Last updated: 16 September 2026
This Privacy Policy explains how AppointGem handles personal information when you visit appointgem.com, use the AppointGem mobile apps or business platform, contact us, or receive services from an organisation that uses AppointGem. It covers partner organisations, their staff and administrators, app account holders, and customers whose information is recorded through the service.
1. Who we are
Identity of the controller for AppointGem’s own processing: M&M Tech Ltd. M&M Tech Ltd is the legal operator of AppointGem and is located at 102 Ausden Place, Pumphouse Crescent, Watford WD17 2AJ, United Kingdom.
For privacy enquiries and account or data-deletion requests, email contact@appointgem.com or telephone 07301 414143 (international: +44 7301 414143).
2. AppointGem and partner organisations
A salon, clinic or other organisation using AppointGem is referred to in this policy as a partner organisation. The partner collecting your appointment, consultation or treatment information is responsible for the purposes for which it uses those records and for handling requests about them. Its own privacy notice also applies to its activities.
AppointGem provides the platform through which those records are managed. Where we process information on a partner’s behalf, we act on its instructions. We are responsible for processing we determine ourselves, including administration of our service relationships, enquiries and platform security. A request may therefore involve AppointGem, the partner organisation, or both; we will help direct it appropriately.
3. Information we collect and how we obtain it
Information may be provided directly by you, entered by a partner organisation or its authorised staff, generated when you use the service, or supplied by a provider involved in payments or notifications. The information collected depends on the features used:
- Contact and identity details: full name, email address, telephone number, postal address, date of birth, gender and emergency-contact information.
- Account and business details: login and account information, partner and staff information, and access permissions needed to use the platform.
- Photographs and signatures: profile photos, images attached to consultation or treatment records, and signatures captured or uploaded within the service.
- Booking and transaction information: appointments, treatment records, invoices, payments, refunds, gift cards and purchase history. AppointGem does not store full payment-card numbers; card processing is handled by payment providers.
- Consultation and health-related information: information entered into consultation and patch-test forms, which may include allergies, skin conditions and relevant medical history.
- Device identifiers: push-notification tokens and device identifiers used for notifications, trusted-device recognition, account security and two-factor authentication.
- Technical and support information: IP addresses in website request logs or received by mapping features, and information you provide when contacting us.
Information necessary to provide a requested service or protect an account may be required. If it is not provided, the relevant feature or service may not be available. Please provide only information relevant to the purpose and avoid including passwords, card details or unnecessary health information in support messages.
4. How information is used
- Provide and administer accounts, partner access, bookings, consultations and treatments.
- Support invoices, payments, refunds, gift cards and transaction records.
- Deliver notifications and service communications, and respond to enquiries and support requests.
- Authenticate users, recognise trusted devices, protect accounts, investigate faults and prevent fraud or misuse.
- Meet applicable legal obligations and establish, exercise or defend legal rights.
We do not sell or rent personal information. Health-related information is used for the relevant consultation, safe provision of treatment and necessary operation of that service; it is not provided to third parties for their own advertising.
5. UK GDPR, EU GDPR and lawful processing
Where the UK GDPR or EU GDPR applies, personal information must be processed on an applicable lawful basis. Service delivery and account administration may be necessary to perform a contract; security, fraud prevention and proportionate service administration may rely on legitimate interests; and legally required processing relies on the relevant legal obligation. Processing that requires consent must be supported by a freely given, specific and informed choice.
The responsible controller must identify the basis applicable to its processing and explain it to you. In particular, a partner’s treatment records and AppointGem’s own business-account records may involve different purposes and responsibilities. You can contact us or the relevant partner for information about the processing that affects you.
Reading this policy or using AppointGem does not by itself constitute consent to every form of processing. Where processing relies on consent, you may withdraw it without affecting the lawfulness of processing before withdrawal.
6. Consultation and health information
Health information is special-category personal data under UK and EU data-protection law. Its processing requires an applicable special-category condition in addition to a lawful basis. A partner collecting this information must identify and explain the condition it relies on, obtain explicit consent where applicable, and limit collection and access to what is necessary.
Authorised partner staff use consultation and patch-test information for the relevant service. AppointGem handles partner-controlled records on the partner’s instructions. Where an authorised service provider processes records to operate the platform, that is processing for the service, rather than permission to use health information for an unrelated purpose.
7. Device permissions and choices
Photos and signatures may be captured or uploaded when you use the relevant features. Push notifications use a device notification token. Where a feature requests device access, review the permission explanation before choosing whether to allow it. You can manage available permissions, including notification permissions, in your device settings. Disabling a permission may affect its related feature.
Visiting a mapping feature can disclose technical information such as your IP address to the mapping provider. Website login and session functions may use cookies; your browser provides controls for stored cookies, although blocking necessary cookies may affect sign-in. A device permission or browser setting does not replace any separate consent required by law.
