Legal

Privacy Policy

Version 1 · Last updated 11 July 2026

1. Who we are

MUAH ("MUAH", "we", "us", "our") operates the MUAH mobile application (the "App"), a marketplace that connects clients ("Clients") with independent beauty professionals ("Service Providers") for makeup, hair, nail and related beauty services.

For the purposes of UK data protection law, the data controller for the personal data described in this policy is:

Our role in the marketplace. MUAH is an intermediary: we facilitate introductions, bookings and payments between Clients and Service Providers. The Service Providers are independent providers, not our employees or agents, and they deliver the beauty services themselves. We are the controller of your platform and account data (as set out below); the Service Provider is a separate, independent controller of the personal data you share with them to receive their service.

This policy is governed by the laws of England and Wales, and we process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Who this service is for

MUAH is intended only for adults aged 18 or over. The App is not directed at children, and we do not knowingly collect personal data from anyone under 18. We check the date of birth you give us at registration and reject registrations that do not meet the age requirement, and we will remove accounts we find to belong to under-18s.

3. The personal data we collect

We collect only what we need to run the marketplace safely. Data is deliberately separated by sensitivity: some is held on your public profile (visible to other users for discovery), some is held privately (accessible only to you, and to our systems and moderators where necessary), and the most sensitive categories are held in dedicated, restricted stores.

3.1 Identity and contact details

Full name, email address, phone number, and (for Service Providers) a business/correspondence email and profile photo. Purpose: to create and operate your account, identify you to the people you book with, and contact you about your bookings. Lawful basis: performance of a contract (UK GDPR Article 6(1)(b)).

3.2 Date of birth and age

Your date of birth, which we use to confirm you are 18 or over. Registrations that do not meet the age requirement are rejected, and we run a periodic check that removes accounts which no longer meet it. Your date of birth is stored privately and is not shown on your public profile. Lawful basis: performance of a contract and compliance with our age-restriction obligations (Article 6(1)(b)); and our legitimate interest in operating an adults-only service (Article 6(1)(f)).

3.3 Location

Location is handled in graduated steps to protect your privacy:

Purpose: provider discovery, accurate service delivery, and arrival confirmation. Lawful basis: performance of a contract (Article 6(1)(b)).

3.4 Payment information

A payment-provider customer identifier and, for Service Providers, a connected-account identifier and payout/verification status. Your card details are handled and stored by our payment processor (Stripe) and never touch MUAH's servers — we receive only tokens and identifiers, not card numbers. Purpose: to take payment, calculate fees, and pay Service Providers. Lawful basis: performance of a contract (Article 6(1)(b)).

3.5 Identity verification (Service Providers)

Service Providers may complete identity verification through Stripe Identity, which processes their name, date of birth, address and identity-document images (and may process biometric data derived from an identity document). MUAH receives only the verification outcome and timestamp, not the underlying documents. Purpose: trust and safety, and to meet payment-provider requirements. Lawful basis: performance of a contract and our legitimate interest in a safe marketplace (Articles 6(1)(b) and 6(1)(f)).

3.6 Special-category data (Article 9)

3.7 Device and technical data

Push-notification tokens, app-attestation tokens (used to confirm requests come from a genuine copy of our App), crash-diagnostic data (device model, operating-system version, and error information, via Firebase Crashlytics), and your language/locale. Purpose: to deliver notifications, prevent abuse, keep the App stable, and show it in your language. Lawful basis: our legitimate interest in a secure, reliable service (Article 6(1)(f)), and performance of a contract for notifications you have set up (Article 6(1)(b)).

3.8 Content you create

Service-provider portfolio images, in-app chat messages, and reviews. Purpose: to operate the marketplace and let users make informed choices. Lawful basis: performance of a contract and our legitimate interest in a trustworthy platform (Articles 6(1)(b) and 6(1)(f)).

3.9 Marketing preferences

If you opt in, your consent to receive marketing emails, together with the date, time, IP address and policy version at the moment you consented (kept as evidence of consent). Purpose: to send you offers and updates you asked for. Lawful basis: consent (Article 6(1)(a); and the Privacy and Electronic Communications Regulations).

3.10 Records of your permissions

We keep an internal, tamper-evident log of the permissions and acceptances you give — for example when you accept our Terms, acknowledge this policy, or grant or withdraw a consent — recording what you agreed to, when, and from which IP address. Purpose: to demonstrate we handle your data lawfully (accountability, Article 5(2)). Lawful basis: compliance and legitimate interest (Articles 6(1)(c) and 6(1)(f)).

3.11 How you use the App

Information about how you use the App — for example, screens viewed and actions taken — collected as usage and diagnostic events. Purpose: to understand how the App is used, fix problems, and improve the service; this information is analysed only in a privacy-scrubbed, aggregated form. Lawful basis: our legitimate interest in maintaining and improving the App (Article 6(1)(f)).

