SENTIREV

Privacy Policy

Last updated: 3 September 2026

Who we are

SENTIREV ("we", "us") provides a platform for service and general businesses and their customers — bookings, AI tools, websites and an online shop — available at sentirev.com, app.sentirev.com and our mobile app. We are the data controller for the personal data described in this policy. Contact: support@sentirev.com.

What we collect

Account data — name, email address, phone number, password (stored as a salted hash, never readable by us).

Booking data — appointments you make or receive: service, branch, time, notes, attendance history, reviews you write.

Shop order data — if you buy from a business's online shop, we process your email address and, for delivery orders, your name and shipping address, so the order can be recorded and passed to the business to fulfil. You can buy as a guest without a SENTIREV account.

Consent and patch-test records — where a business records that you gave consent for a treatment, we store that record on its behalf: the date, the type of consent and any note the business adds. For some treatments this says something about your health, so it is treated as sensitive: the business asks for it and decides what it needs, we store it under its instruction, and it is never used for anything else or shown to another business.

Shop notifications you ask for — if you ask to be told when a product is back in stock we hold your email address for that product until we send that one email, then delete the request. If a shop has reminders switched on and you gave your email address before paying, we hold it with the unfinished order so we can send a single reminder an hour later.

Business data — if you run a business on SENTIREV: business details, services, prices, products, team members, opening hours.

Communications — messages you send to a business through our platform, including website chatbot conversations and emails handled by our AI assistants, which are logged so the business can serve you.

Payment data — handled by Stripe. We never see or store full card numbers.

Technical data — IP address and device information in server logs, used for security (e.g. blocking break-in attempts).

How we use it

To run bookings and shop orders between you and businesses (performance of a contract); to send booking confirmations, order confirmations, reminders and security alerts; to power AI features such as booking assistants, no-show estimates and business analytics (legitimate interest in providing the service); to prevent fraud and abuse; and to comply with law.

We do not sell personal data, and we do not use it for third-party advertising.

AI features

Some features use artificial intelligence: chat and phone assistants that answer on behalf of businesses, no-show risk estimates based on booking history, and business analytics. Message content may be processed by our AI providers (such as Anthropic) solely to generate the response; it is not used to train their models under our agreements. AI responses can make mistakes — businesses review and remain responsible for their customer communications.

Our assistants always identify themselves as automated and never claim to be a person. A business can also upload its own material for its AI to read — price lists, policies, FAQs — which is used only to answer for that business. Please do not put anything into those documents that you would not want its AI to repeat to a customer.

Who we share it with

Trusted processors, only as needed to run the service: Stripe (payments), Hetzner (hosting, EU data centres), Anthropic / OpenAI (AI responses), and our email delivery provider. Businesses you book with or buy from see the booking or order details (including any delivery address) and messages you send them — they are independently responsible, as their own data controllers, for how they use them.

Security

Data is encrypted in transit (TLS 1.2+). Access to production systems is restricted to key-based authentication with brute-force protection. Passwords are hashed; two-factor authentication is available on every account and mandatory for platform administrators. Databases are backed up daily with off-site copies.

Retention

We keep your data while your account is active. If you delete your account, personal data is removed or anonymised within 30 days, except records we must keep for legal or accounting reasons (e.g. payment and order records, kept 6 years).

Your rights

Under UK GDPR you can ask us to access, correct, delete or export your data, or object to or restrict processing. Email support@sentirev.com and we will respond within one month. You can also complain to the ICO (ico.org.uk).

Cookies

We use only essential cookies and local storage needed to keep you signed in. No advertising or cross-site tracking cookies.

Changes

If we make material changes to this policy we will notify you by email or in-app before they take effect.