Privacy Policy
Last updated: 15 May 2026 · UK GDPR & Data Protection Act 2018
Alaa Beauty Studio (“we”, “us”, “our”) operates the website alaa.beauty. This policy explains what personal information we collect when you sign in with Google, send a Free Consultation request, request a booking, message us on WhatsApp, or view the London weather and prayer-times widgets - and how to ask us to delete it under UK GDPR.
1. Who we are
Alaa Beauty Studio is a ladies-only hair, makeup, bridal and home-visit beauty service based in London, United Kingdom. We are the data controller for the information described in this policy.
Contact: beauty.by.alaashareef@gmail.com
WhatsApp / phone: 07825 957159
2. Social Login (Google, Apple & Facebook)
Our website offers “Continue with Google”, “Continue with Apple” and “Continue with Facebook” buttons so you can create an account or sign in without remembering another password. We use the official sign-in product from each provider (Google Identity Services, Sign in with Apple, and Facebook Login) with the popup-based flow. We never see or store your password for any of these providers.
What we ask each provider for
When you choose social login we request only your public profile (name) and email address — the same two pieces of information from whichever provider you choose:
- Google — scopes
openid,profile,email: your Google account ID (sub), name and email. - Apple — Sign in with Apple: a stable user identifier, your name (first sign-in only) and email (which may be Apple's private relay address).
- Facebook — permissions
public_profileandemail: your name and the email on your Facebook account. We request no other Facebook permissions and never post to Facebook on your behalf.
What we actually store
| Data we receive from Google | What we do with it |
|---|---|
Google account ID (sub) |
Used as a stable identifier so we can recognise you on your next visit. |
| Name | Shown in your account, pre-filled into the booking and Free Consultation forms, and used to address you in confirmation messages. |
| Email address | Used to send booking confirmations, password-reset links and important service updates. Never sold or shared for marketing. |
We do not store your Google password, your Google contacts, your calendar, your photos, your YouTube history, or any other data from your Google account beyond the three fields above. We do not post to Google on your behalf.
3. Free Consultation
The Free Consultation form gates through Google Login (so we know who we are talking to). When you submit it, the data we collect is:
- your name and email (taken from your Google account, with the option to edit before sending);
- your mobile phone number;
- which service you are interested in;
- your free-text message describing your occasion and what advice you would like.
Submitting the form opens WhatsApp on your device with the message pre-filled. Sending the message there delivers it to Alaa on 07825 957159. WhatsApp is operated by Meta - see §6.
4. Booking requests
When you fill in the booking form on the homepage, we collect:
- your full name, email and mobile number;
- the service category, service, appointment type, date and time you have requested;
- your area or postcode if you are requesting a ladies-only home visit;
- any free-text notes you add for Alaa;
- your preferred confirmation method (email, SMS, or WhatsApp);
- whether you have ticked the optional marketing-messages checkbox.
Bookings are not confirmed automatically. Alaa reviews every booking personally and replies to confirm availability. We use third-party services to deliver our reply messages - see §6.
5. WhatsApp contact
Several buttons on the site (the green “WhatsApp Alaa” buttons in the hero, footer, contact section and Free Consultation gate) open WhatsApp directly on your device with a message pre-filled.
- We do not see your WhatsApp profile, your contacts, or any other chats.
- The conversation that follows is between you and Alaa on WhatsApp; the data inside that chat is governed by Meta’s WhatsApp privacy policy and is end-to-end encrypted.
- We retain WhatsApp messages for booking and customer-care purposes only. We will delete a WhatsApp conversation history on request - see §10.
6. Other information we collect
- Account details if you register with email + password instead of Google (name, email, password hash, optional mobile and address).
- Technical data automatically logged by our hosting provider (IP address, browser type, referring page) for security and basic analytics.
- Loyalty-points balance after Alaa confirms a completed appointment.
7. London weather widget
The small “London Beauty Weather Today” card on the homepage helps customers plan home visits and bridal appointments around the weather. It is powered by the free Open-Meteo API.
