Legal
Privacy Policy
Last updated 6 June 2026
Who we are
Next Generation Barbers (“we”, “us”, “our”) is a barbershop in Llanelli. This policy explains what personal information we collect when you use our website and online booking system, how we use it, and the rights you have over it.
The data controller — the person legally responsible for your information — is Mark Gee, trading as Next Generation Barbers. You can reach us using the details in the Contact us section below.
The information we collect
We only collect what we need to take and manage your appointments:
- Your name, phone number and (if you give it) email address.
- Your bookings — the service, barber, date, time, price and status (e.g. completed, cancelled, no-show), and any notes you add to a booking.
- If you create an account: your sign-in email and a securely-hashed password (we never see your actual password), and your notification preferences.
- Private notes a barber may keep about your visits (for example a preferred cut or an allergy) — visible only to shop staff.
- Whether you've agreed to receive marketing, if we ever offer it.
- Basic technical data needed to run the site securely, such as the strictly-necessary cookie that keeps you signed in.
We do not take payment online, so we do not hold card or bank details. We do not knowingly collect any special category data (such as health information) beyond anything you choose to tell a barber.
How we use your information, and our lawful basis
Under UK GDPR we must have a lawful basis for using your data:
- To provide the booking service — taking, changing, reminding you about and managing your appointments. Lawful basis: performance of a contract with you.
- To send booking confirmations, reminders and cancellation notices by email (and, in future, SMS). Lawful basis: contract — these are service messages, not marketing.
- To run the shop responsibly — keeping booking and takings records, and recording no-shows or cancellations so staff can manage the diary. Lawful basis: our legitimate interests in running the business.
- To keep accounting and tax records. Lawful basis: legal obligation.
- To send you a one-off email after a visit inviting you to leave a Google review. Lawful basis: our legitimate interests in growing a small local business; every such email has a one-click opt-out and we only ever ask once.
- To send marketing or offers, only if we ever introduce it and you have opted in. Lawful basis: your consent, which you can withdraw at any time.
Who we share it with
We never sell your data. We share it only with the trusted service providers (“processors”) that run the system on our behalf, under contracts that require them to protect it:
- Supabase — our database, sign-in and file storage. Your data is held in a data centre in London, UK.
- Resend — sends our booking confirmation, reminder and account emails (email provider based in the USA).
- Twilio — sends text-message reminders and notices, if and when we enable SMS (provider based in the USA).
- Netlify — hosts and serves the website.
- Sentry — collects technical error and diagnostic reports when something goes wrong, so we can find and fix faults quickly (provider based in the USA). We have it configured not to record your IP address, and it does not capture a recording of your screen.
- Our website developer — builds, maintains, patches and improves the website and booking system on our behalf under a written agreement, and only accesses personal data as far as needed to keep it running securely.
Each of these acts only on our written instructions and may not use your data for their own purposes. We may also disclose information if the law requires it, or to establish, exercise or defend legal claims.
Sending data outside the UK
Our database is hosted in the UK. Some providers (our email and SMS senders) are based in the United States, so limited data — such as your name and the message we send you — may be processed there. Where that happens, the transfer is protected by appropriate safeguards recognised under UK data protection law, such as the UK International Data Transfer Agreement / Addendum or the UK extension to the EU–US Data Privacy Framework.
How long we keep it
We keep booking and takings records for as long as needed to run the business and to meet our accounting and tax obligations (generally up to six years). Your account details are kept while your account is active. If you ask us to delete your information, we will remove or anonymise it where we are not legally required to keep it — past bookings may be retained in an anonymised form that no longer identifies you, for our financial records.
Your rights
Under UK GDPR you have the right to:
- Be told how your data is used (this policy).
- Ask for a copy of the data we hold about you.
- Have inaccurate data corrected.
- Ask us to delete your data (the right to erasure) — or, if you have an account, delete it yourself any time from your account settings.
- Ask us to restrict or object to how we use it.
- Ask for your data in a portable format.
- Withdraw consent at any time, where we rely on consent.
To exercise any of these, contact us using the details below. We'll respond within one month. There's normally no charge.
Marketing and messages
Confirmations, reminders and cancellation notices are part of the service you ask for, so we send them without needing separate consent. We will only send marketing if you have opted in, and every marketing message will include a way to opt out. Any text messages will include a STOP option.
Cookies
We use only strictly-necessary cookies — chiefly the one that keeps you signed in to your account. We don't use advertising or third-party tracking cookies, so no cookie banner is needed. If that ever changes, we'll update this policy and ask for your consent first.
Children
We offer cuts for children, but a parent or guardian should make and manage the booking. We don't knowingly create accounts for children.
Keeping your data secure
Access to customer data is limited to shop staff through password-protected accounts, passwords are stored only in hashed form, and data is encrypted in transit. No system is perfectly secure, but we take reasonable steps to protect your information and will tell you and the regulator about a serious breach where the law requires.
Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last changed. Significant changes will be highlighted on this page.
Complaints
If you're unhappy with how we've handled your data, please contact us first so we can put it right. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk or on 0303 123 1113.
Next Generation Barbers is registering with the ICO as a data controller.
Contact details
If you have any questions about this privacy policy or our privacy practices, or you want to exercise any of your rights, please contact the data controller in the following ways:
Mark Gee
Next Generation Barbers
By email: markgee0@gmail.com
By post: 38 B Thomas Street Llanelli United Kingdom
