Privacy Policy
Sanctuary Stories - Privacy Policy
Last updated: 18/06/2025
Welcome to the Sanctuary Stories Privacy Policy. We know that you care how information about you is used and shared, and we appreciate your trust in us to do that carefully and sensibly. This Privacy Policy describes how we collect and use your personal information when you visit our website or use our Sanctuary Stories mobile or web application (the “App”) and tells you about your privacy rights.
Who we are
The controller is Sanctuary Stories Ltd (referred to as “Sanctuary”, “we”, “us” or “our”) in respect of your personal data.
If you have any questions about this privacy notice or how we use your personal data, please email contact@sanctuarystories.co.uk.
The personal data we collect about you
The types of data we collect include:
Identity Data: your first name, surname, date of birth and email address.
Financial Data: your bank account, payment card details and other data necessary for processing payments (if applicable).
Transaction Data: details of payments made by you (if applicable) and services you have subscribed to.
Usage Data: information about how you use our services, for example your reading or listening history, saved stories, stories or authors you have engaged with or search history.
Profile Data: your username and password, your preferences, any feedback and survey responses.
Content Data: information that you store or generate via the App, including in relation to stories that you produce or content that you may engage with.
Digital Information Data: IP address, geographical location (country only), type of device, name of device, operating system, app version, app settings.
Marketing Preferences: your preferences in receiving marketing from us and any third parties.
Other information you provide to us: other information you might need to provide to us, for example to allow us to assist you with a support or troubleshooting matter.
We also collect and use aggregated data such as statistical or demographic data which is not personal data as it does not identify you as an individual. For example, we may aggregate individual users’ Usage Data to calculate the percentage of users accessing specific content, advertising or features in order to analyse trends in how users are interacting with our App and content to help monitor and improve our service offering.
We do not intentionally collect any special categories of personal data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data).
It is important that the personal data we hold about you is accurate and current. Please notify us of any changes to your Identity Data by updating your account as soon as possible.
How we collect your personal data
You may give us your personal data by filling in online forms (to create your user account and subscribe to any services we offer via the App) and by interacting with us (to email us, to respond to survey or feedback requests or otherwise). We also automatically collect data about how you use our services via the App including the content you have accessed or inputted and any comments or reviews you submit.
You will also share personal data via the App if you voluntarily include it in any content that you make available via the App. This could include your username, profile description in the App and any personal data you include in content you post – these types of personal data in content you post will be visible to other users as well as us.
Our systems also automatically record information technical data about how you use the App including the location (country level), IP address and usage patterns. We collect these types of technical data by using cookies. We also use third party analytics providers and advertising networks to collect data about how you use the App.
How we use your personal data
We will only use your personal data when the law allows us to do so. Most commonly we will use your personal data in the following circumstances:
Where we need to perform a contract we are about to enter or have entered with you.
Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
Where we need to comply with a legal or regulatory obligation.
Where you have consented before the processing.
Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. We have set out in a table below a description of all the ways we plan to use your personal data and the legal basis we rely on to do so. We have also identified what our legitimate interests are where appropriate. Whenever we process your personal data under the ‘legitimate interest’ lawful basis, we make sure that we take into account your rights and interests and will not process your personal information if we feel that there is an imbalance.
We may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please see the below table for the purposes for which we will use your personal data:
Purpose/activity | Type of data | Lawful basis for processing | ||
---|---|---|---|---|
To register you as a user of our services | Identity Data, Profile Data, | Performance of a contract with you | ||
To deliver our services to you including identifying you as a user within the App, making content available, making recommendations to you and enforcing the terms of use for using the service | Identity Data, Transaction Data, Profile Data, Usage Data, Content Data | Performance of a contract with you | ||
To manage our relationship with you including notifying you of changes to our services or provide you with technical support and/or troubleshooting assistance | Identity Data, Content Data, Profile Data, Usage Data, Digital Information Data | Performance of a contract with you | ||
Necessary for our legitimate interests (to keep records updated and to analyse how customers use our services) | ||||
To administer and protect our business including troubleshooting, data analysis, system testing, maintenance, reporting and hosting data, prevention of spam, fraud and abuse | Identity Data, Usage Data, Digital Information Data | Necessary for our legitimate interests (for running our business | provision of administration and IT services | network security) |
To measure and analyse the effectiveness of the content | recommendations and advertising we serve you | |||
,"Identity Data, Content Data, Profile Data, Usage Data, Digital Information Data | Necessary for our legitimate interests (to monitor how users use our services and to develop our services and grow our business) | |||
To manage payment of fees for the service (where applicable) and recover money owed to us | Identity Data, Financial Data | Performance of a contract with you | ||
To use data analytics to improve our services, user relationships and experiences and to measure the effectiveness of our communications and marketing | Usage Data, Digital Information Data | Necessary for our legitimate interests (to define types of users for our services, to keep our services updated and relevant, to develop our business and to inform our marketing strategy) | ||
To serve advertising via the App, make personalised suggestions and recommendations about content and send you relevant marketing communications and services that may be of interest to you based on your Profile Data | Identity Data, Usage Data, Profile Data, Digital Information Data, Marketing preferences | Necessary for our legitimate interests (to serve advertising via the App, develop our products/services, grow our business and carry out marketing) | ||
To request feedback on our services and measure your satisfaction with our services | Identity Data, Usage Data, Profile Data | Necessary for our legitimate interests (to study how users use our services and to help us improve and develop our products and services). |
Advertising and marketing
As our App is made available without charge, users will be served with advertising (which may be for our own as well as third party products) via the App.
