Privacy

What is held, who it belongs to, and who else can see it. Written against what the software does rather than from a template, so it is specific and occasionally unflattering.

Draft — not yet in force

This wording describes what the software actually does, and it has not been reviewed by a solicitor. It is missing 8 details only the business can supply: legalName, companyNumber, registeredAddress, icoRegistration, privacyEmail, contactEmail, jurisdiction, effectiveDate. Until those are filled in this page is not offered to search engines and should not be relied on by anybody.

Who is responsible for what

Two different things happen here and the law treats them differently.

A shop’s clients. When a barber, tattooist, makeup artist or nail technician uses Wunderhand, they decide what to record about the people who book with them and why. That shop is the data controller for it; we are their processor and act on their instructions. Each shop’s data sits in its own compartment, enforced by the database rather than by application code, and no shop can read another’s.

The shop itself, and visitors. For the account a shop owner signs up with, and for anybody browsing the marketplace, we are the controller. That is [legalName], company number [companyNumber], registered at [registeredAddress], ICO registration [icoRegistration].

If you booked an appointment and want to know what is held about you, the shop you booked with is the right first place to ask. Write to [privacyEmail] if that goes nowhere.

What is held about a client

To make the booking
Name, email address, phone number. Email is required for a guest booking, because it is the only way to send a confirmation and a link to change or cancel.
The appointments
What was booked, with whom, when, what it cost, what was paid, and whether it happened. Counts of visits, spend and no-shows follow from that.
What the shop writes
Notes a shop keeps on a client, and a date of birth where the shop records one.
Replies to emails
A reply to a booking email is stored against that booking so the shop can read it in context, including the address it came from.
Consent forms
Where a shop uses them: what was agreed, when, and the exact wording as it read on the day rather than as it reads now.
Health answers
Where a service needs them — allergies, medication, skin conditions. Encrypted before they are stored, with a retention date, and every read is logged against the member of staff who made it.
Photographs
Portfolio and cover images a shop uploads. These are the shop’s own material; a client who appears in one should ask the shop.

What never reaches us

Card details. Payment is handled entirely by Stripe. A deposit goes directly into the shop’s own Stripe account, in the shop’s own name — we are not in the middle of it, we never hold the money, and no card number, expiry or security code ever touches our servers or our database.

Passwords. Stored as a hash and never in a form we can read. The same goes for the link in a booking email: only a hash of it is kept, so somebody reading our database cannot use one to open a booking.

Who else sees it

Only the companies that run parts of the service, each doing one job:

Stripe
Payments, deposits and refunds, and the shop’s own subscription. Holds card details; we do not.
Resend
Sends confirmations, reminders and password resets, and receives replies to them.
Neon
The database everything is stored in.
Vercel
Runs the site and serves every page.
Backblaze
Stores the photographs a shop uploads.
Google Fonts
The typeface on these pages is fetched from Google when the page loads, which tells Google the reader’s IP address. Nothing else is sent, and there is no analytics, advertising or tracking of any kind on this site.

Nothing is sold, and nothing is shared for advertising. There is no analytics package, no advertising pixel and no third-party tracker anywhere on the site.

Cookies

One, and only once you sign in: the cookie that keeps you signed in. There is no cookie banner because there is nothing to ask about — no analytics, no advertising, and nothing set for anybody who is only reading or booking.

How long it is kept

Booking links
The link in a confirmation or reminder email stops working after 30 days.
Health answers
Kept until the retention date the shop set, then deleted outright — not flagged as deleted.
Appointments
Kept while the shop is a customer, because they are the shop’s own trading records and its takings depend on them.
Email delivery log
Every send attempt and whether it worked, so “no email arrived” is a question with an answer. Recipient address and subject, not the message.

Your rights, and one honest limit

You can ask for a copy of what is held about you, ask for it to be corrected, ask for it to be deleted, object to how it is being used, and complain to the Information Commissioner’s Office. Where the data belongs to a shop’s clients, those requests go to the shop, and we help the shop answer them.

The limit, stated plainly. Removing a client from a shop’s list currently marks the record as deleted and hides it, rather than erasing it — their past appointments are part of the shop’s own accounts. A genuine erasure request has to reach the consent and health records as well, and today that is done by hand rather than by a button. Health records already delete properly. Ask at [privacyEmail] and it will be done; we would rather say that than imply a button exists that does not.

Where it is stored

The database and the servers that run the site are in the European Union. Stripe, Resend, Backblaze and Google are each their own companies with their own arrangements for moving data outside the UK and the EU, and each publishes them.

Changes

This wording took effect on [effectiveDate]. If it changes in a way that matters, shops are told before it takes effect.