Legal Information
Privacy Policy
How Aesthetic Be You collects, uses, stores, and protects personal data from website visitors, online shop customers, booking customers, and treatment clients.
Business
Aesthetic Be You
Contact
a.estheticsbeyou@gmail.com
Last Updated
1 April 2026
Who This Policy Applies To
This policy explains how Aesthetic Be You collects, uses, and protects personal data when you browse this website, use the online shop, add items to cart, request a shipping quote, contact the clinic, subscribe to updates, book an appointment, pay a deposit or shop order, complete pre-treatment paperwork, attend a consultation, or receive an aesthetic treatment.
For UK data protection purposes, Aesthetic Be You is the data controller for the personal data described on this page.
Controller details
Aesthetic Be You
171 High St, Burton-on-Trent DE14 1JE
Email: a.estheticsbeyou@gmail.com
Telephone: +44 7530 967900
What Information We Collect
Contact and enquiry data
- name, email address, telephone number, subject line, and message content sent through the contact form or by email
- appointment-related messages exchanged with you about availability, changes, aftercare, or follow-up support
- shop-order or delivery-support messages, complaints, claim evidence, and follow-up communications about fulfillment issues
Booking and clinic payment data
- selected treatment, appointment date, appointment timeslot, and your name, email address, and mobile number entered during booking
- Stripe customer, checkout session, payment status, and transaction reference information
- calendar event details created after successful payment so your appointment can be reserved
Online shop and fulfillment data
- cart contents, selected product variants, quantities, discount code attempts, and the shipping country or delivery details entered to request a live quote or complete checkout
- delivery name, address, email address, telephone number, tax or customs identifiers where supplied, selected shipping option, order totals, Stripe checkout session data, and shop order references
- CJdropshipping order identifiers, fulfillment status, carrier or logistics details, tracking-related updates, delivery exceptions, and evidence submitted for damaged, missing, delayed, or incorrect parcel claims
- payment-risk indicators, chargeback or dispute references, address-validation results, return or cancellation records, and any evidence reasonably needed to investigate fraud, delivery, customs, safety, or payment disputes
Medical, consultation, and consent data
- date of birth, birth sex, body weight, and skin tone information entered in the clinic consent form
- health information such as medical conditions, medications, allergies, reproductive status, neurological or mental health information, lifestyle factors, and prior aesthetic or surgical history
- treatment-specific consent, aftercare acknowledgement, optional photography and marketing preferences, and your signed confirmation that the information provided is accurate
Technical and website usage data
- IP address, browser and device information, pages requested, timestamps, and similar technical data generated when the site is used
- the preferred_locale cookie used to remember language choice and the shop_info_dismissed cookie used to remember when a shop information notice has been closed
- theme preference saved in local storage, the shop-cart-v1 local-storage cart, and overpass-nearby map cache data stored in local storage to improve repeat visits and storefront usability
- analytics, performance, anti-abuse, and external-content request data generated when the site loads hosted checkout pages, maps, product images, or similar third-party resources
Photography and media
Where relevant to treatment, photographs or videos may be taken before, during, or after a procedure to maintain an accurate clinical record. Any separate use of those images for marketing is optional and is based on the consent choice made in the clinic's treatment form.
How We Collect It
- directly from you when you submit the website contact form, newsletter form, booking form, pre-treatment questionnaire, add products to the cart, request a shipping quote, or enter delivery and checkout details
- from Stripe when you complete a deposit payment or shop payment through hosted checkout
- from CJdropshipping, carriers, or fulfillment channels when order creation, fulfillment, tracking, claim, or delivery-status updates are returned
- from Google services used by the clinic to manage the live consent form, booking emails, and calendar bookings
- automatically through normal website operation, hosting infrastructure, cookies, local storage, analytics or performance tooling, and map features
- from you during consultations or follow-up communications when additional clinical or administrative information is needed
How We Use Personal Data
Bookings and administration
We use contact, booking, and payment data to take deposits, reserve appointments, prevent double-booking, send confirmations, and manage cancellations, rescheduling, and follow-up communication.
Online shop orders and fulfillment
We use shop, contact, delivery, and payment data to generate live shipping quotes, take payment, create or reconcile orders with CJdropshipping, coordinate dispatch and delivery, send order updates, and investigate lost, damaged, delayed, incorrect, or disputed deliveries.
Fraud, chargeback, and ecommerce risk management
We use order, payment, device, correspondence, and fulfillment data to verify orders, manage suspected fraud or misuse, respond to payment disputes or chargebacks, recover losses where legally justified, and keep records needed to defend the business against ecommerce-related claims.
Consultation and treatment safety
We use the information in the pre-treatment consent form to assess suitability, identify contraindications, keep treatment notes, provide aftercare, and protect client safety.
Marketing and updates
If you choose to subscribe, we use your email address to send offers, updates, and clinic news. You can unsubscribe at any time.
Website operation and improvement
We use technical and storage-related data to keep the site functioning, remember user preferences such as language, theme selection, and cart state, improve map and storefront performance, detect abuse, and maintain website security.
