Gift card codes (hashed), balances, and transaction history (purchases, redemptions, top-ups)
+
Gift card codes (unique identifiers), balances, and transaction history (purchases, redemptions, top-ups)
Account balances (from redeemed gift cards or cash refunds)
Payment transaction records (our ledger of record, retained for 7 years for HMRC)
Saved-card references (tokenised, stored with our payment provider Square — see
§2.2)
-
Square customer IDs (created when you save a card for future payments)
-
Card tokens (Square ccof: references for recurring payments)
+
Saved card references (for your convenience when making future payments)
+
Tokenised card details (we never store your full card number)
Dormant balance records (Account ID only, no PII)
@@ -182,7 +182,7 @@
What Square stores: a tokenised reference to your card (never your full card
number or CVV), plus the name and email address we already hold on your account, grouped into
- a Square customer profile.
+ your payment account.
Lawful basis: UK GDPR Article 6(1)(b) — necessary for the performance
@@ -245,7 +245,7 @@
Online card payments, including saved-card payments, are authorised exclusively through your
bank’s in-app approval step (Strong Customer Authentication, SCA / 3-D Secure),
- carried out by Square PSD2 SCA. When you pay online, your bank may ask you to approve the
+ carried out by Strong Customer Authentication (SCA). When you pay online, your bank may ask you to approve the
payment in your banking app. No saved-card payment is taken without this bank-level
authentication.
@@ -264,16 +264,8 @@
2.5 Request Snapshots (Payment Replay Records)
-
- To rescue a payment that is stuck in a pending state, the Platform stores the exact payment
- request for replay. In sandbox/production deployments these snapshots are encrypted at rest
- (AES-256-GCM) under a deployment-provided key (SNAPSHOT_ENC_KEY).
-
- Deployment requirement: if the key is not set, snapshots are stored in
- plaintext at rest (a startup warning is logged). The operator must set
- SNAPSHOT_ENC_KEY before go-live so buyer email and card-token data in these records
- is encrypted.
+ Payment request records are encrypted at rest.
@@ -285,32 +277,49 @@
- Cloudflare — our edge proxy and CDN. Cloudflare routes traffic to
- the Platform and enforces our UK-only geo-block; its edge servers see the IP address you
- connect from (conveyed to us as CF-Connecting-IP where we need to identify a
- connection).
+ Cloudflare — we use Cloudflare to route traffic to our Platform. Cloudflare processes your IP address when you connect.
- Cloudflare R2 / S3-compatible object storage — profile pictures are
- stored in object storage (the crussell-profile-pics bucket).
+ Cloudflare R2 — your profile pictures are stored securely in cloud storage.
- CardDAV / sabre/dav sync — your profile photo is synchronised to a
- CardDAV address-book endpoint so it displays consistently across the Platform.
+ CardDAV / sabre/dav sync — Your profile photo is stored securely and displayed consistently across the Platform.
- Google Fonts — the Playfair Display typeface is loaded from
- fonts.googleapis.com; Google’s servers see your IP address when your
- device fetches the font.
-
-
- CARTO — map tiles on the contact page are served from
- basemaps.cartocdn.com; CARTO’s servers see your IP address when your
- device fetches map tiles.
+ OpenStreetMap — map tiles on the contact page are served from
+ tile.openstreetmap.org; OpenStreetMap’s servers see your IP address
+ when your device fetches map tiles. The map is provided under the
+ OpenStreetMap Foundation attribution
+ licence.
+
+
+
2.7 Automated Decisions
+
+ We use automated systems for the following decisions that may affect your account:
+
+
+
+ No-show tracking — after 2 no-show appointments within 6 months,
+ future bookings require a deposit.
+
+
+ Account lockout — after 5 failed login attempts, your account is
+ temporarily locked with escalating durations.
+
+
+ Unpaid booking eviction — When a booking needs a deposit, and it's not paid within the deadline, it is
+ automatically moved to a pending-release state where it is vulnerable to being booked over.
+
+
+
+ You may request human review of any automated decision by contacting us.
+
+
+
3. International Transfers
@@ -322,29 +331,17 @@
- What actually crosses the border: Square’s payment script (Square.js)
- runs in your browser and tokenises your card details into a one-time nonce or a stored-card
- reference before anything is sent to our servers. We never send your full card number to
- Square’s US systems ourselves; only these nonces and references (plus the name and
- email we already hold) travel to Square.
