CBK Beauty Privacy Policy
Effective date: 4 August 2026 Last updated: 4 August 2026
1. Who we are
CBK Beauty is a booking and commerce service operated by CBK Beauty, trading as CBK Beauty ("CBK Beauty", "we", "us", or "our"). We provide salon and beauty-service bookings, waitlists, product ordering and delivery, payments, loyalty and promotional programmes, notifications, and customer support through our mobile applications, websites, and related services (collectively, the "Services").
For purposes of Ghana's Data Protection Act, 2012 (Act 843), the data controller is:
- Legal name: CBK Beauty
- Business address: Airport Residential
- Privacy email: coloursbyk@gmail.com
This policy explains how we collect, use, disclose, retain, and protect personal data when you use the Services or otherwise interact with us. It applies to registered customers, guest customers, website or app visitors, recipients of deliveries, and people who contact support. Separate workforce notices may apply to staff and job applicants.
2. Personal data we collect
The data we collect depends on how you interact with us.
2.1 Data you provide
We may collect:
- Account and contact data: full name, email address, telephone number, password in hashed form, email-verification status, and account preferences.
- Social sign-in data: when you choose Google or Apple sign-in, the provider, provider account identifier, provider email, and information needed to authenticate or link your account. We do not receive your Google or Apple password.
- Booking data: selected services and options, assigned staff member, appointment and waitlist dates and times, booking source, status, pricing, deposit details, cancellation or rescheduling reasons, no-show information, and notes you choose to provide.
- Order and delivery data: cart contents, products, quantities, order history, recipient name and phone number, street or digital address, GhanaPostGPS code, landmark, delivery instructions, and, where you choose location-based address features, latitude, longitude, and location accuracy.
- Payment and transaction data: amounts, currency, payment status, transaction and provider references, payment channel, receipts, refunds, discounts, and related fraud or error information. Paystack processes the payment interface and payment credentials. We do not intend to receive or store your full card number, card security code, PIN, or mobile-money authentication credentials.
- Loyalty and promotion data: points or qualifying activity, rewards, entitlements, referrals, campaign participation, claims, redemptions, and offer eligibility.
- Support and communications data: ticket subject and messages, complaint or feedback details, booking or order references, uploaded images, PDFs, text files or other permitted attachments, satisfaction ratings, and correspondence with us.
- Guest data: name and at least one of an email address or phone number when a booking or waitlist entry is created without a registered account.
- Other people's data: recipient or guest details you provide. You must have authority to provide this information and should direct the person to this policy.
Please do not include unnecessary highly sensitive information in free-text notes, support messages, or attachments. If information about health, allergies, pregnancy, accessibility, or another sensitive matter is reasonably needed to perform a requested service safely, we will limit its use to that purpose and handle it in accordance with applicable law.
2.2 Data collected automatically
When you use the Services, we may collect:
- IP address, device identifier and name, device platform, push-notification token, operating system, browser or app information, language, and time zone;
- login method, session identifiers, authentication times, session expiry or revocation information, and security events;
- request identifiers, timestamps, pages or features used, actions taken, booking, order and payment events, notification delivery/read state, and error or performance information; and
- cookies, local storage, or similar technologies needed for authentication, security, preferences, service operation, and—where enabled and permitted—analytics.
Our mobile apps request device permissions, such as location or notifications, through your device. You may manage these permissions in your device settings. Disabling a permission may prevent the related feature from working but should not prevent unrelated features from working.
2.3 Data received from others
We may receive personal data from:
- Google or Apple when you use social sign-in;
- Paystack and payment-method providers when they initialise, authorise, verify, refund, reverse, or dispute a transaction;
- GhanaPostGPS, mapping, reverse-geocoding, or address providers when you ask us to resolve or confirm a delivery location;
- a person booking for you, naming you as a recipient, or contacting us on your behalf;
- our staff when they create or update a booking, order, payment, support, or service record; and
- security, communications, hosting, analytics, and technical service providers.
3. Why we use personal data
We use personal data for the following purposes and on grounds permitted by applicable law:
| Purpose | Examples | Ground we rely on |
|---|---|---|
| Provide the Services and perform our agreement with you | Create and secure accounts; arrange bookings and waitlists; fulfil and deliver orders; process payments; issue receipts; manage rewards; provide support | Necessary to enter into or perform a contract, or to take requested pre-contract steps |
| Communicate about the Services | Verification and security messages; booking reminders; payment confirmations; waitlist, order, delivery, cancellation, and support updates | Contract performance and our legitimate operational interests |
| Process optional location data | Resolve a GhanaPostGPS code, reverse-geocode current coordinates, calculate delivery availability or fees, and deliver to the selected location | Your request and consent where required |
| Protect customers and the Services | Authenticate users; manage sessions; prevent fraud, abuse and duplicate transactions; scan permitted support attachments; investigate incidents; enforce our terms | Legal obligations and legitimate security interests, subject to your rights |
| Operate and improve the Services | Troubleshoot, measure feature performance, maintain audit trails, forecast demand, and create aggregated or de-identified reports | Legitimate business interests, subject to your rights and reasonable expectations |
| Meet legal and regulatory duties | Maintain financial and business records; respond to lawful requests; exercise or defend legal claims; handle complaints and disputes | Compliance with law and legal process |
| Send marketing and personalised promotions | Send promotional notifications or messages; evaluate eligibility under published campaign rules | Your prior consent where required; you may withdraw it at any time |
If we ask for information that is mandatory, we will explain this at or before collection where practicable. Without information needed for an account, booking, payment, delivery, or support request, we may be unable to provide that part of the Services.
Promotional and loyalty rules may automatically evaluate objective events such as registration, verification, completed bookings, completed orders, time windows, and previous redemptions. These decisions concern promotional eligibility and do not determine access to essential services. You may contact us if you believe a result is incorrect and request human review.
We will not use personal data for a materially incompatible purpose without providing appropriate notice and, where required, obtaining consent.
4. When we disclose personal data
We disclose only what is reasonably needed for the relevant purpose. Recipients may include:
- Payment providers: Paystack and relevant banks, card networks, mobile-money operators, or payment-method providers to process and verify transactions, refunds, reversals, and disputes.
- Identity providers: Google and Apple when you choose their sign-in services or ask us to link, unlink, or revoke an identity.
- Notifications and communications providers: for example, Firebase Cloud Messaging, Expo Push Service, and our email or messaging providers, to deliver operational or consented marketing messages.
- Location and delivery providers: GhanaPostGPS resolution, mapping or reverse-geocoding providers, and dispatch or delivery personnel. Depending on our production configuration, these may include SperixLabs, OpenStreetMap/Nominatim, Google Maps, or Mapbox. Delivery personnel receive only the contact and address details reasonably needed for fulfilment.
- Hosting, storage, security, and technical providers: cloud infrastructure, media-storage, database, monitoring, malware-scanning, and support vendors. Depending on configuration, media may be stored using Cloudinary or Cloudflare R2.
- Professional advisers and insurers: lawyers, accountants, auditors, consultants, and insurers subject to appropriate duties of confidentiality.
- Authorities and other parties: regulators, law-enforcement bodies, courts, or other persons when required by law or legal process, to protect rights or safety, to investigate fraud or abuse, or in connection with a merger, financing, reorganisation, or sale of all or part of our business, subject to appropriate safeguards.
Service providers may process personal data only for contracted services, their own lawful regulatory responsibilities, or as otherwise explained in their notices. Paystack's privacy information is available at paystack.com/gh/terms. Google, Apple, and other third-party services are also governed by their own privacy notices.
We do not sell personal data. We do not provide personal data for third-party direct marketing without the consent required by law.
5. International transfers
Some providers or their systems may be located outside Ghana. This means personal data may be accessed, processed, or stored in another country. Where required, we will disclose such transfers to the Data Protection Commission, obtain consent, use appropriate contractual or organisational safeguards, and take reasonable steps to ensure the recipient protects the data consistently with Act 843 and this policy.
Contact us for more information about relevant transfer destinations and safeguards.
6. Retention
We keep personal data only for as long as reasonably necessary for the purposes described above, including service delivery, security, accounting, regulatory compliance, dispute handling, and legal claims. Retention depends on the type of record:
- Account and authentication data: kept while the account is active and then deleted or anonymised under our account-deletion process, except where a longer period is required for security or legal claims. Expired verification, reset, authentication-challenge, and security-event records are removed according to operational schedules.
- Bookings, orders, payments, refunds, receipts, and audit records: kept for the period required by applicable financial, tax, electronic-transaction, consumer, fraud-prevention, and limitation laws, and then deleted or anonymised where feasible. These records may remain linked to an anonymised account identifier after account deletion.
- Saved addresses, active cart data, push devices, and customer notification-recipient records: removed when a customer completes the in-app account-deletion process, subject to immutable delivery-address snapshots retained with completed order records.
- Closed support tickets: our ordinary target is to remove attachments after 90 days, purge message content after 365 days, and anonymise remaining ticket metadata after 730 days, measured from closure. These periods may be suspended or extended where needed for an open dispute, safety matter, fraud investigation, or legal obligation.
- Location data: reusable saved-location records are retained until you delete the address or account; an address and coordinates used for an order may be preserved in that order's fulfilment record.
- Analytics: retained in identifiable or pseudonymous form only as long as needed for the relevant operational or analytical purpose, then aggregated, de-identified, or deleted.
When a retention period expires, we delete, anonymise, or securely isolate the data unless continued retention is required or permitted by law. Backups may retain residual copies for a limited period until overwritten, with access restricted to recovery and security needs.
7. Account deletion
Eligible customer accounts may use the account-deletion control in the app. Deletion signs the user out, disables the account, removes CBK Beauty credentials and active Google/Apple identity links, revokes Apple access where applicable, and removes disposable contact, session, device, saved-address, cart, and notification-recipient data.
Deletion does not erase records we must retain to document completed or disputed bookings, orders, payments, refunds, receipts, support interactions, fraud prevention, accounting, or compliance. We detach or replace direct account identifiers in retained records where reasonably possible and preserve them under an inactive anonymised identifier. Some information you gave to a payment, identity, or other provider must be deleted through that provider and is subject to its policies.
You may contact us if you cannot use the in-app deletion control.
8. Your rights and choices
Subject to Act 843 and other applicable law, you may have the right to:
- be informed about the collection and use of your personal data;
- ask whether we process your data and request access to it, including relevant purposes and recipient categories;
- request correction of inaccurate or incomplete data;
- object to or request prevention of processing that causes or is likely to cause unwarranted damage or distress;
- give or withdraw consent, without affecting processing already lawfully performed;
- require us to stop direct marketing;
- request that a decision significantly affecting you not be based solely on automated processing, where the statutory right applies;
- use our account-deletion process and request erasure where applicable, subject to lawful retention; and
- complain to us, a relevant processor, or Ghana's Data Protection Commission and seek any other remedy available by law.
To exercise a right, contact coloursbyk@gmail.com. Describe your request and the account or transaction concerned. We may verify your identity and authority before responding. A request may be limited or refused where the law permits; if so, we will explain the reason where we lawfully can.
You can also:
- withdraw marketing consent through the message's unsubscribe control, app settings, or by contacting us;
- disable push notifications or location access in device settings;
- manage or remove saved delivery addresses in the app; and
- unlink available social sign-in providers through account settings.
If you remain dissatisfied, you may contact Ghana's Data Protection Commission. Its current complaint and contact information is available at dataprotection.org.gh/for-individuals.
9. Security
We use administrative, technical, and organisational measures designed to protect personal data. Measures include role-based access controls, authenticated and time-limited sessions, hashing of passwords and sensitive tokens, transport encryption, restricted administrative access, rate limits, audit records, provider-signature verification, data minimisation and redaction, attachment validation and optional malware scanning, backups, monitoring, and incident-response processes.
No transmission or storage system is completely secure. You are responsible for protecting your login credentials and devices and for notifying us promptly if you suspect unauthorised account use. Do not send us payment PINs, passwords, one-time codes, full card details, or other credentials through support messages.
10. Children
The Services are intended for people aged 18 or older. A person under 18 may use a service only through, and with the involvement and consent of, a parent or legal guardian where lawful. We do not knowingly permit a child to create an independent customer account or knowingly use a child's data for direct marketing.
If you believe a child provided personal data without appropriate authority, contact us so we can investigate and take appropriate action.
11. Third-party services
The Services may link to or rely on third-party apps, sites, payment pages, maps, or services. Their handling of personal data is governed by their own notices. We encourage you to review those notices before providing information directly to them.
12. Changes to this policy
We may update this policy to reflect changes in the Services, providers, practices, or law. We will post the revised policy with a new "Last updated" date. If a change is material, we will provide additional notice through the app, website, email, or another appropriate channel and request consent where required.
13. Contact us
Questions, requests, or complaints about this policy or our handling of personal data should be sent to:
Email: coloursbyk@gmail.com / info@coloursbyk.com Contact Number: +233 54323 2659 Address: Airport Residential CBK Beauty / COLOURSBYK