V
VaxiGo
Legal

Privacy Policy

How VaxiGo collects, uses, stores, and shares your personal data when you use our website and vaccination booking services, and your rights under UK GDPR.

Version 1.0 · Effective 23 July 2026
Plain English Summary
Who we are
VaxiGo Ltd is a UK-based online marketplace that helps you book private vaccination appointments with regulated healthcare providers. We are the data controller responsible for your personal data on our platform.
What data we collect
Your name, email, date of birth, and contact details when you register; your appointment and payment information when you book. At booking we also ask three short health questions — whether you are pregnant, whether you have been vaccinated before, and whether you have any known allergies. We do not store your answers to these three questions: we pass them straight to your chosen provider and do not keep a copy. We also collect technical data about how you use our website.
Who we share it with
The healthcare provider delivering your vaccination, our payment processor (Stripe), and the technology partners that help us run the platform (Supabase, Vercel, Resend, GoDaddy). We never sell your data.
How long we keep it
It depends on the type of data. Most data — including your account and consent records — is kept for up to 5 years from your first login. Payment records are kept for 7 years, and booking records (excluding health information) also for 7 years. The three health questions are never stored by us at all.
Your rights
You can access, correct, or delete your data, restrict or object to processing, request portability, and withdraw consent at any time. Contact our DPO at dpo@vaxigo.co.uk.
Questions or complaints
Email dpo@vaxigo.co.uk or contact the Information Commissioner’s Office at ico.org.uk.
Data Controller

VaxiGo Ltd (company number 17192717) · Registered office: 1 Chidden Holt, Chandler’s Ford, Eastleigh, SO53 4RJ, England
Registered with the ICO under registration number ZC177441.
Data Protection Officer: dpo@vaxigo.co.uk · General enquiries: support@vaxigo.co.uk

1. About Us

This Privacy Policy explains how VaxiGo Ltd (company number 17192717), whose registered office is at 1 Chidden Holt, Chandler’s Ford, Eastleigh, SO53 4RJ, England (“we”, “us”, “our”, or “VaxiGo”), collects, uses, stores, and shares your personal data when you use our website at vaxigo.co.uk and our vaccination booking services.

VaxiGo is the data controller for the personal data described in this Privacy Policy, except where we act as joint controller with healthcare providers as described in Section 13. We are registered with the Information Commissioner’s Office (ICO) under registration number ZC177441.

2. How We Collect Your Data

We collect personal data in the following ways:

  • Directly from you when you create an account, make a booking, answer the three health questions asked at the time of booking, make a payment, or contact our support team;
  • Automatically through your use of our platform, including technical and usage data collected via cookies and similar technologies; and
  • From third parties where applicable, such as payment confirmation data from our payment processor, Stripe.

3. Data We Collect

We collect seven categories of personal data. The specific data fields within each category are set out below.

Account and Registration Data

  • Full name
  • Email address
  • Date of birth
  • Contact telephone number
  • Account login credentials (passwords are hashed and never stored in plain text)

Booking Data

  • Vaccination service selected
  • Provider selected
  • Appointment date, time, and location
  • Booking confirmation details
  • Booking status (Complete Vaccination, Not Administered, or Cancelled)
  • Booking history

Booking-Time Health Questions — Special Category Health Data

At the time of booking, we ask you three short health questions so that they can be relayed to your chosen healthcare provider for clinical safety screening. These three items constitute special category health data under Article 9 of UK GDPR. The three questions are:

  • Whether you are pregnant (yes/no)
  • Whether you have previously been vaccinated (yes / no / unsure)
  • Whether you have any known allergies (yes/no)

We do not store your answers to these three questions. They are relayed to your provider in real time and no copy is kept by VaxiGo.

Payment Data

  • Platform Fee transaction records, including amount, date, and booking reference
  • Payment method type (card type only — we do not store full card details)
  • Stripe payment reference

Important: VaxiGo does NOT store full payment card details. All card data is processed directly by Stripe Technology Europe Limited through their secure payment interface. VaxiGo only receives a payment reference and confirmation of the card type used.

