Last updated: 3 September 2026 · itsstartupsLTD is the data controller
In plain English
We collect only what we need to run the platform — your name, email, booking info, and payment data (processed by Stripe). We don't sell your data. You have full rights to access, correct, or delete it under UK GDPR.
Want your account gone? Go to your profile and use "Delete your account". We action it within 30 days.
itsstartupsLTD (Company Number: 16974754), registered at 135 Trundleys Road, London, SE8 5JQ, is the data controller for personal data collected through the Omnisio platform.
If you have any questions about how we handle your data, contact our team at info@omnisio.co.uk.
We collect the following categories of personal data:
Account data
Name, email address, hashed password, profile photo, and phone number (optional).
Booking data
Services booked, scheduled dates and times, booking notes, and booking history.
Payment data
Billing details are processed and held by Stripe. We do not store full card numbers. For Providers, Stripe Connect also processes bank account details for payouts.
Provider data
Business name, service descriptions, cover images, and event listings.
Usage data
Pages visited, search queries, device type, IP address, and browser type. Used only for analytics and security.
Media uploads
Images uploaded to listings or profiles, stored and served via Cloudinary.
Google Calendar data (Providers only, if connected)
If you're a Provider, you can optionally connect your Google Calendar from Settings to keep your Omnisio bookings in sync. We only ever request the minimum Google access needed for this — nothing is accessed unless you choose to connect, and connecting is never required to use Omnisio.
What we access: with your permission, we check which time slots on your calendar are already busy, so we can stop customers double-booking you, and we add a new event to your calendar automatically whenever a customer confirms a booking with you.
What we deliberately don't access: we never read the titles, descriptions, guests, locations, or any other content of your existing calendar events — only whether a time slot is free or busy. We don't touch any other Google service (Gmail, Drive, Contacts, and so on) — the permission we request only covers calendar events.
How to disconnect: go to your dashboard's Settings tab, find Google Calendar, and select Disconnect. This immediately deletes the access we were granted from our systems and stops all syncing. You can also revoke Omnisio's access directly from your Google Account at any time, at myaccount.google.com/permissions.
This data is used solely to power calendar sync for your own business. It is never sold, shared with other Providers, or used for advertising or marketing.
Service Providers (the businesses on Omnisio)
When you make a booking, your name, contact details, and booking information are shared with the relevant Provider so they can fulfil your booking.
Stripe (payments)
Payment processing and, for Providers, Stripe Connect for payouts. Stripe is a PCI-DSS Level 1 certified processor. Data may be processed in the US under Standard Contractual Clauses.
Supabase (database)
Our database provider stores account, booking, and transaction data. Data is stored in the EU (AWS eu-west-2 region). Access is restricted to authorised team members only.
Cloudinary (media)
Profile photos and service images are stored and served via Cloudinary (US-based). Transfer is covered by Standard Contractual Clauses.
Resend (transactional email)
Booking confirmations, ticket receipts, and operational notifications are sent via Resend. Only your email address and necessary booking details are shared.
Google (Calendar sync) — Providers only, opt-in
If a Provider chooses to connect Google Calendar, we exchange data with Google's Calendar API to check free/busy time and create booking events — see section 2 for exactly what is and isn't accessed. Nothing is shared with Google for any other purpose, and nothing happens unless the Provider actively connects their calendar.
Brevo (marketing email) — consent-only
If you opt in to marketing communications, your name and email address are added to our mailing list managed by Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France). Brevo processes data within the EU. You can unsubscribe at any time via the link in any marketing email or by emailing info@omnisio.co.uk. We will only add you to Brevo where you have given explicit, freely given consent — your data is never transferred to Brevo without it.
Data Exports by Providers
Providers (business owners) may use the Omnisio dashboard to download a CSV export of booking and ticket sale records relating to their own business. These exports include customer names, email addresses, booking details, and transaction amounts. Once data is downloaded, the Provider becomes an independent data controller for that data and is solely responsible for handling it in compliance with UK GDPR. Omnisio requires Providers to agree to compliant use of exported data as a condition of using this feature (see our Terms and Conditions). If you have concerns about how a Provider has used your data, contact us at info@omnisio.co.uk and we will investigate.
Event Organiser Marketing (consent-based)
During ticket purchase or service booking, you may be given the option to consent to receiving marketing communications from the relevant Provider (event organiser or business). This is always opt-in, never pre-selected, and your consent is recorded and passed to the Provider. You may withdraw consent at any time by contacting the Provider directly or by emailing info@omnisio.co.uk. Omnisio does not send these communications — they are the sole responsibility of the Provider.
We do not sell your personal data to any third party. We may disclose your data to law enforcement or regulators where required by law.
Some processors transfer data outside the UK/EU. We ensure appropriate safeguards are in place for each:
We retain your data for as long as your account is active and for a period thereafter as required by law. Payment records are retained for 7 years for tax purposes.
You may request deletion of your account at any time from the Delete your account section of your profile page, or by emailing info@omnisio.co.uk. We complete deletion requests within 30 days. See section 9 for what deletion involves.
We use cookies and similar technologies. For full details on what we use, why, and how to manage your preferences, see our Cookie Policy.
You have the right to:
To exercise any right, contact us at info@omnisio.co.uk. We will respond within 30 days. You also have the right to complain to the Information Commissioner's Office (ICO).
How to delete your account
Sign in and go to your profile page, then use Delete your account. You can also email us. Either way we will confirm receipt, and complete the erasure within 30 days.
What gets erased: your name, email address, phone number, profile photo, password, booking notes, review comments, support conversations, marketing preferences, and your login itself. Once complete you will not be able to sign in again.
What we must keep: UK law requires us to retain financial and transaction records for 7 years (Companies Act 2006 and HMRC requirements). This is an exception to the right to erasure under Article 17(3)(b) UK GDPR. We keep the booking amount, dates and reference only — these records are stripped of anything that identifies you. We may also need to retain limited records where there is an unresolved dispute, chargeback, or a legal claim.
If you run a business on Omnisio: we may need to settle outstanding bookings, payouts and disputes before we can erase your account. We will tell you if that applies and keep you updated within the 30-day window.
We implement appropriate technical and organisational measures to protect your data, including encrypted data transmission (HTTPS), secure database access controls, and restricted admin access. However, no system is completely immune to risk and we cannot guarantee absolute security.
Omnisio is not intended for users under 18. We do not knowingly collect personal data from children. If you believe we have, please contact us immediately.
We may update this policy from time to time. We will notify you of significant changes by email or on the Platform. The date at the top of this policy reflects the most recent update.
For privacy-related questions or to exercise your rights:
Email: info@omnisio.co.uk
Post: itsstartupsLTD, 135 Trundleys Road, London, England, SE8 5JQ