HOLO GUILD
Privacy Policy.
Plain English: we collect the information needed to consider applications, run member accounts and community features, moderate the service and take membership payments. We do not sell personal information.
1. Who is responsible
The controller of personal information used for Holo Guild is Neil Spencer trading as Holo Guild, a UK sole trader.
[Privacy/support email to be added before launch]
[Business correspondence address to be added before launch]
2. Information we collect
- Application information: name, email, referral code, collecting experience and interests, membership goals, UK-residency and age confirmations, and acceptance records.
- Account and profile information: name, email, password hash, biography, collecting focus, approximate location, profile image, favourite set, chase card, collection highlight, social handle, badge and membership status.
- Community information: posts, comments, listings, wanted cards, offers, images, watchlists, messages, meetup information, feedback, reports, referrals and testimonials.
- Membership and payment information: chosen plan, subscription status, billing dates and Stripe customer or subscription identifiers. Card details are entered with Stripe and are not stored by Holo Guild.
- Technical and security information: essential session-cookie data, IP address, device/browser information, request logs and security events made available by our hosting and infrastructure providers.
Please avoid putting a full home address, payment-card details, identity documents or other unnecessary sensitive information into profiles, posts, listings or messages.
3. How and why we use it
- To review an application and take steps you request before entering a membership contract.
- To provide and bill for membership, authenticate accounts and deliver community features under our contract with you.
- To keep the community secure, prevent fraud and abuse, moderate content, investigate reports and improve the service where we have a legitimate interest that is not overridden by your rights.
- To keep tax, accounting, consumer-rights and legal records where required by law.
- To send service messages about applications, accounts, payments, safety and important changes. We will ask for consent before sending optional email marketing where required.
4. Who can see information
Approved members can see information you deliberately post to member areas. A limited collector profile may be publicly accessible where the page says so. Private messages are intended for their participants and are not routinely read, but may be accessed where reasonably necessary to investigate a report, protect someone, provide support, prevent fraud or comply with law.
We may share relevant information with professional advisers, insurers, law enforcement or regulators where reasonably necessary or legally required. We do not sell or rent member information.
5. Service providers
We use providers that process information to help run Holo Guild, currently including:
- Vercel for hosting, server functions, logs and image/file storage.
- Neon for the hosted PostgreSQL database.
- Stripe for checkout, subscriptions, fraud prevention and payment records.
- Google Fonts to deliver the typefaces used by the website.
Some providers may process information outside the UK. Where UK data-protection law requires it, we rely on an adequacy decision or approved contractual safeguards. Providers may also use information as independent controllers for their own legal, security and fraud-prevention duties; their privacy notices explain that use.
6. Cookies
Holo Guild currently uses an essential session cookie so that members can sign in and move securely between pages. It is necessary for the service and is not used for advertising. We do not currently use optional analytics or advertising cookies. If that changes, we will update this policy and ask for consent where required.
7. How long we keep information
- Application records are reviewed periodically and are kept only as long as reasonably needed to make and explain a decision, deal with follow-up questions and prevent abuse.
- Account, profile and community information is normally kept while the account is active. After closure, it is deleted or anonymised within a reasonable period unless it is needed for a legal, safety, payment or dispute reason.
- Payment and accounting records are kept for the period required by tax, accounting and consumer law.
- Reports, security records and relevant messages may be kept for as long as reasonably necessary to investigate, protect members, establish legal claims or prevent repeat abuse.
- Provider logs and backups are kept on rolling schedules set by the relevant provider and are deleted or overwritten in the ordinary course.
Before live launch we will maintain a working retention schedule and carry out deletion or anonymisation manually until suitable automation is introduced.
8. Your rights
Depending on the circumstances, you may ask for access to your information, correction, deletion, restriction, portability, or object to certain uses. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing.
Contact us using the details in section 1. We may need to verify your identity. You may also complain to the UK Information Commissioner’s Office at ico.org.uk.
9. Security and changes
We use technical and organisational measures intended to protect information, including password hashing, access controls and secure service providers. No online service can guarantee absolute security, so please use a unique password and tell us promptly about suspected misuse.
We may update this policy when the service, providers or law changes. We will post the new version here and give appropriate notice of material changes.