1. Who is responsible
Controller for platform accounts, subscription billing, security logs, support tickets, marketplace accounts and this website: COZQ Limited. Company number 16592649. VAT number 519163195. ICO registration ZC022310. Registered in England and Wales. Registered office: 20 Wenlock Road, London, England, N1 7GU.
Privacy requests: [email protected]. Support: [email protected] or cobbtree.com/support.
2. Scope and people
This notice covers:
- customers who browse, book or hold a Cobbtree account;
- people a business records as clients;
- business owners, staff and other authorised users;
- people who contact support or appear in reviews or photos.
3. Information we use
Depending on how Cobbtree is used, we may process:
- identity and contact details: name, email, phone, login, job title;
- business information: trading name, locations, hours, staff profiles, services, Sites and listings;
- booking information: times, services, staff, notes, waitlist entries, cancellation records;
- payment-related metadata: Stripe customer or connected-account identifiers, last four digits, charge status, subscription status, application or commission fees. Full card numbers and CVCs are handled by Stripe, not stored by Cobbtree;
- reviews, photos, logos and other content you upload;
- device and usage information: IP address, browser, app version, cookies and similar storage described in the Cookie Notice, security logs;
- approximate location when you search the marketplace or allow device location;
- support messages and live-chat content if you use chat;
- consultation, allergy, patch-test and treatment information a business records (see section 7);
- marketing preferences, and records that you accepted legal documents (including time, method and IP address, used as evidence of contract formation).
4. Sources
Information comes from you directly; from a business that already holds your client record; from optional integrations a business connects (calendar, Google Business Profile, Facebook booking links); from Stripe; from authentication and device data; and from public listing activity such as reviews.
Cobbtree does not currently offer Sign in with Apple or Sign in with Google for customer accounts. Customer sign-in uses email one-time codes.
5. Controller and processor roles
We are not joint controllers with a business unless a specific activity meets that legal test. In practice:
- Cobbtree as controller: your Cobbtree login, consumer profile, marketplace account, our SaaS invoices, fraud and security, our own marketing, and platform analytics we carry out for our own purposes.
- Business as controller, Cobbtree as processor: client records, appointment notes, consultation forms, marketing lists the business stores, staff rotas the business manages, and similar workspace data. The Data Processing Addendum applies.
- Separate independent controllers: Stripe for much of its payment processing; a business for the treatment contract with its client; app stores for app distribution.
If you book a salon, that business sees the details needed to fulfil the booking. That sharing is necessary for the contract you make with the business.
6. Purposes and lawful bases
- Contract: creating accounts, running bookings, sending booking and receipt messages, billing Cobbtree subscriptions, providing partner software.
- Legitimate interests: securing the platform, preventing fraud, operating marketplace discovery, improving product features, storing legal-acceptance evidence. You may object where the right applies.
- Legal obligation: tax, accounting, and responding to lawful requests.
- Consent: optional Cobbtree marketing, optional support chat, and optional functional storage that is not strictly necessary. You can withdraw consent.
Recognised legitimate interests introduced by the Data (Use and Access) Act 2025 may apply to some processing (for example certain crime-prevention activities) where the statutory conditions are met. We do not rely on a recognised legitimate interest unless it actually fits the activity.
7. Special-category data
Cobbtree can store information that may reveal health or other special-category data if a business records it (allergies, medications, pregnancy, skin conditions, contraindications, disabilities, consultation answers, patch tests, treatment notes). The business must have an Article 9 condition. Our condition for processing as processor is that we act on the business's instructions under Article 28. We do not use that information for our own marketing.
9. International transfers
Some providers process information outside the United Kingdom (including Stripe, Expo, tawk.to, Google font delivery, and Cloudflare's edge). Where a transfer is restricted, we use an adequacy regulation or a UK-approved transfer tool such as the UK Addendum to the EU standard contractual clauses or the UK International Data Transfer Agreement, as applicable to that provider. We do not claim that personal data never leaves the UK.
10. Retention and deletion
Account and billing records are kept while the account is open and then as needed for tax, disputes and security (financial records are typically kept up to six years). Security logs are kept for a shorter operational period unless we are investigating abuse. Booking records a business controls follow that business's retention, subject to our backups and legal holds. Backups are rotated on an operational cycle. We cannot promise that a deleted record vanishes from every backup on the same day.
Customers can request deletion in the iOS or Android app (Account, then Security, then Delete my account) or by emailing [email protected]. On the web you can also request deletion from your account profile. Deleting a personal login does not destroy a live business: a sole owner must confirm that those businesses should be suspended. Staff diaries, appointments and financial records are kept for the business's legal retention.
Customers can request a copy of data we hold as controller by emailing [email protected] or using Request my data in the web account profile. Businesses can export many operational records through reports (CSV, Excel and PDF where the product provides them). Some information may require a separate request where it is not included in an available account or report export.
11. Security
We use TLS for traffic to the public site (including through Cloudflare), access controls, and application security practices appropriate to a hosted SaaS product. We do not claim end-to-end encryption of all data at rest, a named ISO certification, or that "all data is encrypted" in every system. Card data is handled by Stripe.
12. Automated decisions and AI
Cobbtree uses ordinary business logic (for example pricing rules, availability, fraud checks and discovery ranking). We do not currently expose a general-purpose AI assistant that generates legal or clinical advice. We do not make solely automated decisions that produce legal or similarly significant effects about you without human involvement where UK GDPR would require it.
13. Marketing and cookies
Cobbtree marketing to individuals uses consent or another PECR-lawful route. Businesses must not use Cobbtree tools to send marketing without their own lawful basis. Cookies and similar technologies are described in the Cookie Notice. Optional support chat (tawk.to) loads only if you allow it.
14. Children
Cobbtree customer accounts are aimed at adults. We do not knowingly create consumer accounts for children under 13. A business that treats a minor is responsible for appropriate consents, including photographs.
15. Your rights
You may ask for access, correction, erasure, restriction, portability, or to object to legitimate-interests processing, and to withdraw consent. Email [email protected]. If a salon holds your client file, contact that salon as well. You can complain to the ICO at ico.org.uk. We are registered under ZC022310.
16. Changes
We will update this page when our practices change. Significant changes may be emailed to account holders. Related: Terms of Use, Data Processing Addendum.