Privacy Policy
This Privacy Policy explains how personal data is handled when you book a session through Slate. Please read it together with the privacy policy of the studio you are booking with — both apply.
1. Who's who
Two organisations handle your data, with different roles. The studio you book with is the data controller — they decide why your data is used (to confirm bookings, send reminders, and, if you consent, market to you). Slate is the data processor — we run the booking platform on their behalf and process your data on their instructions and under this policy.
For questions about how a specific studio uses your data, contact them directly. For questions about the Slate platform itself, use the contact details at the bottom.
2. What we collect
- Identity & contact: name, email, phone.
- Booking details: session, date, seats, notes, gift card codes.
- Payment: processed by Stripe. Card numbers go directly into Stripe's form and never touch our servers. We see only the success confirmation, the amount, and the last 4 digits.
- Technical: IP, browser, device, pages visited — for fraud prevention and to keep the platform working.
- Diagnostics: when something goes wrong, limited error data (page, error message, basic device info). See section 5.
- Marketing consent: if the studio offers an opt-in at checkout and you accept, we record that.
3. Lawful basis (UK GDPR)
- Contract: to fulfil your booking — taking it, taking payment, sending confirmations and reminders.
- Consent: marketing emails (only if you opt in), and non-essential cookies/analytics (only if the studio enables them and you accept).
- Legitimate interest: fraud prevention, security, error monitoring, and basic analytics — balanced against your privacy rights.
- Legal obligation: records required by tax and accounting law (typically 7 years).
4. Who we share with
These processors are bound by data processing agreements and only handle your data for the purposes listed:
- Stripe — payment processing (PCI-DSS).
- Resend — transactional emails (confirmations, reminders, receipts).
- Sentry — error monitoring and limited session replay (see section 5).
- Supabase — database hosting and file storage.
- Vercel — application hosting.
The studio you book with also receives your booking and contact details so they can run the session.
5. Error monitoring and session replay
We use Sentry to capture diagnostic data when something goes wrong. This may include limited session replay — a partial recording of the page where the error happened. We mask form inputs and sensitive fields so names, emails, payment details, and anything you type are not captured. If you'd prefer to opt out of session replay entirely, email us using the details below and we'll exclude you.
6. Analytics and marketing pixels
The studio you book with can choose to enable third-party analytics or marketing pixels (Google Analytics, Meta Pixel, TikTok Pixel) on their booking page. Where enabled, they rely on your consent under PECR. The studio is responsible for obtaining that consent (e.g. via a cookie banner). You can decline, use your browser's privacy settings, or a tracking blocker.
7. Cookies
Strictly necessary cookies (session, authentication, basket) don't require consent — the platform can't work without them. Analytics and marketing cookies are only set if the studio enables them and you consent. You can clear cookies any time in your browser settings.
8. How long we keep data
- Booking and contact data: the duration of your relationship with the studio plus a reasonable period after, typically up to 7 years where required by tax and accounting law.
- Payment records: 7 years (UK financial record-keeping rules).
- Error logs: 30–90 days, then automatically deleted.
- Marketing data: until you withdraw consent or unsubscribe.
9. Your rights
Under UK GDPR you can:
- Access a copy of the personal data we hold about you.
- Rectify data that's wrong.
- Erase your data (subject to legal exceptions like accounting records).
- Port your data in a structured, common format.
- Object to processing based on legitimate interest.
- Withdraw consent for marketing or non-essential cookies at any time (this doesn't affect prior processing).
- Restrict processing while a query is resolved.
To exercise these rights, email us below. For data held by the studio (the controller), contact the studio directly. We'll normally respond within one month.
10. International transfers
Some processors (notably Stripe and Vercel) may process data outside the UK, including in the United States. Where this happens, transfers are protected by UK adequacy decisions where they apply, or by Standard Contractual Clauses combined with the UK International Data Transfer Addendum and appropriate technical safeguards.
11. Security
We use encryption in transit (HTTPS), access controls, secure hosting, and regular review of our processors' security practices. No system is 100% secure; if we ever become aware of a breach affecting your data we'll tell you and the relevant authorities.
12. Complaints
If you're unhappy with how we've handled your data, please contact us first — we want to put it right. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
13. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top always shows the current version. For material changes we'll surface a notice on the platform.
14. Contact us
For privacy questions about the Slate platform, email hello@slateops.co.uk. For questions about how a specific studio uses your data, contact the studio directly — their details are on your booking confirmation.