← Back to Somewhere Held

Privacy policy

Last updated: [DATE]

In brief

1. Who is responsible for your data

LIMITLOCK LIMITED, trading as Somewhere Held, Dublin, Ireland, registered in Ireland with company number 793491, is the controller of your personal data. Contact us about privacy through our contact page.

This policy is written under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Acts 1988–2018. For customers in the UK, it also covers the UK GDPR and the Data Protection Act 2018.

2. What we collect

While you design (stays on your device)

The studio runs in your browser. The place you choose, the map area, colours, routes, symbols, names, dates and inscriptions you type are kept in your browser's own storage (see our cookie & storage notice). We do not receive them unless you place an order.

If you upload a GPX route, it is processed on your device. Only the route's coordinates and name are kept as part of your design. Timestamps, heart rate, cadence and any other health or activity data in the file are ignored and never leave your device.

When you order

When you contact us

Your email address and what you tell us, including photos you send if something is wrong.

Technical information

Our server records basic technical information such as IP address, browser type and the time of each request. We use it to keep the site secure and to limit how often a visitor can request new map areas. [CONFIRM: if privacy-friendly analytics are enabled] We also measure overall site usage (such as page views and which features are used) in aggregate form, without cookies and without building profiles of individual visitors.

3. Why we use it, and our lawful basis

PurposeLawful basis
Making, delivering and supporting your order, including sending order and delivery emailsContract
Handling faults, returns and refundsContract; legal obligation
Keeping accounts and tax recordsLegal obligation
Keeping the site secure, preventing fraud and abuse, rate-limiting map requestsLegitimate interests (running a safe, reliable service)
Aggregate, cookie-free usage statistics [CONFIRM]Legitimate interests (improving the site)
Answering your questionsLegitimate interests; or contract where it relates to an order
[Marketing emails, only if offered]Consent, which you can withdraw at any time

We do not make decisions about you based solely on automated processing.

4. Who we share it with

We share personal data only with service providers who help us run the shop, under contracts that require them to protect it and use it only on our instructions (except where noted).

ProviderWhat forData
StripePayment processing (hosted checkout)Name, email, billing details, payment data. Stripe also acts as an independent controller for fraud prevention and legal compliance; see Stripe's privacy policy.
ResendSending order and service emailsEmail address, name, email content
Cloudflare, Inc. (website hosting and data storage)Hosting our website, server and order databaseOrder data, technical data
[PRINT SUPPLIER]Printing and dispatching your mapYour design, name and delivery address [confirm whether supplier ships directly]
[COURIER(S)]Delivering your parcelName, delivery address, [email/phone for tracking]
[ANALYTICS PROVIDER, if used]Cookie-free aggregate statisticsTechnical data, processed without identifying you

We may also share data where the law requires it, or with professional advisers or a buyer of our business, under appropriate confidentiality.

Map and content services your browser contacts

To show maps and build your model, your browser fetches data directly from these services. Like any website, they receive your IP address and browser details, along with the map area or search you request. Place searches may include an address you type.

Each of these providers is responsible for how it handles this technical data under its own privacy policy.

5. International transfers

Some providers (for example Stripe, Resend and Google) may process data in the United States or other countries outside the EEA and UK. Where they do, we rely on adequacy regulations or decisions (such as the UK–US Data Bridge and the EU–US Data Privacy Framework, where the provider is certified) or on approved standard contractual clauses with the UK addendum. You can ask us for details of the safeguards used.

6. How long we keep it

7. Your rights

You have the right to:

To use any of these rights, write to us through our contact page. We will reply within one month. There is normally no charge.

8. Complaints

Please contact us first so we can try to help. You also have the right to complain to Ireland's Data Protection Commission (dataprotection.ie). If you live elsewhere in the EU, you can complain to the data protection authority in your country; in the UK, to the Information Commissioner's Office (ico.org.uk).

9. Security and children

We use encrypted connections (HTTPS), restricted access and reputable providers to protect your data. No system is perfectly secure, but we will tell you and the regulator about a serious breach where the law requires.

Our shop is not aimed at children. Orders must be placed by someone aged 18 or over.

10. Changes

We will update this page if our practices change and show the date of the latest version at the top.