← Back to home

Privacy Policy

Last updated: August 2026

This policy explains how GLT Solutions and Ethical Advertising (the “Operators”) collect, use, and protect your personal data when you purchase and use a WiFi pass at Heal Festival Shrewsbury. The Operators act as data controllers for the purposes of the UK GDPR and the Privacy and Electronic Communications Regulations (PECR).

1. Who we are

The WiFi Service is operated by GLT Solutions and Ethical Advertising in partnership with Heal Festival. The Operators are the data controllers for the personal data described in this policy.

Contact for all data protection matters: info@ethicaladvertising.uk

2. What we collect

We collect only the data needed to deliver and manage your Pass:

  • Email address — to send your receipt and activation code(s).
  • Payment data — processed entirely by Stripe. We never see or store your card details.
  • Activation code — the unique 6-character code generated for each Pass.
  • Device identifier — a MAC address or token captured when you activate your Pass on the network, used only to grant your device access.
  • IP address — logged at the point of purchase for fraud prevention.
  • Transaction details — pass tier, day(s) purchased, and order amount.

Guests do not need to create an account. The only authentication on this site is for authorised crew and admin staff.

3. Legal basis for processing

We process your data under the following UK GDPR lawful bases:

  • Contract (Art. 6(1)(b)) — to fulfil your purchase, deliver activation codes, and provide the WiFi service.
  • Legitimate interests (Art. 6(1)(f)) — fraud prevention, dispute handling, and service improvement.
  • Legal obligation (Art. 6(1)(c)) — tax records and Ofcom regulatory compliance.

4. How we use your data

  • Processing your payment and delivering your Pass.
  • Sending activation codes by email.
  • Granting your device access to the festival WiFi network.
  • Processing refunds and recording refund reasons.
  • Handling payment disputes and chargebacks via Stripe.
  • Compiling anonymised aggregate statistics for capacity planning.

We do not use your data for marketing, profiling, or automated decision-making.

5. Who we share your data with

We share data only with parties necessary to deliver the Service:

  • Stripe — payment processing and fraud detection. Stripe processes your card data under its own PCI-DSS-compliant systems.
  • Heal Festival — event coordination and on-site support at Info Points.
  • Network infrastructure provider — receives your activation code and device identifier solely to grant your device network access.

We never sell your data to third parties. We do not share it with advertising networks.

6. Data retention

Personal data (email, activation codes, transaction records, device identifiers) is retained for 6 months after the festival ends (after 12 September 2026), then permanently deleted.

Stripe retains payment records according to its own retention policy and applicable financial regulations; the Operators do not control Stripe’s retention of payment data.

You may request deletion of your data at any time before the retention period expires (see Your rights below).

7. Your rights under UK GDPR

You have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your data.
  • Restriction — ask us to limit processing in certain circumstances.
  • Objection — object to processing based on legitimate interests.
  • Data portability — receive your data in a structured, machine-readable format.

To exercise any of these rights, email info@ethicaladvertising.uk. We respond within 30 days.

8. Cookies

We do not use tracking, analytics, or advertising cookies on the WiFi pass purchase flow. Stripe may set essential session cookies during the checkout process to secure your payment. No cookies are used to build a profile of your behaviour.

9. Security

Your data is stored in a database protected by row-level security policies, with encryption at rest. Access to personal data is restricted to authorised Operators and crew staff. Card data is never stored by the Operators — it is handled exclusively by Stripe under PCI-DSS compliance.

10. Complaints

If you have a concern about how we handle your data and we cannot resolve it, you have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.

11. Contact

For any questions about this Privacy Policy or to exercise your data rights, contact us at info@ethicaladvertising.uk.

See also our Terms of Service.