Privacy Policy
Last updated: 26 June 2026
1. Who we are
Data controller: Louise Parkinson, trading as Spray Tan by Lou, 21 Bridge Street, Coleraine, County Londonderry, BT52 1DR, Northern Ireland.
Contact: via Instagram at @spray_tan_by_lou or through the booking system on the home page.
2. What we collect and why
We collect personal data in two places:
- Booking system (Nashira): when you book an appointment, our booking system Nashira collects your name, email address, phone number (if provided), and the date/time of your appointment. This is used to confirm, remind, and manage your booking.
- In-person at your appointment: we may note skin-type and tan-preference details so we can give you a better, more consistent service on repeat visits.
The lawful basis for processing this information is Article 6(1)(b) of the UK GDPR (performance of a contract — i.e. providing the treatment you booked) and, for aftercare information, Article 6(1)(f) (legitimate interests).
3. How long we keep it
Booking records are retained for up to 24 months after your last appointment, after which they are deleted. Any skin-sensitivity or consultation notes are kept for the same period. We do not retain marketing data.
4. Who we share it with
We do not sell or share your data with third parties for marketing. Your data is processed by the following service providers:
- Nashira — our booking platform. Nashira hosts and processes your booking data. The booking widget embedded on our home page sets no cookies and runs no tracking.
- AWS (Amazon Web Services) — hosts this website (CloudFront and S3).
5. International transfers
Our booking system (Nashira) processes your booking data in the UK. Where any service provider transfers personal data outside the UK, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework, as appropriate. These safeguards are designed to give your data a similar level of protection to that which it would have in the UK.
6. Cookies
This site sets no cookies. Our fonts are served from our own server (no request to Google), and the embedded Nashira booking widget sets no cookies and runs no tracking. Because nothing non-essential is stored on your device, there is no cookie banner. See our Cookie Policy for details.
7. Children's data
This website and service are not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has submitted personal data to us, please contact us and we will delete it promptly. Clients under 18 require parental or guardian consent before booking a treatment.
8. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data ("right to be forgotten")
- Restrict or object to processing
- Data portability
- Withdraw consent at any time (where consent is the lawful basis)
To exercise any of these rights, contact us via Instagram or in person.
9. Complaints
If you have a complaint about how we handle your personal data, please contact us first at hello@wroughtweb.com. We will acknowledge your complaint within 30 days and investigate it without undue delay, keeping you informed of the outcome. If you remain unsatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
10. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top reflects the most recent revision.