Legal

Privacy notice

What this site does with personal information, purpose by purpose: what it collects, why, on what lawful basis, how long it keeps it, and where in the world it goes.

Last updated 25 September 2026

Who is responsible

Sandbanks Digital Ltd is the controller for everything described here. Write to privacy@sandbanksdigital.com. We are not required to appoint a data protection officer and have not appointed one; that address reaches the person who makes these decisions.

BCP Directory is independent of BCP Council and of the Food Standards Agency, whose public register most of the listings come from. Where a listing describes a sole trader, that listing is personal information about a person as well as a record of a business, and this notice covers it.

What we use, and why

Each heading below is one purpose. Under it: what information that purpose uses, the lawful basis for it, and how long it is kept. Where the basis is legitimate interests the interest is named, because the phrase on its own tells you nothing, and you can object to any of them.

Running the directory

What: business name, address, postcode, coordinates, category, contact details, opening hours, hygiene rating and source record for each listing, including listings that describe sole traders and home-based businesses.

Basis: legitimate interests. The interest is keeping an accurate, checkable public record of businesses trading in Bournemouth, Christchurch and Poole so residents can find them and see what a council inspection found. Nearly all of it is already published by the Food Standards Agency under the Open Government Licence; where it comes from is set out in full, including the addresses we deliberately withhold because a food business can be somebody’s kitchen.

How long: for as long as the business trades and the listing is published. A closed business is archived rather than deleted, because a reader arriving from an old link is better served by a page saying it has closed.

Accounts and signing in

What: your email address, the sign-in links issued to it, and session records. Signing in normally means clicking a single-use link that expires after fifteen minutes, and the link is stored only as a hash. If you choose to set a password, we store a salted scrypt hash of it, never the password itself.

Basis: performance of the contract between you and us, which is our terms of use.

How long: while the account exists. A session expires thirty days after it was last used. There is no button that closes an account; ask us and we close it, and the record goes with it.

Reviews and moderation

What: the review, the rating, the public name you chose, any visit date, whether you declared an incentive, the account behind it, and a one-way hash of your address and browser taken at submission. It is recorded so that one person writing under several accounts can be spotted. When a moderator is deciding on a review they are shown how many other reviews came from the same device, how many businesses those are spread across, and how many were written from a different account. They are never shown the hash itself, and it never leaves that screen: it is not published, not written to a log and never put in a web address. Also any report made about a review, with the reporter’s account or the email address they chose to give, and the moderator’s decision and note.

Basis: legitimate interests for publishing, the interest being that first-hand local reviews are useful to readers and useless if they are not real. Legal obligation for the checking: paragraph 13(3) of Schedule 20 to the Digital Markets, Competition and Consumers Act 2024 requires us to take reasonable and proportionate steps to keep fake and concealed-incentivised reviews off the site and to remove them, which we cannot do without keeping the records that show a pattern.

How long: a published review stays while the listing does. A rejected or removed review, its moderation note and any reports about it are kept for two years, because a repeat offence has to be recognisable as a repeat. See the section on reviews and deletion below, which is the part most people want.

Claiming and verifying a listing

What: the claim, the verification route chosen, the business email address or telephone number used, and whatever evidence was supplied.

Basis: legitimate interests. The interest is making sure the person who gains control of a listing is the person entitled to it, which protects the business more than it protects us.

How long: an approved claim is kept while the account holds the listing. A rejected or withdrawn claim, and its evidence, is kept for two years so a repeated attempt on the same listing is visible.

Telling a business about its listing

What: the contact email address a business publishes on its own website, the Companies House number we checked before writing to it, the emails we sent and when, and whether the business claimed the listing, asked us to take it down or asked us to stop. The links in those emails are stored only as hashes.

Why: so that a business we have listed knows what we publish about it, and can correct it, claim it or have it taken down.

Basis: legitimate interests: a business should know what a directory says about it. We only write to limited companies and limited liability partnerships, at an address they publish themselves. We never write to sole traders or partnerships this way, because the law says we would have to ask them first. We send at most three emails about any listing, at least four weeks apart, and none of them asks for money.

Stopping them: every email has a link that stops them straight away and a link that takes the listing down straight away. Replying and asking works too.

How long: the record of what we sent is kept while we hold the listing. If you ask us to stop, or to take the listing down, we keep the address and the fact that you asked for as long as the directory runs, because that is the only way to make sure it is never written to again.

