Privacy Policy
For Login Accounts: The only personally identifiable data this site collects is a name, email address and password. This is used as part of the login process to manage public business listings and will never be shared with anyone.
For Alert Notifications: The only personally identifiable data this site collects is an email address. This is used as part of the login process to manage alerts and will never be shared with anyone.
For PunchCard Tickets: The only personally identifiable data this site collects is a name and email address. This is used to send tickets and as part of the login process to gain access to previously purchased tickets.
Under data protection law, you have rights including:
- Your right of access - You have the right to ask us for copies of your personal information.
- Your right to rectification - You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
- Your right to erasure - You have the right to ask us to erase your personal information in certain circumstances.
- Your right to restriction of processing - You have the right to ask us to restrict the processing of your personal information in certain circumstances.
- Your right to object to processing - You have the the right to object to the processing of your personal information in certain circumstances.
- Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
- You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Cookies
This site does not use any tracking cookies!
This site uses cookies/local storage to remember some of your site settings. If available, we switch to using local storage rather than cookies meaning they never get transmitted to the server.
Any cookies that are received by the server are ignored and never used to track you.
If you use Alert Notifications, a cookie will be sent to keep you signed in.
If you hold an account with us, we will also use a single session cookie to maintain your login session.
Data Storage Location
The data used and stored within this website is held on servers in data centres within the UK.
Data processing: retro.directory
We process your name, email address and password solely for the purpose of account creation, authentication, and access to our website.
This data is used to verify your identity, facilitate secure login, and communicate essential account-related information. Our processing activities comply with applicable data protection laws, and we implement appropriate security measures to safeguard your information from unauthorized access, alteration, or disclosure. We do not use your data for marketing purposes or share it with third parties, except when required by law. By using our website, you consent to the processing of your personal data as outlined in this policy.
We also process your IP address in real time to identify your country and to automatically center the map page accordingly, but we do not store or retain this information.
Data processing: PunchCard Tickets
We process your name and email address solely for the purpose of ticket management.
This data is recorded with each booking and will be shared with the organiser or owner of the event. The organiser is responsible for how your data is handled; please refer to their privacy policy or contact them directly for more information about how your personal data is processed.
Our processing activities comply with applicable data protection laws, and we implement appropriate security measures to safeguard your information from unauthorized access, alteration, or disclosure. We do not use your data for marketing purposes. By using our website, you consent to the processing of your personal data as outlined in this policy.
Data processing: Stripe
We use the “Stripe” service (Stripe, Inc.) for payments. Stripe may collect personal data including via cookies and similar technologies. The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection, loss prevention, authentication, and analytics related to the performance of its services. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.
Stripe, Inc. complies with the U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce (collectively, the “DPF”). For more information, please contact the provider under the following link: https://stripe.com/gb/legal/data-privacy-framework.
Data processing: Cloudflare
We use the “Cloudflare” service (Cloudflare Inc.) for its content delivery network with DNS that is available worldwide. As a result, the information transfer that occurs between your browser and our website is technically routed via Cloudflare’s network. This enables Cloudflare to analyze data transactions between your browser and our website and to work as a filter between our servers and potentially malicious data traffic from the Internet. In this context, Cloudflare may also use cookies or other technologies deployed to recognize Internet users, which shall, however, only be used for the herein described purpose.
The use of Cloudflare is based on our legitimate interest in a provision of our website offerings that is as error free and secure as possible (Art. 6(1)(f) GDPR).
Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details and further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.
The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5666
