Privacy Policy
Effective Date: 29 April 2025
1. Introduction
This Privacy Policy explains how WonderDays Ltd ("we", "us", "our") collects, uses, and protects your personal data when you visit our website, purchase products, or interact with us. WonderDays Ltd is registered in England and Wales (Company Registration Number 11879155).
2. What Data We Collect
We collect and process the following personal data:
- Name, email address, phone number, postal address.
- Account information and purchase history.
- Feedback, survey responses, and customer service interactions.
- Technical data, including IP address, device information, browser type, and website interaction data.
- Email engagement data (opens, link clicks, tracking IDs).
- Behavioural and usage metadata from online interactions.
3. How We Collect Your Data
We collect data when you:
- Register an account or make a purchase.
- Complete surveys, provide feedback, or contact customer support.
- Browse or interact with our website (via cookies and tracking technologies).
- Engage with our emails, website features, or marketing content.
4. How We Use Your Data
We process your personal data to:
- Fulfil orders and manage your experience bookings.
- Provide and improve customer service and account management.
- Send transactional and marketing communications (with consent).
- Analyse user behaviour to improve website and product offerings.
- Detect and prevent fraudulent activity and ensure security.
- Personalise content and advertising based on your preferences and interactions.
5. Third-Party Processors and Platforms
We share personal data with trusted third-party service providers:
Experience Fulfilment & Communication:
- Experience Providers: To redeem vouchers and manage bookings.
- Postmark by ActiveCampaign, Amazon SES: For email delivery and tracking.
- Help Scout: For customer service and messaging.
Payments & Fraud Prevention:
- Stripe & Stripe Radar: For secure payments and automated fraud risk scoring.
Marketing, Analytics, & Personalisation:
- Google Analytics, Google Ads, Bing Ads: For website performance, segmentation, and retargeting.
- Facebook Pixel, Facebook Custom Audiences, Instagram, Meta Platforms: For behavioural advertising and audience targeting.
- Craft Campaign: For email marketing, click tracking, and list segmentation.
- Twitter, YouTube: For advertising and social engagement.
Third-Party Platforms and Independent Data Use
Some third-party platforms we integrate with—such as Google, Meta (Facebook, Instagram), Amazon SES, and Stripe—also act as independent data controllers for certain uses of your personal data. This may include analytics, advertising network enrichment, fraud prevention, and service improvement. These parties process data according to their own privacy policies, which we encourage you to review.
6. International Data Transfers
Where personal data is transferred outside the UK or EEA (e.g., to Google, Meta, or Stripe), we use Standard Contractual Clauses (SCCs) and additional safeguards to ensure an adequate level of data protection.
7. Profiling, Segmentation & Automated Decision-Making
We perform limited profiling to personalise content and improve marketing relevance:
- Stripe Radar uses behavioural data for automated fraud detection and scoring.
- Facebook Custom Audiences and Google Ads help us deliver relevant offers based on website interactions and metadata.
- Craft Campaign allows us to create segmented email lists based on prior engagement.
These activities do not involve automated decisions with legal or similarly significant effects, and you can object to profiling at any time.
8. How We Store Your Data
Your data is securely stored on encrypted servers and cloud platforms. Physical copies, where used, are held securely within our head office.
9. How Long We Keep Your Data
We retain your personal data only as long as necessary to fulfil the purposes set out in this policy, unless a longer retention period is legally required.
10. Your Data Protection Rights
You have the right to:
- Access your personal data.
- Request correction or deletion.
- Restrict or object to processing.
- Data portability (where applicable).
- Withdraw consent at any time.
- Lodge a complaint with the ICO.
To exercise any of these rights, contact us at [email protected].
11. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Keep you signed in.
- Understand website behaviour.
- Deliver personalised marketing.
Types of Cookies:
- Essential: Required for core site functionality.
- Analytics: Measure performance and traffic (e.g., Google Analytics).
- Marketing: Enable personalised ads (e.g., Google Ads, Facebook Pixel).
We use a Consent Management Platform (CMP) in line with Google Consent Mode v2. Non-essential cookies are only activated once you provide clear consent. You can adjust your cookie preferences at any time via the Cookie Settings link.
12. Changes to This Privacy Policy
We review and update our Privacy Policy regularly to reflect changes in legal obligations or business practices. This version is effective from 29 April 2025.
13. Contact Us
Questions? Please contact us at:
gdpr@wonderdays.co.uk
14. Contacting the ICO
If you're unhappy with how we've handled your data, you may contact:
📍 Information Commissioner’s Office (ICO)
🔗 https://ico.org.uk/make-a-complaint/