Independent Worthing
Privacy Policy
Last updated: 20 May 2026
This Privacy Policy explains how Independent Worthing ("we", "us", "our") collects, uses, shares and protects personal data when you use our website and services.
If you have any questions about this policy or want to exercise your rights, contact us using the details in the "Who we are" section below.
1) Who we are (Data Controller)
- Data Controller: Independent Worthing
- Website: independentworthing.co.uk
- Privacy email: privacy@independentworthing.co.uk
2) The personal data we collect
We may collect and process the following categories of personal data:
2.1 Account and membership data
- Name, email address, username
- Password (stored in hashed/encrypted form)
- Membership/subscription level, status, access entitlements
- Access logs relating to membership features
2.2 Subscription and payment administration
- Billing/admin records (invoices/receipts)
- Transaction references and payment confirmations
- Limited payment metadata (e.g., last 4 digits, payment method type, billing country) where provided by Stripe
- (We do not store full card details.)
2.3 Event listing submission data (members only)
- Event details you submit (title, description, date/time, venue details)
- Organiser contact details if you choose to include them
- Images/media you upload
- Moderation notes/metadata related to your submission
2.4 Messaging data (members — businesses/organisers)
- Messages you send and receive via the site (content, timestamps, related metadata)
- Any personal data included within message content
2.5 Newsletter data (Mailchimp)
- Email address and marketing preferences
- Email engagement data (e.g., opens/clicks), where enabled
2.6 Technical and usage data
- IP address, browser type/version, device/OS
- Pages visited, actions taken, referral sources
- Security and diagnostic logs
3) If you don't provide personal data
If you do not provide required information, we may be unable to:
- create or administer your account/subscription,
- accept event submissions, or
- provide messaging functionality.
4) How we use your personal data
4.1 Run the website and provide member services
- Create and manage accounts
- Provide member-only tools (including event submissions)
- Deliver and operate site messaging
- Maintain platform security and performance
4.2 Review, moderate and publish event listings
- Review submissions for quality, spam prevention, and policy compliance
- Publish approved listings publicly
- Contact you about edits, clarifications, or moderation outcomes
4.3 Manage subscriptions and payments
- Administer membership access via our membership system
- Maintain billing/transaction records
- Handle refunds, disputes, or chargebacks where applicable
4.4 Communicate with you
- Respond to enquiries and support requests
- Send service notices (account/subscription-related communications)
4.5 Send newsletters and updates (Mailchimp)
- Send emails you have requested/opted in to receive
- Use engagement metrics to improve communications (where enabled)
4.6 Improve and protect the platform
- Understand site usage and improve services
- Prevent fraud, misuse, and security incidents
- Enforce platform rules and keep users safe
4.7 Legal and compliance
- Meet legal obligations (e.g., accounting)
- Establish, exercise, or defend legal claims
5) Lawful bases for processing (UK GDPR)
We process personal data under one or more lawful bases:
- Contract: to provide your account, subscription, member-only submissions, and messaging features
- Legitimate interests: to operate, secure, moderate and improve the platform; prevent fraud and misuse
- Legal obligation: for record-keeping and compliance
- Consent: for marketing emails where required, and for non-essential cookies where required
You can withdraw consent at any time (where consent is used).
6) Paid subscriptions and payments (Stripe)
6.1 Firebase Auth and Firestore
We use Firebase Auth and Firestore to manage subscriptions, access entitlements, and membership administration. This involves processing your account details and subscription status within our application.
6.2 Stripe
Payments are processed by Stripe. Stripe processes payment information (including card details).
We do not store full card details. We receive limited payment-related information such as:
- confirmation of payment,
- transaction IDs,
- payment method type and partial card details (e.g., last four digits),
- billing country,
- subscription/payment status.
Stripe may process personal data as an independent controller for certain purposes (such as fraud prevention and compliance). Please refer to Stripe's privacy information for details.
7) Messaging (members — businesses/organisers)
Our platform lets members message businesses/organisers through the site. We process messaging data to:
- deliver messages and replies,
- maintain records for support, dispute handling, and safety,
- detect and prevent abuse, spam, and fraud,
- enforce platform rules.
