top of page

Privacy Policy

This privacy policy explains how Little Escapes collects, uses, stores and shares personal information when you visit our website or premises, make an enquiry or booking, attend an escape room or party, use our café or Wi-Fi, or interact with us online.

​

1. Who we are and how to contact us

Little Escapes is the data controller for the personal information described in this policy.

Postal address: Little Escapes, Unit 8, The Venture Eleven, Venture Way, Taunton, TA2 8DG.

For privacy questions or to exercise your data-protection rights, please contact us through the contact form on our website or write to us at the address above.

​

2. Information we may collect

Depending on how you interact with us, we may collect:

Contact details, including names, addresses, email addresses and telephone numbers.

Booking information, including dates, party or escape-room choices, group size, payment status and optional extras.

Information about children supplied by a parent, guardian or booking organiser, such as first name, age, interests and participation requirements.

Health and support information where relevant, including allergies, disabilities, medical conditions, sensory needs, mobility requirements and reactions to cosmetic or craft products.

Permissions and consent records for treatments, activities, photography or marketing.

Correspondence, feedback, complaints, incident reports and customer-service notes.

Transaction details and payment confirmations. Card details are normally processed directly by Wix or its connected payment services rather than stored by us in full.

Images and audio captured by our CCTV system, and photographs or videos taken with appropriate permission.

Technical information from our website and guest Wi-Fi, which may include IP address, device information, browser type, cookie identifiers and usage logs.

Public interactions with our social-media pages, such as comments, messages, reviews and competition entries.

​

3. Information about children

Our experiences are designed for children and families, but bookings must be made by an adult. We normally receive children’s information from the parent, guardian or adult organising the booking. The organiser is responsible for supplying accurate information and obtaining any permissions required from the parents or guardians of other participating children.

We only ask for information that is reasonably needed to personalise the experience, manage the booking, support safe participation and make appropriate adjustments. We do not use children’s information for direct marketing.

​

4. Why we use personal information and our lawful bases

We use personal information for the following purposes:

To respond to enquiries, take bookings, process payments and provide the requested experience. We generally rely on taking steps at your request and performing our contract with the booking organiser.

To plan parties and activities, confirm selections, communicate changes and provide customer support. We rely on contract and our legitimate interests in operating the business effectively.

To maintain financial, tax and business records and respond to lawful requests. We rely on legal obligations and, where appropriate, legitimate interests.

To protect visitors, staff, premises and equipment; supervise escape-room experiences; respond to calls for assistance; and investigate accidents, safeguarding concerns, complaints or suspected crime. We rely on legitimate interests, balanced against the rights of visitors.

To improve our services using feedback and appropriately aggregated booking information. We rely on legitimate interests.

To send promotional emails or messages where we have valid consent or another lawful permission. People can opt out at any time.

To take and use promotional photographs or videos where appropriate permission has been obtained.

​

5. Health information, disabilities, allergies and additional needs

Information about health, disability or certain support needs may be special-category personal data under UK data-protection law. We request this information only where it may be relevant to safe participation, reasonable adjustments, product suitability or emergency arrangements.

Where required, we rely on the booking organiser’s explicit consent, including confirmation that they are authorised to provide relevant information about participating children. Consent may be withdrawn by contacting us, although we may be unable to provide a particular treatment or activity safely without necessary information. In a genuine emergency, information may also be used or shared where necessary to protect someone’s vital interests.

​

6. Treatments, craft activities and permissions

For pamper parties, face painting, cosmetics, hair products, glitter, fragrances or craft activities, we may record selections, sensitivities and confirmation that the organiser has obtained permission from each child’s parent or guardian. We use this information to deliver the selected activity safely and do not use it for unrelated purposes.

​

7. CCTV, monitoring and recorded audio

CCTV operates at our premises for safety, security, supervision of escape-room experiences, responding to requests for help, protecting people and property, and investigating incidents. Selected monitored activity areas may capture both images and audio. CCTV and audio recording are clearly signposted and are not used in toilets or other areas where people would reasonably expect complete privacy.

