PRIVACY POLICY

How BYOUTY LTD collects, uses and protects personal data

Last updated: 2 September 2026

This Privacy Policy explains how BYOUTY LTD processes personal data when you visit shop.byouty.uk, create an account, place an order, contact us, request product or trichology support, book an appointment or otherwise interact with us.

It is intended to provide the information required by the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations and related UK data-protection legislation as amended from time to time.

1. Controller and contact details

BYOUTY LTD is the controller responsible for the personal data covered by this Policy.

BYOUTY LTD

Company number: 13643982

Registered office: Next To 54 College Road, Kensal Vintage Shop

London, England, NW10 5ET

Email: shop@byouty.uk

Website: https://shop.byouty.uk

Contact us at shop@byouty.uk for privacy questions, rights requests or complaints. We have not appointed a data protection officer because we do not currently consider one legally required.

2. Scope

This Policy covers the Website, online shop, account area, contact forms, order and return communications, delivery administration, customer support and connected appointment or communication services used by BYOUTY. Separate third parties may act as independent controllers under their own privacy notices.

3. Personal data we collect

Depending on how you interact with us, we may collect:

  1. Identity and account data: name, username, account identifier, password hash, login and account status. We do not have access to your readable password.
  2. Contact data: email address, telephone number, WhatsApp details, billing and delivery addresses and postcode.
  3. Order and transaction data: products, quantities, order value, discounts, samples, invoices, payment status, delivery, tracking, returns, refunds and complaints.
  4. Payment-related data: payment method, provider references, authorisation and fraud-check results. Full card details are normally handled by the payment provider rather than BYOUTY.
  5. Technical and usage data: IP address, device and browser information, timestamps, security logs, pages viewed, referring source, campaign or order-attribution information, basket and account activity, cookies and similar identifiers.
  6. Communication data: messages, form submissions, emails, customer-service records, photographs, call or appointment notes and preferences.
  7. Product-safety data: product, packaging, batch or lot number, photographs, reported defect, reaction or incident and information needed to investigate or comply with safety duties.
  8. Appointment data: booking time, service, contact details and related notes processed through Fresha or another appointment service.
  9. Marketing data: consent, opt-out, communication preferences and records of messages if marketing is introduced.
  10. Business-customer data: organisation, role, professional status, purchase purpose, invoice information and authorised contacts.

4. How we collect data

We collect personal data directly from you when you register, order, communicate, return goods, request an invoice, book or attend a consultation, submit a review or provide product-safety information. We also collect data automatically through the Website and may receive limited information from payment providers, Royal Mail or other couriers, appointment providers, fraud-prevention services, analytics services and social or review platforms.

5. Purposes and lawful bases

We process personal data only where we have a lawful basis. The main purposes and bases are:

  1. Contract: to create and administer accounts, process orders and payments, deliver goods, provide invoices, manage returns and refunds, respond to order-related enquiries and provide requested appointments or services.
  2. Legal obligation: to keep accounting and corporate records, comply with tax, consumer, product-safety, recall, customs, fraud-prevention and regulatory duties, and respond to lawful authority requests.
  3. Legitimate interests: to operate and improve the Website and business, secure accounts, prevent fraud, maintain records, manage stock, analyse service performance, handle complaints, establish or defend legal claims and communicate with customers about similar products where electronic-marketing rules allow it. We consider and balance the effect on individuals before relying on this basis.
  4. Consent: for non-essential cookies or tracking where consent is required, optional marketing, and special-category information where explicit consent is the appropriate legal condition. Consent may be withdrawn at any time without affecting earlier lawful processing.

6. Account registration and temporary passwords

Registration may create an account, temporary password, password-setting link or automatic authenticated session. We process username, email, security and session data to provide restricted price access, maintain the account and protect the Website. Passwords are stored in protected hashed form rather than as readable text.

We may use the registration email to send necessary service information, including account security, password, product-use instructions relevant to the requested service, order administration and the availability of requested support. We will not treat a necessary service email as consent to unrelated marketing.

7. Orders, payments and fraud prevention

Order data is used to take payment, assess fraud risk, confirm and fulfil orders, issue tracking, provide support, process returns and maintain financial records. Payment methods shown at checkout are provided by third-party payment processors that receive the information necessary to authorise and settle payment. Their handling of card or wallet data is governed by their own privacy information.

