Last updated:
Fiinq Ltd ("we", "us", "our") is committed to protecting the personal data of our users. This Privacy Policy explains what data we collect, how we use it, and your rights in relation to it. By using Fiinq, you agree to the practices described in this policy. This policy applies to everyone who uses Fiinq, in two distinct roles: Salon owners and staff who use the Fiinq dashboard to run their business. Customers who use the Fiinq mobile app to find salons, book appointments, message a salon, and leave reviews. Those two roles matter, because our responsibility differs between them. Where a salon enters records about its own clients into the dashboard, the salon decides how that data is used and we act on its instructions. Where you create your own Fiinq account in the mobile app, we decide how that data is used and we are directly responsible to you for it. In data protection terms we are a processor in the first case and a controller in the second, and your rights in section 9 apply to us directly in the second.
We collect the following categories of personal data: Account data: name, email address, phone number, and password (hashed) provided during registration. Business data: salon name, address, ABN/business number, and subscription details. Usage data: feature interactions, log data, IP addresses, browser type, and device information collected automatically when you use the Service. Client data: names, contact details, appointment history, and notes that you enter about your own clients. This data belongs to you. Payment data: billing address and the last four digits of your card. Full card details are handled directly by our payment processor and are never stored by us. If you use the Fiinq mobile app as a customer, we also collect the following, all of it from you and none of it from anywhere else: Your account: the name, email address and phone number you give us when you sign up, and a password we store only as a hash. We never see your password. Your bookings: which salon, which services, when, what you paid, and any request you write for the salon. Your messages: the content of messages between you and a salon, including any photos you attach. Both you and that salon can read them. Your reviews: your rating, your written review, and any photos you add. These are shown publicly on the salon's page alongside your first name. Your photos: only the images you deliberately choose from your library or camera to attach to a review or a message. The app never reads your photo library otherwise, and has no access to it until you tap to add a picture. Notification tokens: an identifier issued by Apple or Google for your device, so we can send you a booking reminder or tell you a salon has replied. It identifies the device, not you, and is deleted when you sign out or turn notifications off. Crash reports: if the app fails, a technical report of what went wrong. Personal details are stripped from these before they leave your phone — email addresses, phone numbers, postcodes and access tokens are removed automatically. We do not collect your location. The app has no access to it. We do not collect your contacts, your browsing history outside the app, or what you search for within it — searching filters a list already on your phone and is never sent to us. Card numbers are never collected by the app in either role. Card details are entered into a screen provided by our payment processor and we receive only a token, which cannot be used to reconstruct your card.
We use your data to: • Provide, operate, and maintain the Fiinq platform. • Process payments and manage your subscription. • Send transactional emails (booking confirmations, receipts, password resets). • Send service announcements and product updates (you may opt out at any time). • Improve the platform through aggregated, anonymised analytics. • Comply with legal obligations. If you use the mobile app as a customer, we also use your data to: • Make and manage your bookings, and pass the details to the salon so they can prepare. • Send you booking confirmations, reminders and changes, by email and as push notifications. • Let you and a salon message each other, and deliver the photos you attach. • Publish the reviews you choose to write. • Take a deposit, or charge a cancellation or no-show fee, where the salon's policy says so and you agreed to it when booking. • Run your loyalty progress with a salon. • Diagnose crashes so the app stops failing. • Investigate fraud and abuse, and keep people safe. We do not use your data for targeted advertising, we do not sell it, and we do not share it with data brokers.