Communication Data

  • Emails sent to and received from support@vaxigo.co.uk, complaints@vaxigo.co.uk, and dpo@vaxigo.co.uk
  • Booking confirmation emails
  • Booking-related invitation and reminder emails
  • Transactional notifications

Technical and Usage Data

  • IP address
  • Browser type and version
  • Device type and operating system
  • Pages visited and time spent on each page
  • Referral source
  • Cookie identifiers (see our Cookie Policy)

Consent Records

  • Explicit consent given at booking to relay the three health questions to your provider, recorded as timestamped structured database fields (healthDataConsentGiven and healthDataConsentAt)
  • Terms and Conditions acceptance record
  • Cookie consent record

4. Legal Bases for Processing

We only process your personal data where we have a lawful basis to do so under UK GDPR. The legal bases we rely on depend on the category of data and the purpose of processing.

Article 6 Legal Bases

  • Contract performance (Article 6(1)(b)): We process your account data, booking data, and payment data because it is necessary to perform our contract with you — to facilitate your vaccination booking, manage your account, and process the Platform Fee payment.
  • Legal obligation (Article 6(1)(c)): We retain certain data to comply with our legal obligations, including financial record-keeping (HMRC), responding to ICO requests, and complying with court orders or law enforcement obligations.
  • Legitimate interests (Article 6(1)(f)): We process technical and usage data for platform security, fraud prevention, and service improvement. We have balanced these interests against your privacy rights and concluded that this processing does not override your fundamental rights and freedoms, particularly given that we minimise the data collected and do not use it for profiling.
  • Consent (Article 6(1)(a)): We rely on your consent for non-essential cookies (see our Cookie Policy) and for any marketing communications. You may withdraw your consent at any time as described in Section 8.

A Legitimate Interests Assessment has been conducted and is available on request by contacting dpo@vaxigo.co.uk.

Article 9 Legal Basis — Booking-Time Health Questions

Your answers to the three health questions asked at booking (pregnancy status, previous vaccination history, and known allergies) constitute special category health data under Article 9 of UK GDPR and require an additional legal basis for processing. Although VaxiGo does not store this information and only relays it to your provider in real time, relaying is itself a form of processing, so an Article 9 condition is required.

Explicit consent (Article 9(2)(a)): At the time of booking, you are asked to give explicit consent for VaxiGo to relay your answers to the three health questions to your chosen healthcare provider. Explicit consent under Article 9(2)(a) is the sole condition we rely on for this processing. Your explicit consent is recorded with a timestamp in our systems.

5. How We Use Your Data

  • To create and manage your VaxiGo account
  • To facilitate vaccination bookings between you and healthcare providers
  • To relay your answers to the three booking-time health questions to the healthcare provider delivering your vaccination
  • To process Platform Fee payments via Stripe
  • To send you booking confirmations, appointment reminders, and transactional notifications
  • To respond to your enquiries, complaints, and data protection requests
  • To maintain the security and integrity of our platform
  • To detect and prevent fraud
  • To improve our services and user experience
  • To comply with our legal and regulatory obligations

6. Who We Share Your Data With

We share your personal data with the following categories of recipients. We do not sell, rent, or trade your personal data for marketing or commercial purposes.

Healthcare Providers

We share your booking details, name, contact information, and your answers to the three booking-time health questions with the healthcare provider you have selected. This sharing is necessary so that the provider can fulfil your booking and deliver your vaccination safely, using the three health question answers for clinical safety screening. VaxiGo and the relevant healthcare provider act as joint controllers under Article 26 of UK GDPR in respect of the shared booking dataset and the three booking-time health questions (see Section 13).

Stripe Technology Europe Limited

Stripe processes Platform Fee payments on our behalf. Stripe is an Electronic Money Institution authorised by the Central Bank of Ireland (reference C187865) and regulated by the Financial Conduct Authority in the UK. Stripe acts as a data processor under Article 28 of UK GDPR, and we have a Data Processing Agreement in place. We share your payment transaction data and booking reference with Stripe; full card details are entered by you directly into Stripe’s secure interface and are not shared by VaxiGo.

Supabase

Supabase provides our database hosting service (PostgreSQL), hosted in Supabase’s eu-west-2 region (London, UK). Supabase acts as a data processor under Article 28, and we have a Data Processing Agreement in place. Supabase hosts your account data, booking records, and consent records. The three booking-time health questions are never stored by VaxiGo and are not hosted in Supabase. Supabase’s US parent company staff may have residual access to infrastructure for support and maintenance, governed by the DPA and the transfer safeguards described in Section 7.

Vercel

Vercel provides web hosting and CDN services, hosted in Vercel’s lhr1 region (London, UK). Vercel acts as a data processor under Article 28, and we have a Data Processing Agreement in place. Vercel’s US parent company staff may have residual access to infrastructure for support and maintenance, governed by the DPA and the transfer safeguards described in Section 7.

