Privacy Policy
1. Who we are
MUAH ("MUAH", "we", "us", "our") operates the MUAH mobile application (the "App"), a marketplace that connects clients ("Clients") with independent beauty professionals ("Service Providers") for makeup, hair, nail and related beauty services.
For the purposes of UK data protection law, the data controller for the personal data described in this policy is:
- Controller: muah-app LTD
- Company number: 17331321, registered in England & Wales
- Registered/operating address: 66 Paul Street, London, EC2A 4NA
- ICO registration number: ZC195084
- Contact for privacy matters: privacy@muah-app.co.uk
Our role in the marketplace. MUAH is an intermediary: we facilitate introductions, bookings and payments between Clients and Service Providers. The Service Providers are independent providers, not our employees or agents, and they deliver the beauty services themselves. We are the controller of your platform and account data (as set out below); the Service Provider is a separate, independent controller of the personal data you share with them to receive their service.
This policy is governed by the laws of England and Wales, and we process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Who this service is for
MUAH is intended only for adults aged 18 or over. The App is not directed at children, and we do not knowingly collect personal data from anyone under 18. We check the date of birth you give us at registration and reject registrations that do not meet the age requirement, and we will remove accounts we find to belong to under-18s.
3. The personal data we collect
We collect only what we need to run the marketplace safely. Data is deliberately separated by sensitivity: some is held on your public profile (visible to other users for discovery), some is held privately (accessible only to you, and to our systems and moderators where necessary), and the most sensitive categories are held in dedicated, restricted stores.
3.1 Identity and contact details
Full name, email address, phone number, and (for Service Providers) a business/correspondence email and profile photo. Purpose: to create and operate your account, identify you to the people you book with, and contact you about your bookings. Lawful basis: performance of a contract (UK GDPR Article 6(1)(b)).
3.2 Date of birth and age
Your date of birth, which we use to confirm you are 18 or over. Registrations that do not meet the age requirement are rejected, and we run a periodic check that removes accounts which no longer meet it. Your date of birth is stored privately and is not shown on your public profile. Lawful basis: performance of a contract and compliance with our age-restriction obligations (Article 6(1)(b)); and our legitimate interest in operating an adults-only service (Article 6(1)(f)).
3.3 Location
Location is handled in graduated steps to protect your privacy:
- Before a booking (public): an approximate location only — your coordinates are coarsened to roughly a 110-metre grid, together with a general service-area label (such as a postcode district). This is what other users see when discovering providers nearby.
- Privately: your precise coordinates and full postcode, used to deliver the service accurately.
- At booking acceptance: for bookings at a Service Provider's premises, the provider's exact address is revealed to you only once they accept your booking; and for bookings at your location, your exact address is shared with the provider for that booking.
- During a booking: for mobile ("we come to you") bookings, we use location at the point of arrival to confirm the provider has reached the agreed location (a short-range geofence). The appointment is then started with a 6-digit arrival code that you share with the provider. We do not continuously track your location outside of an active booking.
Purpose: provider discovery, accurate service delivery, and arrival confirmation. Lawful basis: performance of a contract (Article 6(1)(b)).
3.4 Payment information
A payment-provider customer identifier and, for Service Providers, a connected-account identifier and payout/verification status. Your card details are handled and stored by our payment processor (Stripe) and never touch MUAH's servers — we receive only tokens and identifiers, not card numbers. Purpose: to take payment, calculate fees, and pay Service Providers. Lawful basis: performance of a contract (Article 6(1)(b)).
3.5 Identity verification (Service Providers)
Service Providers may complete identity verification through Stripe Identity, which processes their name, date of birth, address and identity-document images (and may process biometric data derived from an identity document). MUAH receives only the verification outcome and timestamp, not the underlying documents. Purpose: trust and safety, and to meet payment-provider requirements. Lawful basis: performance of a contract and our legitimate interest in a safe marketplace (Articles 6(1)(b) and 6(1)(f)).
3.6 Special-category data (Article 9)
- Beauty attributes: Clients may share their skin-tone range and hair-texture preferences, and Service Providers may share their skin-tone and hair-texture expertise, to improve matching. Because these can reveal information about racial or ethnic origin, we treat them as special-category data under Article 9. They are stored in a restricted, owner-readable store; only a coarse, generalised version is published to support discovery. We do not infer ethnicity or any demographic characteristic from your photographs. We rely on your explicit consent (Article 9(2)(a)) for this processing.
