Effective 21 September 2026

Privacy Policy

PrimpHub connects customers with beauty and wellness professionals — hair, nails, lashes, brows, makeup, massage, barbering, skin and more. To do that we hold personal information about you. This policy explains, in full, what we collect, why and on what legal basis, who sees it, where it is stored, how long we keep it, how we protect it, and what you can do about it. It applies to primphub.com, the PrimpHub customer app and the PrimpHub Studio app for professionals.

  1. 1. Who we are and how to reach us
  2. 2. Who this policy covers
  3. 3. What we collect, and where it comes from
  4. 4. Why we use it, and the legal basis
  5. 5. Who we share it with
  6. 6. Location data in detail
  7. 7. Cookies and similar technologies
  8. 8. How long we keep it
  9. 9. Your rights
  10. 10. What deleting your account actually does
  11. 11. How we protect it
  12. 12. Children
  13. 13. Where your data is stored and international transfers
  14. 14. Links and third-party services
  15. 15. Extra notes for professionals and salons
  16. 16. Changes to this policy

1. Who we are and how to reach us

PrimpHub ("PrimpHub", "we", "us") operates the PrimpHub marketplace, website and mobile apps from London, United Kingdom. For the information described in this policy we are the data controller: we decide what is collected and why.

Our privacy team can be reached at support@primphub.com, or by post at PrimpHub, London, United Kingdom. Write "Privacy" in the subject line and we will route it to the right person. We aim to acknowledge within two working days and to resolve within one month.

Professionals and salons are separate controllers for the records they keep about their own clients: their private notes on a visit, allergies you have told them, photos they take of their work with your permission, and anything they record outside PrimpHub. When you book, you share your details with them under their own responsibility, and questions about how a particular professional uses your data should go to them first. This policy covers what PrimpHub itself does.

2. Who this policy covers

This policy applies to everyone who uses PrimpHub, and the sections below say when something applies only to one group:

  • Customers — people who browse, book and pay for services.
  • Professionals — people who list services and take bookings, whether independent, mobile, or part of a salon or studio.
  • Team members — staff invited into a salon's PrimpHub account by its owner.
  • Visitors — anyone reading primphub.com without an account.
  • Emergency contacts — people named by a user in the home-visit safety check-in, who may receive a message from us without having an account.

PrimpHub is for people aged 18 and over. See Children.

3. What we collect, and where it comes from

Most of what we hold, you give us directly. Some is generated by using the service. A little comes from third parties you have chosen to connect. Category by category:

Account and identity — name, email address, phone number, password (held only as a one-way hash by our authentication provider; we cannot read it), profile photo, date you joined, preferred language, country and currency, the kind of account you hold, and whether your email and phone have been confirmed.

Customer beauty profile (optional) — allergies, hair type, skin type, sensitivities and preferences you choose to tell us, so a professional can prepare. You can leave every one of these blank.

Professional business profile — business name, description, category, services and prices, opening hours, business address and the coordinates it geocodes to, the area you cover for home visits, travel fee rules, portfolio photos and videos, cancellation and deposit policies, and your public page's URL slug.

Verification documents (professionals) — photo ID, business registration, insurance certificates, qualification certificates, DBS certificates and home-visit or infection-control training certificates you upload for a badge, plus the expiry dates and our decision.

Bookings — services, staff member, date and time, price, deposit, location type (salon or home visit), the address given for a home visit, notes either side adds, promo codes and loyalty points used, status changes (confirmed, moved, cancelled, no-show, completed) and who made each change, and the reason for a cancellation.

Payments — amounts, currency, payment method type, the last four digits and card brand, status, refunds, commission and the professional's share, and receipts and invoices. Full card numbers never reach PrimpHub: they go straight from your device to our payment provider, who gives us a token. For professionals: the bank account name, sort code and last four digits of the account payouts go to, and each payout's amount and status.

Messages — the text, photos and attachments in conversations inside PrimpHub, when they were sent and read, and — where a professional has connected Instagram or Facebook — messages from those platforms that they have chosen to bring into their PrimpHub inbox.

Reviews — the rating and words you leave after an appointment, the professional's reply, and any report made about a review.

Cases, complaints and disputes — what you write when you raise a case, evidence you attach, the other party's response, our team's notes and the outcome.

Safety check-in (optional) — the emergency contact's name and phone number you provide, the check-in and check-out times, and — only if you switch it on — your device's location at check-in and when an alert is sent.

