Privacy notice
Last updated 5 September 2026. Questions about anything on this page go to privacy@diaryhub.co.uk.
Who holds your information
It depends on who you are, and the difference matters.
If you booked an appointment, the salon or stylist you booked with decides what to hold about you and why. They are the data controller. diaryhub is their data processor: we run the software and store the records on their behalf, and we do not decide what happens to them. Ask them first — and if you cannot reach them, ask us and we will help.
If you run your business on diaryhub, we are the controller for your own account — your name, your email address, your subscription — and the processor for everything you record about your clients.
What we hold, and why we are allowed to
Every purpose below has a lawful basis under UK GDPR. They are not interchangeable: consent can be withdrawn and the others cannot, so it is used only where it genuinely applies.
| What | Why | Lawful basis |
|---|---|---|
| Your name, mobile number and email address | Making and keeping your appointment, and telling you if it changes | Contract |
| Your appointments, deposits and payments | Running the booking, and the business records HMRC requires | Contract, then legal obligation |
| Reminders and confirmations | So you are not charged for missing something you were not told about | Legitimate interest |
| Marketing messages | Offers and news from the business you booked with | Consent, recorded separately and withdrawable at any time |
| A record of what changed and who changed it | Settling disputes about a cancellation or a deposit | Legitimate interest |
| Which parts of the product get used | Finding out where people get stuck | Legitimate interest — these records carry no name, email or phone number |
What we deliberately do not collect
diaryhub does not collect health, allergy, medical or patch-test information, and it is not a place to record it. This is not a preference — it is built in. The questions a business can put on its booking form are checked, and one asking about allergies, medication, skin conditions, pregnancy or anything similar is refused rather than accepted with a warning.
Nor do we collect anything about your race, religion, politics, sex life or biometrics. If a business needs to keep consultation records, it must keep them somewhere designed for that, not here.
How long it is kept
Nothing is kept indefinitely. A scheduled job runs every night and deletes whatever has passed its date, whether or not anyone remembers to ask it to.
- Appointments and payments — seven years. Not our choice: they are the business's tax records.
- The record of who changed what — two years.
- Product usage statistics — twenty-five months. These carry no name or contact detail.
- Files you export — seven days, then the download link stops working and the file is deleted.
- An uploaded client list — thirty days after the import, then the file goes.
- A closed account — thirty days, so it can be reopened by mistake-correction, then everything in it is permanently deleted.
What you can ask for
You can ask for a copy of everything held about you, ask for it to be corrected, or ask to be forgotten. Ask the business you booked with; every one of them can produce your full record from inside diaryhub without needing us, and can erase it in one action.
One thing survives erasure, and we would rather say so here than surprise you. Your name, contact details and any notes about you are removed — from your record and from your appointments. The appointments themselves stay: what was booked, how long it took and what it cost. They are the business's accounts, HMRC requires them to be kept for seven years, and once your details are gone they no longer identify you.
Who else sees it
Four companies, each doing one job, none of them permitted to do anything else with what they are given. We do not sell anything to anyone, and we do not use client data to train anything.
- Stripe — taking deposits and payments. They receive the amount and your card details; we never see the card.
- Google — only if the business connects its own Google Calendar, and only the times. Your name and contact details are never written to it.
- Postmark — sending confirmations and reminders. They receive your email address and the message.
- Our hosting provider — where the database lives.
Some of these are US companies. Where information leaves the UK it does so under the UK's approved transfer safeguards, and the full register — including each company's location and the safeguard relied on — is available on request.
How it is protected
Everything travels over an encrypted connection. Free-text notes are encrypted in the database itself, so they are unreadable even to someone holding a copy of it. Your IP address is never stored as itself, only as an irreversible fingerprint. Each business's records are isolated from every other business's by default.
If something does go wrong and your information is at risk, we tell the Information Commissioner's Office within 72 hours of finding out, and we tell you directly if the risk to you is a serious one.
Complaints
Tell us first — privacy@diaryhub.co.uk — and we will try to put it right. You can also complain to the Information Commissioner's Office at ico.org.uk without going through us first.