1. Data Controller
MeFirst Ltd is the data controller for personal data processed through mefirst.ie in connection with operating the marketplace, accounts, bookings, and Platform communications. Contact for privacy enquiries: privacy@mefirst.ie.
Each Shop is an independent controller of personal data it collects directly at its premises and of how it delivers services. Where a Merchant imports client lists or initiates flash-slot emails, the Merchant determines the purposes of that outreach and MeFirst acts as a processor for the technical sending/storage functions described below.
2. What We Collect
We collect and process personal data necessary to operate the Platform, including:
•
Account data: Google account identifier, email address, display name (where provided by Google), and role (customer, owner, or admin). New Google sign-ins are created as customers. Owner is set only when a Shop is created for that account. Admin is assigned only by MeFirst.
•
Booking data: appointment times, service selections, staff assignment, payment preference, financial totals and Stripe references (PaymentIntent, SetupIntent, Checkout Session, refund IDs as applicable), gift recipient names, group session identifiers, flash-slot identifiers, and optional checkout vibe / service-preference notes
•
Shop data: business name, slug, category, Eircode, address lines, coordinates, photos, services and groups, staff roster, social URLs, VAT settings, Stripe Connect account identifiers, booking policy settings, and receipt template fields
•
Social / lookbook data: media files, captions, likes, comments (including optional anonymous display), follows, related notifications, and Shop Stories that expire after 24 hours
•
Imported client records uploaded by Merchants (typically name, email, phone and visit metadata) stored under the Shop for Merchant reference and optional flash alerts
•
Search terms typed into Platform search by signed-in users (used to improve discovery and show popular searches)
•
Account-lock fingerprints: hashed email, account id, and address/Eircode fingerprints used only to enforce one Shop per email/address and the fourteen-day reopen cooldown after deletion
•
Contact-form submissions: name, email, and message content
•
Technical and usage data: authentication session data, IP address and device/browser signals as processed by our infrastructure providers, and aggregated page-view counts for Platform statistics
3. How We Structure Data (Marketplace Isolation)
MeFirst separates public directory information from customer booking PII wherever practicable.
Customer emails and payment-card vaults are not published on public Shop pages. Public shop listings show business information, services, lookbook media, and location suitable for discovery.
A limited busy-slot mirror (time ranges without customer names or financials) may be readable so visitors can see free/busy availability on public booking calendars without exposing customer identity.
4. Legal Bases for Processing
We process personal data under the following GDPR legal bases:
•
Contract performance — creating accounts, facilitating bookings and payments you request, providing Merchant tools you activate
•
Legitimate interests — platform security, fraud prevention, abuse detection (including automated media moderation), product improvement, aggregated traffic metrics, and enforcing our Terms
•
Legal obligation — tax, accounting, and regulatory compliance
•
Consent — where we rely on consent for a specific optional processing activity (you may withdraw consent where applicable without affecting the lawfulness of processing before withdrawal)
5. Processors & Third Parties
We use service providers (processors / independent controllers as applicable) to deliver the Platform. Key categories include:
•
Google Firebase / Google Cloud — authentication, Firestore database, Cloud Storage, Cloud Functions (EU regions where configured)
•
Stripe — payment processing, SetupIntents, Connect payouts (PCI-DSS)
•
Google Sign-In — identity authentication
•
Google Cloud Vision — SafeSearch moderation of lookbook upload stills before storage
•
OpenStreetMap / Leaflet tile providers — map display
•
Nominatim (OpenStreetMap) — address geocoding for Shop setup
•
OSRM public routing services — estimated drive times for multi-stop itineraries
•
Email delivery providers configured for transactional mail (booking, cancellation, flash alerts, contact routing)
•
Google AdSense — third-party advertising when enabled on web pages (AdSense is an independent controller of data it collects for ads; see Google's policies)
6. Advertising & Analytics
MeFirst may show first-party promotions (including paid Shop Spotlight placements) and, when configured, Google AdSense units on web.
We do not sell personal data to data brokers. AdSense and similar networks may process device and cookie identifiers under their own policies when ads are served.
We record limited Platform page-view aggregates for operational analytics. This is not sold as an advertising audience dataset.
7. Automated Moderation
Lookbook media may be analysed by automated SafeSearch classification before it is stored. This processing is necessary for Platform integrity and child/user safety interests. Rejected uploads are not published.
Shop gallery photos uploaded by Merchants in settings/onboarding are Merchant-controlled content; Merchants must ensure those images are lawful.
8. Data Retention
Account data is retained while your account is active and thereafter as needed for legal, accounting, dispute, and fraud-prevention obligations (often up to seven (7) years for financial records under Irish requirements).
If you use Delete my account in Settings, live profile and Shop listing data are removed. Hashed uniqueness locks may be kept for fourteen (14) days (and any longer period needed to enforce the one-shop rule or a legal hold). Appointment and payment records may be retained as required for Merchant and Platform financial compliance.
Contact inquiries and support correspondence are retained as needed to handle your request. You may request earlier erasure subject to legal retention exceptions.
9. Your GDPR Rights
Under the GDPR (and Irish Data Protection Act 2018), you may have the right to:
•
Access your personal data (Subject Access Request)
•
Erase data ("right to be forgotten") where legally applicable
•
Restrict or object to certain processing
•
Data portability where applicable
•
Lodge a complaint with the Data Protection Commission (Ireland): www.dataprotection.ie
9A. Portability & Merchant Exports
Shop owners may export their appointment history from the business dashboard (CSV/JSON formats that omit certain sensitive payment identifiers). Customers who need a copy of their personal data may use Delete my account for erasure where applicable, or contact privacy@mefirst.ie or support@mefirst.ie to exercise portability/access rights.
10. International Transfers
Some providers may process data outside the European Economic Area. Where this occurs, we rely on appropriate safeguards such as Standard Contractual Clauses or other mechanisms approved under GDPR.
11. Contact
Data Protection enquiries: privacy@mefirst.ie · General support: support@mefirst.ie · MeFirst Ltd · mefirst.ie · Contact form on the Platform.