Legal ยท Privacy

    Privacy Policy

    Last updated: February 2026

    1. Who We Are

    North Wales Local (northwaleslocal.co.uk) is a regional business directory serving the six principal areas of North Wales.

    The platform is operated by:

    Steam Vibe Ltd

    Company No. 12536654

    Registered in England and Wales

    Registered Office: Unit A 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE

    Email: [email protected]

    ICO Registration: ZC095648

    Steam Vibe Ltd is the Data Controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

    For all data protection queries, contact: [email protected]

    2. Categories of Data We Process

    2.1 Registered Account Data

    • Email address
    • Display name
    • Authentication session tokens (OTP-based; passwords are optional and, if set, stored in hashed form only)
    • Account activity timestamps

    2.2 Business Listing Data (Claimed Listings)

    • Business name
    • Trade category
    • Operating area(s)
    • Phone number and/or email address
    • Website URL and social media links
    • Business description
    • Logo and uploaded photographs
    • Stripe customer and subscription identifiers (if applicable)
    • Verification evidence submitted during ownership claims

    Verification evidence (e.g., branded vehicle photos or documentation) is:

    • Used solely to assess ownership claims
    • Never publicly displayed
    • Accessible only to authorised administrators
    • Automatically deleted 12 months after verification

    Businesses are instructed to redact any non-essential personal data before uploading documents.

    2.3 Publicly Sourced Business Data (Unclaimed Listings)

    Prior to launch, North Wales Local compiled a structured database of thousands of businesses operating within North Wales.

    This information was obtained from publicly available sources including:

    • Google Business Profiles
    • Facebook business pages
    • Print directories
    • Publicly accessible websites

    Data stored may include:

    • Business name
    • Trade category
    • Operating area
    • Publicly listed phone number
    • Publicly listed email address
    • Website URL

    Where publicly available contact details relate to a sole trader or identifiable individual, this constitutes personal data.

    We process such data on the basis of legitimate interests (Article 6(1)(f)) in operating a regional business directory. We consider this processing proportionate because:

    • The information has already been made public for commercial contact purposes
    • It is limited to business-related contact details
    • It supports discoverability of local services
    • A clear and accessible removal mechanism is provided

    Each unclaimed listing contains a notice explaining the public data source and how to request removal.

    2.4 Customer Activity Data

    • Reviews and star ratings
    • Recommendations ("thumbs up")
    • Contact form submissions

    2.5 Analytics & Usage Data

    • Pseudonymous session identifiers
    • Profile view events
    • Search queries (anonymised)
    • Click events on contact details and links

    Session identifiers are used solely to calculate listing analytics and prevent duplicate counting. They are not used for behavioural profiling, advertising, or cross-site tracking.

    3. Lawful Bases for Processing

    We rely on the following lawful bases:

    Contract โ€” Article 6(1)(b)

    Processing necessary to:

    • Create and manage user accounts
    • Display business listings
    • Process subscriptions
    • Provide analytics dashboards
    • Deliver transactional communications

    Legitimate Interests โ€” Article 6(1)(f)

    Processing necessary to:

    • Operate a publicly accessible business directory
    • Display publicly sourced business contact information
    • Conduct limited outreach to business owners
    • Prevent fraud and abusive behaviour
    • Maintain review system integrity
    • Monitor platform security

    We have conducted a legitimate interest assessment balancing:

    • The commercial nature of the data
    • The reasonable expectations of businesses
    • The minimal scope of information processed
    • The availability of removal mechanisms

    Recipients of outreach communications may request no further contact at any time. Objections are recorded and respected.

    Legal Obligation โ€” Article 6(1)(c)

    Processing necessary to comply with applicable law, including responding to Subject Access Requests and data deletion obligations.

    4. How We Use Personal Data

    We use personal data to:

    • Publish and maintain business listings
    • Authenticate users via OTP
    • Process payments via Stripe
    • Send transactional emails
    • Deliver analytics dashboards
    • Invite businesses to claim their listings
    • Detect fraudulent activity
    • Comply with legal obligations

    North Wales Local does not:

    • Sell personal data
    • Share personal data for advertising purposes
    • Use data to train machine learning models
    • Use automated decision-making that produces legal or similarly significant effects within the meaning of Article 22 UK GDPR

    Automated moderation filters may flag reviews for human review. Final moderation decisions are made by an administrator.

    5. Third-Party Processors

    We use:

    ProcessorLocationPurpose
    Supabase Inc.UK (London region)Database, user authentication (OTP login), and server-side logic via Edge Functions.
    Resend / transactional email providerUnited StatesDelivery of transactional emails (OTP codes, verification confirmations, contact form forwards)
    Stripe Inc.United StatesPayment processing and subscription management
    Lovable / VercelEU / United StatesFrontend hosting, content delivery network, and static asset serving

    All processors operate under data processing agreements.

    6. International Transfers

    Stripe processes limited billing data in the United States. Transfers are safeguarded under the ICO-approved International Data Transfer Agreement (IDTA), the UK equivalent of Standard Contractual Clauses.

    Database and authentication infrastructure is hosted in the UK.

    7. Data Retention

    Data TypeRetention
    Active account dataWhile account remains active
    Deleted account personal dataDeleted within 30 days
    Review text by deleted usersAnonymised and retained indefinitely based on legitimate interests
    Verification evidence12 months post-verification
    Visitor analyticsRolling 24 months
    Consent logs6 years
    Contact form submissionsDeleted after 90 days

    8. Data Security

    We implement:

    • TLS encryption
    • Encryption at rest
    • Row-Level Security controls
    • Rate limiting on authentication and review endpoints
    • File validation and sanitisation
    • Principle of least privilege for admin access

    No system is entirely secure. Suspected compromise should be reported immediately to [email protected].

    9. Your Rights

    You have the right to:

    • Access
    • Rectification
    • Erasure
    • Restriction
    • Portability
    • Object to legitimate interest processing
    • Withdraw consent

    Requests are handled within 30 days. Contact us at [email protected].

    Exercising your portability right: Registered users can download a copy of their personal data (profile, reviews, and activity) directly from their account dashboard settings โ€” no request needed. Business account holders can export their listing data, analytics summary, and contact form submissions from the business dashboard.

    Removal of Unclaimed Listings

    Business owners may request removal without creating an account. Proof of connection to the business is required. Verified requests are actioned within 7 working days.

    10. Cookies

    We use only strictly necessary authentication cookies (Supabase session management) and a single first-party functional identifier (nwl_session) used solely to deduplicate profile view counts for business analytics dashboards. No advertising, affiliate tracking, or cross-site behavioural cookies are deployed.

    See our full Cookie Policy for details on each cookie, its purpose, and duration.

    11. Children

    This platform is not intended for individuals under 18. We do not knowingly collect children's data.

    12. Changes

    We may update this policy periodically. Material changes will be communicated to registered users in advance.

    13. Complaints

    If you have a complaint about how we handle your personal data, please contact us first so we can try to resolve it: [email protected]

    Under the Data (Use and Access) Act 2025 (in force from 19 June 2026), we will acknowledge your complaint without undue delay and provide a substantive response within 30 days (extendable by up to two further months for complex cases, with notice to you within the initial 30 days). Full details of this process are set out in our Complaints Policy, Section 2.

    If you remain dissatisfied, or we fail to respond, you may complain to the UK Information Commissioner's Office:

    Information Commissioner's Office

    ico.org.uk/make-a-complaint

    0303 123 1113

    ICO Registration: ZC095648