Privacy notice

MAILING LIST

What information do we collect?

If you sign up to join our mailing list through our website, you will be asked to enter your email address and this is the only information we collect from you, in order to send you emailed newsletters.

If you choose to join our mailing list when purchasing tickets through Tall Stories Tickets, we will receive contact information about you comprising: your name, address and email address, and about the booking comprising the performance you are planning to attend, the seat locations booked, the booking reference, seat prices, amounts paid and when the booking was made.

We do not receive any financial data from you such as credit card information. We do not receive any special categories of data such as sensitive information or information about children. We do not carry out any automated decision making or profiling on your data.

Consent is the legal basis for processing information when you sign up to our mailing list and agree to receive email communications from us.  Your consent can be withdrawn at any time, either by using the unsubscribe link on each emailed newsletter or by contacting us directly on tallstories@subjectaccessrequests.org.
 

What do we use your information for?

If you select to receive emailed newsletters from us, we will email you approximately 6-12 times per year.  Our newsletters contain information on forthcoming productions and company news.

If we are storing additional data (see above), we may use this to conduct research into the audiences we are reaching, which can help us achieve our aims as a charity. This information will never be used to contact you without your consent and will never be passed onto third parties.
 

How do we protect your information?

Only we will receive and have control of your data. We do not sell or otherwise transfer control of your data to anyone else. In order to process the data (for example to store it securely or make it available for sending you information), we engage companies who have the facility to process data securely. We only permit those companies to process your data if we have a written agreement with them. They are only permitted to process the data in ways that we instruct them in that agreement and which are consistent with the privacy notice.

We implement a variety of security measures to maintain the safety of your personal information. If you have signed up to our mailing list through our website, the data is held in our account on the email marketing site MailChimp. We have two-factor security procedures in place to ensure that this data cannot be accessed by anyone other than authorised employees. The data is not stored on Tall Stories servers or in a physical form.
 

How can you stop receiving newsletters once you’ve signed up?

You are given the option to unsubscribe from receiving news from us with every emailed newsletter, or you can email us at tallstories@subjectaccessrequests.org and your data will be removed from our list.
 

SHOP

What information do we collect?

When you make a purchase in our online shop the transaction is processed through PayPal. Some information about your transaction is stored on our website server and we receive an order confirmation email from PayPal to let us know you have made a purchase. This information consists of your name, email address, the item(s) you ordered, the total payment due for your order, the time and date of the transaction and the shipping address.

Since all payments are processed through PayPal we never have access to your financial information.
 

What do we use your information for?

We use this information to fulfil your order. Records are kept in case there is a problem with your order and we need to check the transaction history. We will only use your email address to contact you if there is a problem with your order; these are not added to any mailing list or shared with any third parties.
 

How do we protect your information?

The data stored on our website server is secure password-protected and is deleted every three months. The data about your transaction that we receive by email is deleted once we have fulfilled your order. Records of the transaction are kept on our PayPal account.
 

WEBSITE AND COOKIES

We use third-party analytics services on our site, such as Google Analytics. The analytics providers that administer these services use technologies such as cookies, web server logs and web beacons to help us analyse your use of our website. The information collected through these means (including IP address) may be disclosed to these analytics providers and other relevant third parties who use the information, for example, to evaluate use of the website.

Cookies are small text documents that are stored by your web browser on your computer or mobile device when you visit our website. They enable an enhanced experience for you by storing things such as your user details or preferences. They don’t tell us who you are.  You can decide whether or not to allow cookies on your computer. The cookies we use are listed below:

Google Analytics:

Cookie name: _ga
Purpose: Used to distinguish users
Duration of cookie: 2 years

Cookie name: _gid
Purpose: Used to distinguish users
Duration of cookie: 24 hours

Cookie name: _gat
Purpose: Used to throttle request rate
Duration of cookie: 1 minute

ExpressionEngine CMS:

Cookie name: exp_last_visit
Purpose: Sets the date/time that the user last visited the site
Duration of cookie: 1 year

Cookie name: exp_tracker
Purpose: Tracks the last five pages viewed by the user, and is used primarily for redirection after logging in, etc.
Duration of cookie: 1 year

Cookie name: exp_last_activity
Purpose: Used to determine page expiry for logged in members
Duration of cookie: 1 year

Cookie name: exp_csrf_token
Purpose: Helps ensure that form submissions are genuine
Duration of cookie: 1 hour

Cookie name: exp_store_cart
Purpose: Keeps a hashed reference to your shopping cart once you’d added an item
Duration of cookie: 1 day
 

EMPLOYMENT

Job Applications

If you contact us for casting or employment purposes, we will retain your information that you provide to us in digital and physical forms for up to three years, after which time the data will be securely destroyed. You may contact us at any time to request that we destroy any copies of your personal data and we will always comply.
 

Employment Contracts

By signing a contract of employment with us, you agree to your personally identifiable information including, but not limited to, your address, phone number, bank details and email address being kept on file for the duration of this contract and for the following twelve months. Your information will be stored securely and will not be shared with anyone outside of Tall Stories. After twelve months following the end of the contract, your contact and bank information will be erased from all files, physical and online, except where we are required to keep records under employment law.

However, we would like to keep your email address and phone number on file following the twelve months after your contract has ended to keep in touch regarding any future work opportunities. These contact details will be stored securely and will not be shared with anyone outside of the company. We will obtain your consent in order to keep this data.
 

General

Your rights

You have the right to be informed whether your personal data is being processed by us or under our instruction. This Privacy Notice complies with that right.

You have the right to know what information is comprised in the personal data of yours that we process or is processed under our instruction. This Privacy Notice complies with that right.

You have the right to withdraw your consent for us to process your personal data at any time, including immediately after you have provided it if you simply change your mind. If you do so in writing to us at the address below for Subject Access Requests we will delete your data from our records and we will instruct anyone we allow to process your data for us to do the same within a reasonable amount of time.

You have the right to require us to correct any personal data of yours which we process which is incorrect. You may do this verbally or in writing.

You have the right to object to the processing of your data for direct marketing. By giving your consent, you grant us permission to market our products and services directly to you. Each time we do this we will provide a method by which you can withdraw your consent which will also exercise your right to object.
 

Do we disclose any information to outside parties?

We do not sell, trade, or otherwise transfer to outside parties your personally identifiable information. This does not include trusted third parties who assist us in operating our website, conducting our business, or servicing you, with whom we hold data protection agreements that ensure this information is kept confidential. We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect our or others’ rights, property, or safety.
 

Third party links

On our site we provide links to other sites, for example theatres’ websites where you can buy tickets for our productions. These third party sites have separate and independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked sites and we do not receive data from them. Nonetheless, we seek to protect the integrity of our site and welcome any feedback about these sites.
 

Contacting us

We may from time-to-time make changes to this information, in order to comply with latest legislation.  If you have any questions regarding this privacy information you may contact us using the information below:

Tall Stories, Somerset House, West Wing Strand, London WC2R 1LA

info@tallstories.org.uk

020 8348 0080
 

Subject Access Requests

To make a Subject Access Request or to contact us about anything else concerning the use of your personal data as a result of your granting consent, please email us at tallstories@subjectaccessrequests.org. There will be no charge for this.