We may review unusual ordering patterns, repeated claims, payment failures, chargebacks, account activity and delivery information to prevent fraud and protect customers and BYOUTY. We do not currently make decisions producing legal or similarly significant effects solely by automated means without appropriate safeguards.

8. Delivery and international orders

We share necessary recipient, address, contact, parcel and tracking information with Royal Mail or another selected carrier. For international delivery, information may be disclosed to postal operators, customs authorities, freight or clearance providers and destination carriers, including outside the United Kingdom.

You must provide accurate delivery and customs information. Carrier tracking and delivery data may be returned to us so that we can administer the order and investigate loss or delivery disputes.

9. Customer support, email and WhatsApp

When you contact us by form, email or WhatsApp, we process the details and content of the communication to respond, keep an appropriate record and protect legal rights. WhatsApp is provided by a Meta group company and may process account, device and communication metadata under its own terms and privacy notice.

Do not send more personal or sensitive information than necessary. We may move a conversation to email or another appropriate channel where this better protects privacy or creates a reliable record.

10. Trichology enquiries and health-related information

A message about hair loss, alopecia, allergies, irritation, scalp conditions, medication or health history may reveal special-category health data. Please do not include health information in a general shop message unless it is necessary for the support or consultation you request.

Where you intentionally provide health-related information for a trichology enquiry or product-safety report, we will use it only for the relevant request, safety assessment, referral or legal obligation. Where required, we will ask for explicit consent or identify another lawful Article 9 condition before further processing. Information may be shared with the selected trichology professional or product-safety recipient only where necessary and with appropriate safeguards.

Online product or trichology communications are not emergency or medical services. Do not submit urgent medical information through the Website.

11. Fresha and appointment services

If you request or book an appointment, consultation or related service, relevant contact, booking and service information may be processed through Fresha or another scheduling provider. That provider may act as our processor for some functions and as an independent controller for its own platform operations. Its own privacy notice also applies.

We will not add shop customers to an appointment platform merely because they purchased a product unless this is necessary for a service they requested or another lawful basis applies.

12. Product defects, adverse reactions and recalls

We process product, order, contact, photographic, batch and incident information to investigate defects, adverse reactions, safety concerns and recalls. Where necessary, we may disclose limited information to the manufacturer, Nubea, the UK Responsible Person, importer, distributor, insurer, professional adviser or competent authority.

We do not routinely provide customer data to Nubea for marketing or ordinary sales administration. A safety-related disclosure will be limited to what is reasonably necessary or legally required.

13. Cookies and similar technologies

The Website uses cookies and similar storage or access technologies. These may include:

  1. strictly necessary technologies for security, login, account access, basket, checkout, payments, load balancing and fraud prevention;
  2. preference technologies that remember choices or presentation settings;
  3. statistical technologies used to understand Website use and improve performance, including WordPress, WooCommerce, Jetpack or Automattic services;
  4. order-attribution technologies that record referral, campaign or session information; and
  5. third-party technologies such as Google reCAPTCHA used to distinguish legitimate use from spam or abuse.

Where the law requires consent, non-essential technologies should not be used until consent is obtained. Certain limited statistical technologies may be used without consent where the legal statistical-purpose exception applies, clear information is provided, data is appropriately aggregated and a simple free means of objection is available. You can also control cookies through browser settings, although disabling essential cookies may prevent account or checkout functions.

14. Marketing

BYOUTY does not currently treat account registration or purchase as automatic consent to newsletters or WhatsApp marketing. If marketing is introduced, we will use consent or the limited existing-customer exception only where its legal conditions are met and will provide an easy opt-out in each electronic message.

You may withdraw marketing consent or object at any time by using the unsubscribe method provided or contacting shop@byouty.uk. We may keep a minimal suppression record so that your preference is respected.

15. Who we share data with

We may share personal data, only as necessary, with:

  1. Website, hosting, WordPress, WooCommerce, Elementor, security, backup and technical-support providers;
  2. payment processors, banks, wallet providers and fraud-prevention services;
  3. Royal Mail, international postal operators, couriers, customs and delivery partners;
  4. email, form, customer-support and communication providers, including WhatsApp where used;
  5. Fresha or another appointment provider and the selected professional supporting a requested consultation;
  6. Google reCAPTCHA, Automattic, Jetpack, WooCommerce Analytics and other analytics or infrastructure providers used by the Website;
  7. accountants, insurers, lawyers, auditors and other professional advisers;
  8. manufacturers, the UK Responsible Person, importers, distributors and authorities for product safety, adverse events or recalls;
  9. law enforcement, courts, regulators and public authorities where disclosure is required or legally justified; and
  10. a purchaser, investor or successor in connection with a genuine business sale, restructuring or due-diligence process, subject to confidentiality and legal safeguards.

