YOUR INFORMATION
Privacy, plainly.
Updated 4 October 2026.
Who we are
Yolleg Ltd, 71–75 Shelton Street, London, England, WC2H 9JQ, operates Booking System for Salons. Contact [email protected]. We are the controller for salon account and subscription information. For a salon’s client and appointment records, the salon is the controller and we act as its processor.
When you book with a salon
The salon receives your name, email, phone, selected service, appointment time and any practical note you enter. This allows it to manage the appointment and contact you. Your booking is confirmed in a private page; email notifications and reminders are queued. The salon determines its legal basis and retention needs. Contact the salon to request access, correction or deletion of appointment data. Please avoid medical information in the ordinary booking note field.
Workspace accounts and billing
We use owner/reception names, email addresses and password hashes to provide accounts, secure access and administer the software contract. We do not store plaintext passwords. Stripe processes the software subscription, payment details and invoices; we store Stripe customer/subscription references and subscription status, not your full card number. Our basis for account and subscription processing is contract; necessary fraud/security processing relies on legitimate interests and required financial records are retained for legal obligations.
Who processes data
The workspace and database run on hosting.com infrastructure. Cloudflare processes connection/request information to deliver and protect the site. Twilio SendGrid processes recipient details and email contents for confirmations, reset links and reminders; email click/open tracking is disabled by this app. Stripe handles SaaS billing. Providers may process data outside your country under their applicable safeguards. We do not sell salon client records or use them for unrelated marketing.
Cookies and security records
A necessary session cookie supports login, booking forms and security. It is HttpOnly, SameSite=Lax and Secure on the live site. Login/reset/booking rate-limit identifiers are hashed using a server secret; short-lived attempts are cleared after a day. Password reset tokens expire after one hour. Hosting and Cloudflare may retain operational security logs under their policies. This site adds no advertising pixels or visitor analytics.
Keeping and exporting data
The salon retains its workspace records while it uses the service, including during read-only access after a trial/subscription ends. Salon owners can export clients, appointments and payment records. Contact us to close an account, request a full return or arrange deletion; we authenticate requests, then delete or return data unless retention is required by law. Expiring backups may retain a copy temporarily. Payment/refund records in the workspace reflect the salon’s own payments and do not charge or refund a card.
Private appointment links
The private confirmation URL allows its holder to see and, within the salon’s cutoff, cancel that appointment. Treat the link as private. It is not included in public search listings, and responses use no-store and a no-referrer policy. Calendar downloads contain the appointment’s service, time and salon address, not internal notes.
Your choices and rights
Contact the salon about its client records, or us about your workspace account. Depending on applicable law you may request access, correction, deletion, restriction, portability or object to certain processing. You can also complain to the UK Information Commissioner’s Office. You control whether you book online; the salon’s contact details are available if you prefer to contact it directly.