✦ UK GDPR Compliant

Privacy Policy

Effective: January 2026 Last updated: May 2026

Gessica Freire MUA takes data protection seriously. This policy explains what personal information is collected when you use this website or book a service, why it is held, how it is protected, and what rights you have over your own data. If anything is unclear, please get in touch at hello@gessicafreire.com.

Data Controller
Gessica Freire MUA
Studio: Darlington, County Durham, United Kingdom
Email: hello@gessicafreire.com
Instagram: @gessicafreiremakeup
ICO Registration: Pending — register at ico.org.uk

What data we collect and why

We only collect information that is necessary to provide the service or respond to your enquiry. The table below sets out exactly what is collected, the reason for collecting it, and the legal basis under UK GDPR.

Data collected Why Legal basis
Name, email address, phone number To respond to your enquiry and manage your booking Contract / Legitimate interests
Wedding date and venue To check availability and plan your service Contract
Location (North East / London / International) To confirm eligibility for the £49 trial offer and quote correctly Contract
Service preferences and vision notes To personalise your trial and wedding day service Contract
Payment card details To charge for services. Card data is handled exclusively by Stripe — we never see or store full card numbers. Contract
Before and after photos (with your consent) For service records and, where you have specifically agreed, for portfolio and social media use Consent
Google review and social media posts Public reviews linked to your Google or Instagram account. We do not store these — they live on your accounts. Consent (yours, via those platforms)

How long your data is kept

We retain client data for 2 years after your wedding date, after which all personal records are deleted from our systems. This period allows us to handle any post-wedding queries and comply with financial record-keeping obligations.

Who your data is shared with

Your data is never sold, rented or shared with third parties for marketing purposes. It is shared only with the services that are essential to running your booking:

Processor What they receive Why
HoneyBook (USA) Name, email, booking details, messages, contracts CRM, contract and invoice management. A Data Processing Agreement is in place covering UK-to-US data transfer under Standard Contractual Clauses.
Stripe (USA) Payment card details (encrypted token only) Secure payment processing. PCI DSS Level 1 certified. We never see your full card number.
Formspree (USA) Name, email, and form submission content Routing website enquiry forms to our inbox. Data is not retained by Formspree beyond delivery.
Google Pinterest pixel analytics (anonymised) Understanding how visitors find the website. No personal data linked.

All processors listed above are contractually required to handle your data only as instructed, to maintain appropriate security standards, and to not use it for their own purposes.

Card data and payments

Payment processing is handled entirely by Stripe, a PCI DSS Level 1 certified provider. When you add a card to file, your card details go directly to Stripe's encrypted systems. Gessica Freire MUA sees only the last four digits of your card number — never the full number, CVV, or expiry date in a usable form.

If you have provided a card on file and wish to have it removed, please email hello@gessicafreire.com and the team will remove it from Stripe within 5 business days.

Cookies and tracking

This website uses minimal tracking. The only third-party code running on this site is the Pinterest pixel, which tracks anonymised page visits to help Gessica's team understand how people find the site via Pinterest. No personal data is associated with these events.

No other cookies, analytics scripts or advertising trackers are active on this site. There is no cookie banner because there are no non-essential cookies to consent to.

Photography and social media

Gessica's team may take before and after photos during your trial and on your wedding day. These are used internally for your service record and, only with your explicit written or verbal consent, for portfolio, website or social media use.

Your rights

Under UK GDPR you have the following rights in relation to your personal data. To exercise any of them, email hello@gessicafreire.com and the team will respond within 30 days.

👁
Right of access
Request a copy of all personal data held about you.
✏️
Right to rectification
Ask us to correct inaccurate or incomplete information.
🗑
Right to erasure
Ask us to delete your data where there is no lawful reason to keep it.
Right to restriction
Ask us to pause processing your data while a dispute is resolved.
📦
Right to portability
Request your data in a structured, machine-readable format.
🚫
Right to object
Object to processing based on legitimate interests, including direct marketing.

If you believe your data has been handled incorrectly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

Marketing communications

We do not send marketing emails unless you have specifically opted in. The only communications you will receive are those directly related to your booking — confirmations, reminders, pre-wedding prep, and post-wedding follow-up.

If you receive a referral prompt or follow-up email after your wedding and would prefer not to, simply reply asking to be removed and you will not be contacted again.

Security

All client data held in HoneyBook is stored on encrypted, SOC 2 Type II certified servers. Emails are transmitted over TLS encryption. Payment data is handled by Stripe's PCI DSS Level 1 infrastructure. No client data is stored on personal devices or unencrypted local files.

In the event of a personal data breach that poses a risk to your rights and freedoms, we are legally required to notify the ICO within 72 hours and to inform affected individuals without undue delay.

Changes to this policy

This policy may be updated from time to time to reflect changes in our practices or legal requirements. The date at the top of this page will always show when it was last updated. Continued use of the website after an update constitutes acceptance of the revised policy.

Contact

For any data protection queries, requests to exercise your rights, or to withdraw consent for photo use, please contact the team: