The short version
- We only collect what we need to help you find a physio near you, and later to book and pay them.
- What you tell us about your pain or injury is health information. We only keep it if you choose to save it, and only with your clear permission.
- The body map works on your device. Nothing you tap is sent to us unless you choose to save it.
- We do not sell your data. We do not use advertising or tracking cookies.
- You can ask to see, correct or delete your data at any time. Email privacy@limberly.co.uk.
Who we are
Limberly is run by Thrive Haven Ltd, a company registered in England and Wales (company number 16319387). Our registered office is 22 Waltham Road, Newton Abbot, Devon, TQ12 1LH, United Kingdom. Thrive Haven Ltd also runs MatchyMatch UK.
In this policy, “Limberly”, “we” and “us” mean Thrive Haven Ltd. We are the “controller” of the personal data described here. That means we decide how it is used and we are responsible for looking after it.
For anything about your data, email privacy@limberly.co.uk. The person who reads that mailbox is responsible for privacy at Limberly.
What this policy covers
This policy explains how we use personal data on limberly.co.uk and in the Limberly service. It follows the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We are opening Limberly in stages, so some parts of this policy describe things that are not live yet:
- Live today: our website, our blog, and a body map that helps you say where it hurts.
- Opening soon: accounts for patients and physios, a short questionnaire about your pain, and physio profiles.
- Later: booking and paying a physio online.
Where a section only applies once a feature opens, we say so. We will update this policy before anything changes in a way it does not already describe.
What we collect and why
The law says we need a reason, called a “lawful basis”, for each use of your data. We give it for each item below.
When you visit our website
Like every website, our servers receive your IP address, the page you asked for, your browser type and the time. We use this to send you the page, keep the site working and protect it from attacks. Our fonts come from our own servers, so no font company sees your visit.
We count visits with Vercel Web Analytics. It uses no cookies and stores nothing on your device. It records the page, the website that sent you, your browser, device type and country, and a few steps in the symptom check and sign-up. For the symptom check it records only the kind of advice shown (emergency, NHS 111, GP or physio), never where it hurts or your answers. Vercel does not keep your IP address for this: it tells visits apart with a code made from your request that is thrown away every day, so the figures cannot be traced back to you.
We do not use advertising tools, and we do not track you across other websites. See our cookie policy.
Lawful basis: legitimate interests (running a secure website, and learning which pages help people so we can improve them).
When you use the body map
The body map lets you tap the places where you have pain. Your taps stay on your device. They are not sent to us, and today they are gone when you close the page. When accounts open, you will be able to save your answers. Only then do they reach us, as described under “Your health information” below.
When you create an account (patients)
- Your name and email address, so you can sign in and we can contact you about your account.
- Your phone number, if you give it, for appointment reminders once booking opens.
- Your date of birth, so we can check you are 18 or over and so a physio knows your age if you book with them.
- Your postcode, so we can show physios near you and check whether a physio can visit your home.
- Your password is handled by our sign-in provider (Firebase Authentication, part of Google). We never see it.
Lawful basis: contract (we need this to give you the service you signed up for).
Your health information
If you save your body map, we keep the areas you chose and the answers you give to our short questionnaire about your pain. This is health information. We explain how we protect it in the next section.
When you join as a physio
- Your name, email address and phone number, to run your account.
- Your HCPC registration number. We check it against the public register of the Health and Care Professions Council (HCPC) before your profile goes live, and may check it again later.
- Your profile: the name you practise under, a short description, the year you qualified, the body areas you treat, your clinic addresses, whether you offer home or video appointments, and your prices.
Your public profile shows your name, description, HCPC number, the areas you treat, your prices and the general area of each clinic (for example SW11). It never shows your email address, phone number or full street address. A patient sees a clinic’s full address only once they have a booking there.
Lawful basis: contract (to list you), and legitimate interests (checking your registration so patients can trust that every physio on Limberly is registered).
