CrownSuite ← Back to home
Legal

Privacy Policy

Last updated: 17 May 2026

01 Who We Are

CrownSuite is a booking management platform for hair salons. CrownSuite is a trading name of T J Bungwe, a sole trader based in the United Kingdom.

For data protection purposes, CrownSuite is the data processor for customer booking data and the data controller for salon owner account data.

Contact: [email protected] · Post: [BUSINESS ADDRESS — TO ADD]

02 Data We Collect — Salon Owners

DataPurposeLegal basis
Name, email, phoneAccount creation & communicationContract
Business name, address, postcodeSalon profile & booking pageContract
Payment informationSubscription billing via StripeContract
Login credentials (hashed)AuthenticationContract

03 Data We Collect — Salon Customers

DataPurposeLegal basis
Name, email, phoneBooking confirmation & communicationLegitimate interest
Booking detailsAppointment managementLegitimate interest
Payment referenceDeposit verificationLegitimate interest

04 How We Use Your Data

  • Provide and maintain the CrownSuite platform
  • Process bookings and send confirmation emails
  • Process subscription payments
  • Communicate service updates or changes
  • Respond to support enquiries

We do not sell, rent, or share your personal data with third parties for marketing purposes.

05 Third-Party Processors

ServicePurposeData shared
StripePayment processingPayment details, email
SendGrid (Twilio)Transactional emailsEmail address, booking details
RailwayApplication hostingAll platform data (encrypted at rest)

Each processor is bound by their own privacy policies and data processing agreements.

06 Data Retention

Salon owner data: retained for the duration of your account plus 30 days after account closure.

Customer booking data: retained for the duration of the salon's account. Salon owners may request deletion of individual customer records at any time.

Payment records: retained for 7 years as required by UK tax regulations.

07 Data Security

  • HTTPS encryption on all connections
  • Passwords hashed using bcrypt
  • Multi-tenant data isolation between salons
  • Rate limiting on login, signup, and booking endpoints
  • Account lockout after repeated failed login attempts

08 Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data (right to be forgotten)
  • Restrict processing of your data
  • Port your data to another service
  • Object to processing of your data

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

09 Cookies

We use essential session cookies to keep you logged in. We do not use tracking cookies, advertising cookies, or third-party analytics. See our Cookie Policy for details.

10 Data Breach Notification

In the event of a personal data breach that affects your data or your customers' data, CrownSuite will notify you without undue delay and no later than 48 hours after becoming aware of the breach. We will provide details of the nature of the breach, the data affected, and the steps we are taking to mitigate it.

As required under UK GDPR, we will also assist you in meeting your obligation to report the breach to the Information Commissioner's Office within 72 hours where required. For full details, see our Data Processing Agreement.

11 International Transfers

Your data is stored on servers within the EEA or in jurisdictions that provide adequate protection under UK GDPR. Where data is transferred outside the UK, appropriate safeguards are in place.

12 Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email. The "last updated" date at the top reflects the most recent revision.

13 Complaints

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

14 Contact

For any privacy-related enquiries, contact us at [email protected].

Terms · Privacy · Cookies · DPA · Contact