Privacy Policy

Last Updated: February 2026

1. Introduction

Trimlinea ("we", "us", "our") provides a white-label booking platform for barbershops, salons, and similar service businesses ("Clients"). This Privacy Policy explains how we collect, use, and protect personal information.

This policy covers:

  • Visitors to our marketing website (trimlinea.co.uk)
  • Sales leads and prospective customers
  • Client business users (administrators, barbers, staff) who use our platform
  • Support ticket and enquiry handling
  • Our role as a data processor for Client customer data

For End-Customers: If you book an appointment through a business using our platform, that business is the data controller for your booking data. Please refer to their privacy policy. This policy explains our role as their data processor.

2. Who We Are

Data Controller (for our own processing):

Trimlinea
4th Floor, 14 Museum Place, Cardiff, CF10 3BH
[email protected]

Business Type: Sole Trader
ICO Registration: ZC083991

3. Our Role: Controller vs Processor

We act in different capacities depending on whose data we're processing:

Data SubjectOur RoleData Controller
Marketing website visitorsControllerTrimlinea
Sales leads & prospectsControllerTrimlinea
Client business users (admins, barbers)ControllerTrimlinea
Support ticket submittersControllerTrimlinea
End-customers booking appointmentsProcessorThe Client business
End-customers (platform feedback)ControllerTrimlinea

4. Information We Collect

4.1 Marketing Website Visitors

When you visit trimlinea.co.uk, we may collect:

DataSourcePurpose
IP addressAutomaticSecurity, analytics (with consent)
Browser/device informationAutomaticWebsite optimisation
Pages visitedAutomatic (with consent)Analytics to improve our site
Referral sourceAutomatic (with consent)Marketing effectiveness

Cookies: We use essential cookies and, with your consent, analytics cookies. See our Cookie Policy.

4.2 Sales Leads & Prospects

When you enquire about our services or request a demo, we collect:

DataPurposeLegal Basis
NameIdentify youLegitimate interest
Email addressRespond to your enquiryLegitimate interest
Phone number (optional)Follow-up callsLegitimate interest
Business nameUnderstand your needsLegitimate interest
Enquiry detailsProvide relevant informationLegitimate interest

4.3 Client Business Users

When Clients register and use our platform, we collect data about their administrators, barbers, and staff:

Account Registration:

DataPurpose
First name, last nameUser identification
Email addressLogin, communications
Phone number (optional)Account recovery, support
Password (hashed)Account security
Role (Admin/Barber)Access control

Professional Profile (Barbers):

DataPurpose
BioDisplay on booking page
SpecialtyService matching
Profile photoVisual identification
Job titleDisplay purposes

Business Information:

DataPurpose
Business namePlatform branding
Business addressLocation display, compliance
Business email & phoneContact purposes
Logo & brandingWhite-label customisation

Financial Data:

DataPurpose
Stripe Account IDPayment processing
Commission settingsRevenue splitting
Subscription detailsBilling management
Payment historyInvoicing, support

Usage Data:

DataPurpose
Login timestampsSecurity monitoring
Actions performedAudit trail
IP addressesSecurity, fraud prevention
Feature usageProduct improvement

4.4 Support Tickets & Communications

When you contact our support team:

DataPurpose
Name, emailIdentify you, respond
Ticket contentResolve your issue
Attachments (if provided)Troubleshooting
Conversation historyContext for support

4.5 End-Customer Data (As Processor)

When end-customers book appointments through Client websites, we process their data on behalf of our Clients:

Data ProcessedPurpose
NameBooking identification
EmailBooking confirmations
Phone (optional)Contact for bookings
Booking detailsService delivery
Payment informationTransaction processing
NotesService customisation

Important: We only process this data according to our Client's instructions. We do not use end-customer data for our own marketing.

4.6 Platform Feedback (As Controller)

We may contact end-customers who have booked appointments through our platform to request feedback about the booking experience. For this limited purpose, we act as an independent data controller.

Data UsedPurposeLegal Basis
Email addressSend feedback requestLegitimate interest
Booking referenceContext for feedbackLegitimate interest

Your rights:

  • Every feedback email includes an unsubscribe link
  • We honour opt-out requests within 48 hours
  • We do not use this data for marketing or share it with third parties
  • The Client business may also opt out its customers from feedback requests

5. How We Use Information

5.1 Our Own Processing (As Controller)

PurposeLegal Basis
Provide our platformContract performance
Process payments & subscriptionsContract performance
Send service communicationsContract performance
Provide customer supportContract / Legitimate interest
Request platform feedback from end-customersLegitimate interest
Improve our productsLegitimate interest
Ensure platform securityLegitimate interest
Prevent fraud & abuseLegitimate interest
Comply with legal obligationsLegal obligation
Marketing (with consent)Consent

5.2 Processing on Behalf of Clients (As Processor)

We process end-customer data solely to provide the booking platform service:

  • Storing and displaying booking information
  • Sending booking confirmations and reminders (on Client's behalf)
  • Processing payments (via Stripe)
  • Generating reports for Clients
  • Maintaining audit trails

We do NOT:

  • Use end-customer data for our own marketing
  • Sell end-customer data to third parties
  • Access end-customer data except as necessary to provide the service or as instructed by the Client

