Privacy
Last updated
This page is a starting structure, not legal advice, and it is not complete. A platform like this one holds two kinds of personal data and is in a different legal role for each: you are the controller of your own users’ data, and a processor of the data belonging to the customers who book through your tenants’ storefronts. Those two roles carry different obligations, and a single privacy policy that does not separate them is the mistake this structure exists to prevent. This is template text: consult a lawyer and adapt every paragraph below to what your company actually does before publishing.
Who we are
Turnhouse Systems, Bristol, United Kingdom. Questions about this policy go to the email address on the contact page.
The two roles, and why this page has two halves
When you visit this website or hold an account in the console, we decide what is collected and why. In the language of data protection law we are the controller for that data, and the first half of this page describes it.
When one of our customers uses Turnhouse to take a booking from one of their customers, we hold that booking on their behalf and act on their instructions. For that data we are a processor, our customer is the controller, and the second half of this page describes what that means for the person who made the booking.
Half one: data we control
What this website collects
The demo request form collects a name, a work email address, a company name, how many locations you run, and anything you write in the message box. That is all it collects, and it is the minimum needed to reply to you and to arrange a demo that is worth your time.
The site sets no analytics or advertising cookies and embeds no third-party
tracking. If you add analytics later, this paragraph has to change and so does
the Content-Security-Policy in public/_headers.
What a console account holds
An account holds a name, a work email address, the role and locations it is scoped to, and a record of the changes it has made. That last one is the audit log, and it exists because a platform where money and time are agreed needs to be able to answer who changed what.
What we do with it
We use it to run the product and to reply to you. We do not sell it, and we do not use it to train anything.
How long we keep it
Demo requests are kept for twelve months. Account data is kept for as long as the account exists, and audit records for twenty-four months after the change they describe.
Half two: data we process for our customers
Bookings made through a storefront
If you booked something through a site that runs on Turnhouse, the company you booked with is responsible for that data and decides what happens to it. We hold it for them, under a contract that says what we may and may not do with it.
Your rights, and who to ask
Ask the company you booked with. They can answer questions about their own records, correct them and delete them; we can only act on their instruction. Their contact details are on the site you booked through. If you cannot reach them, write to us and we will point you at them.
What we do not do with it
We do not use one customer’s booking data for another customer, we do not aggregate it into a product of our own, and we do not sell it.
Where data is held
Name the regions and the sub-processors you actually use. This is the section a business buyer reads most carefully, and the one they will ask you to put in writing anyway — writing it here first saves a round of email.
Changes to this policy
The date at the top is the date this page last changed.