Legal
Privacy Policy
Bedminster Sun and Beauty Ltd
3-5 North Street, Bedminster, Bristol, BS3 1EN
info@bedminstersunandbeauty.co.uk
Last updated: May 2026
Who we are
Bedminster Sun and Beauty Ltd ("we", "us", "our") is the data controller for personal data collected through the Sun & Beauty mobile application ("the App"). We are registered in England and Wales.
What data we collect
When you create an account through the App, we collect:
- Personal details — full name, date of birth, email address, phone number, and optionally your home address and GP name
- Health screening information — answers to UV tanning screening questions, skin type, and relevant medical conditions (eczema, psoriasis, photosensitivity, medication affecting skin)
- Account activity — sunbed credit purchases, usage history, and transaction records
- Consents — records of your agreement to our terms, UV risk acknowledgement, GDPR consent, and marketing preferences
- Membership identifier — a unique QR code assigned to your account
Why we collect it and our legal basis
| Purpose | Legal basis |
|---|---|
| Creating and managing your sunbed account | Contract |
| Health screening before UV treatment | Legal obligation / Vital interests |
| Sending your welcome email and QR code | Contract |
| Recording your GDPR and liability consents | Legal obligation |
| Sending occasional marketing emails (if opted in) | Consent |
How we store your data
Your data is stored securely using Google Firebase, hosted in the United Kingdom (Google Cloud region: europe-west2, London). Google LLC acts as a data processor on our behalf under a Data Processing Agreement.
Your welcome email is delivered via Resend (Resend Inc.), which processes your email address and name solely for the purpose of sending that email. No data is retained by Resend beyond delivery.
We do not sell, rent, or share your personal data with any third parties for their own purposes.
How long we keep your data
- Active accounts — retained for as long as your account is active
- Inactive accounts — accounts with no login or transaction activity for 3 years will be permanently deleted
- Transaction records — kept for 7 years to comply with UK financial record-keeping requirements, even if your account is deleted
- Deletion requests — processed within 30 days of your request
Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data (via the profile section of the App, or by contacting us)
- Delete your account and personal data (via the "Delete my account" option in the App, or by contacting us)
- Restrict or object to processing in certain circumstances
- Withdraw consent for marketing emails at any time (via the profile section of the App)
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk
To exercise any of these rights, contact us at info@bedminstersunandbeauty.co.uk.
Health data
The health and medical information you provide is classified as special category data under UK GDPR. We collect it solely to assess your suitability for UV tanning treatment and to fulfil our duty of care. It is not used for any other purpose and is not shared with third parties.
Children
The App is intended for users aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has registered, please contact us and we will delete the account promptly.
Changes to this policy
We may update this policy from time to time. We will notify you of significant changes via the App or by email. The date at the top of this page shows when it was last updated.
Contact
Bedminster Sun and Beauty Ltd
3-5 North Street, Bedminster, Bristol, BS3 1EN