Privacy Policy
Last updated: July 2026
1. Introduction
Mardi Gras Blackpool ("we", "us", "our") is committed to protecting your personal data and your right to privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller
Mardi Gras Blackpool, 41-43 Lord Street, Blackpool, Lancashire, FY1 2BD, is the data controller for the purposes of UK GDPR. This means we are responsible for deciding how and why your personal data is processed.
3. Data We Collect
We may collect the following types of personal data: • Identity data: Name, date of birth, gender • Contact data: Email address, phone number, postal address • Booking data: Reservation details, room preferences, event ticket purchases, booking history • Payment data: Payment card details (processed securely by our payment provider — we do not store full card details) • Usage data: IP address, browser type, device information, pages visited, time spent on pages • Marketing data: Your preferences in receiving marketing communications • Loyalty data: Points, badges, visit history, reward redemptions • Forum data: Display name, post content, uploaded images (your real identity remains private on the public forum)
4. How We Use Your Data
We process your personal data for the following purposes: • To process and manage your bookings, including room reservations and event tickets • To communicate with you about your stay, booking, or upcoming events • To process payments and manage transactions • To provide loyalty rewards and track your bar visits • To moderate and display forum content (using a display name, not your real name) • To send promotional materials (only with your explicit consent) • To improve our services, website experience, and venue operations • To comply with legal obligations and licensing requirements
5. Legal Basis for Processing
We process your personal data under the following legal bases: • Performance of a contract: To fulfil your booking and provide the services you have requested • Legal obligation: To comply with licensing laws, age verification, and tax requirements • Legitimate interests: To operate our business, ensure security, and improve our services • Consent: For marketing communications and non-essential cookies. You can withdraw consent at any time.
6. Data Sharing
We do not sell your personal data. We may share your data with trusted third-party processors who are contractually bound to protect your information: • Payment providers (e.g., Stripe) for processing card payments • Booking platforms (e.g., Booking.com) if you booked through them • Email service providers for sending communications • IT service providers for website hosting and maintenance • Public authorities where legally required (e.g., HMRC, police investigations) Forum content (posts, images) you create is displayed publicly but uses your chosen display name — your real identity is not shown to other users.
7. International Data Transfers
Your personal data is primarily stored and processed within the United Kingdom and the European Economic Area. Where data is transferred outside these areas, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.
8. Data Retention
We retain personal data only for as long as necessary for the purposes outlined in this policy or as required by law: • Booking and payment records: 7 years (for tax and accounting purposes) • Loyalty account data: While your account is active, plus 2 years after closure • Marketing data: Until you withdraw consent or unsubscribe • Forum posts: Until you request deletion or the post is archived • CCTV footage: 30 days, unless retained for investigation purposes
9. Your Rights
Under UK GDPR, you have the following rights: • The right to access — request a copy of the personal data we hold about you • The right to rectification — correct inaccurate or incomplete data • The right to erasure — request deletion of your personal data ("right to be forgotten") • The right to restrict processing — limit how we use your data • The right to data portability — receive your data in a machine-readable format • The right to object — object to processing based on legitimate interests or for direct marketing • Rights regarding automated decision-making — you can request human review of automated decisions To exercise any of these rights, contact us at hello@mardigrasblackpool.com.
10. Cookies
Our website uses cookies to enhance your browsing experience. Essential cookies are required for the website to function properly and cannot be disabled. Analytics cookies help us understand how visitors interact with our website. Marketing cookies are used only with your consent. You can manage cookie preferences through your browser settings. For full details, see our Cookie Policy.
11. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including encrypted data transmission (SSL/TLS), secure payment processing, access controls, and regular security reviews. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
12. Children's Data
Mardi Gras Blackpool is an adults-only venue (18+). We do not knowingly collect personal data from anyone under 18. If you believe we have collected data from a minor, please contact us immediately and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.
14. Contact
For any data protection enquiries, to exercise your rights, or to submit a complaint, please contact us at: Mardi Gras Blackpool 41-43 Lord Street, Blackpool, Lancashire, FY1 2BD Email: hello@mardigrasblackpool.com If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
