1. Introduction

This Privacy Policy explains how FootAndArch.com ("we", "us", "our") collects, uses, stores and protects your personal data when you visit our website, book a foot scan, purchase custom insoles, or use our B2B services.

We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all relevant UK laws.

By using our website or services, you agree to the practices described in this policy.

2. Data Controller

FootAndArch.com
Email: contact@footandarch.com
Phone: 0121 448 0707
Address: Birmingham, United Kingdom

3. Information We Collect

We collect the following categories of personal data:

A. Contact Information

  • Name
  • Email address
  • Phone number
  • Address (if required for delivery)

B. Booking & Service Data

  • Appointment details
  • Service type and location
  • Communication preferences
  • Payment confirmations (processed by third-party providers)

C. Foot Scan & Biomechanical Data

This may include:

  • 3D foot scans
  • Pressure mapping data
  • Gait analysis metrics
  • Foot posture and alignment information
  • Custom insole specifications

This data may be considered special category health data under GDPR.

D. B2B Partner Data

  • Clinic or business name
  • Staff accounts
  • Uploaded scans
  • Order history
  • Device usage analytics

E. Technical & Usage Data

  • IP address
  • Device information
  • Cookies and analytics
  • Browsing behaviour on our website

F. Payment Information

We do not store card details. Payments are processed securely by:

  • Stripe
  • PayPal
  • Other authorised payment processors

4. How We Use Your Data

We use your data for the following purposes:

  • To process bookings and appointments
  • To provide foot scanning and custom insole services
  • To manufacture and deliver custom orthotics
  • To manage B2B partner accounts
  • To improve our website and services
  • To send appointment confirmations and reminders
  • To provide customer support
  • To comply with legal obligations
  • To send marketing communications (only with your consent)

5. Legal Basis for Processing

We process your data under the following legal bases:

  • Consent — for marketing, cookies, and optional data
  • Contractual necessity — to provide services you request
  • Legitimate interest — analytics, service improvement, fraud prevention
  • Legal obligation — record-keeping, tax, compliance

For foot scan data (special category data), we rely on:

  • Explicit consent
  • Provision of health-related services

6. Sharing Your Data

We may share your data with:

  • Foot scanning hardware/software providers
  • Custom insole manufacturing partners
  • Payment processors (Stripe, PayPal)
  • Calendar and communication tools (Google Calendar, WhatsApp API)
  • IT and hosting providers
  • B2B partner clinics (only with your consent)

We never sell your data to advertisers or third parties.

7. International Transfers

Some service providers may operate outside the UK.

Where this occurs, we ensure appropriate safeguards such as:

  • UK GDPR adequacy decisions
  • Standard Contractual Clauses (SCCs)
  • Data Processing Agreements

8. Data Retention

We retain data only as long as necessary:

  • Booking records: 6 years
  • Foot scan data: up to 5 years (or until consent withdrawn)
  • B2B partner data: duration of contract + 6 years
  • Marketing data: until you unsubscribe

9. Your Rights

Under UK GDPR, you have the right to:

  • Access your data
  • Correct inaccurate data
  • Request deletion ("right to be forgotten")
  • Restrict processing
  • Object to processing
  • Data portability
  • Withdraw consent at any time

To exercise your rights, contact: contact@footandarch.com

10. Cookies & Tracking

We use:

  • Essential cookies (required for site functionality)
  • Analytics cookies (Google Analytics, etc.)
  • Marketing cookies (only with consent)

You can manage cookie preferences at any time.

11. Security Measures

We use:

  • Encrypted servers
  • Secure data storage
  • Access controls
  • Regular security audits
  • Encrypted transmission (HTTPS)

12. Children's Data

We only collect children's data with parental or guardian consent.

13. Updates to This Policy

We may update this policy periodically.

The latest version will always be available on our website.

14. Contact

For privacy questions or complaints: