Privacy policy

PART 1 — THE INFORMATION WE CAN COLLECT AND HOW WE USE IT

1a. Purchasing tickets
If you purchase tickets through the website or telephone, we will collect the information we need to fulfil your order and notify you of the status of your order, which will include sending you a confirmation email. We may also use your email address to contact you on the rare chance that a screening you have booked tickets for is postponed or cancelled.

Where you make a purchase by credit/debit card via the Website, the cardholder data is passed securely by Savoy Systems (our ticket purchasing provider) to the online payment provider (Cardstream) immediately and not stored on our machines. Savoy Systems only stores a hash encrypted portion of the card (first six and last four digits of the card number) along with expiry date and cardholder name to allow collection by card at the Box Office.

1b. Becoming a Member
If you purchase membership either in person at the Box Office or online, we will collect the following information: First Name, Surname, Email Address, Address, and Post Code. Your Email Address is needed to log in to our online ticket purchasing portal (Savoy Systems) and purchase tickets. Your First Name, Surname, and Postcode can be used as verification of identification when claiming Membership discounts at the Box Office.

If you sign up to become a Member using our website, we will also ask you what age-range you belong to and what film genres interest you. These fields are non-compulsory, but provide us with a greater insight into the demographics and interests of our members and may be used to inform some of our programming and marketing decisions.

1c. Signing up for our Weekly E-newsletter
If you choose to receive our Weekly E-newsletter, the email address that you submit to us will be forwarded to MailChimp who provide us with email marketing services. Your email address will remain within MailChimp’s database for as long as we continue to use MailChimp’s services or until you specifically request removal from the list. You can unsubscribe at any time using the link at the bottom of all of our email newsletters.

If you joined the mailing list over one year ago and you haven’t opened any of our newsletters in the last 20 weeks (and you don’t have a Membership), then we will automatically remove you from the mailing list.

1d. Correspondence
If you contact us for any reason via email ([email protected]), we may keep a record of that correspondence. We archive email correspondence with customers, in case we need to refer to the issue or resolution at a future date. We delete archived emails after five years.

PART 2 — YOUR DATA RIGHTS

2a. Rights of access, rectification, and erasure
Under the new GDPR regulations, you have the right to access, rectify, or erase any of the personal data which we have collected from you. If you wish to do so, please email us at [email protected] with an email entitled ‘Customer Data Request’.

You will be asked to provide us with necessary identification before we can process your request. Once you have provided us with the necessary identification, we are obliged to fulfil your request within 30 days.

PART 3 – INFORMATION ON OUR SERVERS

3a. Website domain info (http://www.uppcinema.com)
Our website is hosted on a LAMP/Nginx server managed by WP Engine, physically located in the Google europe-west2 data center, Harbour Exchange Square, Canary Wharf, London. WP Engine is responsible for notifying the webmaster of any data breaches. Automated backups run at 4am every day.

3b. Savoy Systems server info (http://uppoxford.savoysystems.co.uk)
The ticket booking pages are hosted by Savoy Systems whose database is stored on a dedicated server in Nottingham. Savoy automatically performs near real-time backups of their databases for disaster recovery purposes. These backups are stored on one of three dedicated Disaster Recovery servers in a RapidSwitch Data Centre.

PART 4 — WEBSITE COOKIES & TRACKING

4a. Cookies
We use Session Cookies all of which are necessary for the functionality of the site and enhanced security. None of these cookies contains any personally identifiable information. The booking pages (managed by Savoy Systems) use Status Cookies (to determine whether a user is logged into the booking website and to keep track of basket contents) and a few innocuous Persistent Cookies (whether or not to remember the Patron’s email address for login purposes).

4b. Third Party Cookies
Our website uses Google Analytics to track user interaction. We use this data to determine the number of people using our site, to better understand how you find and use our web pages. Google Analytics records data such as your geographical location, device, internet browser and operating system, but none of this information personally identifies you to us. Google Analytics also records your computer’s IP address which could be used to identify you personally, but Google does not grant us access to this.

PART 5 — THIRD PARTY LINKS

We use a number of third parties to process personal data on our behalf. These third parties have been carefully chosen and all of them comply with the proper legislation.

Savoy Systems – Link to privacy policy
iZettle – Link to privacy policy
Google – Link to privacy policy
MailChimp – Link to privacy policy
Survey Monkey – Link to privacy policy
Crazy Egg – Link to privacy policy