Privacy.
How Storystone Ltd uses personal data in The Boys Trip Guide.
Controller
Storystone Ltd is the controller for The Boys Trip Guide. Company number 16922351. Registered office: Cuffley Hill, Goffs Oak, Waltham Cross, EN7 5HB, England. Privacy enquiries and rights requests: contact@theboystripguide.com.
1. Data we collect and where it comes from
- Account data: name, email, sign-in identifiers and optional profile details supplied by you.
- Trip and member data: destinations, dates, bookings, costs, reminders, notes, invitations and details entered by organisers or members.
- Uploads: documents, photos, videos, captions, filenames and related metadata supplied by users.
- Payment data: payment status, amount, currency, Stripe references and limited billing details. Storystone Ltd does not receive full card numbers.
- Support and safety data: messages, attachments, complaints, reports, decisions and correspondence supplied by you or another affected person.
- Technical data: device/browser information, IP address, authentication records, security logs and service events generated when the service is used.
2. Purposes and UK lawful bases
- Provide accounts, trips, invitations, paid features and support: performance of a contract or steps requested before a contract.
- Process and evidence payments and refunds: contract and legal obligations.
- Secure the service, prevent abuse, troubleshoot and improve reliability: Storystone Ltd's legitimate interests in operating a safe and reliable service.
- Handle illegal-content reports, disputes and regulatory requests: legal obligations, legitimate interests and establishment, exercise or defence of legal claims.
- Send operational messages and reminders: contract and legitimate interests. Consent is used where UK law requires it.
We do not use personal data for third-party advertising, sell personal data or make solely automated decisions producing legal or similarly significant effects.
3. Data required to provide the service
An email address and core trip/access data are required to create, authenticate or join a trip. If they are not provided, those functions cannot be supplied. Optional profile fields and most uploads may be omitted.
4. Who receives data
Authorised members of the relevant trip can see the information made available to their role. We use Cloudflare for delivery and security, Supabase for database, authentication, functions and storage, Stripe for payments, and Resend or another approved transactional-email provider for service emails. Providers act under contractual and security controls. Data may also be disclosed to professional advisers, law enforcement, regulators or a buyer in a genuine business reorganisation where lawful.
5. International transfers
Some providers may process data outside the UK. We rely on UK adequacy regulations where available or use an approved safeguard such as the UK International Data Transfer Agreement or UK Addendum, together with appropriate risk and security measures. Contact us for information about the safeguard relevant to a particular transfer.
6. Retention
- Trip and account data: kept while needed to provide the trip or account, until deleted or a valid deletion request is completed, subject to backups and legal retention.
- Full Trip media: the live storage entitlement lasts 12 months from purchase; media becomes eligible for removal after that period.
- Invitations: kept while needed for the relevant trip, security and access records.
- Purchase, refund and accounting records: normally kept for up to six years after the relevant accounting period.
- Support, complaint and safety records: normally kept for up to two years after closure, longer where a dispute, safeguarding matter or legal obligation requires it.
- Security logs and backups: kept for the provider's rolling retention cycle and only as long as needed for security, recovery or legal obligations.
7. Your rights
Under UK data-protection law you may have rights to access, correct, erase, restrict or object to processing, and to data portability. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Rights may be limited where an exemption applies.
Contact contact@theboystripguide.com. You may also complain to the Information Commissioner's Office. We ask that you contact us first, but you do not have to.
8. Security and private trips
Trips are private and invitation-only. We use access controls, signed media links, transport encryption and proportionate organisational measures. Organisers must invite only intended people and remove access when appropriate. No online service can guarantee absolute security.
9. Children
The service is for people aged 18 or over. We do not knowingly offer accounts to children. If you believe a child has access or that a child's data has been added improperly, report it through our Safety and Complaints page.
10. Cookies and similar storage
Details are in our Cookie Policy. We currently use only essential or user-requested storage and do not use advertising cookies.
11. Changes
We will update this notice when processing changes materially and will show the revision date. Material changes will be notified where appropriate.