When you contact us
If you email us, we keep your message and our reply so we can help you and deal with any follow-up.
Lawful basis: legitimate interests (answering you). If your email includes health information, we use it only to answer you.
When booking and payments launch
We will keep a record of each booking: who it is with, when, where, the type of appointment and the price. Payments will be taken by Stripe. We will never see or store your full card number.
Lawful basis: contract (to arrange your appointment), and legal obligation (we must keep financial records for tax).
Keeping Limberly safe
We may use any of the data above to prevent fraud, investigate misuse, and keep records of important actions on our systems (for example, when a physio is approved or suspended).
Lawful basis: legitimate interests (keeping patients, physios and the service safe), and legal obligation where the law requires it.
Your health information
Information about your pain, injuries or symptoms is “special category data” under Article 9 of the UK GDPR. It gets extra protection.
- We only keep it with your explicit consent. We will ask you clearly before you save it. You do not have to give it: you can still look for a physio without saving anything.
- You can withdraw your consent at any time by emailing privacy@limberly.co.uk. We will then delete it. This does not affect what we did with it before you withdrew.
- Who can see it. From a web browser, only you can read it. Physios cannot see it unless you book with them and choose to share it (once booking opens). Our own team can only reach it through a logged support process, and only when we need to in order to help you or to meet a legal duty.
- What it is for. To help you find a physio who treats your problem, and to give the physio you book useful background. We never use it for advertising and we never sell it.
Lawful basis: your explicit consent (Article 6(1)(a) and Article 9(2)(a) UK GDPR).
Once you share it with a physio for a booking, the physio keeps their own copy as part of your clinical record. They are responsible for that copy under their own professional and legal rules.
If you are a physio we contact
To help patients find care near them, we may contact physios who practise near a patient and invite them to join Limberly. To do this we use business contact details that physios or their clinics have made public, for example on a clinic website or a professional directory, and the public HCPC register to check that they are registered.
- We only use your business details: your name, clinic name, clinic address, and business email or phone.
- We tell you where we got your details in our first message.
- Every message tells you how to stop hearing from us.
Lawful basis: legitimate interests (growing a service that helps patients reach registered physios).
You can object at any time. Reply to our message or email privacy@limberly.co.uk and we will stop. We then keep only your email address on a do-not-contact list, so that we never contact you again by mistake.
Who we share your data with
We do not sell your data. We share it only with the companies that help us run Limberly, and only what they need. They act on our instructions under contracts that protect your data.
| Who | What they do | Where |
|---|---|---|
| Vercel | Hosts our website, runs our servers and counts visits (Web Analytics, no cookies). | Servers in London, United Kingdom (pages may be served from a location near you). Vercel is a US company. |
| Google (Firebase) | Stores our database, and handles sign-in and passwords. | Database in the European Union. Sign-in may be processed in the United States. |
| ImprovMX | Forwards emails you send to our @limberly.co.uk addresses. | May be outside the UK |
| Google (email) | Hosts the mailbox our emails are forwarded to. | United States and worldwide |
| Twilio SendGrid | Sends our emails, once we send emails from the platform. | United States |
| Stripe | Takes card payments, once payments launch. | UK, European Union and United States |
| postcodes.io (Ideal Postcodes) | Turns postcodes into map locations so we can show physios near you. Receives the postcodes of physio clinics and home-visit areas, and later the postcode you search from. Never your name or contact details. | Ideal Postcodes is a UK company. Requests pass through Cloudflare’s network, which may be outside the UK. |
We also share data:
- With a physio you book (once booking opens): your name, contact details, age, the booking, and any health information you choose to share with them.
- With Stripe as its own controller (once payments launch): Stripe also uses payment data for its own legal duties, such as fraud and money laundering checks. See Stripe’s privacy policy.
- With regulators, the police or courts when the law requires it, or to protect someone from serious harm. This could include telling the HCPC about a serious concern with a physio.
- With a buyer if our business is sold or merged. They would have to protect your data in the same way.
