Privacy policy
Last updated: 30 August 2026
This policy explains, in plain English, what Craftrun does with personal data. It applies to the Craftrun application, our website, and the public booking pages we host for businesses that use us. We have tried to write it so that a person can read it in one go, rather than burying the important parts in defined terms.
We handle personal data in line with the UK GDPR and the Data Protection Act 2018.
Who is responsible for what
This distinction matters, because it decides who you go to about your data.
- Your data as a Craftrun account holder. If you run a business and subscribe to Craftrun, we are the data controller for your account: your name, email address, business details and billing records.
- Your customers' data. When a business uses Craftrun to take bookings, that business is the data controller of its own customers' information. We are its data processor — we store and process that information on the business's instructions, and we do not use it for our own purposes.
So: if you booked an appointment with a business through a Craftrun booking page and you want your details corrected or removed, contact that business first. They control the record. If they cannot help, contact us and we will assist them.
What we collect and why
If you have a Craftrun account
- Account details — your name, email address, password (stored only as a hash, never in readable form), business name, trade and public booking page address. We need these to give you an account at all.
- Business content you enter — services, prices, availability, stock items, quotes, bookings, invoices, income and expense records. This is your working data; we hold it so the product works.
- Billing information — your subscription plan, billing period and payment history. Card numbers are handled by Stripe and never reach our servers.
- Technical and security logs — IP address, browser type, and timestamps of sign-ins and significant actions. These exist so we can detect abuse and diagnose faults.
If you book with a business that uses Craftrun
- Contact details — your name, email address and phone number, so the business can confirm the appointment and reach you on the day.
- Booking details — the service, date, time, address where relevant, and any answers you gave to the business's booking questions.
- Payment records — whether a deposit or balance has been paid, and when. Card details go directly to Stripe.
Some trades ask health-related questions on their booking form — a beauty business may need to know about allergies or patch tests, for example. That is special category data. The business asking for it is responsible for having a lawful basis to do so and for asking only what it genuinely needs; we store it encrypted and restrict access to it the same way we do everything else.
Our lawful bases
- Performance of a contract. Running your account, taking your subscription payment, and sending booking confirmations, reminders and receipts. These are the service itself — a booking confirmation is not marketing and you cannot opt out of it while holding a booking.
- Consent. Marketing emails from us about new features or offers, and any non-essential cookie. You give consent by a positive action and you can withdraw it at any time, by using the unsubscribe link in any marketing email or by changing your cookie choice. Withdrawing consent does not affect anything done before you withdrew it.
- Legitimate interests. Keeping the service running, secure and free of abuse; understanding which features are used so we can improve them; and defending legal claims. We have weighed these against your interests and limited what we do accordingly — for example, our security logs are kept short and are not used to profile anyone.
- Legal obligation. Keeping accounting and tax records, and responding to lawful requests from authorities.
How long we keep things
- Account and business records — 6 years after your account closes. This is the one that surprises people, so here is the reason: HMRC requires business records to be kept for at least six years, and a booking or a payment is a business record. If we deleted your bookings the moment you cancelled, we would be destroying the evidence you may need for a tax enquiry. After six years, records are deleted.
- Marketing contact details — until you unsubscribe, and then only a minimal suppression record so that we do not email you again by mistake.
- Security and access logs — 12 months.
- Backups — rolling 30 days, after which deleted data disappears from backups too.
If you ask us to erase data that we are legally required to retain, we will restrict it instead — locked away, not used for anything — and delete it as soon as the retention period ends. We will tell you when we do this and why.
Your rights
Under UK GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have data deleted, where we have no overriding obligation to keep it.
- Portability — receive your data in a common, machine-readable format. In practice you do not need to ask us for this: CSV export is built into the product and you can use it whenever you like.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time, with no reason needed.
- Restriction — ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
Email privacy@craftrun.co.uk and we will respond within one month. There is no charge. We may ask you to confirm who you are first, which is a protection for you, not an obstacle.
Where your data lives
The application is hosted on Vercel in London and the database and file storage sit on Supabase in the EU. Data is encrypted in transit (TLS) and at rest. Where a sub-processor handles data outside the UK or EEA, that transfer is covered by UK-approved safeguards — the International Data Transfer Addendum or standard contractual clauses.
Sub-processors
We use a small number of suppliers to run the service. Each is bound by a data processing agreement and may only use data to provide their service to us.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database, file storage and authentication — where your business's records are held | EU (Frankfurt) region |
| Vercel | Application hosting and content delivery — serves the pages you and your customers use | London (lhr1) region |
| Stripe | Subscription billing, and card payments your customers make to you | EU and US, under Stripe's standard contractual clauses |
| Resend | Transactional email — booking confirmations, reminders and account emails | EU and US, under standard contractual clauses |
We do not sell personal data, and we do not share it with advertisers or data brokers. If we add or change a sub-processor we will update this page and, where the change is significant, tell account holders by email before it takes effect.
Security
- Encryption in transit and at rest.
- Passwords stored as salted hashes; we cannot read your password.
- Database-level access rules, so one business's records are not reachable from another business's account.
- Access to production systems limited to those who need it, with multi-factor authentication.
No system is perfectly secure. If a breach occurs that is likely to risk your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours and tell affected people without undue delay.
Children
Craftrun is a business tool and is not intended for anyone under 18. We do not knowingly create accounts for children. A business may legitimately hold a booking made by a parent on a child's behalf; that record belongs to the business as controller.
Cookies
Cookies are covered separately, including the categories we set and how to change your mind. See our cookie policy.
Complaints
Please come to us first at privacy@craftrun.co.uk — most things are a misunderstanding we can fix quickly. If you are not satisfied, you have the right to complain to the UK supervisory authority:
- Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- Helpline 0303 123 1113 — ico.org.uk/make-a-complaint
Complaining to the ICO does not stop you from also seeking a remedy through the courts.
Changes to this policy
If we change this policy we will update the date at the top. For changes that materially affect how we use your data, we will email account holders before the change takes effect.