At Happystackeditin (operated by Happystackeditin Travel Media Ltd., "we", "us", or "our"), accessible from happystackeditin.store, the privacy of our visitors is one of our primary commitments. This comprehensive Privacy Policy document delineates the categories of personal and non-personal data that are collected, stored, processed, and safeguarded when you navigate our European destination platform.
1. Data Controller Information
Happystackeditin Travel Media Ltd.
Company Registration No: 12948210
Registered Office: 74 Victoria Crescent, London SW1V 1QT, United Kingdom
Official Privacy & Data Protection Contact: [email protected]
2. Categories of Data We Collect
We may collect and process the following information:
- Voluntarily Provided Information: Full name, email address, subject matter, and inquiry text submitted through our interactive contact forms or travel newsletter subscriptions.
- Automated Device & Usage Information: Anonymized Internet Protocol (IP) addresses, browser type, operating system version, referring/exit pages, timestamps, clickstream sequence, and interactions with our month selectors and category filters.
- Cookie & LocalStorage Identifiers: Persistent consent state flags stored in your browser’s localStorage to record your cookie preferences without repeatedly displaying banners.
3. Legal Basis for Data Processing (GDPR Article 6)
We process personal data only when lawful grounds exist:
- Consent (Art. 6(1)(a)): You have granted unambiguous consent for analytics cookies or newsletter communications.
- Legitimate Interests (Art. 6(1)(f)): To maintain website security, prevent fraudulent bot traffic, analyze aggregate European destination trends, and ensure continuous technical performance.
- Legal Obligation (Art. 6(1)(c)): Compliance with statutory tax, corporate, and digital publishing regulations in the United Kingdom and European Union.
4. Third-Party Processors and Data Transfers
We do not sell, rent, or lease your personal information to third parties. We may engage vetted third-party technical vendors (e.g., CDN providers, server hosts, and aggregated analytics tools) that adhere to equivalent data security standards under Standard Contractual Clauses (SCCs).
5. Your Rights Under GDPR and CCPA
Depending on your jurisdiction, you retain the following statutory rights:
- Right of Access: Request a complete copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal records.
- Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your data when no overriding statutory retention obligation exists.
- Right to Data Portability: Receive your data in a structured, commonly used, and machine-readable format.
- Right to Withdraw Consent: Revoke prior consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
To exercise any of these rights, email our Data Protection Officer at [email protected]. Requests are fulfilled within 30 days without charge.
6. Data Retention Period
Contact inquiries are retained for up to twenty-four (24) months to facilitate contextual support follow-up. Anonymized server logs are purged every ninety (90) days.
7. Security Measures
We implement industry-standard technical measures including 256-bit TLS (Transport Layer Security) encryption for all in-transit traffic, strictly isolated database environments, and regular vulnerability scanning.