Privacy Policy
Last updated: 15 September 2026
1. Who we are
Retrohobby ("we", "us", "our") operates this website. We are the "data controller" responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy explains what personal data we collect, how we use it, and the rights you have. If you have questions, contact us at privacy@Retrohobby.com.
2. The data we collect
- Account data — if you create an account, your email address and any name you provide.
- Purchase data — when you buy an ebook or certificate, payment is processed by Stripe. We store a record of your purchase (item, amount, currency, status) but we never see or store your full card details.
- Activity data — the hobbies you view and interact with, used to power features such as earned certificates. For signed-out visitors this is tied to a random first-party identifier, not to your identity.
- Analytics data — if you consent, privacy-friendly usage analytics (e.g. pages visited). See our Cookie Policy.
- Callback requests — if you ask us to arrange a call, we collect your UK mobile number and preferred contact time. Please do not include health information or other sensitive details.
- Preferences — your language, currency and cookie choices, stored in first-party cookies.
3. Our lawful bases
Under UK GDPR we rely on the following lawful bases (Article 6):
- Contract — to provide your account, deliver purchases and support them.
- Consent — for optional analytics cookies. You can withdraw consent at any time.
- Legitimate interests — to keep the site secure, prevent fraud/abuse and improve our service, balanced against your rights.
- Steps at your request — to receive and pass on a callback request when you ask us to do so. We do not use your mobile number for direct marketing without a separate lawful basis and any consent required by PECR.
4. How we share data
We share personal data only with service providers who process it on our behalf, including:
- Stripe — payment processing.
- Vercel — website hosting and, with consent, analytics.
- Neon — database hosting.
- Relevant independent provider — only where needed to respond to a callback request.
- Google Calendar — if you choose to book through a Google Calendar link, the information you submit is shared with Google and the relevant booking provider to arrange the appointment. Google processes that information under its own privacy policy and terms.
We do not sell your personal data. We do not provide medical or dental advice, and information about providers, groups, views or activities is for general information only.
5. Third-party providers and international transfers
We use independent third-party providers to host, secure, analyse, deliver and process parts of the service. Depending on the service and the provider's infrastructure, your information may be stored or accessed outside the UK or European Economic Area, including in countries whose privacy laws may differ from those where you live.
Providers may include Vercel for hosting, Neon for database services, Stripe for payments, YouTube for embedded video content, and email, analytics or security providers we may add as the service develops. The applicable provider may receive only the information needed for its service, but it processes that information under its own terms, privacy notice and security practices. Review those documents before using the relevant feature.
Where UK GDPR or EU GDPR applies, we use an appropriate transfer mechanism where required, such as an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum, or EU Standard Contractual Clauses, together with supplementary measures where appropriate. International transfers can still involve risks, including changes in law, outages, security incidents or actions by a provider outside our control.
To the extent permitted by law, we are not responsible for a third-party provider's separate acts, omissions, systems, content, security practices, privacy decisions or service outages. This does not remove any legal responsibility that cannot lawfully be excluded, nor our duties as controller for processing we determine.
6. Security and incidents
We use reasonable technical and organisational measures designed to protect personal data, including access controls, encrypted connections and restricted access to operational systems. No internet service, provider or transmission method is completely secure, and we cannot guarantee that information will never be accessed, lost, altered or disclosed unlawfully.
If an incident affects information under our responsibility, we will assess it and take steps required by applicable data-protection law, which may include notifying the ICO or affected people. We cannot promise to prevent or control an incident occurring solely within a separate third-party provider's systems.
7. How long we keep it
We keep personal data only for as long as needed for the purpose collected, then securely delete or anonymise it. Callback mobile numbers and callback details are retained for no longer than 90 days; expired requests are removed during callback-processing maintenance, unless we need to retain a record longer to resolve a complaint, establish or defend a legal claim, or comply with a legal obligation. We do not keep a callback request indefinitely.
Account data is kept while your account is active and for a short period after closure where needed for security or support. Purchase records are retained as required for legal, tax and accounting purposes, typically up to six years. Preference and consent cookies expire within 12 months.
8. Callback requests and data minimisation
A callback request is optional. You may provide a number in international or UK format, and you may ask us to delete it at any time. We use the number only to respond to the request and share it only with people who need it to arrange that response. We apply access controls and encrypted connections, but no online service can guarantee absolute security.
9. Your rights
Under UK GDPR you have the right to:
- access a copy of your data;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to processing;
- data portability; and
- withdraw consent at any time.
To exercise any of these, email privacy@Retrohobby.com.
10. Complaints
If you are unhappy with how we handle your data, you can complain to the UK's supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk. We'd appreciate the chance to address your concerns first.