What is held, who it belongs to, and who else can see it. Written against what the software does rather than from a template, so it is specific and occasionally unflattering.
Draft — not yet in force
This wording describes what the software actually does, and it has not been reviewed by a solicitor. It is missing 8 details only the business can supply: legalName, companyNumber, registeredAddress, icoRegistration, privacyEmail, contactEmail, jurisdiction, effectiveDate. Until those are filled in this page is not offered to search engines and should not be relied on by anybody.
Two different things happen here and the law treats them differently.
A shop’s clients. When a barber, tattooist, makeup artist or nail technician uses Wunderhand, they decide what to record about the people who book with them and why. That shop is the data controller for it; we are their processor and act on their instructions. Each shop’s data sits in its own compartment, enforced by the database rather than by application code, and no shop can read another’s.
The shop itself, and visitors. For the account a shop owner signs up with, and for anybody browsing the marketplace, we are the controller. That is [legalName], company number [companyNumber], registered at [registeredAddress], ICO registration [icoRegistration].
If you booked an appointment and want to know what is held about you, the shop you booked with is the right first place to ask. Write to [privacyEmail] if that goes nowhere.
Card details. Payment is handled entirely by Stripe. A deposit goes directly into the shop’s own Stripe account, in the shop’s own name — we are not in the middle of it, we never hold the money, and no card number, expiry or security code ever touches our servers or our database.
Passwords. Stored as a hash and never in a form we can read. The same goes for the link in a booking email: only a hash of it is kept, so somebody reading our database cannot use one to open a booking.
Only the companies that run parts of the service, each doing one job:
Nothing is sold, and nothing is shared for advertising. There is no analytics package, no advertising pixel and no third-party tracker anywhere on the site.
One, and only once you sign in: the cookie that keeps you signed in. There is no cookie banner because there is nothing to ask about — no analytics, no advertising, and nothing set for anybody who is only reading or booking.
You can ask for a copy of what is held about you, ask for it to be corrected, ask for it to be deleted, object to how it is being used, and complain to the Information Commissioner’s Office. Where the data belongs to a shop’s clients, those requests go to the shop, and we help the shop answer them.
The limit, stated plainly. Removing a client from a shop’s list currently marks the record as deleted and hides it, rather than erasing it — their past appointments are part of the shop’s own accounts. A genuine erasure request has to reach the consent and health records as well, and today that is done by hand rather than by a button. Health records already delete properly. Ask at [privacyEmail] and it will be done; we would rather say that than imply a button exists that does not.
The database and the servers that run the site are in the European Union. Stripe, Resend, Backblaze and Google are each their own companies with their own arrangements for moving data outside the UK and the EU, and each publishes them.
This wording took effect on [effectiveDate]. If it changes in a way that matters, shops are told before it takes effect.