Last updated: 16 May 2026
This Privacy Policy explains how Crystal Confidence Aesthetics collects, uses, stores, and shares personal information when you use this website, contact us, book an appointment, pay for a treatment, or receive appointment follow-up emails.
Who We Are
Crystal Confidence Aesthetics provides aesthetic treatments and consultations in Kirby Cross, Frinton-on-Sea. For data protection purposes, Crystal Confidence Aesthetics is the controller of the personal information described in this policy.
You can contact us using the contact details or contact form provided on this website.
Personal Information We Collect
We collect the information needed to respond to enquiries, manage bookings, provide treatments, take payments, and keep appropriate business records.
Information You Give Us
- Your name, email address, and phone number.
- Contact form messages and any information you choose to include in them.
- Appointment details, including the treatment or consultation selected, appointment date and time, payment option, and booking status.
- Information shared before, during, or after an appointment, including treatment suitability details, preferences, concerns, allergies, medication, medical conditions, contraindications, previous treatments, reactions, aftercare matters, or other information relevant to providing a safe and appropriate service.
- Your follow-up email preference, including if you unsubscribe from appointment follow-up emails.
Payment Information
Payments are processed by Stripe. This website stores local payment status and Stripe reference details, such as a checkout session ID or Stripe customer ID, so that we can match a payment to a booking. We do not store your full card number, card security code, or full payment card details in this website.
Technical Information
When you use the website, we may process technical information such as your IP address, browser or device information, request logs, security events, and information stored in necessary cookies. The contact form uses Cloudflare Turnstile, so verification information is sent to Cloudflare to help distinguish genuine enquiries from automated spam. Pages with an embedded Google Map may allow Google to process technical information when the map loads.
How We Use Your Information
We use personal information for the following purposes:
- To respond to enquiries sent through the contact form.
- To let you choose a treatment, select an appointment slot, and complete a booking.
- To create and manage appointments, including cancellations, completions, and admin-created payment links.
- To send appointment confirmations, payment links, appointment notifications, and service follow-up emails connected with appointments you have attended.
- To take and reconcile payments through Stripe.
- To keep internal appointment notes needed for service continuity, treatment suitability, aftercare, client support, and complaint handling.
- To manage follow-up email preferences and unsubscribe requests.
- To protect the website, prevent spam or misuse, maintain security, troubleshoot issues, and keep audit and operational records.
- To meet legal, tax, accounting, insurance, and dispute-resolution obligations.
Our Lawful Bases
Under UK data protection law, we rely on one or more lawful bases depending on why we use your information:
- Contract: to take steps at your request before providing a treatment or consultation, to manage bookings, and to provide services you have requested.
- Legitimate interests: to run and protect the business, respond to enquiries, keep proportionate client records, prevent fraud or spam, send service follow-up emails, and improve our operations.
- Legal obligation: where we need to keep records or disclose information to comply with applicable law.
- Consent: where we ask for your consent for a specific use of information.
Some information you provide may include health-related or treatment suitability information. This can be special category data under UK data protection law. Where we need to process that information, we do so only where we have an Article 9 condition, such as your explicit consent, where it is necessary for legal claims, or another condition that applies to the circumstances.
Who We Share Information With
We only share personal information where needed for the purposes described in this policy. Recipients may include:
- Stripe, for payment processing, checkout, payment status, fraud prevention, and customer/payment records.
- Email and hosting providers used to deliver enquiries, appointment emails, payment links, and website services.
- Cloudflare, for Turnstile verification on the contact form.
- Google, where you choose to load or interact with embedded Google Maps on the website.
- Professional advisers, insurers, regulators, law enforcement, courts, or other parties where this is needed for legal, regulatory, insurance, accounting, or dispute-resolution reasons.
We do not sell your personal information.
International Transfers
Some service providers may process personal information outside the UK. Where this happens, we expect those providers to use legally recognised transfer safeguards, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU standard contractual clauses, or another lawful transfer mechanism.
How Long We Keep Information
We keep personal information only for as long as needed for the purposes described in this policy, including service delivery, business administration, legal obligations, insurance, tax, accounting, and dispute handling.
- Client identity and contact details are generally kept for up to 6 years after your latest retained appointment.
- Appointment history, booking contact snapshots, local payment linkage records, and appointment follow-up workflow records are generally kept for up to 6 years after the appointment date.
- Internal appointment notes are generally cleared 12 months after the appointment date.
- Abandoned checkout appointment holds are deleted after checkout expiry. Public booking checkouts expire after 45 minutes. Admin-created payment links expire after 24 hours.
- Contact form messages held in the business email inbox are generally kept for 12 months.
- Website admin login session records are kept for a fail-safe maximum of 7 days after last activity.
- Database backups are retained for a maximum of 30 days, so information deleted from the live system may remain in backups until those backups expire.
Cookies And Embedded Content
The website uses necessary cookies and similar storage for booking flow continuity, security, admin login, fraud or spam prevention, and remembering that you closed the cookie notice. These cookies are needed for the website to work properly.
The contact and home pages may include embedded Google Maps. The contact form uses Cloudflare Turnstile. Payment pages are provided by Stripe. These third-party services may set their own cookies or process technical information under their own privacy notices.
We do not currently use advertising cookies or analytics cookies on this website.
Service Follow-Up Emails
Follow-up emails are service messages connected with completed appointments. They are not marketing emails. You can unsubscribe from appointment follow-up emails using the link provided in those emails.
Your Rights
Depending on the circumstances, you may have the right to:
- Ask for access to your personal information.
- Ask us to correct inaccurate or incomplete information.
- Ask us to delete information.
- Ask us to restrict how we use information.
- Object to uses based on legitimate interests.
- Ask for a copy of information you provided in a portable format.
- Withdraw consent where we rely on consent.
- Complain to the Information Commissioner's Office.
Some rights are not absolute. For example, we may need to keep certain records for legal, accounting, insurance, or dispute-resolution reasons.
You can contact us using the contact details or contact form provided on this website if you want to exercise your rights or ask a privacy question.
Complaints
We would appreciate the chance to deal with your concern first. You also have the right to complain to the UK Information Commissioner's Office at https://ico.org.uk/make-a-complaint/.
Automated Decision-Making
We do not use your personal information for solely automated decision-making that has legal or similarly significant effects on you.
Changes To This Policy
We may update this Privacy Policy from time to time. The latest version will be available on this page.