Privacy Policy

Last updated: 19 August 2026

1. Who is responsible for your data

Glamia is an appointment, client-management and payment application for beauty professionals.

There are two different situations, and they matter:

When you book an appointment with a professional, that professional decides what to record about you and why. She is the controller of your data. Glamia acts as her processor: we hold and handle it on her instructions, to run her booking page and her diary. Requests about your appointment record go to her first; we will help her answer.

When a professional creates a Glamia account, Glamia is the controller of her own account data.

2. What we collect

When you book online, we collect:

  • first name and surname;
  • email address;
  • phone number;
  • the services chosen, and the date and time of the appointment;
  • any optional comment or inspiration photo you send;
  • answers to any question your professional asks before booking.

3. Payments

If you pay online — a deposit, a card held on file, or a payment through Glamia Pay — we record the amount, the type and the date of the transaction, and technical payment references.

Your card details are entered and processed directly by Stripe, a payment provider certified to the PCI-DSS standard. They never pass through Glamia and are never stored on our servers.

When you leave a card on file, no money is taken at booking. It is an authorisation allowing your professional to charge the agreed amount if you do not turn up without cancelling, under the conditions shown to you before you authorised it.

4. Why we use it, and on what basis

We use your data only to run the booking service: managing your appointment, sending confirmations and reminders, processing payments and refunds, and letting you and your professional communicate about the appointment.

If you are in the United Kingdom or the European Economic Area, our lawful bases are the performance of the service you asked for (Article 6(1)(b) UK GDPR / GDPR), our legal and accounting obligations for payment records (Article 6(1)(c)), and our legitimate interest in keeping the service secure and working (Article 6(1)(f)).

If you are in Canada, we collect and use your information with your knowledge and consent, for the purposes described here, as required by PIPEDA.

If you are in the United States, we process your information for the business purposes described here.

5. We do not sell your data

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the past twelve months. This statement is made for the purposes of the California Consumer Privacy Act as amended (CCPA/CPRA), and applies equally everywhere else.

Your data is accessible only to the professional you book with, and to the technical providers listed below.

6. Who else handles it

We use technical providers strictly necessary to run the service:

  • Hosting: Supabase, on servers located in the European Union.
  • Payments: Stripe, for secure processing of Glamia Pay transactions.
  • Email delivery: our emailing provider, for confirmations and reminders.
  • Push notifications: Expo, to alert your professional on her phone.

7. Where your data is held, and transfers

Your data is hosted in the European Union.

For users in the United Kingdom, transfers rely on the UK’s adequacy regulations for the EEA. For users elsewhere, where a transfer is needed we rely on Standard Contractual Clauses or another lawful transfer mechanism, and we require our providers to protect your data to the same standard.

8. How long we keep it

Your appointment data is kept for as long as you have a commercial relationship with your professional, then deleted within 12 months of your last appointment.

Payment and invoicing records are kept for as long as our legal and accounting obligations require, which may be longer.

9. Your rights

Wherever you are, you can ask us to give you a copy of your data, correct it, or delete it. Depending on where you live you may also have the rights below.

United Kingdom and EEA: access, rectification, erasure, restriction, portability, and the right to object to processing based on legitimate interests.

Canada: access to your personal information, correction of inaccuracies, and withdrawal of consent, subject to legal and contractual limits.

California: the right to know what we collect and why, to delete it, to correct it, to opt out of sale or sharing (we do neither), and not to be treated differently for exercising any of these rights.

To exercise any of these rights, contact us at: contact@glamia.pro

10. Children

The booking service is not intended for children under 16. We do not knowingly collect data from them. If you believe a child’s data has been recorded, write to us and we will remove it.

11. Cookies

The Glamia booking site does not use advertising cookies. Only technical cookies necessary for the service to work are used.

12. Security

Data is encrypted in transit and at rest. Access is limited to what each part of the service needs. Card details are never held by us. No system is perfectly secure, but we will tell you and the relevant authority without undue delay if a breach affects your rights.

13. Complaints

If you are not satisfied with how we handled your data, you can complain to your supervisory authority: the Information Commissioner’s Office in the United Kingdom, the Office of the Privacy Commissioner in Canada, your State Attorney General in the United States, or the CNIL in France.