Youzse Ltd

Privacy Policy

Last updated: 2 June 2026

About this Privacy Policy

This Privacy Policy explains how Youzse Ltd collects, uses and protects your personal data when you use the Youzse mobile application (the App).

Youzse Ltd is the data controller for the personal data described in this Policy. We handle your data in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).

Our privacy philosophy

We want to be completely straight with you.

Youzse Ltd has zero interest in the contents of your data, and we do not sell, rent or exploit it. We are not in the business of monitoring or mining your personal information. We have exactly two priorities when it comes to data:

  • keeping it secure, by running on robust and well protected infrastructure
  • using it only to give you a smooth and frictionless experience in the App

We collect the minimum we need to make Youzse work well for you, and nothing more.

1. Who we are and how to contact us

  • Data controller: Youzse Ltd, company number 17254677
  • Registered office: 66 Paul Street, London, England, EC2A 4NA
  • Privacy contact: [email protected]

If you have any question about this Policy or how we handle your data, please contact us using the details above.

2. Our role and the businesses you deal with

Youzse provides software to businesses such as salons, garages and beauty professionals, who use it to manage their bookings and their own customers. Our role under data protection law depends on whose data it is.

  • When you use the App to manage your own Youzse account, Youzse Ltd is the data controller for that account information.
  • For the personal data a business records about its own customers through Youzse, that business is the data controller and Youzse Ltd acts as its data processor.

Our work as a processor is governed by a Data Processing Agreement (DPA) that every business accepts before using Youzse. We only process customer data on the business's documented instructions, and we keep records of our processing activities as required by Article 30 of the UK GDPR.

3. The personal data we collect

Information you give us:

  • Account details: your name, email address and password, or the identifier returned by Apple Sign In or Google Sign In.
  • Profile information: any details you choose to add to your profile.
  • Appointment information: details connected to a booking, and where a business has enabled it and the customer has agreed, images captured or uploaded in connection with an appointment.
  • Content you submit: information you enter when using App features.

Information collected automatically:

  • Device and technical data: device type, operating system, app version, language settings and similar technical identifiers.
  • Usage data: how you interact with the App, which features you use and general performance and diagnostic information.
  • Location data: approximate or precise location, only where you grant permission.

Information from third parties:

  • Apple and Google: when you use Apple Sign In or Google Sign In, we receive basic account information, such as your name and email address or a private relay email if you choose to hide it, to create and secure your account.
  • Stripe: confirmation and status of payments. We never receive your full card number.

Some services may involve special category data, for example health information or appointment images that could reveal it. We only handle special category data on the basis of explicit consent, as explained in section 5. Your biometric login data never leaves your device, as explained in section 7.

4. Device permissions

The App asks for certain device permissions so it can work properly. You are always in control and can change these at any time in your device settings.

  • Location: to power discovery, address look up and showing relevant services to you on a map.
  • Camera: to scan QR codes and, where a business has enabled it and the customer has agreed, to capture images in connection with an appointment. We do not use the camera for any other purpose, and we never capture images in the background.
  • Push notifications: to send you app alerts, updates and important account messages.
  • Face ID and biometrics: for secure sign in. Matching happens on your device only.

If you decline or later withdraw a permission, the related feature may stop working, but you can continue to use the rest of the App.

5. Special category data (Article 9)

Some bookings involve information that the UK GDPR treats as special category data, for example health details, or appointment images that may reveal a health condition.

  • We only process special category data where explicit consent has been given, separately and not bundled into agreeing to these terms.
  • We record what was shown and when consent was given.
  • The data is encrypted while stored, access to it is restricted and logged, and it is kept for a strict and limited period.
  • Consent can be withdrawn at any time, and you can ask us or the relevant business to delete the data.

We never use special category data for marketing or profiling.

6. How and why we use your data and our lawful bases

Under UK GDPR we must have a lawful basis for using your data. Here is how we rely on each.

