How Nuance collects, uses, and protects personal data.
| Service | Nuance — profit intelligence for beauty brands (nuance-detail.io) |
| Provider | Tinkerlab Services Ltd. (company no. 14840839), United Kingdom |
| Effective date | 16 August 2026 |
| Version | 1.1 |
| Contact | privacy@tinkerlab.co.uk |
Nuance provides profit-intelligence analytics to e-commerce and beauty brands. This policy explains how we handle personal data in connection with our website and service. For questions, contact us at the address above.
When we analyse a merchant's commercial data on their behalf, the merchant is the data controller and we act as their data processor, handling data only on their instructions. We are the controller for the limited personal data we collect directly — for example, the contact details of people who sign up or get in touch.
We use website enquiry data to respond, send one automatic receipt confirming that the message arrived, and continue the conversation personally. We rely on our legitimate interests in answering business enquiries and developing Nuance. The receipt is not a marketing sequence.
We may use limited business contact data for carefully targeted business-to-business outreach where data protection and electronic-marketing rules allow it. We rely on legitimate interests only after considering necessity, proportionality and the person's reasonable expectations. Every first contact identifies us, links to this policy and offers a clear way to object. We stop direct marketing when someone objects.
We also process data to provide, secure and support the service, relying on performance of a contract, our legitimate interests in operating and protecting Nuance, and — when acting for a merchant — the merchant's instructions and lawful basis. We do not sell personal data.
Website enquiry data comes directly from the person who submits it. For selected business outreach, details may come from a third-party business-contact data provider. Our first message identifies the specific source and provides this privacy information. We provide that information no later than our first communication and within one month of obtaining the details.
We share data only with providers needed to run Nuance. Render hosts the application and its database in Frankfurt, Germany. Resend processes email addresses and message content to deliver the notification and automatic receipt. These providers are contractually required to protect the data and use it to provide their services to us.
The Nuance production database is hosted in the European Union. Resend's primary processing takes place in the United States. For transfers outside the UK or EEA, we use recognised safeguards such as the UK Extension to the EU-US Data Privacy Framework or contractual clauses approved for international transfers.
We automatically delete landing-page leads after 24 months with no activity. We apply the same 24-month maximum after last activity to business outreach contact records unless we need a shorter period or must retain a minimal suppression record so that someone who opted out is not contacted again. When a merchant relationship ends, we delete or return merchant and customer data as agreed, subject to legal requirements.
We protect data with encryption in transit and at rest, least-privilege access, multi-factor authentication, and a documented information-security and incident-response program.
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, and may object to or restrict certain processing. You have an absolute right to object to use of your personal data for direct marketing. To exercise a right or ask us to delete a landing lead, email the address above. Where we process data on a merchant's behalf, we will pass the request to that merchant. You may also complain to your local data protection authority (in the UK, the ICO).
We may update this policy from time to time and will post the current version here with a revised effective date.