1. Who We Are
North Wales Local (northwaleslocal.co.uk) is a regional business directory serving the six principal areas of North Wales.
The platform is operated by:
Steam Vibe Ltd
Company No. 12536654
Registered in England and Wales
Registered Office: Unit A 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE
Email: [email protected]
ICO Registration: ZC095648
Steam Vibe Ltd is the Data Controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
For all data protection queries, contact: [email protected]
2. Categories of Data We Process
2.1 Registered Account Data
- Email address
- Display name
- Authentication session tokens (OTP-based; passwords are optional and, if set, stored in hashed form only)
- Account activity timestamps
2.2 Business Listing Data (Claimed Listings)
- Business name
- Trade category
- Operating area(s)
- Phone number and/or email address
- Website URL and social media links
- Business description
- Logo and uploaded photographs
- Stripe customer and subscription identifiers (if applicable)
- Verification evidence submitted during ownership claims
Verification evidence (e.g., branded vehicle photos or documentation) is:
- Used solely to assess ownership claims
- Never publicly displayed
- Accessible only to authorised administrators
- Automatically deleted 12 months after verification
Businesses are instructed to redact any non-essential personal data before uploading documents.
2.3 Publicly Sourced Business Data (Unclaimed Listings)
Prior to launch, North Wales Local compiled a structured database of thousands of businesses operating within North Wales.
This information was obtained from publicly available sources including:
- Google Business Profiles
- Facebook business pages
- Print directories
- Publicly accessible websites
Data stored may include:
- Business name
- Trade category
- Operating area
- Publicly listed phone number
- Publicly listed email address
- Website URL
Where publicly available contact details relate to a sole trader or identifiable individual, this constitutes personal data.
We process such data on the basis of legitimate interests (Article 6(1)(f)) in operating a regional business directory. We consider this processing proportionate because:
- The information has already been made public for commercial contact purposes
- It is limited to business-related contact details
- It supports discoverability of local services
- A clear and accessible removal mechanism is provided
Each unclaimed listing contains a notice explaining the public data source and how to request removal.
2.4 Customer Activity Data
- Reviews and star ratings
- Recommendations ("thumbs up")
- Contact form submissions
2.5 Analytics & Usage Data
- Pseudonymous session identifiers
- Profile view events
- Search queries (anonymised)
- Click events on contact details and links
Session identifiers are used solely to calculate listing analytics and prevent duplicate counting. They are not used for behavioural profiling, advertising, or cross-site tracking.
3. Lawful Bases for Processing
We rely on the following lawful bases:
Contract โ Article 6(1)(b)
Processing necessary to:
- Create and manage user accounts
- Display business listings
- Process subscriptions
- Provide analytics dashboards
- Deliver transactional communications
Legitimate Interests โ Article 6(1)(f)
Processing necessary to:
- Operate a publicly accessible business directory
- Display publicly sourced business contact information
- Conduct limited outreach to business owners
- Prevent fraud and abusive behaviour
- Maintain review system integrity
- Monitor platform security
We have conducted a legitimate interest assessment balancing:
- The commercial nature of the data
- The reasonable expectations of businesses
- The minimal scope of information processed
- The availability of removal mechanisms
Recipients of outreach communications may request no further contact at any time. Objections are recorded and respected.
Legal Obligation โ Article 6(1)(c)
Processing necessary to comply with applicable law, including responding to Subject Access Requests and data deletion obligations.
4. How We Use Personal Data
We use personal data to:
- Publish and maintain business listings
- Authenticate users via OTP
- Process payments via Stripe
- Send transactional emails
- Deliver analytics dashboards
- Invite businesses to claim their listings
- Detect fraudulent activity
- Comply with legal obligations
North Wales Local does not:
- Sell personal data
- Share personal data for advertising purposes
- Use data to train machine learning models
- Use automated decision-making that produces legal or similarly significant effects within the meaning of Article 22 UK GDPR
Automated moderation filters may flag reviews for human review. Final moderation decisions are made by an administrator.
5. Third-Party Processors
We use:
| Processor | Location | Purpose |
|---|---|---|
| Supabase Inc. | UK (London region) | Database, user authentication (OTP login), and server-side logic via Edge Functions. |
| Resend / transactional email provider | United States | Delivery of transactional emails (OTP codes, verification confirmations, contact form forwards) |
| Stripe Inc. | United States | Payment processing and subscription management |
| Lovable / Vercel | EU / United States | Frontend hosting, content delivery network, and static asset serving |
All processors operate under data processing agreements.
6. International Transfers
Stripe processes limited billing data in the United States. Transfers are safeguarded under the ICO-approved International Data Transfer Agreement (IDTA), the UK equivalent of Standard Contractual Clauses.
Database and authentication infrastructure is hosted in the UK.
7. Data Retention
| Data Type | Retention |
|---|---|
| Active account data | While account remains active |
| Deleted account personal data | Deleted within 30 days |
| Review text by deleted users | Anonymised and retained indefinitely based on legitimate interests |
| Verification evidence | 12 months post-verification |
| Visitor analytics | Rolling 24 months |
| Consent logs | 6 years |
| Contact form submissions | Deleted after 90 days |
8. Data Security
We implement:
- TLS encryption
- Encryption at rest
- Row-Level Security controls
- Rate limiting on authentication and review endpoints
- File validation and sanitisation
- Principle of least privilege for admin access
No system is entirely secure. Suspected compromise should be reported immediately to [email protected].
9. Your Rights
You have the right to:
- Access
- Rectification
- Erasure
- Restriction
- Portability
- Object to legitimate interest processing
- Withdraw consent
Requests are handled within 30 days. Contact us at [email protected].
Exercising your portability right: Registered users can download a copy of their personal data (profile, reviews, and activity) directly from their account dashboard settings โ no request needed. Business account holders can export their listing data, analytics summary, and contact form submissions from the business dashboard.
Removal of Unclaimed Listings
Business owners may request removal without creating an account. Proof of connection to the business is required. Verified requests are actioned within 7 working days.
10. Cookies
We use only strictly necessary authentication cookies (Supabase session management) and a single first-party functional identifier (nwl_session) used solely to deduplicate profile view counts for business analytics dashboards. No advertising, affiliate tracking, or cross-site behavioural cookies are deployed.
See our full Cookie Policy for details on each cookie, its purpose, and duration.
11. Children
This platform is not intended for individuals under 18. We do not knowingly collect children's data.
12. Changes
We may update this policy periodically. Material changes will be communicated to registered users in advance.
13. Complaints
If you have a complaint about how we handle your personal data, please contact us first so we can try to resolve it: [email protected]
Under the Data (Use and Access) Act 2025 (in force from 19 June 2026), we will acknowledge your complaint without undue delay and provide a substantive response within 30 days (extendable by up to two further months for complex cases, with notice to you within the initial 30 days). Full details of this process are set out in our Complaints Policy, Section 2.
If you remain dissatisfied, or we fail to respond, you may complain to the UK Information Commissioner's Office:
ICO Registration: ZC095648
