Legal
Privacy Policy
Last updated 12 July 2026
This Policy explains how Glowlist collects, uses and protects your personal data when you use our marketplace as a client or as a freelance artist, and the rights you have under UK data-protection law.
1. Who we are
Glowlist (“Glowlist”, “we”, “us” or “our”) operates the marketplace at glowlist.app that connects clients with freelance beauty artists. For the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, Glowlist is the “controller” of the personal data described in this Policy. This Policy explains how we collect, use, share and protect your personal data, and your rights in relation to it. It applies to both clients and artists.
2. The information we collect
We collect and process the following categories of personal data:
- Account data: name, email address, password (stored securely by our authentication provider), and role (client or artist).
- Artist profile data: the information artists choose to publish, such as display name, location/area, services, pricing, portfolio images, specialties and social links.
- Booking data: the artist or client involved, service, date, time, location or address, notes, and messages exchanged in connection with a booking.
- Payment data: payments and payouts are processed by Stripe. We receive limited information such as payment status, amounts and identifiers. We do not store full card numbers; card details are handled directly by Stripe.
- Communications: messages you send through the Platform and correspondence with our support team.
- Technical and usage data: IP address, device and browser information, and how you interact with the Platform, collected to keep it secure and working.
- Health-related information: some treatments require an artist to ask about your health before they can safely go ahead. Where an artist uses a consultation form, we collect the answers you give (which may cover allergies, skin sensitivities, medication, pregnancy and recent treatments), the consent wording you agreed to, and the time you agreed to it. Where a treatment requires a patch test, we record that it was carried out, its result and when it expires. This is special-category data under Article 9 and is handled as described below.
3. Health information and consultation records
Certain treatments (lash extensions, brow and lash tints, brow lamination and henna among them) carry a risk of allergic reaction. Artists ask about your health before these treatments, and carry out a patch test in advance, because doing so is a professional standard and commonly a condition of their insurance.
Health data is special-category data under Article 9 of the UK GDPR, so we need a further condition beyond our lawful basis to process it. We rely on your explicit consent, which you give when you submit a consultation form, and on the processing being necessary for the establishment, exercise or defence of legal claims where a record is later needed to answer one.
- Who can see it: only the artist who asked, and you. It is never shown on a public profile, never included in a calendar feed, and never shared with other artists on the Platform. Our staff access it only where strictly necessary to investigate a dispute or a safety issue.
- What is kept: your answers together with a copy of the questions as they were asked. If an artist later edits their form, your record still shows what you were actually asked and agreed to. That protects both of you.
- How long: seven years from the date of the record, then deleted automatically. That period reflects how long a claim about a treatment can realistically be brought.
- If you close your account: your name is removed from these records, but the clinical content and dates are kept until the retention period ends. Erasure does not extend to information needed to establish or defend a legal claim (Article 17(3)(e)), and deleting an artist’s only record of a treatment that took place would leave them unable to answer one. The record is then purged in full.
- Withdrawing consent: you can decline a consultation form, but an artist may then be unable to carry out that treatment. Withdrawing consent afterwards does not remove a record we must keep for the reason above.
You can download everything we hold about you, including your consultation answers and patch-test history, at any time from your account settings.
4. How we use your information and our lawful bases
We use your personal data for the following purposes, relying on the lawful bases shown:
- To create and manage your account and to provide the Platform: performance of a contract.
- To facilitate bookings between clients and artists, including sharing the necessary details between them: performance of a contract.
- To process deposits, balance payments, commission and payouts through Stripe: performance of a contract and compliance with legal obligations.
- To send transactional emails (booking confirmations, completion prompts, payout and payment notices): performance of a contract and legitimate interests.
- To provide support, prevent fraud, enforce our Terms, and keep the Platform secure: legitimate interests.
- To comply with legal, tax and accounting obligations: legal obligation.
- Where we rely on consent (for example, certain optional communications), you may withdraw it at any time.
Where we process special-category data (such as health information you provide for a booking), we do so on the basis that it is necessary for the booking and, where required, with your explicit consent.
5. How we share your information
- Between clients and artists: to make and fulfil a booking, we share the details each party reasonably needs (for example, the client’s name and location with the booked artist).
- Stripe: our payment processor, for processing payments, saving cards for balance collection, and paying out to artists (Stripe Connect).
- Infrastructure and service providers: hosting, database and email providers that process data on our behalf under written agreements.
- Professional advisers and authorities: where necessary to comply with the law, respond to lawful requests, or establish, exercise or defend legal claims.
- Business transfers: if Glowlist is involved in a merger, acquisition or sale of assets, in which case we will take steps to protect your data.
6. International transfers
Some of our service providers may process personal data outside the UK. Where they do, we ensure an appropriate safeguard is in place, such as a UK adequacy decision or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, so that your data receives an equivalent level of protection.
7. How long we keep your information
We keep personal data for as long as necessary to provide the Platform and to comply with our legal obligations (for example, tax and accounting records are typically retained for at least six years). Consultation answers and patch-test records are kept for seven years from the date of the record and are then deleted automatically. See “Health information and consultation records” above. When data is no longer needed, we delete or anonymise it. You may ask us to delete your account, and we will do so subject to any records we are required to retain.
8. Your rights
Under UK data-protection law you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to our processing in certain circumstances;
- data portability (to receive certain data in a portable format);
- withdraw consent where we rely on it; and
- not be subject to solely automated decisions producing legal or similarly significant effects.
You can exercise your right of access and portability yourself: Account → settings → download my data returns everything we hold about you, including your consultation answers and patch-test history, as a file you can keep or pass on.
To exercise any of the other rights, contact us at privacy@glowlist.app. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk, though we would appreciate the chance to address your concerns first.
9. Cookies and similar technologies
We use only strictly necessary cookies and similar technologies: to keep you signed in, to keep the Platform secure (including session limits), and, via our payment provider Stripe, to help prevent payment fraud. We do not use analytics, advertising, or tracking cookies. Because these are essential to a service you have requested, no consent banner is required, but we show a brief notice so you know they are in use. If we ever introduce any non-essential cookies, we will ask for your consent first and provide controls to manage them.
10. How we protect your information
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and using reputable providers (such as Stripe for payments) who maintain recognised security standards. No system is completely secure, but we work to protect your data and will notify you and the ICO of a personal-data breach where required by law.
11. Children
The Platform is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
12. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will take reasonable steps to notify you. The “last updated” date at the top shows when this Policy was last revised.
13. Contact us
For any privacy question or to exercise your rights, contact us at privacy@glowlist.app.
