Barbalon

Privacy Policy

Last updated: June 2026

This Privacy Policy explains how Kye Atkinson, trading as Barbalon (“Barbalon”, “we”, “us”) collects, uses and protects personal data when you use our websites, apps and booking platform (the “Service”). We are the data controller for the information described here. We comply with the UK GDPR and the Data Protection Act 2018.

1. Information we collect

  • Shop account data — name, business name, email, phone and login details of the barbers and salons that subscribe.
  • Booking data — when a client books an appointment we process their name, contact details and appointment information on behalf of the Shop.
  • Payment data — payments are handled by Stripe; we do not store full card details. We receive limited information such as payment status and the last digits of a card.
  • Usage data — basic technical information such as device type, pages viewed and approximate location, used to keep the Service secure and improve it.

2. How we use it

  • To provide, operate and support the Service.
  • To process subscriptions and take payments.
  • To send service-related messages, such as booking confirmations and reminders.
  • To keep the Service secure and prevent fraud or abuse.
  • To comply with our legal obligations.

Our lawful bases are performance of a contract, our legitimate interests in running and improving the Service, and compliance with legal obligations.

3. Controllers and processors

For booking data belonging to a Shop’s clients, the Shop is the data controller and Barbalon acts as a data processor, handling that data only to provide the Service. For Shop account data and the running of the platform itself, Barbalon is the controller.

4. Sharing your data

We share data only with the service providers needed to run the platform, including:

  • Stripe — payment processing.
  • Supabase — database and authentication hosting.
  • Netlify — website hosting.
  • Email and notification providers used to deliver confirmations and reminders.

We do not sell your personal data. Where providers process data outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement.

5. Retention

We keep personal data for as long as needed to provide the Service and to meet legal, accounting and reporting requirements. When it is no longer needed we delete or anonymise it.

6. Your rights

Under UK data-protection law you have the right to access, correct, delete or restrict the processing of your personal data, to object to processing, and to data portability. To exercise these rights email hello@barbalon.co.uk. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.

7. Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls and reputable hosting providers. No system is completely secure, but we work to keep your data safe.

8. Cookies

We use only the cookies and similar technologies necessary to run the Service and keep it secure. We do not use advertising-tracking cookies.

9. Changes

We may update this policy from time to time. We will post the updated version here and change the “last updated” date above.

10. Contact

For any privacy question, email hello@barbalon.co.uk or write to [Registered/trading address].