- Health-related information you provide before a service: when you book, you may be asked a short pre-service checklist (for example, allergies, sensitive skin, skin conditions, or eye sensitivity) so the Service Provider can perform the service safely. You are asked not to include medical diagnoses or detailed health information. Where you do provide such information it may amount to health data under Article 9. Purpose: your safety during the service. Condition relied on: your explicit consent (Article 9(2)(a)) — you choose whether to provide any of this information after being told why we ask, and you can leave it blank. This information is shared with the Service Provider assigned to your booking so they can perform the service safely, and is kept only as part of that booking record.
3.7 Device and technical data
Push-notification tokens, app-attestation tokens (used to confirm requests come from a genuine copy of our App), crash-diagnostic data (device model, operating-system version, and error information, via Firebase Crashlytics), and your language/locale. Purpose: to deliver notifications, prevent abuse, keep the App stable, and show it in your language. Lawful basis: our legitimate interest in a secure, reliable service (Article 6(1)(f)), and performance of a contract for notifications you have set up (Article 6(1)(b)).
3.8 Content you create
Service-provider portfolio images, in-app chat messages, and reviews. Purpose: to operate the marketplace and let users make informed choices. Lawful basis: performance of a contract and our legitimate interest in a trustworthy platform (Articles 6(1)(b) and 6(1)(f)).
3.9 Marketing preferences
If you opt in, your consent to receive marketing emails, together with the date, time, IP address and policy version at the moment you consented (kept as evidence of consent). Purpose: to send you offers and updates you asked for. Lawful basis: consent (Article 6(1)(a); and the Privacy and Electronic Communications Regulations).
3.10 Records of your permissions
We keep an internal, tamper-evident log of the permissions and acceptances you give — for example when you accept our Terms, acknowledge this policy, or grant or withdraw a consent — recording what you agreed to, when, and from which IP address. Purpose: to demonstrate we handle your data lawfully (accountability, Article 5(2)). Lawful basis: compliance and legitimate interest (Articles 6(1)(c) and 6(1)(f)).
3.11 How you use the App
Information about how you use the App — for example, screens viewed and actions taken — collected as usage and diagnostic events. Purpose: to understand how the App is used, fix problems, and improve the service; this information is analysed only in a privacy-scrubbed, aggregated form. Lawful basis: our legitimate interest in maintaining and improving the App (Article 6(1)(f)).
4. How we use your data and our lawful bases — at a glance
| What we do | Lawful basis |
|---|---|
| Create and run your account; take bookings and payments; deliver and support the service | Contract — Article 6(1)(b) |
| Your Terms acceptance, cancellation-policy acceptance, and Service-Provider licence/insurance declarations and identity verification | Contract / contractual representation — Article 6(1)(b) |
| Matching you using beauty-attribute preferences (special category) | Explicit consent — Articles 6(1)(a) + 9(2)(a) |
| Keeping the platform safe: content moderation, contact-masking, image-safety checks | Legitimate interest — Article 6(1)(f) (not consent) |
| Importing a Service Provider's free/busy calendar to prevent double-booking | Legitimate interest — Article 6(1)(f) (not consent) |
| Security, abuse prevention, crash diagnostics, service reliability | Legitimate interest — Article 6(1)(f) |
| Marketing emails | Consent — Article 6(1)(a) |
| Keeping records to demonstrate compliance | Legal obligation / legitimate interest — Articles 6(1)(c), (f) |
A note on moderation and calendar import. Keeping the marketplace safe, and preventing double-bookings, are things we do under our legitimate interests — they are not optional add-ons you consent to. This means they continue for as long as you use the service, and turning off an optional consent does not switch them off. You do, however, have the right to object to processing based on legitimate interests (see section 7). We have carried out a legitimate-interests assessment for these activities.
Future features. From time to time we may introduce new features. Where a new feature needs additional data or a new permission from you, we will ask you at that point and, where the law requires it, seek your consent before the feature processes your data.
5. Who we share your data with
We do not sell your personal data. We share it with the parties below so the service can work.
Other users. Your public profile (and, once a booking is accepted, the details needed to complete that booking) is shared with the Clients or Service Providers you interact with.
