Privacy Policy
This Privacy Policy explains how Good to Glow ("we", "us", "our") collects, uses, and protects your personal data when you use Good to Glow ("the Service"). We are committed to GDPR compliance and your data sovereignty.
1.Data Controller
Good to Glow
Dubai, United Arab Emirates
Email: hello@goodtoglow.ae
For all data protection enquiries, please contact us at the email above. We will respond within 30 days.
2.Data We Collect
We collect the following personal data to provide our at-home beauty service:
- Account & contact data: your name, phone number, and (optional) email address.
- Service address & location: the address you book to, and — with your permission — your device's precise location, used to set that address accurately and match you with nearby specialists.
- Booking data: the services you book, your chosen specialist, appointment times, and your booking history.
- Profile photo: only if you choose to add one.
- Notification token: a device push token, if you enable notifications, so we can send booking updates.
- Consent records: timestamps and choices recorded when you accept terms or opt in/out of marketing.
We do not sell your data, and we do not use it for advertising or cross-app tracking.
3.Location Data
The Good to Glow mobile app uses location data to deliver the service:
- Customers: with your permission, we use your device location to match you with nearby specialists, estimate arrival times, and help you enter your service address accurately.
- Team members (specialists and drivers): while you are on shift and the app is open, your device shares your live location so the team and customers can see arrival progress and coordinate visits.
Location is collected only while the app is in use (foreground) — we do not track your location in the background. You can revoke location permission at any time in your device settings; the app still works, but location-dependent features (specialist matching, live tracking) will be limited. Live team positions are retained only transiently for operational coordination and are not used for advertising or sold to third parties.
4.Legal Basis for Processing (GDPR Art. 6)
- Contract performance (Art. 6(1)(b)): processing your account and organisation data to deliver the Service.
- Consent (Art. 6(1)(a)): marketing emails — you can withdraw consent at any time by clicking "unsubscribe" or emailing us.
- Legitimate interest (Art. 6(1)(f)): usage analytics and security logging to maintain and improve the Service.
- Legal obligation (Art. 6(1)(c)): tax records and billing history where required by law.
5.Sub-processors
We share data only with service providers who process it on our behalf:
- Supabase — secure database & authentication. Data stored in eu-central-1 (Frankfurt, Germany). Privacy policy.
- Vercel — application hosting. Privacy policy.
- Google Maps Platform — geocoding your address and estimating drive times / arrival ETAs. Privacy policy.
- Resend — sending transactional emails (confirmations, reminders, receipts).
- Expo — delivering push notifications.
- Stripe — payment processing when you pay by card. We never store your card number.
- Anthropic — powering in-app assistant and personalisation features; inputs are processed transiently and are not used to train models.
6.International Data Transfers
Your personal data is stored in Frankfurt, Germany (EU) by default. Some of our sub-processors (Vercel, Google, Resend) are headquartered in the United States. Data transfers to the US are covered by the EU–US Data Privacy Framework or Standard Contractual Clauses (SCCs) pursuant to GDPR Art. 46.
7.Data Retention
- Active account data: retained for the duration of your account.
- Deleted accounts: soft-deleted immediately; hard-deleted after 30 days. Backups purged within 90 days.
- Billing records: retained for 7 years as required by tax law.
- Consent logs: retained for 5 years as evidence of lawful processing.
- Usage logs: aggregated and anonymised after 90 days.
8.Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access (Art. 15): request a copy of all data we hold about you.
- Rectification (Art. 16): correct inaccurate data.
- Erasure (Art. 17): request deletion of your account and associated data.
- Portability (Art. 20): receive your data in a machine-readable format (JSON).
- Restriction (Art. 18): request that we restrict processing while a dispute is resolved.
- Objection (Art. 21): object to processing based on legitimate interest.
- Withdraw consent: for marketing emails, at any time, without affecting prior processing.
To exercise any right, email hello@goodtoglow.ae. We will respond within 30 days. You can also delete your account and all associated data instantly in the app: Account → Delete account.
If you believe we have violated your rights, you may lodge a complaint with the German Federal Commissioner for Data Protection (BfDI) at bfdi.bund.de, or with the supervisory authority in your country of residence.
10.Security
We implement appropriate technical and organisational measures including:
- AES-256 encryption at rest (Supabase managed)
- TLS 1.3 in transit
- Row-Level Security enforced at the database layer
- Service-role API keys never exposed to the client
- Passwords hashed with bcrypt (handled by Supabase Auth)
In the event of a data breach, we will notify affected users and the relevant supervisory authority within 72 hours as required by GDPR Art. 33.
11.Changes to This Policy
We will notify you of material changes by email and/or by posting a notice in the application at least 14 days before the change takes effect. Continued use of the Service after that date constitutes acceptance of the updated policy.