Privacy Policy

Last updated: 16 August 2026.

Who we are

Lili Pod (operated by Lili Pod Ltd, company number 17335620, registered office 153 Christchurch Road, Ringwood, BH24 3AL, England) provides a booking, scheduling and HR platform to UK training providers and similar businesses. This policy explains how we handle personal data as both a data controller (for our own website visitors and business customers' accounts) and a data processor (for the booking, HR and customer data a business processes using our platform, on that business's own instructions).

If you're a customer of one of our business users — for example, you booked a course through a business's Lili Pod booking page — that business is the controller of your data, and this policy sits alongside their own privacy notice. You can still contact us directly using the details below.

Data we collect

On this marketing website:

  • Anything you submit through a contact or demo-booking form (name, email, business name, and your message).
  • We do not run analytics, advertising or tracking cookies on this site. See Cookies and site storage below for the full list of what is stored.

Through the Lili Pod app, once a business signs up:

  • Account and staff details: name, email, phone number, role.
  • Booking data: what a business's customers book, when, and any notes taken about the booking.
  • Payment references processed via the business's own connected Stripe account — we never see or store full card numbers.
  • Where a business switches on HR: employment records, leave and sickness records, and whether a staff member holds a DBS check plus its renewal date. We do not store DBS certificate numbers or the contents of DBS certificates.
  • Documents and certificates a business or its staff choose to upload.
  • Messages sent to "Lily," our in-app assistant, when a business chooses to use it.

Why we process it, and on what basis

  • Performance of a contract — running the booking platform a business has subscribed to, including taking bookings, payments and sending confirmations.
  • Legal obligation — keeping the financial records HMRC requires, and (for businesses using HR) records tied to statutory employment duties.
  • Legitimate interests — keeping the platform secure, responding to support requests, and improving the product, balanced against your rights.
  • Consent — where a business opts in to something optional, like the Lily assistant or marketing communications from us.

Special category data (health information in sickness records) and DBS-related data (limited to whether a check is held, its level, and when it's due for renewal — never certificate numbers) are only processed where a business switches on HR features, on that business's own lawful basis as data controller for its staff.

Who we share it with

We use a small number of specialist providers to run the Services, each acting as our sub-processor under their own data protection agreement with us:

  • Supabase — database, authentication and file storage.
  • Cloudflare — application hosting and content delivery.
  • Stripe — payment processing, via each business's own connected account.
  • Resend — delivery of transactional emails (confirmations, reminders).
  • Anthropic and OpenAI — generate replies from the optional "Lily" assistant, only for businesses that choose to use it, and never for HR special-category data.

We do not sell personal data, and we do not share it with anyone for their own marketing purposes. Where a sub-processor is based outside the UK/EEA, we put an appropriate legal safeguard in place (such as the UK's International Data Transfer Addendum or Standard Contractual Clauses) before any data is transferred.

Cookies and site storage

We do not use cookies for analytics, advertising or tracking, and we do not sell or share browsing data with anyone. Because nothing we set requires your consent under UK law, there is no cookie banner — we would rather tell you exactly what is stored. Here is the complete list.

On this marketing site

  • One small flag, stored only for the current browser tab, that remembers you have already been shown the assistant's introduction so it does not reappear on every page. It contains no information about you and disappears when you close the tab.
  • On the Book a demo page, the booking calendar is provided by Cal.com. Loading it sets a short-lived security cookie (about 30 minutes) used by their provider to tell real visitors from automated traffic. It is not used to track you, and it is set by Cal.com rather than by us — their own privacy notice covers it.
  • Some pages load typefaces from Google Fonts. That means your browser contacts Google to fetch the font file, which tells them your IP address. No cookie is set.

In the Lili Pod app

  • A booking page belonging to one of our businesses sets no cookies at all. It stores one or two flags for the current tab only — remembering, for instance, that you have already dismissed an offer — and nothing that identifies you.
  • If you sign in, we store your sign-in session in your browser so you stay signed in. This is strictly necessary to provide an account, and clearing it signs you out.
  • At the point you enter card details, Stripe sets its own cookies for fraud prevention. These are necessary to take a payment safely; Stripe's privacy policy covers them. We never see your card number.
  • If the business whose page you are visiting has chosen a custom typeface, that font is loaded from Google Fonts, as above.

You can clear all of this at any time through your browser's settings. Doing so will sign you out, and nothing else will be lost.

How long we keep it

As a rule, we keep account and booking data for as long as a business's Lili Pod subscription is active, plus what the law separately requires afterwards — for example, financial records relevant to HMRC generally need to be kept for a minimum of six years. If a subscription lapses, the account is not deleted straight away: it enters a grace period in which everything is retained and the business keeps access, we may lock it more fully after 30 days, and we may delete it and the data in it after 90 days. We contact the business before deletion, and their data can be exported or returned at any point beforehand. Financial records are retained for their statutory period regardless of whether the account is deleted. Loyalty reward codes are held for as long as the issuing business's account is active and are deleted with it. DBS-related records are limited to check status and renewal dates — we never hold certificate numbers — and are deleted with the rest of a staff member's HR record when it goes. We're finalising a fuller, per-category retention schedule; this policy will be updated once that work is complete, and a business can always ask us to delete data sooner using the rights below.

Data security

Personal data is encrypted in transit and at rest by our infrastructure providers, and kept isolated between businesses so one business can never see another's data. Access inside a business's own account is role-based — for instance, HR records are only visible to the people a business has specifically granted that permission.

Your rights

Under UK data protection law, you can ask to:

  • Access a copy of the personal data we (or a business, as controller) hold about you.
  • Correct inaccurate data, or have incomplete data completed.
  • Have your data deleted ("the right to be forgotten"), subject to what the law requires us to keep.
  • Receive your data in a portable format, or ask us to transfer it elsewhere.
  • Object to, or ask us to restrict, certain processing.

If you're a customer of a Lili Pod business, the quickest route is the export/delete tools in your account, or asking that business directly — they hold the data as controller. You can also contact us using the details below, or complain to the UK's Information Commissioner's Office (ico.org.uk) if you're unhappy with how a request was handled.

Children

Lili Pod is intended for use by businesses and their adult staff and customers. Where a business's own services are directed at under-18s (for example, youth training courses), responsibility for any additional safeguards for that data sits with the business as controller.

Changes to this policy

We'll update this page if how we handle data changes, and update the "last updated" date above. Material changes will be flagged to business customers directly.

Contact us

For questions about this policy or our privacy practices, email us at info@lilipod.co.uk, or contact us via the form on our website.