Answers

Is my salon client data safe and GDPR compliant?

Last updated by the LushLane editorial team.

Short answer

Under UK GDPR a salon must have a lawful basis for holding client data, collect explicit consent for marketing, keep data only as long as needed, keep it secure, and be able to export or delete a client's record on request. Your booking software should make consent flags, export and deletion one-click actions.

Marketing consent is separate

A client giving you their number to book is not consent to be marketed to. Record marketing consent separately, with a date, and honour opt-outs immediately.

Right of access and erasure

Clients can ask for a copy of their data or its deletion. You need to be able to do both without contacting your software provider.

What to check in your software

UK/EU data hosting, role-based staff permissions, per-client export and delete, and a clear data processing agreement. LushLane provides all four.

Try LushLane free for 60 days. £22/month after that, 0% commission, no contract, no card needed to start.

Start 60 days free

In short

Is my salon client data safe and GDPR compliant?

Under UK GDPR a salon must have a lawful basis for holding client data, collect explicit consent for marketing, keep data only as long as needed, keep it secure, and be able to export or delete a client's record on request. Your booking software should make consent flags, export and deletion one-click actions.