Privacy

Privacy Policy

Last updated: 23 June 2026.

Draft — pending legal review.This is a working draft that illustrates Stikky’s intended terms. It is not yet final or legally binding and must be reviewed by a qualified solicitor before launch.

This policy explains how Bravo Marketing Ltd (company 10168703), operator of Stikky Members, handles personal data. Contact: privacy@stikkymembers.com.

1. Roles

We are the data controller for the Stikky platform and for salon-owner accounts. For a salon’s members, the salon is the controller of the membership relationship; we process member data to operate the platform and to create the consent record.

2. What we collect

Salon owners: your name, email, and Google profile basics (via sign-in), plus your salon details and Stripe connection status. Members: your name, email, and a consent record (the terms version accepted, timestamp, IP address, and browser user-agent). Payment and card data are handled by Stripe — we never receive your full card number.

3. How we use it & lawful bases

To provide the service (performance of a contract), to record consent and meet legal obligations, to send transactional email about your account or membership, and to protect the platform (legitimate interests). We don’t use your data for advertising.

4. Who we share it with

Service providers who help us run Stikky: Stripe (payments & Connect), Postmark (transactional email), Cloudflare R2 (image storage), and our database/hosting providers (Neon, UpCloud). They process data on our instructions. We don’t sell personal data.

5. Retention

We keep consent records for as long as needed to evidence what was agreed (and as required by law). Dormant salon accounts are deleted after the inactivity window described in our Business Terms. You can ask us to delete data sooner where no legal basis requires us to keep it.

6. Your rights

You have rights to access, correct, delete, and port your data, and to object to or restrict certain processing. To exercise them, email privacy@stikkymembers.com. You can also complain to the UK ICO.

7. International transfers & security

Where data is processed outside the UK/EEA, we rely on appropriate safeguards. We use technical and organisational measures to protect your data, including encryption in transit.

8. Changes

We may update this policy and will post the revised version here.