top of page

PRIVACY POLICY

LAST UPDATED

Last updated: March 2026

​

The Horsebox Spa Ltd ('we', 'us', 'our') is committed to protecting your personal data and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy explains what data we collect, why we collect it, how we use it, and your rights in relation to it.

​

1. WHO WE ARE

The Horsebox Spa Ltd is a mobile equine wellbeing business operating across Kent, Sussex and Surrey. We are the data controller for the personal data we collect from you.

Data Controller: Allie Macleod

Contact: allie@thehorseboxspa.co.uk |  07946 716189

​

2. WHAT DATA WE COLLECT

When you make a booking, enquire about our services, or use our website, we may collect the following:

  • Your name and contact details (email address, phone number)

  • Your yard name, yard postcode and home postcode

  • Your horse's details (name, condition notes relevant to treatment)

  • Appointment history and treatment records

  • Payment reference information (we do not hold card details - payments are processed via secure third-party processors)

  • Communications you send us (email, text, form submissions)

  • Website usage data (see Cookies section below)

​

3. DATA SUBMITTED BY THIRD PARTIES

3.1 In some cases, a yard organiser or other third party may register a horse or submit personal data on behalf of another horse owner. Where this occurs, the person submitting the data confirms - via a mandatory declaration at the point of registration - that they have obtained the data subject's explicit consent to share their information with us.

3.2 The Horsebox Spa processes third-party data in good faith on the basis that this consent has been obtained. We cannot verify whether consent was given and we accept no liability for data submitted to us without the data subject's knowledge or permission. Responsibility for obtaining appropriate consent lies solely with the person who submitted the data.

3.3 If you believe your personal data has been shared with us without your consent, please contact us immediately at allie@thehorseboxspa.co.uk and we will delete it.

​​

4. HOW WE USE YOUR DATA

We use your data to:

  • Process and manage your bookings

  • Plan our travel routes and appointment schedules

  • Send you booking confirmations, appointment times and reminders

  • Issue cancellation fees where applicable under our Terms of Service

  • Maintain health records for your horse to inform future treatment

  • Contact you about your appointment or in response to your enquiry

  • Comply with our legal and insurance obligations

  • Send no more than one marketing email per month. You can unsubscribe at any time.

  • Process deposit payments for salt therapy courses via our payment processor (Stripe)

We will only use your data for these purposes. We do not use your data for marketing without your explicit consent.

​

5. LAWFUL BASIS FOR PROCESSING

We process your personal data under the following lawful bases:

  • Contract: Processing necessary to fulfil or manage your booking

  • Legitimate interests: Route planning, appointment scheduling, and maintaining treatment records in the interests of horse welfare.

  • Consent: Where a third party submits your data on your behalf, we process it on the basis that they have confirmed your consent at the point of registration

  • Legal obligation: Retaining financial records as required by HMRC (7 years)

​

6. DATA SHARING

We do not sell, rent or share your personal data with third parties for marketing purposes.

We may share limited data with:

  • Our bookkeeping service (access is limited to what is strictly necessary for financial record-keeping and they are bound by confidentiality obligations)

  • Software platforms we use to operate our business (e.g. booking management, email, route planning tools) — all selected for appropriate security standards

  • Stripe (our payment processor for salt therapy course deposits) - Stripe processes your payment securely and is certified to PCI Service Provider Level 1

Some of our software platforms may process data in the USA or other countries outside the UK. Where this is the case, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

​​

6A. PAYMENT PROCESSING (STRIPE) 

When you pay a deposit for a salt therapy course, payment is processed by Stripe, Inc. Stripe collects your card details directly via their secure payment page. We do not see, handle, or store your full card details at any time.

Stripe may collect your name, email address, card number, expiry date, and CVC for the purpose of processing your payment. Stripe’s use of your data is governed by their own privacy policy: https://stripe.com/privacy

We receive only a payment confirmation reference, the last 4 digits of your card, and the payment amount. This information is retained for our financial records as required by HMRC

​

7. HOW LONG WE KEEP YOUR DATA

We retain your data for 7 years from your last appointment or point of contact, in order to:

  • Meet HMRC requirements for financial records

  • Satisfy our professional insurance obligations

  • Maintain continuity of care for your horse

If you have enquired but never made a booking, your data will be deleted after 7 years or on request.

​

8. YOUR RIGHTS

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you

  • Correct inaccurate data

  • Request deletion of your data (subject to our legal obligations)

  • Object to or restrict processing

  • Data portability (receive your data in a structured, machine-readable format)

To exercise any of these rights, contact us at allie@thehorseboxspa.co.uk. We will respond within one month.

If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk | 0303 123 1113

​

9. WEBSITE COOKIES

Our website uses cookies to monitor visitor numbers, how you found us, and which pages you view. This helps us improve our content.

We use IP addresses to analyse site usage trends. IP addresses are not linked to personally identifiable information and are not shared with third parties.

You can disable cookies in your browser settings at any time.

​

10. SECURITY

We take reasonable technical and organisational measures to protect your personal data from unauthorised access, loss or disclosure. We use mainstream software with secure login options and restrict access to your data on a need-to-know basis

.

11. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. Any significant changes will be notified on our website. Continued use of our website or services following a change constitutes acceptance of the updated policy.

​​

COMPANY

The Horsebox Spa Ltd | Registered No: 11294696 (England & Wales) | 6 Dale Hill, Ticehurst, East Sussex, TN5 7DG

Mobile equine therapy & wellness services across Kent, Sussex and Surrey

© 2026 The Horsebox Spa Ltd.  All rights reserved.

WhatsApp 07946 716189

bottom of page