Data stored outside the UK
Some of our providers store or process data outside the UK:
- European Union. Our database is in Google’s European region (Belgium and the Netherlands). The UK government treats the EU as giving adequate protection, so no extra safeguards are needed.
- United States and elsewhere. Vercel, Google, Twilio SendGrid, Stripe, ImprovMX and the network provider of postcodes.io may process data in the United States or other countries. When they do, we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, or on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
Email privacy@limberly.co.uk if you would like more detail about these safeguards.
How long we keep your data
We keep data only as long as we need it, then delete it or make it anonymous.
| Data | How long |
|---|---|
| Body map taps you do not save | Never sent to us. |
| Website server logs (IP address, page, browser) | Up to 30 days. |
| Your account (name, email, phone, date of birth, postcode) | While your account is open. Deleted within 30 days of closing it. |
| Health information you saved but did not send | Until you delete it or close your account. Deleted after 12 months if you never finish it. |
| Health information you sent | While your account is open. Deleted within 30 days of closing it. A physio you shared it with keeps their own copy under their rules. |
| Physio profile and our HCPC checks | While you are listed, then 6 years after you leave, in case of complaints or legal claims. |
| Bookings and payments (once they launch) | 6 years after the end of the financial year they belong to, as tax law requires. |
| Emails you send us | 2 years after our last reply. |
| Physios we invited who did not join | 12 months after our last message. If you ask us to stop, we keep only your email address on a do-not-contact list. |
| Accounts not used for 3 years | We email you first, then close the account and delete its data. |
Your rights
Under UK data protection law you have the right to:
- Access your data: ask for a copy of what we hold about you.
- Correct it if it is wrong or incomplete. You can change most account details yourself.
- Delete it (sometimes called the right to be forgotten), unless we must keep it by law.
- Restrict how we use it while a problem is sorted out.
- Object to how we use it where we rely on legitimate interests. This includes asking us to stop contacting you if you are a physio we invited.
- Move it: get the data you gave us in a common format, to take somewhere else.
- Withdraw consent at any time where we rely on your consent, such as for health information.
To use any of these rights, email privacy@limberly.co.uk. It is free. We will reply within one month. If your request is complicated we may need up to two more months, and we will tell you why. We may ask you to prove who you are before we act, so that we never give your data to someone else.
Automated decisions
We do not make decisions about you by computer alone that have legal effects or affect you in a similarly significant way.
The body map and questionnaire give general information. They are not a diagnosis. If your answers suggest you might need urgent care, we will tell you to get it. That is a safety message, not a decision about you. Only a physio, or another health professional, can assess you.
When we show you physios, we sort them by things like distance, the areas they treat and price. You choose who to see.
Children
Limberly is for adults aged 18 and over. For now we do not accept patients under 18, and we do not knowingly collect data about children. If you think a child has given us their details, email privacy@limberly.co.uk and we will delete them.
How we keep your data safe
- Every page on limberly.co.uk uses an encrypted connection (HTTPS).
- Our database and sign-in are run by Google, which encrypts stored data.
- Passwords are handled by Firebase Authentication. We never see or store them.
- Our database rules mean only you can read your health information from a browser. Staff can only reach it through a logged support process.
- Anything that gives someone more access, such as approving a physio or making someone an administrator, is checked on our servers and recorded.
- Only the people who need access to our systems have it.
- If a data breach puts you at risk, we will tell the Information Commissioner’s Office within 72 hours and tell you without delay.
Changes to this policy
We will update this policy as Limberly grows. The date at the top shows when it last changed. If you have an account and we make an important change, we will email you before it takes effect.
Contact and complaints
Questions or worries about your data: email privacy@limberly.co.uk, or write to us at Thrive Haven Ltd, 22 Waltham Road, Newton Abbot, Devon, TQ12 1LH, United Kingdom.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator, at ico.org.uk or on 0303 123 1113. We would like the chance to put things right first, so please contact us before you go to the ICO.