Legal compliance, product safety, and recalls
Where relevant to the online shop, we use personal data to meet tax, accounting, customs, product-safety, recall, complaint-handling, and legal-reporting obligations, including communicating with customers if a product needs to be withdrawn, investigated, repaired, replaced, or refunded for safety or compliance reasons.
Lawful Bases We Rely On
Contract
To process bookings, take deposits, reserve appointments, handle online shop orders, arrange fulfillment, and communicate with you about the services or products you ask us to provide.
Legitimate interests
To operate the clinic, maintain the website, manage enquiries, keep records, protect the business against misuse, fraud, delivery disputes, or chargebacks, investigate shop-order problems, and improve the way the service runs.
Consent
For optional marketing, optional marketing use of treatment photographs or videos, and explicit consent to process special category health data where required for consultation and treatment planning.
Legal obligations and legal claims
To keep records needed for tax, accounting, insurance, regulatory, and complaint-handling purposes, to meet product-safety or recall obligations, and where necessary to establish, exercise, or defend legal claims.
Special Category Health Data
The clinic's live consent form collects sensitive health information, including medical history, medication use, allergies, reproductive status, mental health indicators, prior cosmetic work, and other suitability information relevant to treatments such as injectables, peels, microneedling, laser-based services, skin procedures, and related aesthetic treatments.
This information is collected because it is necessary to decide whether a treatment is safe and clinically appropriate. If relevant information is not provided, the clinic may not be able to proceed with treatment. Online shop purchases do not normally require this category of health information.
Who We Share Data With
- Stripe, to process online deposits and hosted checkout payments
- CJdropshipping and related warehouses, fulfillment channels, or carriers, to create, route, dispatch, track, investigate, or resolve online shop orders and delivery issues
- payment processors, card issuers, banks, fraud-prevention, insurance, or professional-adviser channels where reasonably necessary to verify orders, respond to chargebacks, or manage ecommerce disputes
- Google services used by the clinic, including Google Forms, Google Calendar, and Gmail or similar Google-hosted communication tools
- Vercel and other infrastructure or hosting suppliers needed to run the website
- technical service providers who help deliver site functionality, maps, notifications, analytics, performance monitoring, or mailing-list workflows
- customs, tax, product-safety, Trading Standards, regulators, courts, or law-enforcement bodies where disclosure is necessary or legally required
- professional advisers and insurers where disclosure is reasonably required to obtain advice, manage a claim, or defend the business
We do not sell your personal data and we do not share health information for unrelated marketing by third parties.
International Transfers
Some of the suppliers used to run the website, booking, payment, and communication systems may process data outside the UK. This can include fulfillment, logistics, analytics, mapping, or hosted infrastructure providers, and may include overseas fulfillment partners or carriers involved in online shop orders. Where that happens, we rely on the provider's contractual safeguards and other recognised transfer mechanisms to protect your information.
How Long We Keep Data
Clinical and consent records
Treatment-related consultation notes, consent forms, and clinical images are generally kept for at least 7 years after the last treatment, or longer where needed for insurance, legal, or clinical reasons.
Financial and booking records
Payment, tax, and core booking records are kept for as long as reasonably needed for accounting and legal compliance, which is commonly up to 6 years.
Online shop and fulfillment records
Order, payment, fulfillment, and delivery-dispute records are generally kept for as long as reasonably necessary to complete the order, deal with returns, recalls, chargebacks, or claims, and meet tax, accounting, fraud-prevention, product-safety, or legal obligations, which is commonly up to 6 years and may be longer where a dispute or investigation remains open.
Enquiries
Contact enquiries that do not lead to treatment are usually kept only for as long as needed to respond, manage follow-up, and deal with any later issues.
Marketing preferences
Newsletter data is kept until you unsubscribe or ask us to stop. Marketing-use photography consent can also be withdrawn for future use, although material already published may not always be instantly removable from every channel.
Cookies and browser storage
Cookie and local-storage durations vary by feature. For example, the locale cookie may remain for up to 12 months, the shop information dismissal cookie for up to 180 days, the map cache for around 12 hours, and the cart or theme data until cleared or overwritten in your browser.
Cookies, Local Storage, and Similar Technologies
The website uses browser-side technologies to make the site work properly and remember limited preferences. This includes the language-preference cookie, the shop information dismissal cookie, theme preference storage, the local-storage shopping cart, map caching, and technical platform features needed for pages, forms, analytics, and secure third-party services such as Stripe checkout.
Full details are set out in the Cookie Policy.
Your Rights
- to ask for a copy of the personal data held about you
- to ask for inaccurate data to be corrected
- to ask for deletion where there is no lawful reason to keep the data
- to object to or restrict certain processing
- to withdraw consent where consent is the basis relied on
- to complain to the UK Information Commissioner's Office at ico.org.uk if you believe your data has been handled unlawfully
Security
We use reasonable technical and organisational measures to protect personal data, including controlled access to systems and the use of specialist providers for hosting, payments, email, and calendar management. No internet transmission or online platform can be guaranteed to be completely secure, so please avoid sending unnecessary sensitive information through the general contact form.
Updates and Contact
We may update this policy from time to time to reflect changes to the clinic, the website, or legal requirements. The latest version will always be published on this page.