Calendar sync (optional, professionals) — when you connect Google Calendar or Apple Calendar, the busy/free times of the calendar you choose, and the details of PrimpHub bookings we write to it.

Social accounts (optional, professionals) — when you connect Instagram or Facebook, your account identifier, the access token Meta issues us, and the messages and comments the connection is for.

Device and usage — device type and operating system, app version, a push-notification token, IP address, the pages and screens you view and the actions you take, the time of each request, referring links and the campaign tags on them, crash reports and error logs, and — only with your permission — your approximate location to sort professionals by distance.

Communications with us — emails, support cases and anything you send to support@primphub.com.

Emergency contacts — the name and phone number of a person you have named; we hold no other information about them.

4. Why we use it, and the legal basis

UK GDPR requires a lawful basis for each use. These are ours.

To provide the service you have asked for (performance of a contract):

  • Creating and securing your account; signing you in; resetting your password.
  • Showing professionals' profiles and availability; taking bookings; sending confirmations, reminders and changes.
  • Processing payments, deposits, refunds and payouts, and producing receipts and invoices.
  • Delivering messages between customers and professionals.
  • Running the professional tools: calendar, clients, team, rota, stock, promotions, loyalty schemes, finance reports.
  • Operating the free month and subscription plans, and billing for them.

Safety, trust and preventing abuse (our legitimate interests, and in some cases legal obligation):

  • Verifying professionals' identity, insurance, qualifications and checks, and showing the badges that result.
  • Handling complaints, disputes and reviews fairly, which means showing each side what the other has said.
  • Detecting fraud, repeat no-shows, fake reviews and misuse; rate-limiting and blocking abusive traffic.
  • Running the home-visit safety check-in and alerting the contact you named.
  • Keeping an audit trail of privileged actions by our staff.

Improving PrimpHub (legitimate interest): measuring which features are used, fixing crashes and errors, understanding where bookings come from, and testing changes. We use aggregated figures wherever they answer the question.

Telling you about PrimpHub (consent, or legitimate interest for service messages): service messages — a change to these terms, a security notice, a reminder that your free month is ending — are sent because you have an account. Tips, offers and news are sent only if you have opted in, and every one has an unsubscribe link. Professionals may receive occasional messages about tools relevant to their business, which they can switch off in Notification settings.

Legal obligations: keeping financial records for tax and accounting law; responding to lawful requests from courts, police or regulators; complying with anti-money-laundering rules through our payment provider.

With your consent, which you can withdraw at any time: using your device location; sharing your location in a safety check-in; connecting a calendar or social account; marketing email; using your photo in a professional's portfolio.

We do not make decisions about you by automated means that have legal or similarly significant effects. Search rankings and "top rated" sorts are based on distance, ratings and availability, not on profiling you.

5. Who we share it with

Between customers and professionals. This is the point of the service, so it is worth being precise.

  • A professional you book sees your name, profile photo, phone number (once confirmed), the booking details, notes you add, your beauty profile if you have filled it in, messages you send them, and your booking history with them. For a home visit they see your address once the booking is confirmed. They never see your payment card details or your other bookings.
  • A customer sees a professional's public profile: business name, photo, description, services and prices, portfolio, opening hours, area and — once a salon booking is confirmed — the exact address, plus reviews, verification badges and reply messages. They never see a professional's bank details, earnings, other clients or private notes.
  • In a salon, team members and managers see the bookings and client records their role allows. The owner sets roles.
  • When you raise a case, the other party is shown what you wrote so they can respond.

Service providers who process data for us under contract, only on our instructions and only for the purpose stated:

  • Supabase — database hosting, authentication (including password hashing), and file storage for photos and documents.
  • Vercel — hosting the website and API.
  • Stripe — card, Apple Pay, Google Pay and PayPal payments; refunds; payouts to professionals' bank accounts; identity checks required for payouts.
  • Resend — sending email (confirmations, receipts, reminders, security notices).
  • Twilio — sending SMS where you have a phone number and the notification warrants it.
  • Expo — delivering push notifications to the apps, together with Apple and Google's notification services.
  • PostHog — product analytics (which screens are used, where bookings come from).
  • Sentry — error and crash reporting.
  • postcodes.io — turning a UK postcode into map coordinates. Only the postcode is sent.
  • Apple and Google — maps and directions in the apps; calendar sync where you connect it; the app stores themselves.
  • Meta (Instagram and Facebook) — only for professionals who connect an account, to read and reply to the messages they have chosen to bring in.

