Norfolk Tide Times
Back to tide tables

Privacy

The short version: if you buy something, Stripe collects an email address so we can identify and re-send your order. We use Google Analytics to see which tide pages people use, and only if you accept it — nothing loads until you do. There is no marketing list, and nothing is ever sold or shared for advertising.

Last updated 13 August 2026

Who is responsible for your data

Norfolk Tide Times is a trading name of FHCM Commercial Activities, a sole trader at 5 Avondale Road, South Creake, Norfolk, NR21 9PH, United Kingdom. We are the data controller for everything described on this page.

For anything about your data — or a problem with a file you bought — email ahoy@norfolktidetimes.co.uk.

What we process, and why

Reading the free tide tables requires nothing from you at all — no sign-up, no account, no name. The list below applies from the moment you start a purchase.

  • Your email address

    Stripe collects it with your payment. We use it to identify your order — so we can reissue your download link if you lose it, and reply if you contact us. We do not send marketing.

    Lawful basis · Performance of a contract (Art. 6(1)(b)) — we need it to support and reissue what you bought.

  • Your payment details

    To take the £20. These go straight to Stripe. We never see or hold your card number.

    Lawful basis · Performance of a contract (Art. 6(1)(b)).

  • Which location you bought

    To build the right calendar file and to reissue it if you lose the link.

    Lawful basis · Performance of a contract (Art. 6(1)(b)).

  • Google Analytics — pages you view, roughly where you are, your device and browser, and a random identifier stored on your device

    To see which tide pages people actually use, so we know what to improve. This only happens if you press Accept on the cookie banner. If you reject it, or ignore it, none of it is collected and Google’s script is never loaded.

    Lawful basis · Consent (Art. 6(1)(a)) — freely given, and you can withdraw it at any time using “Cookie settings” at the bottom of any page.

  • Server logs — IP address, page requested, timestamp, browser user agent

    To keep the site up, spot abuse, and diagnose faults.

    Lawful basis · Legitimate interests (Art. 6(1)(f)) — keeping a small site secure and working.

  • Fraud signals collected by Stripe at checkout

    To stop stolen cards being used. Stripe does this for every merchant it serves.

    Lawful basis · Legitimate interests (Art. 6(1)(f)) — preventing payment fraud.

There are no accounts, no passwords, no profiling, no automated decision-making, and no special category data. We do not knowingly collect anything from children, and there is nothing on this site aimed at them.

Cookies and analytics

Nothing is stored on your device, and no third-party script is loaded, until you have made a choice. On your first visit a banner asks whether you accept analytics. Until you answer, this site has set nothing at all — no cookie, no identifier, no pageview. Accept and Reject are the same size, in the same place, and either one dismisses the banner for the same length of time.

If you accept, the page loads Google Analytics 4 and Google sets two cookies — _ga and a second beginning _ga_ — which last two years and hold a randomly generated identifier. Google receives the pages you view, roughly where you are, and what device and browser you use. We look at this in aggregate to see which tide pages get used; we do not try to identify anyone, and we do not run advertising or remarketing features.

If you reject, or if you never answer, Google's script is never requested and no analytics cookie is ever set. The only thing kept is your answer itself, stored in your browser's local storage — not a cookie, and never sent to us — for about six months, after which the banner asks again.

You can change your mind at any time with Cookie settings at the bottom of any page. Switching to Reject stops any further collection immediately. To be straight with you about what that does and does not do: it does not reach back and delete cookies Google has already set, or data already sent. Your browser's own settings will clear those.

With JavaScript turned off, none of this runs — no banner, and no analytics either. The typefaces are served from this site rather than from Google Fonts, so if you have not accepted analytics, nothing is fetched from a third party while you read a tide table.

Two further cookies appear only if you start a purchase, whatever you chose above. When you press Continue to payment, the page loads Stripe's checkout script for the first time, and Stripe sets:

  • __stripe_mid

    Fraud prevention. Lasts 12 months.

  • __stripe_sid

    Fraud prevention within a single checkout. Lasts 30 minutes.

Both exist to stop stolen cards being used, which is exactly what regulation 6(4) of the Privacy and Electronic Communications Regulations calls strictly necessary for a service the user has requested. Consent is not required for cookies of that kind, so the banner does not cover them — it asks about analytics, and nothing else. If you never start a purchase, no Stripe cookie is ever set and Stripe's script is never loaded, whatever you answered.

Who else touches your data

Stripe is our payment processor. Stripe collects your card details and your email address directly through its own embedded checkout — those details never pass through this site. Stripe acts as our processor for order data and as its own controller for fraud prevention and its regulatory duties. Read stripe.com/privacy.

Google receives analytics data, and only from visitors who accepted it. Google acts as our processor for that data, and it is processed on servers outside the UK, including in the United States. That transfer is made under the UK–US Data Bridge (Google's self-certified extension of the EU–US Data Privacy Framework), with Standard Contractual Clauses behind it as a backstop, so the transfer stays covered if that framework ever falls away. If you would rather your data did not leave the UK at all, reject analytics (or change your answer under Cookie settings) and nothing is sent. Read policies.google.com/privacy.

Our hosting and email providers keep the site online and carry the message containing your download link. They process data only on our instructions and under written terms.

That is the whole list. We do not sell data, we do not share it with advertisers or data brokers, and we do not run a mailing list. If we are ever legally compelled to disclose something, we will, and we will tell you unless we are prohibited from doing so.

Where your data goes

Data is held in the UK and the European Economic Area wherever we can arrange it. Stripe is a global business and may process payment data in the United States and elsewhere. Where data leaves the UK, the transfer is covered by the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or by UK adequacy regulations for the destination country. Stripe's transfer terms are set out in its privacy policy, linked above.

How long we keep things

  • Order records — six years. Your email address, the location you bought and the amount paid. HMRC requires business records to be kept for six years from the end of the accounting period, so we cannot delete these earlier.
  • Server logs — 30 days, then deleted, unless a specific entry is part of an ongoing investigation into abuse.
  • Support emails — two years from the last message, so we can pick up a thread if you come back.
  • Payment data held by Stripe follows Stripe's own retention schedule, which is bound by financial regulation.

Your rights

Under the UK GDPR you can ask us for any of the following. Email ahoy@norfolktidetimes.co.uk and we will answer within one month. It is free, and we will not make you justify the request.

  • Access

    Ask what we hold about you and get a copy.

  • Rectification

    Get anything wrong or incomplete corrected.

  • Erasure

    Ask us to delete it, where we do not need it for tax or legal records.

  • Portability

    Get the data you gave us in a machine-readable form, or sent elsewhere.

  • Restriction

    Ask us to pause processing while a dispute is sorted out.

  • Objection

    Object to anything we do on the legitimate interests basis above.

We may need to confirm you are the person who placed the order before we act — usually by replying from the email address used to buy.

Complaints

If we have got something wrong, tell us first — it is a small operation and we will fix it quickly. You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk or on 0303 123 1113. You do not have to come to us first.

Security

The site is served over HTTPS only. Card details are handled entirely by Stripe, a PCI DSS Level 1 service provider, and never reach our systems. Order records are held in access-controlled storage. No system is perfect, and if a breach ever put your rights at risk we would tell the ICO within 72 hours and tell you without delay.

Changes to this notice

If what we do with data changes, this page changes with it and the date at the top moves. We will not quietly start collecting more than is described here.

See also our terms of sale.