Privacy Policy

Last updated: 13 April 2026

1. Who we are

Petal & Prosper (“we”, “us”, “our”) provides cloud-based business management software for floristry businesses. We are the data controller for the personal information we collect through our website at petalandprosper.com and the Petal & Prosper application (together, the “Service”).

If you have questions about this policy or your personal data, please contact us at privacy@petalandprosper.com.

2. Information we collect

We collect information you provide directly when you create an account, subscribe to a plan, or contact us. This typically includes your name, email address, phone number, business name, and billing details.

When you use the Service we also collect data you enter into the application, such as client contact details, enquiry records, order information, and financial data. This information is stored on your behalf and you remain the data controller for your own client records.

We automatically collect certain technical information when you visit our website or use the Service, including your IP address, browser type, device information, pages visited, and referring URLs. We use cookies and similar technologies for this purpose (see section 7).

3. How we use your information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process your subscription payments
  • Send you important service communications (e.g. security alerts, billing notices)
  • Respond to your enquiries and support requests
  • Send marketing communications where you have opted in
  • Detect, prevent, and address technical issues and security threats
  • Comply with our legal obligations

4. Legal basis for processing

We process your personal data on the following legal grounds under UK GDPR:

  • Contract: processing necessary to provide the Service you have subscribed to
  • Legitimate interests: improving the Service, ensuring security, and communicating with you about your account
  • Consent: marketing communications and non-essential cookies
  • Legal obligation: where we are required to retain or disclose data by law

5. Sharing your information

We do not sell your personal data. We may share your information with trusted third-party service providers who help us operate the Service (e.g. hosting, payment processing, email delivery). These providers are contractually required to protect your data and may only use it to perform services on our behalf.

We may also disclose your information if required by law, to protect our rights, or in connection with a business transfer such as a merger or acquisition.

6. Data retention

We retain your account data for as long as your account is active or as needed to provide the Service. If you close your account, we will delete or anonymise your personal data within 90 days, except where we are required to retain it for legal, accounting, or regulatory purposes.

Business data you enter into the Service (client records, orders, invoices) is retained for the duration of your subscription and deleted within 90 days of account closure unless you export it beforehand.

7. Cookies

We use essential cookies to keep you signed in and remember your preferences. We may also use analytics cookies to understand how the Service is used. You can manage cookie preferences through your browser settings. Disabling essential cookies may affect functionality.

8. Data security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS/SSL), encryption at rest, regular security assessments, and access controls. However, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.

9. International transfers

Your data may be processed in countries outside the United Kingdom. Where this occurs, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the UK Information Commissioner's Office.

10. Your rights

Under UK data protection law, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Request portability of your data
  • Withdraw consent where processing is based on consent

To exercise any of these rights, please email us at privacy@petalandprosper.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

11. Changes to this policy

We may update this privacy policy from time to time. We will notify you of material changes by email or through a notice in the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.