Back to Home

Privacy Policy

Last updated: April 2026

Stones & Stories (“we,” “us,” or “our”) is committed to protecting your privacy. This privacy policy explains how we collect, use, store, and protect your personal data when you use our website (stonesandstories.co.uk) and our interactive treasure hunt experiences.

We are the data controller for the personal data we process. This policy is written in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025.

Data Controller

Stones & Stories

Operated by Hutton

Dartmouth, Devon, United Kingdom

Email: support@stonesandstories.co.uk

What Personal Data We Collect

We collect the following personal data:

When you purchase an access code:

  • Full name
  • Email address
  • Phone number (optional)
  • Payment information (processed by Stripe — we do not store your card details)

When you use the treasure hunt app:

  • Team name (chosen by you)
  • Hunt progress (which stops you have completed, your answers, and your score)
  • GPS/location data (processed locally on your device to determine proximity to stops — we do not store or track your location on our servers)
  • Selfie photo (optional — only if you choose to take one at the end of the hunt)

When you visit our website:

  • IP address and browser information (collected automatically via cookies and analytics tools)
  • Pages visited and interactions (collected via Google Analytics and Microsoft Clarity)

How We Use Your Data

We use your personal data for the following purposes:

To deliver the service (Legal basis: Contract):

  • Processing your payment and sending your access code
  • Enabling the treasure hunt experience (progress tracking, clue delivery, leaderboard)
  • Sending your purchase confirmation email
  • Customer support

To improve our service (Legal basis: Legitimate Interest):

  • Analysing hunt completion rates and clue difficulty to improve the experience
  • Understanding website usage patterns through analytics
  • Microsoft Clarity session recordings to identify usability issues (these recordings do not capture passwords or payment information)

To market our service (Legal basis: Consent or Legitimate Interest):

  • If you consent, sharing your selfie photo on our social media channels
  • Sending you information about new hunts or experiences (only with your explicit consent)

How We Share Your Data

We share your personal data with the following third-party service providers who help us deliver our service:

  • Stripe (payment processing) — processes your payment securely. Stripe's privacy policy: stripe.com/privacy
  • Resend (email delivery) — sends your purchase confirmation and access code emails. Resend's privacy policy: resend.com/legal/privacy-policy
  • Google Analytics (website analytics) — collects anonymous website usage data. Google's privacy policy: policies.google.com/privacy
  • Microsoft Clarity (session analytics) — records anonymised session replays to help us improve usability. Microsoft's privacy policy: privacy.microsoft.com
  • Mapbox (map display) — provides the map within the treasure hunt app. Mapbox's privacy policy: mapbox.com/legal/privacy

We do not sell your personal data to third parties. We do not share your data with any parties other than those listed above.

Leaderboard

If you complete the treasure hunt, your team name, completion date, time, and score may be displayed on our public leaderboard at stonesandstories.co.uk/leaderboard. Your real name, email address, and other personal details are never shown on the leaderboard.

You can request removal of your team from the leaderboard at any time by contacting us at support@stonesandstories.co.uk.

Selfie Photos

If you choose to take a selfie at the end of the hunt, you will be asked whether you consent to us sharing the photo on our social media channels. If you give consent, we may use the photo on our Instagram, TikTok, or Facebook pages.

You can withdraw your consent at any time by contacting us at support@stonesandstories.co.uk and we will remove the photo.

If you do not give consent, your photo will still be saved for your personal use on the completion screen but will not be used by us for any marketing purposes.

Cookies and Tracking

Our website uses cookies and similar technologies:

  • Essential cookies: Required for the website to function, including storing your access code in local storage so your hunt progress is preserved between visits.
  • Analytics cookies: Google Analytics and Microsoft Clarity use cookies to collect anonymised data about how visitors use our website. This helps us understand which pages are popular and how we can improve the experience.

You can control cookies through your browser settings. Disabling essential cookies may affect the functionality of the treasure hunt app (for example, your progress may not persist between sessions).

Data Retention

We retain your personal data for the following periods:

  • Purchase and customer data (name, email, phone): Retained for 6 years from the date of purchase for tax and accounting purposes, in accordance with HMRC requirements.
  • Hunt progress data (team name, scores, answers): Retained indefinitely for leaderboard purposes unless you request deletion.
  • Selfie photos: Retained for 2 years or until you request deletion, whichever is sooner.
  • Analytics data: Google Analytics and Microsoft Clarity retain data in accordance with their own retention policies. We have configured Google Analytics to retain data for 14 months.
  • Access codes: Retained for 12 months after expiry for customer support purposes, then deleted.

Data Security

We take appropriate technical and organisational measures to protect your personal data, including:

  • All data transmitted between your browser and our servers is encrypted using HTTPS/TLS
  • Payment processing is handled entirely by Stripe, who are PCI DSS Level 1 certified — the highest level of payment security
  • Access to customer data is restricted to authorised personnel only via a password-protected admin panel
  • Our database is hosted with industry-standard security measures

Your Rights

Under UK GDPR, you have the following rights:

  • Right of access: You can request a copy of the personal data we hold about you.
  • Right to rectification: You can ask us to correct any inaccurate data we hold about you.
  • Right to erasure: You can ask us to delete your personal data, subject to our legal obligations (such as tax record retention).
  • Right to restrict processing: You can ask us to limit how we use your data.
  • Right to data portability: You can request your data in a structured, commonly used format.
  • Right to object: You can object to our processing of your data based on legitimate interests.
  • Right to withdraw consent: Where we process data based on your consent (such as selfie sharing), you can withdraw that consent at any time.

To exercise any of these rights, email us at support@stonesandstories.co.uk. We will respond within one month.

Children’s Privacy

Our treasure hunt is designed primarily for adults. We do not knowingly collect personal data from children under 16. The purchase process requires a payment card, which is typically held by an adult. If we become aware that we have collected data from a child under 16 without parental consent, we will delete it promptly.

International Data Transfers

Your data may be processed outside the UK by our third-party service providers (Stripe, Google, Microsoft, Mapbox). Where this occurs, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses or adequacy decisions, in accordance with UK GDPR requirements.

Changes to This Policy

We may update this privacy policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically.

Complaints

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Website: ico.org.uk

Phone: 0303 123 1113

We would appreciate the opportunity to address your concerns before you contact the ICO. Please email us at support@stonesandstories.co.uk in the first instance.

Contact Us

If you have any questions about this privacy policy or how we handle your personal data, please contact us:

Email: support@stonesandstories.co.uk

Stones & Stories

Dartmouth, Devon, United Kingdom