Corrections, reports and event submissions

What: what you sent, and the name and email address you chose to attach to it. Both are optional on a correction.

Basis: legitimate interests: correcting the directory, and being able to go back to whoever told us when a correction turns out to be wrong.

How long: two years after the decision.

Payments

What: a Stripe customer identifier, the plan, the subscription status and the renewal date. Card numbers never reach this site. Payment happens on Stripe’s own checkout, and what comes back to us is an identifier and a status.

Basis: performance of the contract for the subscription, and legal obligation for the accounting records behind it.

How long: six years from the end of the financial year the payment falls in, which is how long HMRC requires a company to keep its records.

Listing insights for business owners

What: a count of profile views, website clicks, phone clicks, direction clicks and saves against each listing, each stamped with the time and a hashed identifier. The identifier is a random value your browser generates and keeps in its own local storage; your browser sends it to us as it is, and it is hashed with a server secret on arrival — the stored value is the hash, but the raw identifier does reach our server first. It exists to stop one person’s repeated clicking being counted five times: a repeat of the same action on the same listing within thirty minutes is discarded.

Basis: legitimate interests. The interest is telling a business owner how their listing is doing, which is the main thing an owner asks for and the reason a claim is worth making. The hashed identifier keeps that possible without profiling anybody: it is not linked to an account, it is not shared, and it does not follow you to another website.

How long: the dashboards read the last thirty days and compare them with the thirty before, so nothing older than sixty days is ever shown. The rows themselves are not deleted on a schedule today, and we would rather say so than describe a clear-out that does not happen.

Audience measurement

What: page view counts, measured by an instance of Umami that Sandbanks Digital runs itself. It sets no cookie, stores nothing on your device and builds no cross-site profile.

Basis: legitimate interests: knowing which pages are read at all. Because nothing is stored on or read from your device, this needs no consent under the Privacy and Electronic Communications Regulations, and it is not affected by the cookie choice.

Keeping the site up and stopping abuse

What: a counter per action, keyed by a salted SHA-256 hash of your IP address. The address itself is never written down. Only the hash is stored, alongside a count and the hour it belongs to.

Basis: legitimate interests: stopping one person flooding the review form, the report form or the sign-in email.

How long: the code deletes these rows two days after the window they belong to, as a housekeeping step it runs on itself. This is the one retention rule on the site that a piece of code enforces rather than a person.

The newsletter

What: your email address, an optional name, the areas and interests you picked, and the fact and time of your consent. The confirmation and unsubscribe links are stored only as hashes.

Basis: your consent. Nothing is sent until you click the confirmation link in the first email, so an address typed in by somebody else never receives anything.

Withdrawing it: every email carries an unsubscribe link and it works immediately. Withdrawal does not undo what was already sent.

How long: while you are subscribed. After you unsubscribe we keep the address and the fact you unsubscribed, so that a later import cannot put you back on the list.

Emails to us

What: whatever you write, and your address. There is no contact form; the addresses on the contact page are ordinary mailboxes.

Basis: legitimate interests: answering you, and being able to see what was said if the matter comes back.

How long: two years, longer if the exchange concerns a dispute that is still live.

Administration records

What: an audit log of every administrative decision — which administrator changed what, when, and what the value was before and after.

Basis: legitimate interests, and legal obligation where the decision concerns a review. Being able to show who approved, rejected or removed a review, and on what grounds, is exactly what the CMA expects a review publisher to be able to produce.

How long: indefinitely. A log with a gap in it is not a log.

Advertising

Third-party advertising is switched off. If it is ever switched on, Google may set cookies or similar identifiers, and only if you have chosen Accept all. The basis is your consent, and the cookies page holds the control that gives or withdraws it.

Who else handles it

These are the only companies that touch personal information for us. Each acts on our instructions under a written contract.

  • Supabase — the database. It runs on Amazon Web Services in the London region, eu-west-2, so the data itself sits in the United Kingdom.
  • Railway — runs the site, the administration back office and the scheduled jobs.
  • Cloudflare R2 — stores uploaded photographs, both the approved ones and those waiting to be checked.
  • Resend — delivers sign-in links, moderation decisions, the newsletter and the emails telling a business about its listing.
  • Stripe — takes payments and holds the card details we deliberately never see.
  • Sentry — records errors so we find out when something breaks. It is sent the fault and where in the code it happened, never a request body, headers, cookies or an account. Anything that looks like a credential, an email address, a session token or a postcode is stripped before it leaves. Only used when it is configured; the site runs without it.