We process your personal data on the following legal bases under the UK GDPR: Contract: processing necessary to provide the Service you have subscribed to. Legitimate interests: improving our platform, fraud prevention, and security monitoring. Legal obligation: where processing is required to comply with applicable law. Consent: for optional marketing communications, which you may withdraw at any time. For customers using the mobile app, specifically: Contract, for your account, your bookings, your messages with a salon, and any deposit or fee the salon's policy provides for. We cannot give you the service without these. Legitimate interests, for crash reporting, security, fraud prevention, and publishing reviews so other customers can judge a salon. We have considered your interests against ours in each case and you may object at any time under section 9. Consent, for push notifications and for any marketing. You can withdraw either without losing the service — turning notifications off does not stop you booking. Legal obligation, for keeping payment records for the periods in section 6. Special category data. A salon may ask you about allergies, skin conditions, pregnancy or medication, because it needs to know before treating you. That is health data, and the law treats it as more sensitive. It is collected by the salon, for the salon, on the basis of your explicit consent given to them at the time. We store it on the salon's behalf, and we do not use it for anything of our own.
We share data only where it is needed to provide the service. Below is every recipient and exactly what they receive. The salon you book with. When you book, we send that salon your name, your phone number, your email address, the services and time you booked, anything you wrote in your booking request, and your booking history with that salon. They need it to prepare for your appointment and to contact you if something changes. From that point the salon is responsible for that data under its own privacy policy, and you should read it. A salon may only send you marketing if you have separately agreed to receive it — booking an appointment is not agreement to marketing. Stripe, our payment processor. Receives your card details directly, entered into Stripe's own screen. We never see or store your card number. We receive back only a token, the card brand, the last four digits and the expiry date. Stripe acts as an independent controller for payment data under its own privacy policy, not as our processor. Sentry, our error monitoring provider. Receives technical crash reports on the European Union region. Personal details are removed before the report leaves your device — email addresses, phone numbers, postcodes, payment keys and access tokens are stripped automatically. Reports may still contain a pseudonymous account or device identifier so we can tell one person's repeated crash from many people's single crash. Apple and Google. Receive a notification token in order to deliver push notifications to your device. Supabase and Amazon Web Services, our hosting providers. Store the data described in this policy. Brevo, our email provider. Receives your email address and the content of transactional emails such as booking confirmations. Each of these is bound by a data processing agreement, except Stripe which acts as an independent controller. None of them may use your data for their own purposes. We do not sell your data, we do not share it with data brokers, and we do not use it for advertising. We will disclose data where we are legally required to, and where necessary to investigate fraud or to protect someone's safety.
We keep data only as long as we need it. These are the actual periods: Your account, while it is open. Deleted within 30 days of you closing it, except where a period below is longer. Booking and payment records: 6 years from the date of the appointment. This is not our choice — HMRC requires records supporting a transaction to be kept for six years. Messages between you and a salon: 2 years after the last message in that conversation. Messages you unsend: gone from the conversation for both sides straight away, but we keep a copy of what the message said, including any photos, for up to 90 days. This is so that a message someone has reported cannot be destroyed by deleting it. If a report about the message is still open, we keep the copy until 30 days after that report is decided. Only Fiinq can read the copy — the salon cannot, and neither can you. After that it is deleted permanently. Reviews: kept indefinitely while published. See section 13 — a review survives the deletion of your account, though we will remove your name from it on request. Photos you attach to a review or message: for as long as the review or message they belong to. Notification tokens: deleted when you sign out, turn notifications off, or delete your account. Crash reports: 90 days. Marketing consent records: 6 years after you withdraw consent, so we can show when and how consent was given if challenged. Client records a salon enters in the dashboard belong to that salon. We keep them while the salon's account is open, and for 30 days afterwards so the salon can export them, then delete them. Where we are required to keep something longer to defend a legal claim or comply with an investigation, we keep only what is necessary for that purpose.
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, role-based access controls, and regular security reviews. While we take all reasonable steps to protect your data, no system is completely secure. Please notify us immediately at security@fiinq.com if you suspect any unauthorised access to your account.