4. How we use your data and our lawful bases — at a glance

What we doLawful basis
Create and run your account; take bookings and payments; deliver and support the serviceContract — Article 6(1)(b)
Your Terms acceptance, cancellation-policy acceptance, and Service-Provider licence/insurance declarations and identity verificationContract / contractual representation — Article 6(1)(b)
Matching you using beauty-attribute preferences (special category)Explicit consent — Articles 6(1)(a) + 9(2)(a)
Keeping the platform safe: content moderation, contact-masking, image-safety checksLegitimate interest — Article 6(1)(f) (not consent)
Importing a Service Provider's free/busy calendar to prevent double-bookingLegitimate interest — Article 6(1)(f) (not consent)
Security, abuse prevention, crash diagnostics, service reliabilityLegitimate interest — Article 6(1)(f)
Marketing emailsConsent — Article 6(1)(a)
Keeping records to demonstrate complianceLegal obligation / legitimate interest — Articles 6(1)(c), (f)

A note on moderation and calendar import. Keeping the marketplace safe, and preventing double-bookings, are things we do under our legitimate interests — they are not optional add-ons you consent to. This means they continue for as long as you use the service, and turning off an optional consent does not switch them off. You do, however, have the right to object to processing based on legitimate interests (see section 7). We have carried out a legitimate-interests assessment for these activities.

Future features. From time to time we may introduce new features. Where a new feature needs additional data or a new permission from you, we will ask you at that point and, where the law requires it, seek your consent before the feature processes your data.

5. Who we share your data with

We do not sell your personal data. We share it with the parties below so the service can work.

Other users. Your public profile (and, once a booking is accepted, the details needed to complete that booking) is shared with the Clients or Service Providers you interact with.

Our service providers (processors and other recipients). We use carefully selected suppliers who process personal data on our behalf, or receive it to perform their own service:

RecipientWhat they do for usData involved
Google / Firebase (Google Cloud)App infrastructure: sign-in, database, cloud functions, file storage, push notifications, abuse prevention (App Check), crash reporting, and analyticsEffectively all platform data; analytics is exported only as a privacy-scrubbed summary
StripeCard payments, provider payouts, identity verification, subscriptionsPayment tokens and identifiers, amounts; for verification: name, date of birth, address, identity documents
AppleSubscription management, push-notification delivery, Sign in with Apple, and maps/address look-upSubscription and device identifiers, authentication tokens, and coordinates sent for address look-up
SendGrid (via our email tool)Sending transactional emails (e.g. booking confirmations)Your email address and the content of the message
Google Cloud VisionAutomated safety check of uploaded imagesImage content
External calendar feeds (chosen by a Service Provider — e.g. Google, iCloud, Booksy)Reading a provider's free/busy times to prevent double-bookingWe fetch the provider's own calendar link; no Client data is sent out

We put appropriate contracts in place with these suppliers as required by UK GDPR.

Legal and safety disclosures. We may disclose personal data where we are legally required to, or where it is necessary to protect the safety of our users or the public, to prevent fraud, or to establish or defend legal claims.

6. International transfers

Some of our suppliers process personal data outside the United Kingdom (for example, Stripe, Apple, Google and SendGrid operate internationally). Where personal data is transferred outside the UK, we rely on appropriate safeguards — such as UK adequacy regulations, the UK International Data Transfer Agreement / Addendum, or Standard Contractual Clauses — so that your data continues to be protected.

7. Your rights

Under UK data protection law you have the right to: access your data; ask us to correct it; ask us to erase it; restrict or object to certain processing (including processing based on our legitimate interests, and direct marketing at any time); request portability; and withdraw consent at any time where we rely on consent (this does not affect processing done before withdrawal).

How to exercise them in the App:

You also have the right to complain to the Information Commissioner's Office (ICO)ico.org.uk — though we would welcome the chance to resolve your concern first: privacy@muah-app.co.uk.

8. How long we keep your data

We keep personal data only for as long as we need it to provide the service, meet our legal obligations, and resolve disputes. In general, your account data is kept for as long as your account is active and is erased when you delete your account (subject to the limited exceptions in section 7). Certain records are kept for shorter, fixed periods — for example, transactional emails, security and moderation records, and payment-event records are each kept for a limited time and then automatically deleted.

9. How we protect your data

We use technical and organisational measures appropriate to the risk, including: encryption in transit (HTTPS/TLS) and at rest; strict access controls so private data is readable only by you and, where necessary, our systems and trained moderators; secure device storage (Keychain) for sensitive values on your phone; app-attestation and rate-limiting to prevent abuse; and identity checks on our internal task processing. No system is ever completely secure, but we work to protect your data and to detect and respond to incidents.

10. Automated processing

We use automated checks to keep the platform safe — for example, scanning uploaded images for unsafe content and masking contact details in messages to discourage off-platform contact. These checks support human review; they do not make decisions that produce legal or similarly significant effects about you without human involvement.

11. Changes to this policy

We may update this policy from time to time. When we make significant changes we will update the version number and "last updated" date, make the new version available in the App, and — where appropriate — ask you to acknowledge it. Your continued use of the App after an update means the current version applies to you.

12. Contact us

Questions about this policy or your data: