Who we are

Hut & Tide is operated by Darren Swan, trading as Hut & Tide, based in Dorset, United Kingdom. We are the data controller for the personal data collected through this website.

If you have questions about this policy or about how we handle your data, you can contact us at [email protected].

What we collect

The personal data we collect depends on how you use the site. Here is what we may collect and when.

Data When collected
Name and email address When you create an account, make a booking, register as a hut owner, or sign up for email updates.
Phone number When you provide it as part of a booking or owner registration.
Booking details When you book a beach hut: the dates, the hut, the location and the amount paid.
Payment information When you make a payment. Card details are collected and processed by Stripe. We do not see or store your full card number.
Identity verification Stripe may collect proof of identity from hut owners setting up a payment account, as required by their financial regulations. This is handled entirely by Stripe.
Messages When you send a message to a hut owner or to us through the platform.
Email marketing preferences When you subscribe to or unsubscribe from our email updates.
Device and usage data When you browse the site: pages visited, browser type, device type, approximate location (country level). Collected through Google Analytics 4 with your consent. See our cookie policy for details.

Why we collect it

Under UK GDPR, we must have a lawful basis for processing your personal data. The bases we rely on are:

  • Contract: We need your name, email and booking details to fulfil a booking you make through the platform. Without this data, we cannot process your reservation or put you in contact with the hut owner.
  • Consent: We send marketing emails only if you have actively opted in. You can withdraw consent at any time by clicking the unsubscribe link in any email or by contacting us.
  • Legitimate interest: We use analytics data to understand how the site is used and to improve it. We keep records of bookings and messages to resolve disputes and provide customer support.
  • Legal obligation: We may need to retain certain transaction records to meet tax and accounting requirements.

Sharing your details with hut owners

When you book a beach hut through Hut & Tide, we share your name and contact details with the hut owner or manager so they can provide you with check-in instructions, key collection details and any information you need for your hire.

This is necessary to fulfil the booking. The hut owner receives only the information they need to manage your hire. They do not receive your payment card details.

Hut owners are required to use your details only for the purpose of managing the booking. They must not add you to their own marketing lists or share your details with anyone else.

We never pass your personal details to any third party outside of a rental agreement. We do not sell, rent or trade your data to advertisers, data brokers or any other organisation.

Marketing emails

We use MailerLite to manage our email marketing. If you sign up for email updates (for example, to be notified when beach huts become available in your area), we store your email address and any preferences you provide (such as your preferred location) in our MailerLite account.

We will only send you marketing emails if you have given your explicit consent to receive them. We will never subscribe you to marketing emails as a side effect of making a booking or creating an account.

Every marketing email we send contains an unsubscribe link. You can also manage your preferences or unsubscribe entirely by contacting us at [email protected]. We will process your request promptly.

Transactional emails (booking confirmations, check-in instructions, password resets) are not marketing. These are sent as part of the service and do not require separate marketing consent.

Payment processing

Payments are processed by Stripe. When you enter your card details during checkout, that information goes directly to Stripe's servers. We do not see, handle or store your full card number at any point.

Stripe may collect additional information from you as part of their fraud prevention and regulatory requirements, including device data and, for hut owners setting up payout accounts, identity verification documents. Stripe processes this data under their own privacy policy, which you can read at stripe.com/gb/privacy.

Cookies

This website uses cookies for essential functionality, analytics, marketing and payment processing. For full details of which cookies are set, what they do and how to manage your preferences, please read our cookie policy.

You can change your cookie preferences at any time by clicking the cookie icon in the bottom-left corner of any page.

Third-party services

We use a small number of third-party services to operate the platform. Each service processes data under its own privacy policy. Here is who they are and what they do.

Service What it does Privacy policy
Stripe Processes payments, holds deposits, manages owner payouts and performs fraud detection. stripe.com/gb/privacy
Google Analytics 4 Collects anonymised usage data to help us understand how visitors use the site. Only active with your consent. policies.google.com/privacy
MailerLite Manages email newsletter subscriptions and sends marketing emails. Only stores your data if you subscribe. mailerlite.com/legal/privacy-policy
Cookie-Script Manages the cookie consent banner and stores your cookie preferences. cookie-script.com/privacy-policy
Google Fonts Loads typefaces used on the website. Does not set cookies but makes server requests that Google may log. Google Fonts privacy FAQ

We do not share your personal data with any other third-party services, advertisers or data brokers.

International data transfers

Some of the third-party services we use (Stripe, Google Analytics, MailerLite) process data on servers located outside the United Kingdom, including in the United States and the European Economic Area.

Where data is transferred outside the UK, these providers rely on safeguards recognised under UK data protection law, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office, or they are certified under frameworks that provide an adequate level of protection. You can find details of the specific safeguards in each provider's privacy policy linked above.

We only use providers that we are satisfied offer appropriate protection for your data.

How long we keep your data

  • Account data (name, email, phone): kept for as long as your account is active. Deleted when you request account closure (see below).
  • Booking records: kept for six years after the booking completes, as required for tax and accounting purposes.
  • Messages: kept for as long as the associated booking record is retained, then deleted.
  • Marketing subscribers: kept until you unsubscribe. Once you unsubscribe, your email address is removed from our active marketing list. MailerLite may retain a suppression record to ensure we do not email you again.
  • Analytics data: retained by Google Analytics according to their standard data retention settings (currently 14 months for GA4). We do not export or store analytics data that identifies individuals.

Your rights under UK GDPR

Under UK data protection law, you have the following rights in relation to your personal data:

  • Right of access: You can request a copy of the personal data we hold about you. We will respond within one calendar month of receiving your request.
  • Right to rectification: If any data we hold about you is inaccurate or incomplete, you can ask us to correct it.
  • Right to erasure: You can ask us to delete your personal data. See the account closure section below for how this works in practice.
  • Right to restrict processing: You can ask us to limit how we use your data while a complaint or correction request is being resolved.
  • Right to data portability: You can request your data in a structured, commonly used format so you can transfer it to another service.
  • Right to object: You can object to processing based on legitimate interest. You can also object to receiving marketing emails at any time.
  • Right to withdraw consent: Where we process data based on your consent (marketing emails, analytics cookies), you can withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.

To exercise any of these rights, email us at [email protected]. We will verify your identity before processing your request and respond within one calendar month. If your request is complex or we receive a large number of requests, we may extend this by a further two months, but we will let you know within the first month if that is the case.

If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO). You can contact the ICO through their website at ico.org.uk or by phone on 0303 123 1113.

Account closure and deletion

You can request closure of your account and deletion of your personally identifiable information at any time by emailing us at [email protected].

When we process an account closure request, we will:

  • Delete your account profile, including your name, email address, phone number and any saved preferences.
  • Remove your details from any active marketing lists.
  • Anonymise any booking records that we are required to retain for tax purposes. This means the record will exist for accounting, but your name and contact details will be removed from it.
  • Delete any messages associated with your account.

We will confirm deletion by email within one calendar month of your request. Some data may persist in encrypted backups for a short period after deletion, but it will not be used or accessible and will be permanently removed when the backup cycle completes.

Children

Hut & Tide is not intended for use by anyone under the age of 18. You must be at least 18 years old to create an account, make a booking or list a beach hut. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected data from someone under 18, we will delete it promptly.

Security

We take reasonable technical and organisational measures to protect your personal data from unauthorised access, loss, misuse or alteration. These include:

  • All data transmitted between your browser and our servers is encrypted using HTTPS/TLS.
  • Payment card data is handled entirely by Stripe and never touches our servers.
  • Access to personal data within our systems is restricted to authorised personnel only.
  • Our database is hosted on infrastructure with regular security updates and automated backups.

No system is completely secure. If you become aware of any security issue affecting your account, please contact us immediately at [email protected].

Changes to this policy

We may update this privacy policy from time to time, for example if we add new services, change how we process data, or if the law changes. When we update it, we will change the "last updated" date at the top of this page. If the changes significantly affect how we handle your personal data, we will notify you by email or through a notice on the website.

Contact us

If you have questions about this privacy policy, want to exercise any of your data rights, or have a concern about how we handle your personal data, please contact us at:

Hut & Tide
Email: [email protected]

You also have the right to contact the Information Commissioner's Office at ico.org.uk if you have a concern about how your data is being handled.