Privacy notice
Last updated 30 August 2026
This notice covers two different sets of people, and it is worth being clear which is which. There are salon owners, who give us their details when they ask us for a booking page. And there are the clients who book with those salons, whose details pass through the software but belong to the salon, not to us.
Who we are
Dayslot is a product of TKX8 LIMITED, a company registered in England and Wales, company number 17427341. Our registered office is 42 Fountain Road, Birmingham, England, B17 8NR, and you can reach us at info@dayslot.co.uk.
TKX8 LIMITED is the controller for the details a salon owner gives us — everything described under If you are a salon owner. For a salon client’s booking details the salon is the controller and we are its processor: we hold that data on the salon’s instructions, and it is the salon you deal with about it. That is why an erasure request from a client goes to the salon, who can action it immediately, and not to us.
If you are a salon owner
When you ask us to build you a booking page, the form on our site asks for:
- your name or your salon’s name
- your email address
- your mobile number, if you choose to give it — the field is optional
- your Instagram handle, if you choose to give it — also optional
We use those to build the page, to show it to you, and to reply to you. We do not sell them, we do not share them with other salons, and we do not add you to a marketing list you did not ask for.
If you never become a customer, we delete the enquiry automatically after 180 days. That is a scheduled job, not a promise someone has to remember to keep.
If you booked an appointment at a salon
The salon is in charge of your details. We only hold them so the booking works. When you book, that means your name, your email address and your phone number, plus the appointment itself.
We never market to you. If you book with a salon that uses Dayslot, you will hear from that salon about your appointment and from nobody else. We do not build a profile of you across salons and we do not sell anything to you or about you.
You do not need an account and you never set a password. Your confirmation email carries a private link that lets you move or cancel the appointment yourself, which is why there is no login to protect.
If you want your details erased, ask the salon you booked with. Erasure is a single action for them: it removes your personal details and records that the erasure happened, so there is a verifiable trail without keeping the data the trail is about.
Your data rights
Under UK GDPR you can ask us, or the salon, to:
- Tell you what is held about you and give you a copy of it.
- Correct anything wrong.
- Erase it. Salon clients should ask their salon, who can do this immediately. Salon owners can email us.
- Object to how it is used, or ask us to restrict that use.
- Take it elsewhere in a portable format.
Email info@dayslot.co.uk and we will respond within one month, which is the statutory limit. If you are not satisfied with how we handle it, you can complain to the Information Commissioner’s Office at ico.org.uk.
Where your data is kept
Your bookings and your salon’s data live in the United Kingdom, in a database hosted in London. That is the copy that matters: the client list, the appointments, the services and the hours.
Two things travel further, and we would rather say so than imply otherwise. Confirmation and reminder emails are sent through a provider that stores the message and its delivery record in the United States — the message contains the name, email address and appointment time it is about. And the website itself is served from a global network, so a page request may be handled outside the UK even though the data behind it is not.
We deliberately keep personal details out of places they tend to leak into. Booking links never carry your name or email in the address bar, and our error reporting strips personal details before an error is recorded, so an engineer debugging a problem does not see who it happened to.
A small number of suppliers help run the service. Each one only sees what it needs to do its job:
- Supabase — the database and file storage holding salon and booking data.
- Vercel — hosts the website and runs the code behind it.
- Resend — sends the emails: confirmations, cancellations and reschedules.
- Sentry — where it is switched on, records technical errors so we can fix them, with personal details stripped before the error is recorded.
- PostHog — product analytics, only where you have consented.
- Anthropic — powers the AI assistant, where a salon has switched it on.
- Cal.com — handles the booking if you book a call with us.
Some of those suppliers are based in the United States, so some personal data is transferred outside the UK. Where that happens it is covered by a recognised safeguard: either the UK Extension to the EU-US Data Privacy Framework, or the UK Addendum to the Standard Contractual Clauses approved by the Information Commissioner. We do not send personal data anywhere that is not covered by one of those. If you want to know which applies to a particular supplier, email us and we will tell you.
Cookies
We do not use advertising cookies and we do not track you around the internet. Where analytics are switched on they are asked for by consent first, and declining does not change how the site works.
Changes
If this notice changes in a way that matters, we will change the date at the top and, where the change affects you directly, tell you about it rather than relying on you re-reading this page.