Digz N' Lidz ← Home
Legal

Privacy Policy

Last updated: 1 August 2026

Who this policy is about

This site is run by Digz N' Lidz RC Experience Cafe, 535-563 Lord Street, Southport, PR9 0BB. For the purposes of data protection law, Digz N' Lidz is the data controller for personal data collected through this site, meaning it's Mark and Danny's business that decides what happens with customer data, not Sidedoor Digital.

Sidedoor Digital's role is limited to building and maintaining the technical systems this site runs on: the website, booking system, and dashboard. Sidedoor Digital does not manage the site's content or data on an ongoing basis, does not decide what customer data is used for, and does not access customer personal data as part of its work. Its access is limited to site performance and usage data through the dashboard, described below. Responsibility for how the site is run day to day, and for how customer data is used and protected, sits with Digz N' Lidz, not Sidedoor Digital.

What we collect, and why

Booking a session (family or group): name, email address, phone number (optional), how many people and which session length each picked, and any notes you add. Used to hold your booking, contact you about it, and process payment. Corporate and private event enquiries go through a separate process and may involve a deposit agreed directly with you.

Joining the mailing list: your email address, and which type of session you booked (single, couple, family, or group), used to send relevantly targeted offers and updates. This only happens if you tick the marketing opt-in box at booking, it's optional and unticked by default. You can opt out at any time by replying to any marketing email and asking to be removed, we'll action this promptly.

Ordering food or drink: what you ordered and which seat or table it's for. No account or personal details are collected for this beyond payment, covered below.

Contacting us directly: whatever you include in your message, plus your email address to reply to you.

Payments

All card payments are processed directly by Square. Card numbers and card details are entered straight into Square's own secure payment form and never pass through or get stored on our servers or database. We keep a reference to the payment (a transaction ID) so we can match it to your booking or order, not your card details.

Square's payment form sets its own cookies as part of processing your payment securely and detecting fraud, this is confirmed directly in Square's own privacy notice. These aren't set by us and we don't control them, they're part of using Square's payment form, which only loads on the pages where you're actually paying (booking, seat ordering, table ordering).

See Square's own privacy policy for how they handle payment data and cookies.

Other services this site uses

Cloudflare hosts the website, database, and booking system. See Cloudflare's privacy policy.

Resend sends booking confirmations and other transactional emails on our behalf. See Resend's privacy policy.

Where your data is stored

The site and its database are hosted on Cloudflare's global infrastructure. Data may be processed outside the UK and EEA as part of this, Cloudflare maintains its own safeguards for these transfers (including standard contractual clauses), details are in Cloudflare's own privacy policy and data processing terms linked above.

Booking confirmation and other transactional emails are sent through Resend. See Resend's privacy policy.

Cookies and similar technology

Here's everything that's actually used, and why:

What Purpose Type
Square payment cookies Processing your payment securely, fraud prevention Set by Square, only on pages where you're paying
Cloudflare Web Analytics Seeing how many people visit and which pages are popular No cookies, doesn't track you individually
Homepage intro animation flag So the intro only plays once per visit Browser storage, not a cookie, never sent to a server

The Square payment cookies are treated as strictly necessary under UK PECR: they're only set on pages where you've chosen to pay, as part of completing a transaction you've explicitly started, which is why a notice banner is shown rather than a prior opt-in request. Cloudflare Web Analytics doesn't use cookies at all, so no consent question applies to it. The homepage intro flag is stored in your browser, not sent anywhere, and also falls outside cookie consent rules.

How long we keep it

Booking and payment records are kept for 6 years after your visit, in line with standard UK tax and accounting record-keeping requirements, then deleted.

Mailing list entries are kept until you unsubscribe, or automatically removed after 24 months of no engagement with our emails, whichever comes first.

Contact form and enquiry details are kept for 12 months after your enquiry is resolved, then deleted, unless we need to keep something longer to deal with an ongoing issue or a legal requirement.

Your rights

Under UK GDPR, you can ask to see the personal data we hold about you, ask us to correct it, ask us to delete it, or object to how it's used. To do any of this, contact info@digznlidz.co.uk.

If you're not happy with how your data has been handled, you can complain to the Information Commissioner's Office at ico.org.uk.

Questions

Get in touch through our contact page or email info@digznlidz.co.uk.

FacebookInstagramYouTubeTikTok

All systems powered and built by Sidedoor Digital