Privacy
Your data, plainly explained.
What we hold, why we hold it, who else sees it, and how to get a copy or have it deleted.
Who's responsible for what
Yorkshire Bookings is run by Yorkshire Bookings Limited. When you make a booking, the business you booked with decides what it collects and keeps about you, and we handle that information on their behalf. For your own Yorkshire Bookings account, our directory and our billing, the decisions are ours. You can reach us at privacy@yorkshirebookings.com.
In practice, either of us can answer a request. You can download or delete your data yourself, or ask the business directly and they can do it from their dashboard.
What we hold and why
Taking and managing a booking
Names, email addresses, phone numbers, what you booked, anything the business asks on its form, and your payment record.
Why we're allowed to: Performing the contract between you and the business.
Sending booking emails
Confirmations, reminders, balance requests and cancellation notices.
Why we're allowed to: Performing the contract. These aren't marketing and can't be turned off while a booking stands.
Keeping accounts
Amounts, dates and payment references, kept after personal details are removed.
Why we're allowed to: A legal obligation: UK tax records must be kept for six years.
Keeping accounts secure
Sign-in records, IP addresses, and a log of who opened, downloaded or erased personal data.
Why we're allowed to: Our legitimate interest in keeping your data safe and being able to show who reached it.
Offers and news from a business
Only if you ticked the box, and only from the business you ticked it for.
Why we're allowed to: Your consent, which you can withdraw at any time.
We never sell your data, and we don't use it to build profiles or make automated decisions about you.
Who else sees it
Only the business you booked with, and the companies we need to run the service:
| Who | What they do | Where |
|---|---|---|
| Stripe | Takes card payments and pays businesses out. Stripe is a controller in its own right for payments, and keeps its own record of card transactions even after we delete yours. | UK, EU and US |
| Resend | Sends our emails. Gets the recipient's address and the contents of the email. | US |
| Vercel | Runs the website and stores business photos. Sees requests to the site, including IP addresses. | US, with servers in the EU |
| Neon | Hosts our database. Holds everything described above. | EU (Frankfurt) |
Where a company is outside the UK, the transfer is covered by the UK's approved safeguards for international transfers.
How long we keep it
| What | How long |
|---|---|
| Your name, email, phone and any notes a business keeps about you | 3 years after your last booking, by default. A business can set anything from 1 year to 6 years. |
| Booking answers, participant names and notes on a booking | Removed on the same schedule, even if you still book with that business. |
| Amounts, dates and payment references | 6 years, with nothing that identifies you. |
| A record of emails we sent you | 1 year |
| Who opened, downloaded or erased personal data | 2 years, or 6 years for records of a deletion. The IP address on those records is cleared after 90 days. |
| Sign-in sessions | Until they expire, then cleared nightly. |
A nightly job does this automatically, so it happens whether or not anyone remembers.
Your rights
You can ask for a copy of your data, have it corrected, have it deleted, object to how we use it, or withdraw consent for marketing. The quickest way is your account:
- Download your data as one file, or ask for it to be deleted. Deletion is confirmed by email and then waits 14 days, so you can change your mind.
- Deleting your data removes your name, email, phone, booking answers and any notes about you, and we tell every business you've booked with. Amounts and dates stay on record without anything that identifies you, because businesses have to keep six years of accounts.
- Prefer to ask a person? Email privacy@yorkshirebookings.com. We'll answer within a month.
If you think we've got this wrong, you can complain to the Information Commissioner's Office at ico.org.uk. We'd rather you told us first so we can put it right.
Keeping it safe
Passwords are hashed, two-factor secrets are encrypted, and every business can require two-factor for its whole team. Access to customer records is limited by role and recorded, so a business can see who looked at what. More detail on our security page, and what we store in your browser.