Privacy policy
How we collect, use, and protect your personal information.
About this policy
This website is a brochure for our salon. It does not host any contact form, sign-up box, or other way of submitting personal information to us through this site. When you want to reach us, you do so through one of the channels listed on the Contact page: WhatsApp, phone, email, walk-in, or Treatwell. This policy explains what happens to your information when you use any of those channels, and what limited technical data the website itself records.
Who we are
Noor Hair & Beauty is the trading name of Somaira Qureshi, a sole trader operating a hair and beauty salon at 181 Bow Road, London E3 2SJ. For the purposes of UK data protection law, Somaira Qureshi is the data controller of any personal information you give us. If you have questions about your data, contact us at hello@noorhairdressers.com or on 020 8981 7063.
Somaira Qureshi is registered with the Information Commissioner's Office under reference [ICO REGISTRATION NUMBER, pending].
Our website is built and operated on our behalf by bygild (bygild.com), who acts as our data processor under a written data processing agreement. The opening hours, prices, photos, and testimonials shown on this site are managed through bygild's client portal.
What this website collects (and what it doesn't)
The site has no forms, no newsletter sign-up, no booking widget, no comment box, and no account login. Loading any page does cause a small amount of technical processing in the background, listed below under "Infrastructure providers." That processing does not identify you as an individual.
We do not run advertising, marketing, profiling, retargeting, or social-media tracking. We do not sell, rent, or share your data with anyone outside the providers listed in this policy.
When you contact us
Personal information reaches us only when you choose to use one of the contact channels below.
Tapping our WhatsApp button opens a chat with us inside the WhatsApp app on your device. WhatsApp (operated by Meta Ireland Ltd in the EEA / UK) is the controller of the messaging platform; we are the controller of the messages once they reach our phone. WhatsApp's own privacy terms apply to the platform itself: whatsapp.com/legal/privacy-policy.
Phone
When you call us, your phone number and any details you share become part of our day-to-day booking records.
When you email hello@noorhairdressers.com, your email address and the contents of your message are stored in our mailbox until we delete them (see "How long we keep your data" below).
Treatwell booking
Tapping "Book on Treatwell" takes you to treatwell.co.uk to choose a slot and pay. Treatwell (operated by JE Booking Services Ltd) is a separate data controller for the booking flow. Once Treatwell sends us your appointment, we hold your name, phone number, and the chosen service. Treatwell's privacy policy is published on their site at treatwell.co.uk (look for "Privacy" in the footer).
Legal basis for processing
We process the information you give us under UK GDPR Article 6(1):
- Contract (Art. 6(1)(b)), for taking a booking or carrying out the appointment
- Legitimate interests (Art. 6(1)(f)), for general enquiries and the day-to-day running of the salon. Our legitimate interest is operating a small local business and serving the clients who contact us
- Legal obligation (Art. 6(1)(c)), for keeping accounting and tax records where the law requires it
Infrastructure providers
The website runs on shared infrastructure managed by our processor, bygild. The third parties that touch any technical data are:
- bygild (data processor) - hosts and operates this website on our behalf, runs the client portal that powers the site's content (hours, prices, gallery, testimonials), and receives anonymous traffic counts to the Gild dashboard. Acts under a written data processing agreement
- Cloudflare, Inc. (USA) sits in front of the website, providing the content delivery network, basic security against attacks, and cookieless Web Analytics. Cloudflare may record your IP address, request headers, and similar technical signals in short-lived security logs
- Namecheap UK (Stellar shared hosting) hosts the website files in the UK and the salon mailbox at the noorhairdressers.com domain
None of these providers markets to you or builds an advertising profile from your visit. The Gild dashboard records first-party page views and CTA clicks (such as which tap on the Book button) without storing your IP or any visitor identifier.
Embedded map
The Contact page shows an embedded map from OpenStreetMap, operated by the OpenStreetMap Foundation. The map serves tile images without setting marketing cookies. Loading the embed shares your IP address and browser user-agent with OpenStreetMap's tile servers, which is what makes the map render.
International data transfers
Cloudflare processes traffic on servers outside the UK, including in the United States. This transfer relies on the UK Extension to the EU-US Data Privacy Framework, where Cloudflare is self-certified, with the ICO's International Data Transfer Addendum (IDTA) as a fallback safeguard. Our hosting and email remain in the UK.
Cookies
The website does not set any non-essential cookies. Cloudflare may set short-lived security cookies to verify you are a real visitor and to protect the site from attacks; these are strictly necessary under PECR Regulation 6(4) and do not require consent. Because there are no non-essential cookies in use, the site no longer displays a cookie consent banner.
We do not load advertising, marketing, profiling, or social-media tracking cookies. Fonts are self-hosted, so no third-party font network is contacted when a page loads.
How long we keep your data
- WhatsApp message history: up to 24 months from your last contact
- Email correspondence: up to 24 months from your last contact
- Phone and appointment records: for as long as needed for the booking, then 12 months after your last visit, then deleted
- Cloudflare security logs: up to 30 days
- Cloudflare Web Analytics page-view counts: retained as aggregated counts with no personal data attached
Your rights
Under the UK GDPR and the Data Protection Act 2018, you have the right to:
- Access: ask for a copy of the personal data we hold about you
- Rectification: ask us to correct anything inaccurate or incomplete
- Erasure: ask us to delete your data ("right to be forgotten")
- Restriction: ask us to limit how we use your data
- Portability: ask for your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Withdraw consent: where we rely on your consent, you can withdraw it at any time. Withdrawal does not affect processing already carried out
- Complain to the ICO: see the Complaints section below
To exercise any of these rights, email hello@noorhairdressers.com. We will respond within one calendar month.
Complaints
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO):
- Online: ico.org.uk/concerns
- Phone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of this page reflects the most recent version.