Privacy Policy

Last updated: 24th May 2021

The Good Hair Co. respects your right to privacy.  This Privacy Policy explains who we are, how we collect, share and use personal information about you, and how you can exercise your privacy rights.  This Privacy Policy only applies to personal information that The Good Hair Co. (“The Good Hair Group Ltd”,“us”, “our”, “Company” or "we") collect and process about you through our website at www.thegoodhair.co (“Website”), our web application, and consultation service (collectively, the "Service"). 

By using or accessing the Services in any manner, you acknowledge that you accept the practices and policies outlined in this Policy, and you hereby consent that we will collect, use, and share your information in the following ways.

If you have any questions or concerns about our use of your personal information, then please contact us by using the contact details provided at the bottom of this Privacy Policy.

Collecting Personal Data

The personal information that we may collect about you broadly falls into the following categories:

Information that you provide voluntarily

Certain parts of our Website may ask you to provide personal information voluntarily. For example, we may ask you to:

  • Provide your first name, last name, email and phone number in order to register an account with us, 

  • Provide your gender, birthday, hair images, lifestyle information and consultation notes to create your profile.

  • Answer general questions about your hair through online surveys and video consultations

  • Provide feedback on our product and service through product reviews, follow-up surveys or phone call

  • Provide your payments details (excluding bank account and full payment card details) to complete your purchase with us 

  • Subscribe to marketing communications from us

  • Submit enquiries to us.  

Information that we collect automatically

When you visit our Website, we may collect certain information automatically from your device.  In some countries, including countries in the European Economic Area, this information may be considered personal information under applicable data protection laws.

Specifically, the information we collect automatically may include information like your IP address, device type, unique device identification numbers, browser-type, broad geographic location (e.g. country or city-level location) and other technical information. We may also collect information about how your device has interacted with our Website, including the pages accessed and links clicked. 

Collecting this information enables us to better understand the visitors who come to our Website, where they come from, and what content on our Website is of interest to them. We use this information for our internal analytics purposes and to improve the quality and relevance of our Website to our visitors.

 

Information that we obtain from third party sources

From time to time, we may receive personal information about you from third party sources (including Google Calendar, Typeform, Stripe, Flodesk, Acuity), but only where we have checked that these third parties either have your consent or are otherwise legally permitted or required to disclose your personal information to us. 

We may also receive your data indirectly from Google analytics, Facebook ads conversion tracking (Facebook Pixel) and referrals via friends and family. 

The types of information we collect from third parties include usage data (such as details of your use of the Service, such as traffic data and the features that you access), transaction data (such as details about purchases and payments, but excluding bank account and full payment card details). We use the information we receive from these third parties to maintain and improve the accuracy of the records we hold about you and improve our services to you.

 

Sharing Personal Data

We may disclose your personal information to the following categories of recipients: 

  • to our group companies, third party services providers and partners who provide data processing services to us (for example, to support the delivery of, provide functionality on, or help to enhance the security of our Website), or who otherwise process personal information for purposes that are described in this Privacy Policy or notified to you when we collect your personal information;

  • to any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person;

  • to an actual or potential buyer (and its agents and advisers) in connection with any actual or proposed purchase, merger or acquisition of any part of our business, provided that we inform the buyer it must use your personal information only for the purposes disclosed in this Privacy Policy;

  • to any other person with your consent to the disclosure.

 

Processing Personal Data

Our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it. 

 However, we will normally collect personal information from you only (i) where we need the personal information to perform a contract with you, (ii) where the processing is in our legitimate interests and not overridden by your rights, or (iii) where we have your consent to do so. 

If we ask you to provide personal information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information). 

If we collect and use your personal information in reliance on our legitimate interests (or those of any third party), this interest will normally be to operate our platform and communicating with you as necessary to provide our services to you and for our legitimate commercial interest, for instance, when responding to your queries, improving our platform, undertaking marketing, or for the purposes of detecting or preventing illegal activities.  We may have other legitimate interests and if appropriate we will make clear to you at the relevant time what those legitimate interests are.

If you have questions about or need further information concerning the legal basis on which we collect and use your personal information, please contact us using the contact details provided below.

Cookies and similar tracking technology

We use cookies and similar tracking technology (collectively, “Cookies”) to collect and use personal information about you which may include your IP address, geolocation data, device identification, "cookie" information, the type of browser and/or device you're using to access our Services, and the page or feature you requested.  

Storing Personal Data

We use appropriate technical and organisational measures to protect the personal information that we collect and process about you.  The measures we use are designed to provide a level of security appropriate to the risk of processing your personal information. If you require further information about these protective measures, you can request it by contacting us using the contact details provided below. 

International data transfers

Your personal information may be transferred to, and processed in, countries other than the country in which you are resident. Our third party service providers and partners operate around the world.  This means that when we collect your personal information we may process it in any of these countries. These countries may have data protection laws that are different to the laws of your country and, in some cases, may not be as protective.

However, we have taken appropriate safeguards to require that your personal information will remain protected in accordance with this Privacy Policy. If you require further information about these protective measures, you can request it by contacting us using the contact details provided below. 

Data retention

We retain personal information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements). 

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.

Data Protection Rights

You have the following data protection rights:

  • If you wish to access, correct, update or request deletion of your personal information, you can do so at any time by contacting us using the contact details provided below. 

  • In addition, you can object to processing of your personal information, ask us to restrict processing of your personal information or request portability of your personal information. Again, you can exercise these rights by contacting us using the contact details provided below.

  • You have the right to opt-out of marketing communications we send you at any time.  You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing emails we send you.  To opt-out of other forms of marketing (such as postal marketing or telemarketing), then please contact us using the contact details below.

  • Similarly, if we have collected and processed your personal information with your consent, then you can withdraw your consent at any time.  Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.

  • You have the right to complain to a data protection authority about our collection and use of your personal information.  For more information, please contact your local data protection authority.

Updating this Privacy Policy

We may update this Privacy Policy from time to time in response to changing legal, technical or business developments. When we update our Privacy Policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make.  We will obtain your consent to any material Privacy Policy changes if and where this is required by applicable data protection laws.

You can see when this Privacy Policy was last updated by checking the “last updated” date displayed at the top of this Privacy Policy. 

Contact Us

The Good Hair Co. is the data controller of your personal information and can be contacted at hello@thegoodhair.co. If you have any questions or concerns about our use of your personal information or wish to exercise any of your rights please do contact our dedicated team at hello@thegoodhair.co.