Privacy Policy
Last updated: June 2026
1. Introduction
Herts Cupping (hertscupping.co.uk) is a specialist Hijama and recovery clinic based in St Albans, Hertfordshire. The site is operated by Herts Cupping Ltd, registered in England and Wales (company number 15291509), which is the data controller responsible for your personal data. We take your privacy seriously and are committed to protecting your information. This policy explains what we collect, how we use it, the cookies we set, and your rights under UK data protection law.
2. Data We Collect
Booking and Contact Forms
When you book a session or submit a contact form, we collect your name, email address, phone number, and any details you provide about your symptoms or requirements. This information is used to manage your booking and provide your treatment. It is never sold and is not used for marketing unless you have separately opted in.
Contact Form and Enquiries
Information submitted through our forms, or sent to us by email or WhatsApp, is received at our business email hosted by Google (Gmail). Google adheres to UK and EU data protection requirements. See their privacy policy.
Website Analytics
We use Google Analytics, loaded through Google Tag Manager, to understand how the site is used so we can improve it. These analytics cookies only load if you accept analytics cookies in our consent banner. They may process online identifiers such as your IP address and device information. You can change or withdraw your choice at any time using the Cookie settings link described in section 6. As an additional control, you can also install the Google Analytics opt-out browser add-on.
Comments
If you leave a comment on the website, we collect the data shown in the comments form, your IP address, and your browser user agent string to help with spam detection.
3. How We Use Your Data
- To manage your bookings and provide your treatment
- To respond to enquiries submitted through the contact form, by email or by WhatsApp
- To send appointment confirmations and aftercare information
- To understand and improve the website, where you have accepted analytics cookies
- To measure and improve our advertising and social content, where you have accepted marketing cookies
- To keep our systems secure
Our lawful bases are: performing the service you have requested (your booking and care), our legitimate interest in responding to enquiries and running the clinic, and your consent for analytics and marketing cookies. We do not use your data for marketing purposes unless you explicitly opt in.
4. Data Storage
We are a UK-based business. Our web servers are hosted in the UK by Hostinger, which is GDPR compliant. See their privacy policy.
5. Embedded Content
Some pages include embedded content from third-party services such as TikTok, Instagram, and YouTube. These services may collect data about you, set cookies, and track your interaction with the embedded content. Where we embed YouTube videos, we use a click-to-load approach so these cookies are only set once you choose to play the video. We have no control over the privacy practices of these third parties.
6. Cookies and Similar Technologies
Cookies are small files stored on your device. We use a small number of essential cookies to make the site and booking system work, and optional cookies for analytics and marketing. Under UK rules, optional cookies are not set until you give consent.
Managing your choices
When you first visit, a consent banner lets you Accept all, Reject all, or choose which categories you allow. Optional cookies do not load until you accept them, and the essential ones are always active because the site needs them to function. You can change or withdraw your consent at any time using the Cookie settings link in the website footer, or by clearing cookies in your browser.
Cookie categories
| Category | What it does | Examples | Consent needed |
|---|---|---|---|
| Strictly necessary | Required for the website, login and booking to work, and to remember your cookie choice. | PHPSESSID, wordpress_logged_in, wordpress_test_cookie, your consent preference cookie | No (always active) |
| Analytics | Helps us understand how visitors use the site so we can improve it. | _ga, _ga_*, _gid (Google Analytics) | Yes |
| Marketing | Used to measure and improve our ads and social content. Set by advertising or social pixels where active. | _fbp (Meta), _ttp (TikTok), and similar | Yes |
We manage these through Google Tag Manager with Google Consent Mode, which holds analytics and marketing tags until you have given consent.
7. Who Has Access to Your Data
Your personal information is only accessible to our clinic administrators and, where necessary, our technical support providers. We do not sell, trade, or share your personal data with any third parties except where required to provide the services you have requested (such as booking confirmations) or where required by law.
8. How Long We Retain Your Data
Booking records and contact form submissions are retained for as long as necessary to provide ongoing care and for our internal records. If you request deletion of your data, we will remove all information that is not required for legal or administrative purposes.
9. Security
We use SSL/HTTPS encryption across the entire website. All communication between your browser and our servers is encrypted. In the event of a data breach, we will notify affected users and the relevant authorities where required, and take all necessary steps to secure the system.
10. Your Rights
Under UK GDPR you have the right to:
- Request a copy of the personal data we hold about you
- Request correction of any inaccurate data
- Request deletion of your personal data (where not required for legal purposes)
- Object to or restrict certain processing
- Withdraw consent for cookies or marketing at any time
To exercise any of these rights, please contact us at hertscupping@gmail.com or call 07466 307267. If you are unhappy with how we have handled your data, you also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
11. Third-Party Links
This website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and recommend reviewing their privacy policies independently.
12. Legal Disclosure
We may disclose your information where required by law or in response to a valid legal request. Any such disclosure will be made in compliance with UK data protection laws.