8. Service providers and disclosures
AppointGem uses providers to support service delivery. The providers identified for the platform include:
- Google Firebase Cloud Messaging: notification delivery and device push-notification tokens.
- Stripe and PayPal: payment processing and related transaction handling.
- Google Maps: mapping features, which may receive your IP address and information necessary for the requested map.
Providers processing information on our behalf are engaged for the relevant service purposes, under contractual restrictions and confidentiality and data-protection requirements. Information is not made available to them for unrelated use. A provider’s own privacy notice explains any separate processing it carries out under its own responsibilities.
Authorised partner personnel may access records relevant to their work. We may also disclose information where required by law. We do not promise that health information is “never shared” when authorised processing by service providers is necessary to operate the platform.
9. Processing locations and international transfers
Our use of international service providers can involve processing across country borders. UK and EU data-protection rules restrict transfers to countries without an applicable adequacy decision unless another lawful transfer mechanism applies. Appropriate safeguards, where used, may include approved contractual protections.
Contact contact@appointgem.com to request information about the processing locations and transfer arrangements relevant to your records, and how to obtain information about any applicable safeguards. Where a partner determines the processing, it is also responsible for explaining its arrangements. This policy does not represent that all information is stored exclusively in the UK or EEA.
10. Security
Data is transmitted using encrypted HTTPS/TLS connections. We apply technical and organisational measures designed to protect personal information from unauthorised access, loss, misuse or disclosure. Account-security features include two-factor authentication and trusted-device recognition where used. No system can guarantee absolute security; please keep account credentials confidential and report suspected unauthorised access promptly.
11. Data retention
Personal information is retained for 60 months after account inactivity and is then automatically deleted. You may request deletion earlier; you do not need to wait for that period to expire.
If an applicable legal obligation requires particular records to be retained, the responsible organisation must explain which records, why they are retained and the relevant period. Such an obligation does not justify keeping unrelated information unnecessarily. You may ask AppointGem or the partner organisation for information about retention applicable to your records, including residual backup copies.
12. Request account and personal-data deletion
You can request deletion of your AppointGem account and associated personal information either directly from AppointGem or from the partner organisation using the service. You do not need to reinstall the app to make a request.
Contact AppointGem directly
Email contact@appointgem.com with the subject “AppointGem account and data deletion”. Include the account email, your name, the relevant partner organisation and whether your request concerns your account, particular records or both. Do not include your password or unnecessary medical details.
Request deletion through a partner
You may ask the salon, clinic or other organisation that holds your records through AppointGem to delete your account and personal information. If it refuses or does not respond, contact contact@appointgem.com and explain what happened. Include copies of your original request and follow-up correspondence if available, with unrelated sensitive information removed. We will review the request and help resolve it with the responsible organisation.
Timeframe and verification
Deletion requests are completed within 30 days of the first request. Escalating a request from a partner to AppointGem does not restart this period. Proportionate verification may be needed to protect your information from unauthorised deletion.
Where specific information must lawfully be retained, the responsible organisation must explain the exception and retention period. Deactivation, account freezing or uninstalling the app is not the same as deleting the account and its associated information. This request process does not limit your statutory privacy rights or complaint rights.
13. Your privacy rights
Subject to applicable law and its conditions, you may request access to your personal information, correction of inaccurate information, erasure, restriction of processing or a portable copy of information. You may withdraw consent where processing depends on it.
Your right to object: you may object to processing based on legitimate interests because of your circumstances. You can object to direct marketing at any time.
Send requests to contact@appointgem.com or the partner responsible for the relevant records. We may need proportionate identity checks. Requests are handled within applicable statutory time limits. Under the EU GDPR, a response is normally due within one month; any permitted extension must be explained within that initial period. Our account-deletion process has the 30-day target described above, without limiting any shorter applicable legal deadline.
If a request is refused or a right does not apply, the responsible organisation must explain the reason and available complaint route. UK residents can complain to the Information Commissioner’s Office. In the EEA, you may complain to the supervisory authority where you live, work or believe an infringement occurred. You do not have to complain to AppointGem first.
14. Information relating to children
If a partner organisation records information about a child in connection with a booking or treatment, it is responsible for meeting the applicable requirements concerning parental authority, consent, safeguarding and age-appropriate information. If you believe a child’s information has been handled improperly, contact the organisation or AppointGem so the concern can be reviewed. This statement does not grant permission to collect unnecessary information about children.
15. Changes to this policy
We may update this policy when our practices or applicable requirements change. The date at the top identifies the current version. Material changes will be brought to users’ attention appropriately, and any new processing requiring consent must obtain that consent before it starts.
16. Contact details
AppointGem — M&M Tech Ltd
102 Ausden Place, Pumphouse Crescent
Watford WD17 2AJ, United Kingdom
Telephone: 07301 414143
Privacy, account deletion and personal-data requests: contact@appointgem.com