You may also receive direct marketing communications from us if you did not opt out of receiving marketing as part of your Marketing Preferences when you first set up your account. Please note that you can change your Marketing Preferences at any time by going into your account or following the opt-out links in any marketing communications we send to you.
Disclosures of your Personal Data
We share your personal information only with the people who need to handle it so we can provide our services to you. This includes:
Our staff engaged in providing you with our services.
Suppliers who provide us with products and services or support to the App and our platforms and systems. This includes our data hosting and data storage providers, payment processors and data analytics platforms. Please contact us for further details of our suppliers.
Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy policy.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
We may also share your personal data with law enforcement authorities and other competent authorities as required and to the extent allowed by relevant data protection laws.
International transfers
Whenever we transfer your personal data out of UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the UK government.
Where we use certain service providers, we may use specific contracts approved by the UK government which give personal data the same protection it has in the UK.
Please contact us if you want further information on any specific mechanisms used by us when transferring your personal data out of the UK.
How we store your personal information
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. All information you provide to us is stored on secure servers and located in the UK.
We have put in place procedures to detect and respond to personal data breaches and notify you and any applicable regulator when we are legally required to do so.
Data retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, regulatory, tax, accounting or reporting requirements.
When determining the specific retention period, we consider various factors, such as the nature of the personal data, the potential risk of harm from unauthorised use, the purposes for which we process your personal data (including the type of service provided to you), the nature and length of our relationship with you, and mandatory retention periods provided by law and any relevant statute of limitations. If you want to learn more about our specific retention periods for your personal data, please email us at contact@sanctuarystories.co.uk
Upon expiry of the applicable retention period we will securely destroy your personal data in accordance with applicable laws and regulations. Alternatively in some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely.
Your data protection rights
You have a number of rights under data protection laws in relation to your personal data.
Your right of access - You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for.
Your right to rectification - You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete.
Your right to erasure - You have the right to ask us to delete your personal information. We may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you at the time of your request.
Your right to restriction of processing - You have the right to ask us to limit how we can use your personal information.
Your right to object to processing - You have the right to object to the processing of your personal data. Where this relates to use of your personal data for direct marketing, you can opt out at any time by changing your Marketing Preferences via your account.
Your right to transfer of your data - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you – however this only applies where processing is carried out by automated means.
Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time.
Third party links
Our platform may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.
Changes to the privacy notice and your duty to inform us of any changes
You agree that we may change, update or otherwise amend our privacy policy from time to time. We will make the updated policy available on our website.
If we update our privacy policy, you are free to decide whether to accept the changes or to stop using our services, website and platforms. If you continue to use our services after we have made any changes, you will be deemed to have accepted the changes.
It is important that the personal data we hold about you is accurate and current. Please notify us of any changes to your contact details by updating your account as soon as possible.
Contact us:
For any questions regarding this Policy, our processing of your personal data, or to exercise your rights, please email us at contact@sanctuarystories.co.uk.
If you are in the UK, you have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk).
If you are based outside the UK, you may have the right to lodge a complaint with your local data protection authority. If you are unsure who that is, please contact us and we will do our best to direct you to the appropriate body.
We would, however, appreciate the chance to deal with your concerns before you approach the ICO or other regulatory body so please contact us in the first instance.