Our service providers (processors and other recipients). We use carefully selected suppliers who process personal data on our behalf, or receive it to perform their own service:
| Recipient | What they do for us | Data involved |
|---|---|---|
| Google / Firebase (Google Cloud) | App infrastructure: sign-in, database, cloud functions, file storage, push notifications, abuse prevention (App Check), crash reporting, and analytics | Effectively all platform data; analytics is exported only as a privacy-scrubbed summary |
| Stripe | Card payments, provider payouts, identity verification, subscriptions | Payment tokens and identifiers, amounts; for verification: name, date of birth, address, identity documents |
| Apple | Subscription management, push-notification delivery, Sign in with Apple, and maps/address look-up | Subscription and device identifiers, authentication tokens, and coordinates sent for address look-up |
| SendGrid (via our email tool) | Sending transactional emails (e.g. booking confirmations) | Your email address and the content of the message |
| Google Cloud Vision | Automated safety check of uploaded images | Image content |
| External calendar feeds (chosen by a Service Provider — e.g. Google, iCloud, Booksy) | Reading a provider's free/busy times to prevent double-booking | We fetch the provider's own calendar link; no Client data is sent out |
We put appropriate contracts in place with these suppliers as required by UK GDPR.
Legal and safety disclosures. We may disclose personal data where we are legally required to, or where it is necessary to protect the safety of our users or the public, to prevent fraud, or to establish or defend legal claims.
6. International transfers
Some of our suppliers process personal data outside the United Kingdom (for example, Stripe, Apple, Google and SendGrid operate internationally). Where personal data is transferred outside the UK, we rely on appropriate safeguards — such as UK adequacy regulations, the UK International Data Transfer Agreement / Addendum, or Standard Contractual Clauses — so that your data continues to be protected.
7. Your rights
Under UK data protection law you have the right to: access your data; ask us to correct it; ask us to erase it; restrict or object to certain processing (including processing based on our legitimate interests, and direct marketing at any time); request portability; and withdraw consent at any time where we rely on consent (this does not affect processing done before withdrawal).
How to exercise them in the App:
- Delete your account and data. You can delete your account from the App's privacy settings. This runs a full erasure process: we cancel and refund any active bookings, remove your services, availability, portfolio images and files, anonymise your past conversations and reviews (so the other person's history stays intact but no longer identifies you), remove your personal identifiers from our loyalty records, and delete your account and profile — including your special-category data, permission logs and notification tokens. Some information may be retained where the law requires (for example, limited transaction records), and some content is anonymised rather than deleted where it forms part of another user's records.
- Get a copy of your data. You can request an export of your personal data from within the App.
- Manage consents. You can withdraw marketing consent, and any optional feature consents, at any time in settings.
You also have the right to complain to the Information Commissioner's Office (ICO) — ico.org.uk — though we would welcome the chance to resolve your concern first: privacy@muah-app.co.uk.
8. How long we keep your data
We keep personal data only for as long as we need it to provide the service, meet our legal obligations, and resolve disputes. In general, your account data is kept for as long as your account is active and is erased when you delete your account (subject to the limited exceptions in section 7). Certain records are kept for shorter, fixed periods — for example, transactional emails, security and moderation records, and payment-event records are each kept for a limited time and then automatically deleted.
9. How we protect your data
We use technical and organisational measures appropriate to the risk, including: encryption in transit (HTTPS/TLS) and at rest; strict access controls so private data is readable only by you and, where necessary, our systems and trained moderators; secure device storage (Keychain) for sensitive values on your phone; app-attestation and rate-limiting to prevent abuse; and identity checks on our internal task processing. No system is ever completely secure, but we work to protect your data and to detect and respond to incidents.
10. Automated processing
We use automated checks to keep the platform safe — for example, scanning uploaded images for unsafe content and masking contact details in messages to discourage off-platform contact. These checks support human review; they do not make decisions that produce legal or similarly significant effects about you without human involvement.
11. Changes to this policy
We may update this policy from time to time. When we make significant changes we will update the version number and "last updated" date, make the new version available in the App, and — where appropriate — ask you to acknowledge it. Your continued use of the App after an update means the current version applies to you.
12. Contact us
Questions about this policy or your data:
- Email: privacy@muah-app.co.uk
- Address: 66 Paul Street, London, EC2A 4NA