Resend

Resend provides our transactional email delivery service and acts as a data processor under Article 28, with a Data Processing Agreement in place. We share your email address, name, booking reference, and transactional content with Resend to send booking confirmations, appointment reminders, account notifications, and complaint acknowledgements. Resend is headquartered in the United States; data may be processed on US-based infrastructure, governed by Resend’s DPA and the transfer safeguards described in Section 7.

GoDaddy

GoDaddy provides business email hosting for our support@, complaints@, and dpo@vaxigo.co.uk addresses, and acts as a data processor under Article 28 with a Data Processing Agreement in place. GoDaddy is headquartered in the United States, and email data may be subject to US jurisdiction; VaxiGo relies on GoDaddy’s DPA and the standard contractual transfer safeguards described in Section 7.

Google LLC (Google Maps API)

We use Google Maps to display provider locations and enable location-based search. When you use map features, your IP address and approximate location (if location services are enabled) are transmitted to Google LLC, which acts as an independent data controller under its own terms. VaxiGo does not control how Google processes this data — see Google’s Privacy Policy. Google LLC is headquartered in the United States; see Section 7.

Legal and Regulatory Authorities

We may share your personal data with legal or regulatory authorities where required by law, including in response to ICO requests, court orders, or law enforcement requests. The legal basis for such sharing is Article 6(1)(c) (legal obligation).

No Sale of Data

VaxiGo does not sell, rent, or trade your personal data to any third party for marketing or commercial purposes.

7. International Data Transfers

We aim to keep your personal data within the United Kingdom wherever possible. Our database and hosting infrastructure are located in the UK — Supabase in eu-west-2 (London) and Vercel in lhr1 (London).

Some processors have US parent entities whose staff may have residual access to UK-hosted infrastructure for support and maintenance, and GoDaddy, Resend and Google LLC may process certain data on US infrastructure. Stripe Technology Europe Limited processes payments within the EEA and UK under its own regulatory framework as an authorised Electronic Money Institution. We do not make any other intentional international transfers of your personal data.

Where personal data is transferred outside the UK in respect of these processors’ US parent company access, we and those providers rely on appropriate safeguards. Specifically, we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the UK International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the EU Standard Contractual Clauses, as set out in each provider’s data processing terms.

8. Your Rights

Under UK GDPR you have the rights below. To exercise any of them, contact our DPO at dpo@vaxigo.co.uk. We will respond within one calendar month; if your request is complex or numerous, we may extend this by up to two further months and will tell you why within the first month.

  • Right of Access (Article 15): request a copy of the personal data we hold about you, in a commonly used electronic format.
  • Right to Rectification (Article 16): have inaccurate or incomplete data corrected.
  • Right to Erasure (Article 17): have your data deleted in certain circumstances. We may be unable to delete data we are legally required to retain (e.g. payment records for HMRC, or booking records within the Limitation Act 1980 window — see Section 9). We do not store your answers to the three booking-time health questions, so there is no such data held by VaxiGo to erase; once received by your provider they form part of that provider’s clinical records, and erasure of those should be requested from the provider directly.
  • Right to Restriction (Article 18): restrict processing in defined circumstances, e.g. while accuracy or our legitimate interests are being verified.
  • Right to Data Portability (Article 20): where we process on the basis of consent or contract by automated means, receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Right to Object (Article 21): object to processing based on legitimate interests (Article 6(1)(f)); we will cease unless we can demonstrate compelling legitimate grounds that override your interests.
  • Right to Withdraw Consent (Article 7(3)): withdraw consent at any time — including your Article 9(2)(a) consent given at booking and your consent for non-essential cookies. Withdrawal does not affect the lawfulness of processing before it; because we do not store the three health answers, withdrawing after they have been relayed leaves no such data held by VaxiGo to delete.
  • Automated Decision-Making (Article 22): VaxiGo does not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning you.

You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk or 0303 123 1113. We would appreciate the chance to address your concerns first — please consider contacting dpo@vaxigo.co.uk in the first instance.

9. How Long We Keep Your Data

We retain your personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Where a statutory period is longer than our general default (5 years from your first login), the statutory period applies.