- The widget always asks for the same fixed coordinates (Central London - 51.5072° N, −0.1276° W). It does not request, use, or transmit your location.
- No personal data is sent to Open-Meteo. No API key is involved.
- The current temperature, condition and rain probability are cached in your browser’s session storage for 30 minutes so a refresh does not re-hit the API. This cache stays on your device.
8. Prayer-times widget
Lower on the homepage there is an optional collapsed “Prayer times for appointment planning” card. It is closed by default - opening it is your choice.
- If you tap “Use my location”, your browser asks you for permission to share your location. We never see your coordinates on our servers; the lookup runs in your browser against the public Aladhan API and the result is shown back to you.
- If you instead type a city or postcode into the widget, the text you type is used to look up coordinates in your browser; the city/postcode itself is not stored on our servers.
- You can revoke the location permission at any time in your browser settings.
9. How we use your data
We use the data above to:
- create and secure your Alaa Beauty Studio account;
- respond to enquiries, Free Consultations and booking requests;
- send appointment reminders and booking-related messages;
- improve the website and prevent abuse;
- meet our legal and tax obligations.
We do not use your data for advertising profiling, and we do not sell your personal data to third parties.
10. Legal basis (UK GDPR)
We process your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The lawful bases we rely on are:
- Consent - when you tick a box, click “Continue with Google”, send a Free Consultation, or grant location permission to the prayer-times widget.
- Contract - to provide the beauty service you have booked.
- Legitimate interests - to keep our site secure and to remember you between visits.
- Legal obligation - to keep records required by UK tax and consumer-protection law.
11. Who we share data with
- Cloudflare - hosts our website and stores your account record (Cloudflare Pages + D1 in the United Kingdom / Europe).
- Google LLC - only the round-trip required to verify your Google Login (the verification call to
oauth2.googleapis.com). - Open-Meteo - only the fixed London coordinates for the weather widget. No personal data.
- Aladhan / your browser’s geolocation - only if you open the optional prayer-times widget. Coordinates do not leave your browser.
- SMS / WhatsApp providers - to send you booking confirmations and reminders, if you have given a phone number.
- Email provider - to deliver booking and account emails.
We never share your name, email or phone number with other clients or third-party marketers.
12. How long we keep your data
- Account data: while your account is active, plus 12 months.
- Booking records: 6 years (UK tax requirement).
- Free Consultation messages: up to 24 months.
- WhatsApp / SMS conversations: up to 24 months from the last message.
- Server access logs: 30 days.
You can ask us to delete your account and all associated personal data sooner - see §14.
13. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- correct anything that is wrong;
- have your data deleted (the “right to be forgotten”);
- restrict or object to certain processing;
- receive a portable copy of your data;
- withdraw consent at any time;
- complain to the UK Information Commissioner’s Office (ico.org.uk).
14. How to request data & account deletion
You can ask us at any time to delete your Alaa Beauty Studio account and any data we received from Google Login, the Free Consultation, the booking form or WhatsApp. There is no charge.
- Email us at beauty.by.alaashareef@gmail.com with the subject line “Account deletion request”.
- Or use the form on our data deletion request page.
We will confirm receipt within 7 days and complete deletion within 30 days. We will keep only the minimum information required by UK law (for example, paid-invoice records) and will tell you exactly what, if anything, has been retained and why.
Need to delete your account now?
Email beauty.by.alaashareef@gmail.com or open the dedicated page below.
Open data deletion page →15. Cookies
We use a small number of strictly necessary cookies to keep you signed
in and to protect against fraud. We do not use third-party advertising
cookies. The Google Login popup may set its own cookies on
accounts.google.com; those are governed by Google.
16. Children
Our services are intended for adults aged 18 or over. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact beauty.by.alaashareef@gmail.com and we will delete it.
17. Changes to this policy
We will update this page if our practices change. The “Last updated” date at the top of the page will always reflect the most recent version.