Last updated: June 2026
This Privacy Policy explains how Green Candle Digital Studio ("we", "us", "our") collects, uses, stores, and shares personal data in connection with the Bookky platform. It applies to:
We are committed to protecting personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Green Candle Digital Studio is the data controller for:
For End User personal data (name, email, phone, booking details collected during a booking), the Client (the business)is the data controller and Green Candle Digital Studio acts as a data processor on the Client's behalf. Clients are responsible for their own privacy notices to End Users.
Contact our data protection point of contact: [email protected]
We process personal data for the following purposes and legal bases:
| Purpose | Legal basis (UK GDPR) | Applies to |
|---|---|---|
| Providing the Platform and booking service | Contract (Art. 6(1)(b)) | Clients & End Users |
| Sending booking confirmations and reminders | Contract / Legitimate interests | End Users |
| Processing payments and issuing receipts | Contract (Art. 6(1)(b)) | Clients & End Users |
| Account management and support | Contract (Art. 6(1)(b)) | Clients |
| Security, fraud prevention, and audit logging | Legitimate interests (Art. 6(1)(f)) | All |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) | All |
| Product improvement and analytics | Legitimate interests (Art. 6(1)(f)) | Clients |
| Marketing and product updates (opt-in only) | Consent (Art. 6(1)(a)) | Clients |
We do not sell personal data. We share data only with the following sub-processors, each bound by data processing agreements:
Supabase
Database, authentication, and file storage
Data location: EU (Frankfurt)
Stripe
Payment processing and Stripe Connect for Clients
Data location: USA (EU SCCs in place)
Resend
Transactional email (booking confirmations)
Data location: USA (EU SCCs in place)
Vercel
Platform hosting, edge CDN, and access logs
Data location: USA / EU edge (EU SCCs in place)
We may disclose personal data to law enforcement, regulators, or courts where we are legally obliged to do so, or to protect the rights, property, or safety of Green Candle Digital Studio, our Clients, or others.
In the event of a business sale, merger, or acquisition, Client Data may be transferred to the successor entity. We will give reasonable notice and ensure equivalent protections are maintained.
Stripe, Resend, and Vercel are based in the USA. We transfer personal data to them under UK International Data Transfer Agreements (IDTA) or Standard Contractual Clauses (SCCs) approved under the UK GDPR adequacy framework. Supabase data is stored within the EU and does not involve a third-country transfer.
We retain personal data only for as long as necessary:
| Data type | Retention period |
|---|---|
| Client account data | Duration of Subscription + 30 days after termination |
| Booking records (financial) | 7 years (HMRC / Companies Act requirement) |
| End User contact details | As directed by the Client (controller); default 2 years from last booking |
| Security / access logs | 90 days |
| Audit log (booking events) | 7 years |
We use strictly necessary cookies only:
We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies. Under PECR and UK GDPR, a cookie consent banner is not required for strictly necessary cookies.
You have the following rights in relation to your personal data. To exercise any of them, email [email protected]. We will respond within one calendar month (extendable by two further months for complex requests, with notice).
We will not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive.
We implement appropriate technical and organisational measures to protect personal data, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay, as required by UK GDPR Articles 33–34.
The Platform is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data about a child, please contact us immediately at [email protected] and we will delete it promptly.
We will post any updates to this page and update the "Last updated" date. For material changes, we will notify registered Clients by email at least 14 days before the change takes effect. Continued use of the Platform after that date constitutes acceptance of the updated policy.
If you have concerns about how we handle your personal data, please contact us first at [email protected]. If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office · Wycliffe House · Water Lane · Wilmslow · SK9 5AF
ico.org.uk/make-a-complaint · 0303 123 1113
This document was last reviewed June 2026. This is not a substitute for independent legal advice.