Emergency contacts you have named receive, by SMS, the fact that you have not checked out of a home-visit appointment, the appointment's time and place, and your location if you chose to share it.

Authorities and legal process — police, courts, regulators or HMRC when the law requires it, or when we believe in good faith it is necessary to prevent serious harm. We record every such disclosure.

A buyer — if PrimpHub is sold or merged, your data would pass to the new owner under this policy; we would tell you first.

We do not sell personal information, and we do not share it with advertisers or data brokers.

6. Location data in detail

Location deserves its own section because it is sensitive and we use it in three distinct ways.

  • Sorting by distance — with your permission, the app reads your device's approximate location to show who is nearest and how far away each professional is. This is used on your device for that sort and is not stored on our servers or shown to professionals. You can refuse and use the "search around" chip to type an area instead; that typed area is stored on your device only.
  • Addresses — a professional's business address, and a customer's address for a home visit, are stored because the appointment happens there. Addresses are geocoded to coordinates so directions work.
  • Safety check-in — only if you switch it on for a particular check-in, your location is recorded at check-in and when an alert is sent, shared with your named contact if an alert goes out, and deleted 24 hours after the check-in ends unless an alert was sent, in which case it is kept with the incident record.

7. Cookies and similar technologies

On primphub.com we use a small number of cookies and local-storage keys:

  • Strictly necessary — the session cookie that keeps you signed in, a security token that protects forms, and your language and currency preference. These cannot be switched off without breaking the site.
  • Attribution — when you arrive from a professional's Instagram, TikTok or other tagged link, a cookie remembers that channel for up to 30 days so the professional can see which links bring bookings. It contains the channel name and campaign tag only.
  • Analytics — PostHog sets a cookie and a local-storage key to tell repeat visits apart. It does not track you across other websites and we do not use it for advertising. You can block it with your browser's cookie controls or a content blocker without affecting the site, and you can ask us to exclude your account from analytics at support@primphub.com.

We do not use advertising cookies or third-party ad networks. The apps use equivalent on-device storage for the same purposes (sign-in, preferences, cached data) and never third-party advertising identifiers.

8. How long we keep it

We keep data for as long as it is needed for the purpose it was collected, then delete or anonymise it. The specific periods:

  • Account and profile — while your account is open. After a confirmed erasure request, deleted within 30 days.
  • Bookings, payments, invoices and payouts6 years from the transaction, as UK tax and accounting law requires. When you erase your account these records are anonymised: the amounts, dates and services stay for the accounts; your name, contact details and notes are removed.
  • Messages — while both accounts exist. Deleted with the account, except where a message is evidence in an open case, in which case it is kept with the case.
  • Reviews — while the professional's profile exists. If you erase your account the review stays, attributed to "a customer", because it is part of the professional's public record; you can ask us to remove it instead.
  • Cases, complaints and disputes — 6 years after closure, so that a pattern of behaviour can be evidenced and legal claims defended.
  • Verification documents — while the badge is valid and for 12 months after it expires or the professional leaves, so a renewal or a dispute about a badge can be checked. Documents are deleted with the account on erasure; the fact that a check was passed, and when, is kept with the anonymised record.
  • Safety check-in location — 24 hours after the check-in ends, unless an alert was sent.
  • Emergency contact details — until you remove them or erase your account.
  • Calendar and social connections — until you disconnect them; tokens are revoked at that point.
  • Analytics and usage — 12 months, then only aggregated figures.
  • Error and crash logs — 90 days.
  • Server request logs — 30 days.
  • Audit log of staff actions — 6 years.
  • Support emails — 2 years after the last message.
  • Backups — encrypted database backups are kept for 30 days and then overwritten; deleted data may persist in a backup for that period and is not restored to the live service.

9. Your rights

Under UK GDPR (and the EU GDPR where it applies) you have the right to:

  • Access — a copy of the personal data we hold about you, and the information in this policy.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — have your data deleted where there is no longer a reason to keep it (the financial retention above is such a reason; those records are anonymised instead).
  • Restriction — have processing paused while a dispute about accuracy or lawfulness is resolved.
  • Portability — receive the data you gave us in a machine-readable format, and have it sent to another service where technically feasible.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time (which we will always stop).
  • Withdraw consent — for anything based on consent, without affecting what was done before.
  • Not be subject to automated decisions with legal or similarly significant effects. We make none.