Two things reach a third party without passing through us at all. The maps are drawn from tiles your browser fetches directly from tile.openstreetmap.org, so the OpenStreetMap project sees the request and your IP address, and we receive nothing back. And if a business owner connects their own Google Business Profile so that their opening hours and telephone number stay current, that connection is between them and Google, made with their own sign-in; we read the details for the locations they authorise, and we read no reviews from Google, ever.

We do not sell personal information, and we do not share it for anyone else’s marketing.

Sending information outside the UK

The database sits in the United Kingdom. The companies operating these services do not: Railway and Resend give San Francisco addresses in their data processing agreements, Stripe and Cloudflare are United States businesses, and Supabase names a Singapore entity as the party receiving the data. Their staff and systems can reach the data they process for us, which makes those transfers restricted transfers under the UK GDPR.

Each one is covered by the International Data Transfer Addendum to the EU standard contractual clauses, version B1.0, issued by the Information Commissioner under section 119A of the Data Protection Act 2018. It is written into the data processing agreement we accept with each of the five, and we satisfy ourselves before relying on it that the protection travelling with the data is not materially lower than it would be here. We do not rely on any of the exceptions in Article 49 for ordinary running of the site.

Your rights

You can ask us to give you a copy of your information, correct it, delete it, restrict what we do with it, or hand it to another service in a portable form. You can object to anything we do on the basis of legitimate interests, including everything listed above under that heading. Where we rely on consent, you can withdraw it at any time and withdrawing it is as easy as giving it: the unsubscribe link for the newsletter, the control on the cookies page for advertising. Withdrawal stops the future, not the past.

There is no automated decision-making with legal or similarly significant effects on this site. Moderation decisions are made by a person.

Ask by emailing privacy@sandbanksdigital.com. We answer within one month and will say so if a request is complicated enough to need longer. There is no charge unless a request is manifestly unfounded or excessive, and we would explain why before deciding that.

Reviews, deletion, and why a review usually stays

This is the awkward corner, so here is our position plainly.

Delete your account and the account goes. A review you wrote and we published generally stays, because Article 17(3)(a) of the UK GDPR disapplies the right to erasure to the extent that processing is necessary for exercising the right of freedom of expression and information, and a published review of a business is that. The ICO is clear that this is not automatic: freedom of expression is itself a qualified right, so we weigh each request rather than refusing by rule.

What we will do without argument is take your name off it. Ask, and the display name is replaced so the review no longer identifies you, while what you wrote about the business stays where a reader can see it.

There is a second reason we do not simply delete on request, and it is not about us. Paragraph 13(5)(i) of Schedule 20 to the Digital Markets, Competition and Consumers Act 2024 says that removing negative reviews while publishing positive ones is publishing in a misleading way. A directory that deleted any review on the author’s say-so would be a directory whose ratings could be cleaned up by asking, and businesses would learn to ask. Our review policy sets out the routes that do exist.

A review comes down when we conclude it is fake, when it breaks the review policy, when it is unlawful, or when the balance in a particular case comes down on the side of the person asking. None of those is a matter of who is asking.

Business owners and sole traders

If you trade under your own name, your listing is personal information about you. If you would rather it was not published here, ask and we will take it down; you do not have to give a reason. Where the record originates with the Food Standards Agency we will say so, because their register is public whatever we do.

Some things we can fix straight away: a private address showing where it should not, an out-of-date detail, a business that has closed. Use the correction route for any of those; it is free and open to anyone, whether or not you own the business.

Children

This is a directory for adults and it is not designed for or aimed at children. We do not knowingly hold information about children, and if you believe we do, tell us and we will remove it.

Complaining

Complain to us first if you can: section 164A of the Data Protection Act 2018 gives you the right to, and we must acknowledge a complaint within thirty days and tell you the outcome without undue delay. Email privacy@sandbanksdigital.com.

You can complain to the Information Commissioner’s Office at any time, whether or not you have come to us first. The ICO is at ico.org.uk and on 0303 123 1113.

Changes to this notice

The date at the top of this page is the date it was last changed. Where a change affects what we do with information we already hold, we will say so here rather than only altering the wording.