Note: Please avoid sending sensitive personal data via the messaging feature.
8) Newsletters and marketing (Mailchimp) + PECR
If you subscribe to newsletters/updates, we use Mailchimp to manage lists and send emails. Mailchimp may also provide engagement metrics (opens/clicks) to help us improve our communications.
You can unsubscribe at any time using the link in our emails.
We comply with PECR rules for electronic marketing, and will ask for consent where required.
9) Who we share personal data with
We may share personal data with trusted providers who support our services, including:
- Email marketing: Mailchimp
- Payments: Stripe
- Membership/auth: Firebase Auth and Firestore
- Hosting/infrastructure: Firebase App Hosting (Google Cloud)
- Security/spam prevention: reCAPTCHA
- Analytics: Google Analytics
We only share what is necessary for the relevant purpose, and we require appropriate contractual and security protections where we use processors.
We may also disclose data where required by law or to protect rights, safety, and prevent fraud.
10) International transfers
Some providers may process personal data outside the UK. Where international transfers occur, we use appropriate safeguards such as UK adequacy decisions or approved contractual safeguards (e.g., the UK IDTA / Addendum).
11) Cookies
We use cookies and similar technologies for:
- Essential site functions (login/session, security, preferences)
- Performance/analytics (if enabled)
- Marketing (if enabled)
Where required, we will request consent for non-essential cookies.
12) Data security
We use appropriate technical and organisational measures to protect personal data. However, no online service is completely secure, and you share information at your own risk.
13) Data retention
We keep personal data only as long as necessary for the purposes in this policy, including legal and operational requirements. Typical retention includes:
- Account data: while your account is active, plus a reasonable period afterwards
- Subscription/payment records: as required for administration and legal/accounting obligations
- Event submissions/listings: while published and for a period afterwards for moderation/audit (e.g., 7 days)
- Messages: for delivery, moderation, dispute handling and safety (e.g., 6 months)
- Marketing data: until you unsubscribe (and/or refreshed consent where required)
14) Your rights (UK GDPR)
You have rights including:
- Access
- Rectification
- Erasure
- Restriction
- Objection (including to direct marketing)
- Data portability (where applicable)
- Withdraw consent (where consent applies)
To exercise your rights, contact privacy@independentworthing.co.uk. We may need to verify your identity.
15) Children
Our services are not intended for children under 13 (or under 16 where applicable). We do not knowingly collect children's data.
16) Third-party links
Our site may include links to third-party websites or embedded content. We are not responsible for their privacy practices.
17) Complaints
If you have concerns, contact us at privacy@independentworthing.co.uk.
You can also complain to the UK data protection authority: the Information Commissioner's Office (ICO).
18) Mobile app and notifications
You can install Independent Worthing as an app from your browser or download it from the Google Play Store. When you do, the following additional considerations apply:
18.1 Notification tokens (Firebase Cloud Messaging)
If you choose to enable push notifications, we ask your browser or device to generate a unique notification token through Google's Firebase Cloud Messaging service. This token lets us deliver event, offer, creative-news and weekly-digest notifications you have opted in to receive. You can turn off any category or all notifications at any time from your account settings or your device's notification settings.
The token identifies your device, not you personally, and is shared only with Google's notification delivery service. Tokens are deleted automatically when you sign out, when you uninstall the app, when you disable push from inside the app, or when the token expires.
18.2 Installed-app session data
When you use the installed app (rather than a browser tab), we record that the session originated from the Progressive Web App or Android Trusted Web Activity so that we can measure adoption. This is aggregated and does not identify individual users.
18.3 Offline data
The installed app stores a copy of recently-viewed listings on your device so they remain available without an internet connection. This local cache contains only data you have already viewed online. It is removed when you uninstall the app or clear site data.
19) Changes to this policy
We may update this policy from time to time. The latest version will be posted on this page with the "Last updated" date.
Contact
Independent Worthing
Privacy email: privacy@independentworthing.co.uk