Most of this you can do yourself, instantly. In the apps: More → Your data & privacy lets you download everything we hold as a file and request erasure; More → Profile corrects your details; Notification settings controls marketing; the phone's settings control location. On the website, Your data does the same. Anything else, email support@primphub.com.

We respond within one month. We may ask you to confirm your identity — usually by replying from the email on the account — so that we do not hand your data to someone else. We do not charge for requests unless they are manifestly unfounded or excessive.

If you are unhappy with how we handle your data or your request, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to resolve it first.

10. What deleting your account actually does

Because people ask, precisely:

  • Your profile, photos, beauty profile, favourites, preferences, device tokens and sign-in are deleted.
  • Your messages are deleted from your side and from the other party's view, except messages held as evidence in an open case.
  • Bookings and payments are anonymised: your name, contact details, address and notes are removed; the transaction stays for 6 years.
  • Reviews you wrote remain as "a customer" unless you ask for them to be removed.
  • Cases are kept, with your name replaced, for the period above.
  • For professionals: your public page is removed from search and returns "not found"; your subscription is cancelled; your clients' booking history with you stays in their accounts with your business name; team members are detached.

Before erasure runs we check for blockers — upcoming bookings, money still owed to or by you, an open dispute — and tell you what needs clearing. You can withdraw the request while it is pending.

11. How we protect it

  • All data is encrypted in transit (TLS 1.2 or higher) and at rest.
  • Passwords are never stored in readable form. New passwords must be at least 8 characters and are checked against known breached-password lists.
  • Card numbers never touch our systems; Stripe is a PCI-DSS Level 1 provider. Bank account numbers are stored encrypted with only the last four digits readable.
  • Access inside PrimpHub is limited by role. Our staff see only what their job needs, every privileged action is logged with the reason, and the log is reviewed.
  • Sessions can be ended from Security in the app — sign out everywhere if a device is lost.
  • Abusive traffic is rate-limited; repeated failed sign-ins slow down and are logged.
  • Verification documents are stored in private buckets accessible only to our verification team through signed, expiring links.
  • Backups are encrypted and access-controlled.

No system is perfectly secure. If we discover a breach that puts you at risk we will tell you and the ICO without undue delay, and within 72 hours where the law requires it.

12. Children

PrimpHub is for people aged 18 and over. We do not knowingly collect information about anyone under 18. If you are a parent or guardian and believe a child has created an account, email us and we will delete it. Professionals who treat minors do so under their own responsibility and outside PrimpHub's booking of the minor.

13. Where your data is stored and international transfers

Our database, file storage and web hosting are in the United Kingdom and the European Union. Some providers process data in the United States: Stripe (payments), Expo (push notifications), Resend (email), Twilio (SMS), PostHog (analytics) and Sentry (error reports). Each transfer is covered by the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, and by the provider's own security certifications. Where we serve professionals in other regions, their data is held in the same UK/EU systems.

14. Links and third-party services

Professionals' profiles may link to their own websites and social accounts; those sites have their own policies. When you connect Instagram, Facebook, Google Calendar or Apple Calendar, the platform's own terms apply to what happens on their side, and you can revoke PrimpHub's access in that platform's settings as well as in ours.

15. Extra notes for professionals and salons

As a professional you are a controller for your clients' data. Practically, that means:

  • Use client details only for the appointment and your relationship with that client. Do not export them to market unrelated businesses or share them with anyone else.
  • Private notes are for professional purposes. Clients can ask you for a copy of notes about them.
  • If a client asks you to delete their data, tell us as well as acting on your own records, so we can handle the PrimpHub side.
  • Photos of a client's results need their permission before going in your portfolio or on social media.
  • Team members you invite see client data according to the role you give them; you are responsible for setting roles appropriately and removing people who leave.
  • When you connect Instagram or Facebook, messages from those platforms are stored in PrimpHub under this policy.

We provide the tools — exports, deletion, roles, audit — to help you meet these duties.

16. Changes to this policy

When we change this policy in a way that matters — a new purpose, a new category of data, a new kind of recipient — we will tell you in the app and by email before it takes effect, and where the law requires it we will ask for your consent. Minor clarifications are made without notice. The date at the top is the version in force, and earlier versions are available on request.