Data categoryRetention period
Booking-time health questionsNot retained — relayed to your provider in real time and never stored by VaxiGo
Account data5 years from the date of your first login
Booking data (non-health)7 years from the booking date (Limitation Act 1980 contractual-claims window)
Payment records7 years from the transaction date (HMRC financial record-keeping)
Consent records5 years from the date of your first login
Communication data3 years from the date of the communication (claim duration + 2 years if part of a legal claim)
Technical and usage data13 months (in line with ICO guidance)
Complaint records3 years from the date the complaint is resolved

The three booking-time health questions are never stored on our systems, so there is no VaxiGo retention period for them. Any retention after relay is the responsibility of the healthcare provider under their own privacy policy.

10. Special Category Data — Additional Safeguards

Your answers to the three booking-time health questions constitute special category health data under Article 9 of UK GDPR. Although VaxiGo does not store this information, we apply the following safeguards to the relay of these answers:

  • Data Protection Impact Assessment (DPIA): We have conducted a DPIA covering the relay of the three health questions, as required by Article 35.
  • Not retained: The answers are not retained by VaxiGo; they are relayed to your provider in real time and not stored on our systems.
  • Encryption in transit: The answers are transmitted to the provider over encrypted connections using Transport Layer Security (TLS).
  • Restricted access and no secondary use: Access is restricted to the relay mechanism. VaxiGo does NOT use this information for any commercial, marketing, analytical, or clinical decision-making purpose; it is collected solely to relay to the provider for clinical safety screening.

11. Security Measures

  • Encryption in transit: All data between your browser and our platform is encrypted using TLS.
  • Encryption at rest: Data stored in Supabase is encrypted using AES-256.
  • Password security: Account passwords are hashed using industry-standard algorithms and never stored in plain text.
  • Access controls: Production access to personal data is restricted to authorised personnel only.
  • Row-level security: Supabase row-level security prevents one patient from accessing another patient’s data.
  • UK data residency: Our primary data stores are hosted in the UK — Supabase in eu-west-2 (London) and Vercel in lhr1 (London).
  • Incident response: We maintain an Incident Response and Breach Notification Policy.
  • Breach notification: We will notify the ICO within 72 hours where required by Article 33, and affected patients without undue delay where a breach is likely to result in a high risk to their rights and freedoms, as required by Article 34.

12. Cookies

Our website uses cookies and similar technologies. For full details of the cookies we use, their purposes, and how to manage your preferences, please see our Cookie Policy. We only use non-essential cookies with your prior consent, obtained through our cookie consent banner when you first visit. You may withdraw your cookie consent at any time via the cookie settings link on our website.

13. Joint Controller Arrangement

Under Article 26 of UK GDPR, VaxiGo and the healthcare provider you select act as joint controllers in respect of the shared booking dataset and your answers to the three booking-time health questions. Responsibilities are allocated as follows:

VaxiGo is responsible for:

  • Collecting your personal data and your answers to the three health questions through the platform
  • Transmitting your data and your answers to the healthcare provider
  • Operating and maintaining the platform
  • Handling data subject rights requests in relation to data held on the platform

The healthcare provider is responsible for:

  • Clinical processing of your answers and any other data received from VaxiGo
  • Maintaining clinical records in accordance with their own legal and regulatory obligations
  • Handling data subject rights requests in relation to clinical records they hold

You may exercise your rights against either VaxiGo or the healthcare provider, regardless of this allocation. For data held on the VaxiGo platform, contact dpo@vaxigo.co.uk; for clinical records, contact the provider directly. If you are unsure which party to contact, email dpo@vaxigo.co.uk and we will assist you.

14. Children

The VaxiGo platform is not directed at children under the age of 13. Account creation requires users to be at least 18 years old. Vaccination bookings for minors (persons under 18) must be made by a parent or guardian using their own account. Where a parent or guardian makes a booking on behalf of a minor and answers the three booking-time health questions, they are responsible for the accuracy of the information provided and for giving the explicit consent at booking to relay those answers to the provider on the minor’s behalf.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Where we make material changes, we will notify you by email at least 30 days before they take effect. The current version is always available at vaxigo.co.uk/privacy, and the version number and effective date are shown at the top of this page.

Contact Us

If you have any questions about this Privacy Policy or wish to exercise any of your data protection rights, please contact us:

Data Protection Officer
Email: dpo@vaxigo.co.uk
Post: Data Protection Officer, VaxiGo Ltd, 1 Chidden Holt, Chandler’s Ford, Eastleigh, SO53 4RJ, England

General enquiries: support@vaxigo.co.uk · Complaints: complaints@vaxigo.co.uk
ICO: ico.org.uk · 0303 123 1113