Your data is stored within the UK and European Economic Area. Our database is hosted in the EU, and our error monitoring uses Sentry's European Union region specifically so that crash reports do not leave it. Some of our providers are based outside the UK, and Stripe processes payments in the United States. Where data is transferred outside the UK we rely on either an adequacy decision by the UK government, or the UK International Data Transfer Agreement, or the UK Addendum to the European Commission's Standard Contractual Clauses. These are the transfer mechanisms recognised under UK law, and they oblige the recipient to protect your data to the UK standard. You can ask us which mechanism applies to a particular provider by writing to privacy@fiinq.com.
Under UK GDPR, you have the right to: • Access: request a copy of the personal data we hold about you. • Rectification: ask us to correct inaccurate data. • Erasure: request deletion of your personal data where there is no legitimate reason for us to continue processing it. • Restriction: ask us to pause processing your data in certain circumstances. • Portability: receive your data in a structured, machine-readable format. • Objection: object to processing based on legitimate interests. • Withdraw consent: at any time for processing based on consent. To exercise any of these rights, contact us at privacy@fiinq.com. We will respond within one month. Exercising them is free, and we will not treat you any differently for doing so. You can delete your account yourself from within the app, under Profile, without asking us. Doing so deletes the data described in section 6 on the timetable set out there. If you are not satisfied with how we have handled your data or your request, you can complain to the Information Commissioner's Office, the UK's data protection regulator. You do not need to complain to us first, though it usually helps: Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 ico.org.uk/make-a-complaint
You must be 18 or over to hold a Fiinq account. Booking an appointment creates a contract and may involve a payment, which is why we set the age there rather than lower. A parent or guardian is welcome to book an appointment for a child using their own account. In that case we hold the child's first name only if you choose to tell the salon it, and we would rather you gave that to the salon directly. We do not knowingly collect data from anyone under 18. If we learn that we have, we delete it. If you believe a child has given us their data, tell us at privacy@fiinq.com and we will remove it promptly.
One thing on Fiinq can happen automatically, without a person reviewing it first, and we think you should know exactly what it is. Cancellation and no-show fees. If a salon has set a no-show fee and you are marked as not having attended, our system can charge that fee to the card you saved, without anybody at Fiinq approving it individually. The amount is set by the salon in advance, is shown to you before you book, and can never be more than the price of the appointment you missed. You have the right to ask a person to look at it. If you are charged and you disagree — you did attend, you cancelled in time, the salon marked it wrongly, or anything else — email privacy@fiinq.com or support@fiinq.com. A person will review it, you can explain what happened, and we can reverse the charge. We will not ask you to argue with the salon first. We do not profile you, score you, or make automated decisions about what you are shown, what you are charged for a service, or whether you may use Fiinq.
A review you write is published. Specifically, we show your rating, your written review, the date, any photos you attach, and your first name with the initial of your surname. We do not publish your full name, your email address or your phone number. Two things about reviews that are easy to be caught out by, so we would rather say them plainly: A review outlives your account. If you delete your account, your reviews stay published, because the salon and other customers have relied on them. What we will do on request is remove your name from a review so it appears anonymously. Email privacy@fiinq.com and we will do it. A photo you attach to a review is public. Anyone who can see the salon's page can see it. Photos in messages to a salon are different — those are private between you and that salon. Please do not put anything in a review or a photo that you would not want a stranger to see, including other people's faces or anything identifying about them.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notice at least 14 days before the changes take effect. Your continued use of the Service after that date constitutes acceptance of the updated policy.
Who is responsible for your data: Fiinq Ltd Registered in England and Wales, company number [COMPANY NUMBER] Registered office: [REGISTERED ADDRESS] Registered with the Information Commissioner's Office, registration number [ICO REGISTRATION] For any privacy question, or to exercise any right in section 9, email privacy@fiinq.com. For a suspected security problem, email security@fiinq.com. We aim to reply within one month and will tell you if we need longer, which we may do only where a request is complex. If you are not satisfied with our response, you can complain to the Information Commissioner's Office: Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 ico.org.uk/make-a-complaint You can complain to the ICO without contacting us first, and complaining does not affect your right to a legal remedy.