Privacy Notice
Last updated: May 16, 2026
1. Who we are
Kalea Breanna Archer Greene (trading as Plume) is the data controller responsible for personal data processed through the Plume platform.
2. Personal data we collect
- Account data — name, email, password hash, member type (clinic, brand, beauty lover).
- Profile and business data — clinic or brand details, products, services, logos.
- Operational data — bookings, client records, orders, inventory, loyalty memberships you create.
- Support data — messages you send us.
- Usage and device data — log data, IP address, browser and device identifiers, pages viewed.
3. How we use personal data
- Create and manage your account and authentication (contract).
- Provide the Service: scheduling, brand-to-clinic ordering, inventory, loyalty (contract).
- Customer support and communications (contract / legitimate interests).
- Security, fraud prevention, and abuse detection (legitimate interests / legal obligation).
- Improve and develop the Service (legitimate interests).
- Marketing emails about Plume (consent, with opt-out in every email).
4. Who we share data with
- Service providers / subprocessors — hosting, database, email delivery, analytics, customer support tooling.
- Merchant of Record — Paddle. Paddle.com processes all payments, subscriptions, tax compliance, refunds, and invoicing on our behalf. Paddle is the seller of record for billing purposes and processes the personal and payment data you provide at checkout under its own privacy notice.
- Other Plume users — clinics can see brands and their public products; brands can see clinic orders placed with them.
- Professional advisers — legal, accounting, where reasonably necessary.
- Authorities — where required by law or to protect rights and safety.
5. International transfers
Personal data may be processed outside your country, including in the United States. Where data leaves the UK / EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
6. Retention
We keep personal data for as long as your account is active and for a reasonable period afterwards, then delete or anonymise it, unless we are required to retain it longer for legal, tax, or accounting purposes.
7. Your rights
Depending on your country, you may have rights to access, rectify, erase, restrict, or port your personal data, to object to certain processing, and to withdraw consent. EEA and UK users also have the right to complain to a supervisory authority. We aim to respond to requests within one month.
8. Security
We use appropriate technical and organisational measures including encryption in transit, access controls, and Row-Level Security in our database. No system is perfectly secure, but we work to protect your data.
9. Cookies
We use strictly necessary cookies for authentication and session management. If we add analytics or marketing cookies, we will request consent and let you manage preferences.
10. Contact
For privacy questions or to exercise your rights, email plumestudioscreatives@gmail.com.