Live feeds and recordings are restricted to authorised people. Routine recordings are retained for no longer than 30 days on a rolling basis and are then overwritten, unless a relevant clip must be preserved for an accident, safeguarding matter, complaint, insurance claim, suspected crime or lawful request. Recordings may be shared with police, emergency services, insurers, professional advisers or other parties where lawful and necessary.

​

8. Photography and social media

Little Escapes will not use identifiable photographs or videos of children for promotional purposes without appropriate permission. Promotional photography permission is optional and separate from accepting our booking terms. Permission can be withdrawn for future use, although we may not be able to retrieve material already printed, shared by others or lawfully published before withdrawal.

Visitors taking their own photographs should avoid photographing or sharing images of other children without permission from their parent or guardian. Social-media platforms process information under their own privacy policies.

​

9. Website, Wix, payments and cookies

Our website, online forms, bookings and connected services are provided through Wix. Wix and its connected payment, communication, analytics and website services may process personal information on our behalf or, for some services, as an independent controller. Their processing is also governed by their own privacy information and contractual safeguards.

Our website uses cookies and similar technologies needed for security, bookings and site operation, and may use optional analytics or marketing technologies where permitted. Non-essential cookies should only be used in accordance with the choices made through our cookie banner. You can also control cookies through your browser settings.

​

10. Who we share information with

Where necessary and lawful, information may be shared with:

Wix and Wix-connected website, booking, payment, email, analytics and technical-service providers.

Banks, payment processors, accountants, insurers, legal advisers and other professional advisers.

IT, security, CCTV, maintenance and data-storage providers working under appropriate obligations.

Emergency services, safeguarding bodies, regulators, courts, law-enforcement agencies or public authorities where required or justified.

A purchaser or adviser in connection with a genuine sale, restructuring or transfer of the business, subject to appropriate confidentiality and legal safeguards.

We do not sell personal information.

​

11. International transfers

Some Wix or connected service providers may process information outside the United Kingdom. Where personal information is transferred internationally, we require an appropriate legal safeguard, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful mechanism.

​

12. How long we keep information

We keep information only for as long as reasonably needed for the purpose for which it was collected, including legal, accounting, insurance and dispute-resolution requirements. Our typical periods are:

Information

Typical retention

Enquiries that do not become bookings

Normally up to 12 months after the last contact

Booking, payment and accounting records

Normally up to six years where required for tax, accounting, insurance or legal purposes

Party choices and operational notes

For the booking and a short period afterwards, unless needed for a complaint, incident or legal claim

Health, disability, allergy and additional-needs information

Normally deleted or securely anonymised within 30 days after the visit, unless an incident or legal obligation requires longer retention

​

CCTV and recorded audio

Up to 30 days on a rolling basis, unless footage is preserved for an incident, complaint, insurance matter or lawful request

Marketing preferences

Until consent is withdrawn or the information is no longer needed; suppression records may be retained to respect an opt-out

Promotional photographs and videos

Until consent is withdrawn or the material is no longer required, subject to practical limits for material already printed or published

Website and cookie data

According to the lifespan of the relevant cookie or Wix service setting, as explained through our cookie controls

 

13. How we protect information

We use reasonable technical and organisational safeguards, including access controls, passwords, secure systems, staff access limitations, appropriate processor agreements and secure deletion or disposal. No internet or storage system can be guaranteed completely secure, but we review risks and respond to suspected personal-data breaches in accordance with our legal obligations.

​

14. Your data-protection rights

Depending on the circumstances and lawful basis, you may have the right to:

Ask for access to your personal information.

Ask us to correct inaccurate or incomplete information.

Ask us to delete information in certain circumstances.

Ask us to restrict how information is used.

Object to processing based on legitimate interests or to direct marketing.

Receive certain information in a portable format.

Withdraw consent at any time where processing relies on consent, without affecting earlier lawful use.

We may need to verify your identity before responding. Some rights are subject to legal exceptions, including where information must be retained for legal claims, accounting or safeguarding purposes. We do not use personal information to make solely automated decisions that have legal or similarly significant effects.

​

15. Complaints

Please contact Little Escapes first if you have a privacy concern so that we can try to resolve it. 

​

16. Changes to this policy

We may update this policy when our services, suppliers or legal obligations change. The latest version will be published on our website with its effective date.

bottom of page