Privacy Policy

1. Who we are

Teignmouth Vibe operates this website and is responsible for the personal data collected through it. The service is intended primarily for UK users, although it may be accessible elsewhere. For privacy questions, contact will@teignmouthvibe.co.uk.

2. Summary of our GDPR approach

We aim to process personal data in line with UK GDPR and, where applicable, EU GDPR principles: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability.

Depending on the activity, we rely on contract, legitimate interests, consent, and legal obligation as the lawful basis for processing.

For account creation, authentication, and ongoing access control, we use the sign-in provider you select together with our session system. For local email/password accounts, passwords are salted and hashed with bcrypt before storage, and we never store raw passwords. For SSO accounts, the provider keeps your password.

3. Personal data we collect

We may collect and store the following categories of data depending on how you use the site:

4. Why we use your data

5. Sharing and recipients

We may share data with trusted service providers who help us run the site, including authentication, hosting, database, analytics-free infrastructure, payment processing, and email/notification delivery tools. These providers may process data on our behalf and under their own terms where applicable.

We also collect aggregate analytics about how users interact with public content on the site. Specifically, when a visitor clicks an external link in an event or business modal (for example, a business website or ticketing link), we record a minimal analytics entry containing the target type (event or business), the target identifier if available, the URL clicked, and a timestamp. We only record these link clicks when you have accepted optional cookies (the "Accept all" choice in the cookie banner). If you choose "Necessary only", we do not record link-click analytics for your session.

If you accept optional cookies, we also record page views to understand overall site traffic. This uses a browser-generated pseudonymous identifier stored in local storage, the page path, a broad visitor category (anonymous, unsubscribed, subscribed, or admin), and a timestamp. We do not store your IP address, browser user-agent, or raw account identifier in these traffic records. The admin area only shows aggregated counts, unique visitors and popular pages.

When link-click analytics are recorded, we do not store raw personal identifiers. If you are signed in and have given consent, we store a pseudonymous, one-way hashed identifier that cannot be used to identify you directly. The aggregated metrics shown to admins are counts and timestamps; no raw user identifiers are published. If you have questions about this tracking, contact will@teignmouthvibe.co.uk.

In specific operational configurations (for example, during troubleshooting or with explicit legal guidance), the service operator may enable anonymised recording for sessions where only "Necessary" cookies are selected. This behaviour is only enabled when a server-side configuration flag is set and the stored identifier is a one-way hash; consult the operator if you need details about that configuration.

We may also disclose data if required by law, to protect our rights and the rights of others, to respond to lawful requests, or to investigate abuse, fraud, or security incidents.

Payment processing is handled externally by Stripe. We receive confirmation and reference data that lets us fulfil the subscription, but we do not store card numbers or full card security codes on our systems.

6. Payments and subscription records

If you purchase access, we receive and store subscription metadata such as the plan purchased, payment status, transaction dates, Stripe session IDs, promo code information, and the access period attached to your account. We do not store full payment card details on our own systems.

7. Device tracking and subscription controls

For subscription access control, we store a pseudonymous device identifier, a device display name, user-agent metadata, and first/last seen timestamps. This allows us to enforce the permitted number of active devices and helps reduce account sharing and unauthorised access.

The device identifier is stored in a cookie so we can recognise a device across visits. Where a device cannot be verified, access may be limited until the account is re-authenticated or a slot is freed.

8. Retention

We keep personal data only for as long as necessary for the purposes described in this policy, including account operation, legal compliance, dispute resolution, fraud prevention, and security. In practice, retention may vary by data type and legal requirement.

Account data may be retained while your account remains active and for a reasonable period afterwards if needed for audit, legal, tax, or security reasons.

Some logs and security records may be retained longer where required to prevent abuse, resolve disputes, enforce our terms, or meet legal obligations.

9. International transfers

Some of our service providers may process data outside the UK or EEA. Where that happens, we aim to use appropriate safeguards such as standard contractual clauses or equivalent legal mechanisms permitted by applicable data protection law.

10. Your rights

Depending on your location and the law that applies, you may have the right to:

If you sign in, you can view your data on the Privacy & Data Controls page in your profile, where you can download your data, delete your account data, and manage subscription device slots.

We are committed to giving users clear access to their own account data and clear control over device access, subscriptions, and notification preferences, subject to legitimate security, legal, and operational requirements.

11. Cookies, consent, and storage

We use necessary cookies and related storage to keep the site secure, remember consent choices, and support sign-in, device recognition, and subscription controls. Optional cookies or storage are only used where the site specifically states they are required or where you consent.

The browser storage we use is limited to functions that support account access, consent memory, and device recognition. We do not use hidden storage mechanisms to bypass your choices or secretly collect extra data beyond what is described here.

12. Children

This website is not intended for children who are too young to lawfully consent to the processing of their personal data under applicable law. If you believe a child has provided us with personal data in breach of this policy, contact us so we can review and remove it where appropriate.

13. Changes to this policy

We may update this policy from time to time to reflect legal, technical, or operational changes. The latest version will always be published on this page.

14. Contact

For privacy questions, data requests, or complaints, email will@teignmouthvibe.co.uk. If you need to exercise rights such as access, correction, deletion, or objection, please use that address and include enough detail for us to identify your account.

If you log in, you can view your data on the Privacy & Data Controls page in your profile, where you can download your data, delete your account data, and manage subscription device slots.