6. Who We Share Information With

6.1 Sub-Processors

We use the following third-party service providers to operate our platform:

ProviderServiceLocationSafeguards
Stripe, Inc.Payment processingUSASCCs, DPA
ZeptoMail (Zoho)Transactional emailEU/IndiaSCCs, DPA
Microsoft AzureBackend & databaseUKISO 27001, SOC 2, GDPR DPA
Cloudflare, Inc.CDN, securityGlobalISO 27001, SOC 2, SCCs
Vercel Inc.Frontend hostingUSASOC 2, SCCs
Google AnalyticsWebsite analytics (consent-based)USAConsent, SCCs
Sentry.ioError monitoring (consent-based)USAConsent, SCCs

6.2 Our Clients

We share end-customer data with the Client business that the customer booked with. This includes:

  • Customer name and contact details
  • Booking history and details
  • Payment status
  • Any notes or preferences

6.3 Legal Requirements

We may disclose information when required by:

  • Law or regulation
  • Court order or legal process
  • Government or regulatory request
  • Protection of our legal rights

6.4 Business Transfers

In the event of a merger, acquisition, or sale, your information may be transferred as part of business assets. We will notify affected parties of any change in data controller.

7. International Data Transfers

We are based in the United Kingdom. Some of our sub-processors operate internationally:

DestinationTransfer Mechanism
European Economic AreaAdequacy decision
United StatesStandard Contractual Clauses (SCCs)
Other countriesSCCs or other approved mechanisms

All transfers are made in compliance with UK GDPR requirements.

8. Data Retention

8.1 Our Own Data (As Controller)

Data TypeRetention Period
Marketing leads (unconverted)2 years from last contact
Client account dataDuration of relationship + 6 years
Billing & subscription records6 years (HMRC requirement)
Support tickets3 years from resolution
Security/audit logs2 years
Website analytics26 months (anonymised)

8.2 End-Customer Data (As Processor)

We retain end-customer data according to our Clients' instructions and our Data Processing Agreement:

  • Active accounts: For the duration of the Client's subscription
  • After Client termination: Deleted within 90 days, unless legal retention required
  • Backup copies: Purged within 180 days of deletion

Clients can request earlier deletion of specific customer data via our support channels.

9. Data Security

We implement comprehensive security measures to protect personal data:

Technical Measures

Encryption in transit

TLS 1.2+ (HTTPS only)

Encryption at rest

AES-256 database encryption

Password security

Bcrypt hashing, complexity requirements

Authentication

JWT tokens, secure session management

Access control

Role-based permissions, multi-tenancy isolation

Payment security

PCI DSS via Stripe (card data never touches our servers)

Organisational Measures

MeasureImplementation
Staff trainingData protection awareness
Access loggingComprehensive audit trails
Incident responseDocumented breach procedures
Vendor managementDPAs with all sub-processors
Regular reviewPeriodic security assessments

Incident Response

In the event of a data breach:

  1. We will assess the breach within 24 hours
  2. We will notify affected Clients without undue delay (within 72 hours for reportable breaches)
  3. We will cooperate with Client's breach notification obligations
  4. We will document and remediate the incident

10. Your Rights

10.1 For Our Direct Data Subjects

If we are the data controller for your information (marketing contacts, Client users, support enquiries), you have the following rights:

RightHow to Exercise
AccessRequest a copy of your data
RectificationCorrect inaccurate information
ErasureRequest deletion ("right to be forgotten")
RestrictionLimit how we process your data
PortabilityReceive your data in a portable format
ObjectionObject to processing based on legitimate interest
Withdraw consentRevoke consent at any time

Contact: [email protected]

We will respond within one month (extendable by two months for complex requests).

10.2 For End-Customers (Data Subjects of Our Clients)

If you are an end-customer who booked through a business using our platform:

  1. First, contact the business directly - They are the data controller
  2. The business may instruct us to fulfil your request
  3. We will action data subject requests within 10 business days of Client instruction

We cannot independently action data subject requests for end-customer data without Client authorisation, as they are the data controller.

11. Data Processing Agreement

We enter into Data Processing Agreements (DPAs) with all Clients, ensuring:

  • Processing only on documented instructions
  • Confidentiality obligations
  • Security measures appropriate to the risk
  • Sub-processor management and notification
  • Assistance with data subject rights
  • Breach notification within 48 hours
  • Deletion or return of data on termination
  • Audit and inspection rights

Clients can request a copy of our DPA template at [email protected].

12. Children's Privacy

Our platform is not directed at children under 16. We do not knowingly collect data from children under 16.

If a Client's business serves children, the Client is responsible for ensuring appropriate parental consent and compliance.

13. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify affected parties of material changes by:

  • Posting a notice on our website
  • Emailing registered Client users
  • Updating the "Last Updated" date

We encourage you to review this policy periodically.

15. Contact Us

General Enquiries

Trimlinea
4th Floor, 14 Museum Place
Cardiff, CF10 3BH

[email protected]

Complaints

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF

ico.org.uk | 0303 123 1113

16. Policy Documents

This Privacy Policy should be read in conjunction with: