Privacy Policy
Last updated: 8 April 2026
1. Who we are
Data controller: Amy McMurray, trading as Meraki Master Sugarist, 13 Waterside, Coleraine, County Londonderry, BT51 3DP, Northern Ireland.
Contact: 07525 459759 or via the contact form on the home page.
2. What we collect and why
When you use the contact form on this website, we collect:
- Name — so we know how to address you in a reply
- Email address — so we can reply to your enquiry
- Subject and message content — to understand what you're asking about
The lawful basis for processing this information is Article 6(1)(f) of the UK GDPR (legitimate interests) — specifically, responding to enquiries from prospective and existing clients.
Online bookings are handled separately by Timely (merakimastersugarist.gettimely.com), a third-party booking platform. Their privacy policy governs any data you provide when booking.
3. How long we keep it
Contact form enquiries are retained for up to 12 months after the last contact, after which they are deleted. If an enquiry turns into a booking, client details are retained for as long as needed to provide treatments, and then for a further period as required by insurance and professional-body guidance.
4. Who we share it with
We do not sell or share your data with third parties for marketing. Your data is processed by the following service providers as part of running this website:
- Formsubmit.co — receives contact form submissions and forwards them to our business email.
- Google (Fonts and Maps) — loaded only after you accept cookies on the home page, and only used to render typography and the embedded map.
- AWS (Amazon Web Services) — hosts this website (CloudFront and S3, London region).
5. International transfers
Some of our service providers (Formsubmit.co and Google) are based in the United States. Where personal data is transferred outside the UK, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework, as appropriate. These safeguards are designed to give your data a similar level of protection to that which it would have in the UK.
6. Cookies
This site uses Google Fonts and Google Maps, which may set cookies. These are loaded only after you give consent via the cookie banner. We do not use advertising or tracking cookies. See our Cookie Policy for the full list.
7. Children's data
This website and service are not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has submitted personal data to us, please contact us and we will delete it promptly. Clients under 18 require parental or guardian consent before booking a treatment.
8. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data ("right to be forgotten")
- Restrict or object to processing
- Data portability
- Withdraw consent at any time (where consent is the lawful basis)
To exercise any of these rights, contact us on the number above.
9. Complaints
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
10. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of the page reflects the most recent revision.