, or “our”) is a booking platform for beauty parlours and barber shops, operated by BytesFX Ltd, registered in England and Wales.
We are the data controller for the personal data we collect to run the platform itself: enquiry and contact details, shop-owner and staff account data, and shop business data.
For customer booking data (the personal data of people who book appointments with a shop), the shop you book with is the data controller and we act as its data processor, handling that data only on the shop’s documented instructions. If you are a booking customer wishing to exercise your data rights, please contact the shop directly and see that shop’s own privacy policy. The terms on which we process booking data as a processor are set out in our Data Processing Agreement.
We are committed to protecting personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Personal Data We Collect
We collect and process the following categories of personal data:
- Enquiry and contact data: your name, email address, phone number, shop name, and message when you submit a contact or onboarding enquiry.
- Account data: email address and hashed password if you register as a shop admin or staff member, or your name and email if you sign in via a social provider (Google or LinkedIn).
- Shop and business data: your shop name, type, address, services, pricing, and staff information provided during onboarding and platform use.
- Customer booking data: customer names, email addresses, phone numbers, appointment details, and service records. For this category the shop is the data controller and we process the data on the shop’s behalf as its processor.
- Payment data: transaction amounts and booking IDs. Full payment card details are processed by Stripe and are never stored on our systems.
- Technical data: IP address, browser type and version, device type, time zone, and operating system, collected automatically when you access our website.
We do not collect sensitive personal data unless you voluntarily provide it. Our platform is not directed at children. Bookings for anyone under 18 should be made or authorised by a parent or guardian, and we do not knowingly collect personal data from children beyond what is needed to fulfil an appointment. If you believe a child has provided us with data, contact us at [email protected] to have it removed.
3. How We Use Your Personal Data
- To respond to enquiries and onboard new shops — lawful basis: legitimate interests / performance of a contract.
- To operate and deliver the platform, including processing bookings, managing staff schedules, and sending appointment reminders — lawful basis: performance of a contract.
- To process payments and calculate commissions — lawful basis: performance of a contract.
- To send service-related communications such as booking confirmations, platform updates, and account notifications — lawful basis: performance of a contract / legitimate interests.
- To comply with legal obligations — lawful basis: compliance with a legal obligation (Article 6(1)(c) UK GDPR).
4. Who We Share Your Data With
We do not sell your personal data. We may share it with the following third parties:
- Cloudflare, Inc. - our infrastructure and hosting provider (application hosting, storage, and security), acting as our processor under its Data Processing Agreement. Some data is replicated across Cloudflare’s global locations, so UK-only or EEA-only residency is not guaranteed.
- Stripe - to process payments securely, via Stripe Payments Europe, Ltd and Stripe Payments UK, Ltd, with Stripe, LLC in the United States. Stripe acts as our processor for payment facilitation and as an independent controller for fraud prevention and legal or regulatory compliance. Stripe is PCI DSS Level 1 certified and we do not store full card details. See Stripe’s Privacy Policy.
- Resend (Plus Five Five, Inc.) - to deliver transactional emails such as booking confirmations and reminders, acting as our processor. Resend processes email data in the United States.
- Law enforcement or regulators - where required by law, or to protect our rights, property, or safety.
International transfers. Some of these providers process personal data outside the UK, including in the United States. Where that happens we rely on a lawful transfer mechanism under UK data protection law, principally the UK International Data Transfer Addendum to the EU Standard Contractual Clauses and, where applicable, the UK Extension to the EU-U.S. Data Privacy Framework. How we process shop customers’ booking data as a processor is set out in our Data Processing Agreement.
Where a provider acts as our processor it must handle your data securely and only for the purposes we specify; where a provider acts as an independent controller, it does so under its own privacy policy.
5. Data Retention
- Enquiry and contact records are retained for up to 2 years.
- Account and shop data is retained for the duration of the shop’s active subscription plus 12 months after termination.
- Booking and transaction records are retained for up to 7 years to satisfy accounting and legal obligations.
- Technical and server logs are typically retained for up to 90 days.
6. Your Rights Under UK GDPR
You have the following rights in relation to your personal data:
- Right of access — to request a copy of the personal data we hold about you.
- Right to rectification — to request correction of inaccurate or incomplete data.
- Right to erasure — to request deletion of your data in certain circumstances.
- Right to restrict processing — to request that we limit how we use your data.
- Right to data portability — to receive your data in a structured, machine-readable format.
- Right to object — to object to processing based on legitimate interests or for direct marketing.
To exercise any of these rights, contact us at [email protected] or write to us at Moselle Avenue, London, UK, N22 6ET. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including HTTPS/TLS encryption, hashed password storage, session token expiry, and access controls restricting data to authorised personnel only. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where required, notify you directly.
8. Cookies
Our website uses cookies and similar technologies. See our Cookie Policy for full details on what cookies we use, why, and how to manage your preferences.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last updated” date. We encourage you to review this policy periodically.
10. Contact Us
For any privacy questions or data rights requests, contact us at [email protected] or write to Pivot Parlor, Moselle Avenue, London, UK, N22 6ET.