Privacy Policy
Fadelio is a booking platform for barbershops and salons. This policy explains what personal data we handle, in which role, and what your rights are — without the fog.
1Who this policy covers
Three situations, three answers:
You run a shop on Fadelio (or work in one with a staff login) — this policy is for you. We are the controller of your account data, and sections 2–9 explain everything.
You're a client of a shop that uses Fadelio — your barbershop is the controller of your data; we only process it on the shop's behalf to run its bookings. The shop's own privacy page (linked on its booking site) is the document that governs, and questions or requests about your data are best sent to the shop. Section 5 below summarises what we do as the shop's processor.
You're just visiting this website — section 6 (analytics & cookies) is all that applies to you.
“Fadelio”, “we” and “us” means The Operating Algorithm Ltd, the company that operates the Fadelio platform — registered in England and Wales under company number 17120198, registered office 22 Connaught Road, Cardiff, CF24 3PT. We are on the Information Commissioner's Office register of fee payers under registration ZC240064. Contact: hello@fadelio.com.
2Shop owners & staff — what we collect and why
Account & profile: your name, email, phone number, shop name, address and branding. We use these to provide the service (contract). Staff logins carry a name and email so the right person sees the right diary.
Billing: your subscription runs through Stripe; we hold your subscription status and invoices, never your card number.
Payout identity: when you set up payouts, Stripe collects your identity and bank details directly under its own terms — we receive only your connected account's ID and status (charges enabled or not), plus the business details we pre-fill for you.
Usage & support: product activity (privacy-respecting, cookieless analytics) and anything you send us when you ask for help. We use these to run, secure and improve the platform (legitimate interests).
Marketing to you: we'll only send you Fadelio marketing with your consent or where the law allows marketing to existing customers — and every message has an opt-out. We treat sole traders with the same care as consumers here, because UK law does.
3What we don't do
We don't sell personal data, and your client list is yours.
We don't sell personal data. We don't rent client lists. We don't market to your shop's clients for our own benefit or anyone else's, and we never use one shop's client list to help another shop. Your client list is yours — that's in our Terms, not just here.
4
The platform runs on a small set of service providers, each bound by data protection obligations. The live list — every service, what it does, what data can reach it, and where it runs — is published at fadelio.com/legal/subprocessors, and it changes only after the notice promised in our Data Processing Agreement. Today it is Vercel (hosting & cookieless analytics), Supabase (database & authentication), Twilio (SMS), Resend (email) and OpenRouter→Anthropic (drafting AI text).
Stripe (payments & payouts) is an independent controller under its own privacy policy — each shop holds its own Stripe account, and card numbers never touch Fadelio.
Beyond that, we disclose personal data only where the law requires it, to protect the platform and its users from fraud or abuse, or as part of a sale or reorganisation of the Fadelio business (in which case this policy still binds the successor).
5Shops' clients — what we do as processor
For a shop's clients we process: name, phone, email, booking history, payment status (never card numbers), attendance history and attendance-risk indicators (computed on the shop's instruction to support its no-show policy), and marketing preferences including STOP/opt-out records. We do this solely to run the shop's bookings, payments, reminders, marketing and reporting — on the shop's instructions, under our Data Processing Agreement, which meets UK GDPR Article 28.
If you're a client and want your data accessed, corrected or deleted, ask your shop — we've built them the tools to do it. If a message asks you to reply STOP to opt out, that works immediately and permanently for that shop's marketing.
6
This site uses essential cookies only — the ones that keep you signed in to your dashboard. Our analytics (Vercel Analytics) is cookieless and doesn't track you across sites, so there's no consent banner because there's nothing to consent to. If we ever add non-essential cookies, we'll ask first. The one-page Cookie Notice lists exactly what's set.
7Where data lives
The platform's compute runs in London and the database lives in Frankfurt — your shop's data rests in the UK/EEA. Where a provider processes data outside the UK (SMS, email and AI drafting run on US services), the transfer is protected by UK adequacy regulations or the ICO-approved International Data Transfer Agreement/Addendum — the basis for each service is on the sub-processor list.
8How long we keep things
Your shop's data: for as long as you subscribe, then a 30-day export window after your account closes, then deletion (except what tax or legal rules make us keep — e.g. invoices). Suppression records (who said STOP) are kept, because forgetting an opt-out is how you end up texting someone who opted out. Backups roll off on a fixed schedule.
9Your rights
You have the UK GDPR rights: access, correction, deletion, restriction, portability, objection (and you can withdraw consent any time where consent is the basis). Email hello@fadelio.com and we'll respond within a month. If you're unhappy with how we handle it, you can complain to the Information Commissioner's Office (ico.org.uk) — though we'd appreciate the chance to fix it first.
10Changes to this policy
If we change this policy materially, we'll tell shop owners by email or in the dashboard before the change takes effect, and record it in the version history. Minor clarifications take effect when posted.