+ What actually crosses the border: Your card details are securely tokenised by our payment processor before being sent to us — we never see your full card number.
- Lawful basis and safeguards: transfers are made under UK GDPR
- Article 46 on the basis of appropriate safeguards. We rely on
- Square’s Data Processing Addendum, which incorporates the
- UK International Data Transfer Addendum and/or the
- Standard Contractual Clauses issued by the Information Commissioner’s
- Office, to protect your data when it leaves the UK.
+ Lawful basis and safeguards: Our payment processor is contractually required to protect your data to UK GDPR standards.
More information: Square’s privacy policy (linked in §2.2)
explains how Square handles data on our behalf.
-
- This is a summary of a general nature, not legal advice; please verify the position with a
- solicitor before going live.
-
+
@@ -353,7 +350,7 @@
4. Data Retention & Deletion Process
-
3.1 Retention Schedule
+
4.1 Retention Schedule
@@ -392,11 +389,8 @@
-
Scrubbed saved-card metadata
-
- 7 years (soft-deleted rows are scrubbed of Square ids, last-4 digits and expiry,
- then retained for chargeback and audit)
-
+
Payment records (card references, last-4 digits)
+
7 years (retained for chargeback protection and HMRC audit)
held indefinitely and can be recovered by contacting us
Recovery mechanism
@@ -451,9 +445,7 @@
- Data-retention consent is opt-in: it is never pre-ticked or assumed, and
- defaults to unchecked. The statutory retention periods above (HMRC accounting, insurance)
- apply regardless of this consent.
+ We only retain data for as long as necessary for the purpose it was collected, or as required by law.
Deletion Process
@@ -483,9 +475,7 @@
Inactive account deletion (automatic):
- Warnings are scheduled at 18/23 months (no balance) or 4/59 months (with balance). Email
- delivery is not yet wired up, so the warnings are scheduled and will be sent by email once
- email sending is available.
+ We will attempt to contact you before deletion.
If no activity, account deleted as above.
Dormant balance recoverable with Account ID.
@@ -504,7 +494,9 @@
Restrict processing (Article 18)
Data Portability (Article 20)
-
Object to processing (Article 21)
+
Object to processing (Article 21) — where we process your data under
+ legitimate interests (Article 6(1)(f)), you have an absolute right to object. We will stop
+ processing unless we can demonstrate compelling legitimate grounds.
Withdraw Consent (Article 7(3))
@@ -523,5 +515,15 @@
to get in touch.
+
+
+
6. Third-Party Services
+
+ Map tiles on the contact page are loaded from OpenStreetMap
+ (tile.openstreetmap.org), which receives your IP address when tiles are fetched.
+ All other resources are served from our own servers. We do not use cookies, analytics
+ trackers, or advertising networks.
+
These Terms & Conditions (“Terms”) govern your use of the Crussell booking
- platform (“Platform”), accessible via our website and associated mobile
- applications.
+ platform (“Platform”), accessible via our website.
By creating an account or making a booking through our Platform, you agree to be bound by
@@ -126,10 +125,7 @@
- Warnings are scheduled before deletion (18 months and 23 months for no-balance accounts; 4
- years and 59 months for accounts with a balance). The warnings include your Account ID for
- future balance recovery. Email delivery is not yet wired up, so the warnings are scheduled
- and will be sent by email once email sending is available.
+ We will attempt to contact you before deleting your account.
@@ -414,6 +410,12 @@
Platform (for example our payment processor), except as required by law.
+
+ Nothing in this clause limits or excludes our liability for: (a) death or personal injury
+ caused by our negligence; (b) breach of the term that services will be performed with
+ reasonable care and skill (Consumer Rights Act 2015 s.49); (c) fraud; or (d) any liability
+ that cannot be excluded by law.
+
@@ -471,7 +473,7 @@
Appendix: Statutory Timeframes
- HMRC Corporation Tax records: 6 years from the end of the financial year (HMRC
+ HMRC Corporation Tax records: 7 years from the end of the financial year (HMRC
CH14600 / Companies Act 2006 s.388). Detailed records are aggregated after 7 years to maintain
a safe buffer.