Privacy Policy
Last updated 21 July 2026 · Version v1.0
Controller: Clements & Catterall LTD (company number 16966378), trading as Thyme Studio
Registered office: 128 City Road, London EC1V 2NX
ICO registration: ZC093528
Contact: privacy@thymestudio.co.uk
1. Who we are
1.1Thyme Studio is a salon and studio management platform operated by Clements & Catterall LTD, a company registered in England and Wales under company number 16966378, whose registered office is at 128 City Road, London EC1V 2NX.
1.2We are registered with the Information Commissioner's Office under registration number ZC093528.
1.3We are the data controller for the personal data described in this policy. You can contact us about anything in it at privacy@thymestudio.co.uk.
1.4We have not appointed a Data Protection Officer. We are not required to, because of the scale at which we operate. Privacy matters are handled directly by the company's directors.
2. What this policy covers — and what it does not
2.1This policy explains how we handle personal data for which we are responsible. That mainly means information about the businesses that use Thyme Studio and the staff who hold logins.
2.2It does not cover your clients' information. When a salon records details about its own clients in Thyme Studio, that salon is the data controller and we act only as its processor, under our Data Processing Addendum.
2.3If you are the client of a salon that uses Thyme Studio and you want to see, correct or delete your information, please contact the salon directly. They control that data. We cannot act on your request without their instruction, but if you contact us we will tell you so and let them know you got in touch.
3. What we collect
3.1When you create and use an account, we collect:
- (a)business details — business name, address, contact details, opening hours and similar settings;
- (b)account details for each staff member — name, email address, role and permissions;
- (c)billing information — subscription plan, payment history and invoices. Payments are handled by Stripe and we never receive or store your card number;
- (d)a verified business mobile number, which you must provide before you can send SMS through the Service, and which exists to prevent misuse of our shared sending number;
- (e)usage records — how much of your plan's allowances you have used, and logs of AI and messaging activity;
- (f)support and feedback you send us; and
- (g)anything you type into the Sprout AI chat.
3.2We also collect limited technical information automatically, including your IP address and details of the browser and device you use, in order to keep the Service secure and working.
4. Why we use it, and our lawful basis
4.1We use personal data for the purposes set out below. In each case we rely on the lawful basis stated.
Providing the Service — Creating and running your account, hosting your data and delivering the features you subscribe to. Lawful basis: performance of a contract.
Billing and payment — Taking subscription payments, issuing invoices and managing plan changes. Lawful basis: performance of a contract.
Keeping accounting records — Retaining financial records as company and tax law require. Lawful basis: legal obligation.
Support — Answering your questions and resolving problems. Lawful basis: performance of a contract.
Security and fraud prevention — Detecting and preventing misuse, including verifying that a sending number is genuine, blocking bot registrations, and rate limiting. Lawful basis: legitimate interests — protecting our platform, our customers and the recipients of messages sent through it.
Improving the Service — Understanding how features are used so we can make the product better. Lawful basis: legitimate interests — developing and improving a product our customers rely on.
Marketing to you — Telling you about features and offers. Lawful basis: legitimate interests for existing customers, and consent for anyone who is not yet a customer.
AI features — Generating suggestions and answering questions through Sprout. Lawful basis: performance of a contract.
4.2Where we rely on legitimate interests, we have assessed that our interests do not override your rights, and you can ask us for a copy of that assessment.
5. AI features and your data
5.1Thyme Studio includes AI-assisted features, which we call Sprout. They are powered by a third-party AI provider identified on our sub-processors page.
5.2For structured suggestions, Sprout receives only business-level and aggregate information — service names, prices, team size, booking volumes and similar. The set of fields that can be sent is fixed in our code, and an automated test prevents any client-identifying field being added to it.
5.3The Sprout chat feature sends whatever you type to our AI provider. We ask you not to type client names or personal details, and we show a permanent reminder in the chat. We do not automatically scan or filter what you type, so this is something you need to control.
5.4Sprout conversations are automatically and permanently deleted 90 days after they take place.
5.5We do not use your data, or anything you type into Sprout, to train AI models.
6. Who we share it with
6.1We share personal data with the service providers we use to run Thyme Studio. Our current providers, what each one does, and where each is located are listed on our sub-processors page, which we keep up to date.
6.2In summary, we use providers for hosting and databases, payment processing, SMS delivery, email delivery, AI features and error tracking.
6.3We may also share personal data where the law requires it, where we need to establish or defend legal claims, or with a buyer if we sell or reorganise our business.
6.4We do not sell personal data, and we do not share it with advertisers.
7. Sending data outside the UK
7.1Our main database is hosted in the UK or the European Economic Area.
7.2Some of our providers are based outside the UK, mainly in the United States. Where we transfer personal data to them, we rely on a transfer mechanism recognised under UK data protection law — normally the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
7.3You can ask us at privacy@thymestudio.co.uk which mechanism applies to a particular provider.
8. How long we keep it
8.1We keep personal data only as long as we need it. Our retention periods are:
Your account and business data — For as long as your account is active. If your subscription ends and you do not request deletion, we keep it for 90 days so you can resubscribe, then delete it.
After you request deletion — You have 30 days to change your mind, during which the deletion can be reversed. After 30 days we permanently and irreversibly delete your dataset and your staff login credentials. All remaining copies, including backups, are purged within a further 90 days.
Financial and accounting records — 6 years, as company and tax law require. This is the only exception to the deletion above.
Support and feedback — 24 months from the date the matter is closed.
AI usage and rate-limiting logs — 12 months, after which we keep only aggregate counts.
In-app notification records — 90 days.
Sprout chat conversations — 90 days, deleted automatically.
Message history — For as long as your account is active, as part of your business records, then deleted with the rest of your data.
Error monitoring records — 90 days.
9. Your rights
9.1You have the right to ask us to:
- (a)give you a copy of the personal data we hold about you;
- (b)correct anything that is wrong;
- (c)delete it, in some circumstances;
- (d)restrict how we use it, in some circumstances;
- (e)transfer it to another provider in a portable format; and
- (f)stop using it where we rely on legitimate interests, or stop using it for marketing at any time.
9.2Where we rely on your consent, you can withdraw it at any time. That does not affect anything we did before you withdrew it.
9.3To exercise any of these rights, email privacy@thymestudio.co.uk. We will respond within one month. We will not charge you, unless a request is manifestly unfounded or excessive.
9.4We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you.
9.5If you are unhappy with how we have handled your personal data, please tell us first so we can try to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113.
10. Cookies
10.1We use a small number of cookies. Our Cookie Policy explains what they are, what they do, and how to object to the ones that are not strictly necessary.
11. Keeping data secure
11.1We take security seriously. Measures include database-enforced separation between customers, role-based access control, encryption in transit, and secure handling of credentials so that no privileged key is ever exposed to a browser.
11.2No system is completely secure, but if a personal data breach occurs that is likely to result in a risk to your rights, we will tell you and the Information Commissioner as the law requires.
12. Changes to this policy
12.1We may update this policy. If a change is material, we will tell you by email or through the Service at least 30 days before it takes effect.
12.2The version and date of this policy are shown at the top of this page.