Privacy policy.

Introduction

This policy explains how Harry Goozee, trading as Clinicraft ("we", "us", "our"), a sole trader based in England, collects and uses personal data as the operator of the Clinicraft platform.

This policy covers data belonging to businesses and their staff who use Clinicraft — account registration, subscription billing, and how you use the platform itself. It does not cover the personal or health data your own customers give you through your bookings and consent forms — for that relationship, Clinicraft acts only as your data processor, not the controller. Your business is responsible for providing an appropriate privacy notice to your own customers. See our Terms of Service for the data processing terms between us and you as a business.

Last updated: 26 July 2026

Who we are

Clinicraft is the data controller for the personal data described in this policy — the data of business owners and staff who create and use Clinicraft accounts.

For any queries relating to this policy or your personal data, please contact us at hello@clinicraft.co.uk.

Information processed on behalf of your business

When you use Clinicraft to store information about your own customers or patients, including appointment details, consent forms, and health information, your business remains the data controller. Clinicraft processes that information only on your documented instructions and for the purpose of providing the platform. Futher details about how we process data on your behalf are set out in our Terms of Service.

What data we collect

We collect and process the following categories of personal data about business owners and their staff:

  • Account data — first name, last name, email address, and password. Passwords are never stored in plain text and are stored only as securely hashed values.
  • Business data — your business name, chosen subdomain, logo, brand colour, and other homepage content you add.
  • Team data — email addresses and roles of staff you invite to your account.
  • Billing data — your subscription status and history. Card details are collected and stored directly by Stripe, our payment processor — we never see or store full card numbers.
  • Usage data — if you consent, anonymised analytics data about how you navigate this website (no personal information is included).
  • Support data — anything you tell us directly if you contact us for help.

Why we collect it

We use this data for the following purposes:

  • To provide the platform — creating and running your account, your team's access, and your public booking page.
  • To bill you — processing your monthly subscription and any additional seats via Stripe.
  • To support you — responding to questions or issues you raise with us.
  • To keep the platform secure — detecting and preventing fraudulent or abusive use of accounts.
  • To improve our service — anonymised analytics data (with your consent) to understand how the website and dashboard are used.

The legal bases we rely on are: performance of a contract (providing the platform and billing), legitimate interests (security and improving the service), and consent (analytics).

Who we share it with

We do not sell or rent your personal data. We share it with the following third-party service providers who process it on our behalf, strictly for the purposes of providing, maintaining, securing, and improving the Clinicraft platform:

  • Stripe — subscription billing and payments. Stripe is PCI-DSS compliant. Their privacy policy is available at stripe.com/gb/privacy.
  • Neon — database hosting. Their privacy policy is available at neon.tech/privacy-policy.
  • Vercel — website hosting, file storage, and site analytics. Their privacy policy is available at vercel.com/legal/privacy-policy.
  • Resend — sends transactional emails generated by the Clinicraft platform, including account, booking, and notification emails. Their privacy policy is available at resend.com/legal/privacy-policy.
  • Sentry — error monitoring, to help us find and fix bugs. Their privacy policy is available at sentry.io/privacy.

We keep your personal data within the United Kingdom and the European Economic Area wherever possible. Where a processor is based outside these regions, we only use processors subject to equivalent data protection standards — either through a UK or EU adequacy decision, or appropriate safeguards such as UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs).

We may also disclose your data if required to do so by law or in response to a valid request from a public authority.

How long we keep it

We retain your account and business data for as long as your account is active, and for a reasonable period afterwards to comply with our own legal, accounting, and tax obligations. If you close your account, we will delete your account and business data within 90 days, except where we're required to retain it for longer by law.

Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, secure password storage, and regular monitoring of our systems. No method of transmission or storage is completely secure, but we work to protect your information using industry-standard practices.

Your rights

Under UK GDPR you have the following rights in relation to your personal data:

  • Right of access — you can request a copy of all personal data we hold about you (a Subject Access Request).
  • Right to rectification — you can ask us to correct inaccurate or incomplete data.
  • Right to erasure — you can request that we delete your data, subject to our own legal obligations to retain it.
  • Right to restriction — you can ask us to restrict how we use your data while a query is being resolved.
  • Right to data portability — you can request a machine-readable copy of the data you have provided to us.
  • Right to object — you can object to processing based on legitimate interests.
  • Right to withdraw consent — where processing is based on consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.

To exercise any of these rights, please contact us at hello@clinicraft.co.uk. We will respond within one month.

If you are not satisfied with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Cookies and analytics

We use Vercel Analytics to collect aggregated, privacy-friendly usage statistics. Analytics is only enabled after you give your consent through our cookie preferences.

We will ask for your consent before enabling analytics. You can withdraw your consent at any time by clearing your browser's local storage for this site.

Changes to this policy

We may update this policy from time to time. Any changes will be posted on this page with an updated date. We encourage you to review this policy periodically.

Contact

If you have any questions about this privacy policy or how we handle your data, please contact us:

Clinicraft

Email: hello@clinicraft.co.uk