Service providers are required to protect data and use it only for authorised purposes where they act on our behalf. Some recipients act as independent controllers and provide their own privacy information.

16. International transfers

Some providers, carriers or recipients may process personal data outside the United Kingdom, including in the European Economic Area, the United States or the delivery destination. Where UK data-protection law requires safeguards, we rely on an adequacy regulation, the UK International Data Transfer Agreement or Addendum, approved contractual safeguards, or another lawful transfer mechanism. You may contact us for information about the applicable safeguards.

17. Retention

We keep personal data only for as long as reasonably necessary for the purposes described, including legal, accounting, safety and dispute requirements. Our current retention criteria are:

  1. Order, invoice, payment, refund and core accounting records: normally six years after the relevant transaction or accounting period, or longer where law or a live dispute requires it.
  2. Account data: while the account is active; inactive accounts are reviewed and may be deleted or anonymised after approximately three years, while order records required by law are retained separately.
  3. General enquiries and customer-service communications: normally up to 24 months after the last meaningful contact, unless connected to an order, complaint or legal claim.
  4. Appointment and consultation information: for the period needed to provide and follow up the service and comply with applicable professional, insurance or legal requirements. Health-related information is kept no longer than necessary for the specific purpose.
  5. Product-safety, adverse-event and recall records: for the period required to investigate, cooperate with responsible parties and satisfy product-safety or limitation requirements.
  6. Security, technical and fraud logs: normally up to 12 months, unless needed for an investigation, legal claim or system security.
  7. Marketing records: until consent is withdrawn or you object, plus a minimal suppression record needed to honour the request.

18. Security

We use reasonable technical and organisational measures designed to protect personal data, including access controls, account authentication, restricted administrative access, payment-provider separation, backups and security monitoring appropriate to the nature of the data. No internet service is completely secure, and you are responsible for protecting your password and devices.

Access is limited to BYOUTY personnel, authorised fulfilment support and service providers who need it for their role. If we become aware of a personal-data breach, we will assess and notify the Information Commission and affected individuals where legally required.

19. Your rights

Depending on the circumstances, UK data-protection law gives you the right to:

  1. request access to your personal data and information about its use;
  2. request correction of inaccurate or incomplete data;
  3. request erasure where there is no continuing lawful reason to retain the data;
  4. request restriction of processing;
  5. receive certain data in a portable format;
  6. object to processing based on legitimate interests or to direct marketing;
  7. withdraw consent at any time where processing relies on consent; and
  8. challenge qualifying solely automated decisions and request human involvement.

Rights are not absolute and exemptions may apply. To make a request, email shop@byouty.uk. We may ask for proportionate identity verification. We normally respond within one month, subject to lawful extensions for complex or multiple requests.

20. Account deletion

You may ask us to close your account by emailing shop@byouty.uk. Closing an account does not require deletion of order, payment, tax, product-safety or dispute records that we must or may lawfully retain. Where possible, non-essential account data will be deleted or anonymised.

21. Privacy complaints

Please contact shop@byouty.uk first if you have a concern about our use of personal data. We will acknowledge a data-protection complaint within 30 days and respond without undue delay, taking into account its nature and complexity.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority. Information is available at https://ico.org.uk. If you live outside the UK, you may also have a right to contact your local data-protection authority.

22. Children

The Website account and checkout are intended for adults aged 18 or over. We do not knowingly create shop accounts for children. If a product is purchased for a child, the adult purchaser is responsible for checking the label, ingredients, age suitability and instructions. Contact us if you believe a child has provided account data without appropriate authority.

23. Third-party websites and platforms

The Website may link to Nubea, social networks, review platforms, payment services, Fresha or other third parties. We do not control their independent processing. Review their privacy notices before providing data directly to them.

24. Changes to this Policy

We may update this Policy to reflect legal, technical or business changes. The current version will be published on the Website with a revised date. Where a change materially affects how we use existing data, we will provide additional notice or seek consent if required.