Learn about how Arc Guiding handles your personal data and privacy
Contents
This website
My website address is: https://arcguiding.com.
What personal data I collect and why I collect it
Comments
The following information is collected to prevent spam and assist with discussion and quality assurance:
- Comment data
- Email address
- Name
- IP address and browser user agent string
Reviews (including the reviewers name) may also be copied (in whole or part) and displayed on Arc Guiding social media channels including Facebook, Instagram, Google and Twitter. Comment data may also be collected from other communications, including emails, texts and hardcopy.
An anonymised string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
If you upload images to the website, you should consider uploading images without embedded location data (EXIF GPS). Visitors to the website can download and extract any location data from images on the website.
Enquiry and Booking Forms
A variety of personal data is collected from guests using digital enquiry and booking forms. This data includes:
- Name
- Address
- Age (or birthday)
- Medical conditions and experience
- Contact phone number
- Email address
- Accommodation address
- Photo/video consent
Similar information may also be submitted on the behalf of other adults or minors.
This information is vital for maximising the safety of guests, staff and general public whilst operating my guiding services. It is also collected for the purposes of detecting fraud, quality assurance and advertising. The information is essential for a booking to be confirmed and, depending on circumstances and activities, additional personal information may be requested.
This information is held securely in both digital and hardcopy format and is held only with the guests consent. Copies of this information can be obtained by the guest and will be provided within in a reasonable timeframe.
This information is also made available to the authorities and emergency services when there is a justifiable reason (for example, medical emergency or for the detection of crime).
By confirming a booking and signing our Terms and Conditions, guests consent to use of their data in this way. Your personal information is only retained for as long as necessary to achieve the above purposes, after which it is securely destroyed or anonymised.
Cookies
If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you have an account and you log in to this site, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracing your interaction with the embedded content if you have an account and are logged in to that website.
Analytics
Certain metrics on your browsing behaviour are collected by this website, in line with industry norms. These anonymous data may include the length of time you spend interacting with pages, your search terms and your IP address, amongst others. This data is collected in order to improve the design of the website and also help detect and guard against automated malicious programs.
Who we share your data with
Social media profiles. Anyone who connects/likes/follows/subscribes to our social media profiles (eg: Facebook, Twitter, Instagram, Linkedin, Google) enters into a separate agreement with that organisation. Users of these platforms are responsible for managing their own engagement with those companies.
Website analytics. The browsing behaviour of website users is shared with Google and collected internally by Arc Guiding, for the purposes of marketing and effective website design. Some analytics data may also be shared with our web developer ‘Yellow Cherry Digital’. Yellow Cherry Digital also has reasonable access to any data stored on this site.
Online payments. Card payments are handled via the well-known payment gateway Stripe and WooCommerce. Customers wishing to pay by online banking have the option to pay via their own online banking service as a direct bank transfer. In both cases, customers enter into a separate and direct relationship with those providers at time of payment.
Repuso is a review-collecting service which displays social media reviews left by my customers, on the website.
How long we retain your data
- Website users who leave a comment or review. The comment and its metadata are retained indefinitely. This is so we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.
- Website users who register an account. The personal information they provide is stored indefinitely. Registered users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Where we send your data
- Visitor comments may be checked through Akismet, an automated spam detection service.
- Basic booking information may in some cases be exported to Google and Microsoft software for administration purposes. All Google and Microsoft cloud accounts used by Arc Guiding are secured using up-to-date encryption technology and 2 Factor Authentication. Where a Google calendar is to be publicly displayed, all bookings will be anonymised.
Your contact information
Your contact and other details are securely retained electronically on this server, in a separate cloud account and as paper hardcopy. They may also exist for short periods of time on personal electronic devices owned by the company. They are not kept longer than necessary for the purposes mentioned above. Antivirus and Firewall protection is used throughout my digital storage and is updated regularly.
Additional information
How we protect your data
Arc Guiding does not require paying guests or website users to create an account, except in the following cases:
- Leaving reviews or comments
- Booking courses which include digital resources
Any personal information you submit as a paying guest using my guiding services is held in a secure and encrypted cloud storage service. Hardcopies are only generated when essential for guiding operations and are then kept securely with guiding staff at all times. Only thoroughly trained and assessed staff, with a reasonable need to see this data are permitted to access and hold it. Hardcopies are then destroyed when that booked activity has been delivered.
Occassionally, full access to website data is given to:
- eCommerce provider (WooCommerce)
- hosting provider (Yellow Cherry digital)
This is to allow essential maintenance and security updates. They also adhere to their own strict data protection rules. These access rights are revoked once the work has been carried out.
What data breach procedures we have in place
Where sensitive personal information is collected, it is done via digital contact forms. Digital forms are encrypted via the HTTPS standard. Downloadable/paper forms are transmitted via secure email, by post, or in person. In the event of a breach, all affected guests/registered website users will be contacted directly and informed of what information has been compromised, so they can take their own remedial steps. Arc Guiding undertakes to regularly review its own data security procedures and infrastructure, in order to comply with legal standards.
What third parties we receive data from
This website is regularly and automatically updated via the Wordpress platform and its curated collection of software vendors. Some software on this website is supplied and monitored by external vendors, separate from Wordpress.
What automated decision making and/or profiling we do with user data
We do not engage in automated decision making, marketing or profiling using visitors/customers data.
Industry regulatory disclosure requirements
Arc Guiding and this website undertake to abide by the GDPR (General Data Protection Regulations) rules.
Updated 9/1/23

