1. Who We Are
BAYY LOUNGE (“we”, “us”, “our”) is a recording studio operating in the United Kingdom. We are the “data controller” for the personal information described in this policy.
You can contact us any time at:
- Email: info@bayylounge.com
- Instagram: @bayylounge
2. What We Collect
When you interact with BAYY LOUNGE we may collect:
- Account & contact details — name, email, phone number, password (hashed), Google sign-in identifier.
- Booking details — service, date & time, duration, guest count, add-ons, promo codes, notes.
- Payment information — processed directly by Stripe. We never see or store your full card number. We only receive a transaction reference and confirmation.
- Identity verification data — for certain sessions, Stripe Identity may verify your government ID and take a live selfie. We receive only a verified/unverified status; the ID document itself is held by Stripe.
- Communication records — emails you send us and our replies, and automated booking confirmation / reminder emails.
- Access-code activity — the unique studio code generated for your booking window and its usage timestamps (from the Igloohome smart padlock).
- Technical data — IP address, browser type, device type, cookie identifiers, timestamps of visits.
- CCTV footage — see Section 8 below.
3. How We Use Your Data
We use your data to:
- Confirm, manage and deliver your booking.
- Take payment and issue refunds through Stripe.
- Verify your identity where required to protect our staff, equipment and other customers.
- Send transactional emails (booking confirmations, reminders, access codes, cancellation notices).
- Send marketing emails only if you have opted in — you can unsubscribe at any time.
- Automate studio lighting and smart-lock access for your booking window.
- Investigate incidents, damage, theft or breaches of our Terms & Conditions.
- Comply with UK legal, tax and accounting obligations.
- Improve our services, availability and website.
4. Legal Basis for Processing
We rely on the following lawful bases under the UK GDPR:
- Contract (Art. 6(1)(b)) — to fulfil the booking you have entered into with us.
- Legitimate interests (Art. 6(1)(f)) — to secure our premises and equipment, prevent fraud, investigate damage and improve our service.
- Legal obligation (Art. 6(1)(c)) — accounting/tax records and responding to lawful requests from authorities.
- Consent (Art. 6(1)(a)) — for marketing communications, and where identity verification requires processing of special-category biometric data.
6. International Transfers
Some of our processors (e.g. Stripe, Resend, Google) may store or process data outside the UK/EEA. Where this happens, transfers are protected by:
- Standard Contractual Clauses approved by the UK ICO / European Commission; and/or
- UK Adequacy Regulations.
7. How Long We Keep Data
We only keep data for as long as needed:
- Booking records & invoices — 6 years from the booking date (UK tax law).
- Account details — until you close your account. You can request deletion at any time.
- Identity verification status — up to 12 months.
- CCTV footage — up to 30 days on rolling overwrite, unless required for an ongoing investigation.
- Marketing lists — until you unsubscribe.
- Access-code logs — up to 12 months for security auditing.
8. CCTV Monitoring
CCTV operates in communal areas only for the safety of customers and protection of studio equipment. Signage is displayed at the studio entrance to inform visitors.
No CCTV is installed inside recording booths, private recording spaces or toilets.
Footage may be reviewed for:
- Security & crime prevention.
- Investigating damage, theft or breaches of our Terms & Conditions.
- Responding to lawful requests from police or regulators.
You can request a copy of footage of yourself (a Subject Access Request) — see Section 10.
9. How We Protect Your Data
- All connections to our website use HTTPS/TLS.
- Passwords are stored hashed with bcrypt.
- Payment card data never touches our servers — it is handled directly by Stripe (PCI DSS Level 1).
- Access to admin systems is restricted to authorised staff with strong authentication.
- Where possible, data is stored inside the UK/EEA.
10. Your Rights
Under the UK GDPR, you have the right to:
- Access — request a copy of your personal data we hold.
- Rectification — ask us to correct inaccurate information.
- Erasure — ask us to delete your data (subject to legal retention obligations).
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interests or for marketing.
- Withdraw consent — where processing is based on consent.
- Complain — to the UK Information Commissioner's Office (ico.org.uk).
To exercise any right, email us at info@bayylounge.com. We'll respond within one month.
11. Marketing Preferences
We'll only send you marketing emails if you have explicitly ticked the marketing opt-in during booking or in your account. Every marketing email includes an unsubscribe link. You can also update your preferences at any time from your account dashboard.
Transactional emails (booking confirmations, receipts, reminders, cancellation notices) are essential to the service and cannot be opted out of while you have an active booking.
13. Children
Our services are aimed at customers aged 18 and over. Under-18s may only use the studio when accompanied by a responsible adult who agrees to our Terms & Conditions on their behalf.
14. Changes to This Policy
We may update this policy from time to time. Material changes will be highlighted on this page and — where relevant — communicated by email. The version number and effective date at the top always reflect the current live policy.
15. Contact & Complaints
For any privacy question, data-rights request or complaint, email us at info@bayylounge.com.
If you believe we have not handled your data properly, you have the right to complain to the UK Information Commissioner's Office (ICO): ico.org.uk · Helpline 0303 123 1113.