Legal
Privacy Policy
Last updated: August 8, 2026
1. Who We Are
TressTime is operated by Tress Labs Ltd., a private limited company registered in England and Wales. Tress Labs Ltd. is the Data Controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
- Contact: support@tresstime.com
- Registered Office: Lakeshore Accountants, Cai Building, North Shields, United Kingdom, NE29 6DE
- Company Number: 17160292
2. What We Collect
We collect account details such as your name, email address, profile image, booking information, reviews, and service-usage data needed to operate TressTime. Shop owners may also provide business, service, availability, and staff information. We also collect device and usage data such as log events, app activity, IP address, and diagnostics. If you enable location services, we collect location data to show nearby shops, validate check-ins, and improve booking accuracy.
3. How We Use Data
We use this information to manage bookings, show availability and queues, send appointment and account notifications, provide customer support, maintain account security, prevent fraud and misuse, and improve the platform.
4. Payments and Stripe
When an online deposit is required, payment is processed by Stripe and, where applicable, the selected shop's Stripe Connect account. TressTime does not store full payment-card numbers. We receive and retain the payment and booking information needed to confirm the deposit, prevent duplicate processing, manage disputes or refunds, and meet our legal and accounting obligations.
5. Shop Subscriptions and Billing
Shop owners may subscribe to a paid Pro plan for reduced fees and additional features. Subscription payments, renewals, and billing history are processed and held by Stripe (via its Billing product) against TressTime's own platform account, separately from deposit payments. TressTime retains the subscription status needed to apply Pro features and pricing, but does not store card details. A shop owner can cancel a Pro subscription at any time from their Billing page; access continues until the end of the period already paid for. From time to time, TressTime may grant a shop complimentary access to Pro features at no charge, for example to let a shop trial the platform; this does not involve any card details or Stripe billing at all.
6. Google Calendar Connection
A shop owner can optionally connect their own Google Calendar from their Shop Details page. If they do, TressTime requests read-only, free/busy access to that calendar (Google's calendar.readonly scope) — we can see when time is marked busy, but not event titles, descriptions, guests, or any other event content. We use this only to block out busy time from that shop's bookable slots, so customers aren't offered a time the owner has already committed elsewhere. We store the OAuth access and refresh tokens needed to keep this connection working, encrypted at rest, and we never see the owner's Google account password. A shop owner can disconnect their calendar at any time from the same page; doing so deletes the stored tokens immediately.
7. Check-In, Reliability, and Fair-Use Decisions
To protect customers and shops, we process booking behaviour data including manual and automatic check-in events, booking status outcomes (including cancelled and no-show), and customer reliability indicators used for abuse prevention. Shop owners may view reliability indicators for customers booking their own shop and may apply shop-level restrictions for repeated misuse. We do not sell this data.
8. Automatic Check-In (Location-Based)
When location permission is enabled on the mobile app, TressTime may automatically check in a confirmed appointment if the customer is within the check-in window and near the shop location, to reduce false no-show outcomes when customers forget to tap check-in. Check-in records include a timestamp and location coordinates. You can disable location access in your device settings, but some check-in features may be unavailable as a result.
9. Legal Basis for Processing (UK GDPR)
We process your data based on: contract performance (to provide booking and, for shop owners, subscription services); legitimate interests (to improve services and prevent fraud); legal obligations; and your consent (for location access, optional notifications, and a shop owner's choice to connect a Google Calendar).
10. Data Sharing
We share the minimum booking details needed by your selected shop and assigned barber to deliver the appointment. Barbers operate as independent service providers. We share information with service providers where necessary to operate TressTime, including Stripe (deposits, payouts, and shop subscription billing), Google (only for shops that choose to connect a calendar, and only free/busy data), and other trusted providers for hosting, transactional email, push notifications, and real-time messaging, under confidentiality obligations. We do not sell personal data. We may disclose information where required by law.
11. International Transfers
Your data may be processed in the United Kingdom. If we or our service providers transfer data outside the UK, we ensure appropriate safeguards are in place in accordance with UK data protection law.
12. Data Retention
We retain personal data as long as necessary to provide services, meet legal requirements, resolve disputes, and prevent fraud. Reliability and anti-abuse records (for example, cancellation/no-show and block history) may be retained for a limited period where required to prevent fraud, resolve disputes, and enforce platform safety policies. Google Calendar OAuth tokens are deleted immediately when a shop owner disconnects their calendar, or if the connection is revoked by Google.
13. Your Rights and How to Complain
Under UK GDPR, you have the right to access your personal data, correct inaccurate data, request deletion, restrict processing, object to processing, and data portability. You can update your profile, change your password, request a data export, manage browser permissions, and request account deletion from Settings. Some information may need to be retained where required for completed bookings, payment records, fraud prevention, or legal obligations.
To exercise your rights or raise a concern about how we handle your data, contact support@tresstime.com first — we'll acknowledge your complaint and aim to resolve it directly. If you're not satisfied with our response, you also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
14. Security
We use reasonable technical and organisational safeguards to protect your information, including encryption of sensitive stored credentials such as Google Calendar OAuth tokens. However, no system can guarantee absolute security.
15. Children's Privacy
TressTime is not intended for children under 13. We do not knowingly collect personal information from children under 13.
16. Changes to This Policy
We may update this policy from time to time. The "Last updated" date above will be revised accordingly.