  • Create and manage your account, to provide the Service you asked for. Lawful basis: contract.
  • Authenticate you, including social and biometric login, to keep your account secure. Lawful basis: contract.
  • Process payments via Stripe, to complete transactions you start. Lawful basis: contract.
  • Manage bookings and appointment information, to deliver the service you or a business asked for. Lawful basis: contract.
  • Handle special category data, such as health information or appointment images, only where explicit consent has been given. Lawful basis: explicit consent under Article 9.
  • Show location based services and maps, to deliver features you turn on. Lawful basis: consent, given through your device permission.
  • Send service and account push notifications, to keep you informed. Lawful basis: contract or legitimate interests.
  • Keep the App secure and prevent fraud and abuse, to protect you and the Service. Lawful basis: legitimate interests.
  • Diagnose problems and improve the App, to keep the App working well. Lawful basis: legitimate interests.
  • Analytics and marketing measurement using Google Analytics 4 and Meta Pixel. Lawful basis: consent.
  • Comply with legal and regulatory duties, because the law requires it. Lawful basis: legal obligation.

Where we rely on consent, you can withdraw it at any time, for example by changing your in app privacy preferences or your device permissions. Withdrawing consent does not affect any processing we carried out before you withdrew it.

7. Biometric authentication

If you enable Face ID, Touch ID or fingerprint login, the matching is performed entirely by your device secure hardware.

Youzse Ltd does not collect, receive, store or have any access to your biometric data. We receive only a simple success or failure signal from your device.

8. Third party services we work with

To run the App we rely on a small number of trusted providers who act as our data processors or operate their own services. Each is bound by its own data protection obligations.

  • Stripe: payment processing. Stripe handles your card details directly and we do not store them.
  • Apple Sign In and Google Sign In: account creation and authentication.
  • Cloudflare: infrastructure, routing, security and content delivery. The App is fully integrated with Cloudflare to keep it fast and protected.
  • Google Analytics 4: usage analytics, used only with your consent.
  • Meta Pixel: advertising measurement and attribution, used only with your consent.

We also use Cloudflare AI Workers on our backend for operational tasks such as generating logos. This is standard automated processing carried out on our own infrastructure to deliver a feature. It does not involve any user facing AI assistant, and we do not use your personal data to train any third party AI model.

9. International data transfers

Some of our providers, such as Stripe, Google, Meta and Cloudflare, may process data outside the UK. Where data is transferred outside the UK, we make sure it is protected by an appropriate safeguard recognised under UK data protection law, such as:

  • the UK's recognition of a country as providing an adequate level of protection
  • a UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses

You can ask us for more detail about these safeguards using the contact details above.

10. How long we keep your data

We keep your personal data only for as long as we need it.

  • Account data: for as long as your account is active, and for a reasonable period afterwards in case you return.
  • Appointment information and images: kept for the limited period set by the business you dealt with, and deleted sooner if you withdraw consent.
  • Special category data: kept for a strict and limited period and deleted when it is no longer needed.
  • Transaction and payment records: kept for as long as required to meet legal, accounting and tax obligations.
  • Diagnostic and usage data: kept for a limited period and then deleted or anonymised.

When we no longer need your data, we securely delete or anonymise it.

11. How we keep your data secure

Security is our top priority. We use measures appropriate to the risk, including:

  • encryption of data in transit and encryption of sensitive data at rest
  • protection through our Cloudflare security layer
  • access controls so that only authorised people can reach our systems, with access to sensitive data restricted and logged
  • biometric authentication that keeps your biometrics on your device and off our servers

No system is ever completely secure, but we work continuously to protect your data, and we have processes to detect, manage and, where required, report any personal data breach to the Information Commissioner's Office within 72 hours.

12. Your rights

Under UK data protection law you have the right to:

  • be informed about how we use your data, which this Policy explains
  • access the personal data we hold about you
  • rectification, to ask us to correct inaccurate or incomplete data
  • erasure, to ask us to delete your data, also known as the right to be forgotten
  • restrict processing in certain circumstances
  • data portability, to receive your data in a portable and machine readable format
  • object to processing based on legitimate interests, or to direct marketing
  • withdraw consent at any time where we rely on consent

To exercise any of these rights, contact us at [email protected]. We will respond within one calendar month, and there is normally no charge. Where the data is held by Youzse on behalf of a business as its processor, that business is the controller, so we will pass your request to them and support them in responding.

13. Complaints

If you are unhappy with how we have handled your data, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

14. Children

The App is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

15. Changes to this Policy

We may update this Policy from time to time. We will change the effective date and, where changes are significant, we will take reasonable steps to notify you in the App.

Contact Youzse Ltd: [email protected].

We value your privacy

Cookies keep Youzse running, improve the platform and help deliver relevant content. Read our privacy policy and cookie policy.