This notice explains what We Love Soho does with your data, whether you're browsing the website, on our mailing list, or using the app as a member or business. We've written it in plain English first, with the legal detail underneath.
Who we are
"We Love Soho" is operated by We Love Soho Limited (company number 15895441, registered in England & Wales). Registered office: 15 Ockford Court, Ockford Road, Godalming, GU7 1RT. For data-protection purposes we are the data controller for the information described in this notice.
You can reach our data team at privacy@welovesoho.co.uk.
What we collect
If you join our mailing list, we collect a deliberately small amount of information:
- Your email address. The whole point of the form.
- Your audience choice (resident, visitor, staff, or Soho business), so we can send you the right information.
- If you tell us you run a business: venue name and venue type, so we can prepare an offer that makes sense for you.
- Technical metadata at the moment you submit, IP-derived country, the page you came from, and any UTM tags in the URL. We use this to count signups by source and country; we don't use it to identify you.
- The date and time you signed up, and the date you confirmed your email.
If you create an account or take out a membership, we collect more, because we have to in order to provide the service: your name, account and contact details, the businesses and offers you interact with, and your payment details (handled by our payment processor). The "app, accounts and payments" section below sets out exactly what we collect there, who processes it, and how it's protected.
Why we collect it
We rely on two lawful bases under the UK GDPR:
Consent (for sending you the launch email)
When you submit the form and then click the confirmation link in the email we send, you're giving us your consent to email you when the app launches. We use double opt-in, meaning a confirmation click is required before you're on the list, so that we never email anyone who didn't ask to be emailed. You can withdraw consent at any time using the unsubscribe link in the email, or by emailing privacy@welovesoho.co.uk.
Legitimate interest (for understanding signups in aggregate)
We use the technical metadata above, country, source, audience mix, to understand where our sign-ups come from. We balance this against your privacy by collecting the minimum possible (no IP addresses stored, just country), and by never using it to make decisions about you individually.
Who we share it with
The short answer is "almost no-one." Specifically:
- Our email-sending provider (currently Resend). They process your email address on our behalf to deliver the confirmation email and, later, the single launch email. Resend delivers email using Amazon Web Services infrastructure, which may involve processing in the United States; that transfer is governed by a data-processing agreement incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. They don't use your data for anything else.
- Our infrastructure providers, Cloudflare (anti-abuse, CDN, with UK points of presence) and our media host (Cloudways), which process data as it moves through their systems under data-processing agreements. Where any of this data is transferred outside the UK it is protected by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
- Authorities, if we're required by law (we'll push back where we can).
We do not sell your data. We do not share it with advertisers. We do not hand it to "data partners" or "marketing affiliates." If that ever changes, it'll be because the law forces it, or because we ask you first.
The app, accounts and payments
When you create an account or buy a membership in the We Love Soho app or at welovesoho.co.uk/account, we (and the providers below) process more information: your name, account details, date of birth, the businesses and offers you interact with, and your payment details. We are the data controller for your account data. Our lawful bases are: performance of your membership contract (to provide the service and take payment), legal obligation (to keep invoice and tax records), and consent (for any marketing you opt into).
You must be at least 16 to create a We Love Soho account. We collect your date of birth when you take out a membership to confirm this and to comply with UK children's data protection requirements (the ICO's Children's Code). If you are 16 or 17, we limit the offers shown to you (excluding age-restricted offers), and we never include you in behavioural analytics, personalised advertising, or audience data products. Age is computed from your date of birth at the time a request is made and is never used for profiling.
The providers we rely on for the app, and how your data is protected:
- Database hosting (Neon). We host our application database with Neon (Neon, LLC, a Databricks company) on AWS infrastructure in the United Kingdom (AWS Europe, London, eu-west-2). Your personal data is stored at rest in the UK. Neon's control-plane operations and support may involve access from the United States; those transfers are governed by our data-processing agreement with Neon, which incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum issued by the ICO. Neon is ISO 27001 and SOC 2 certified.
- Payments (Stripe). We use Stripe to process membership payments. Card details are entered directly into Stripe's secure, PCI DSS Level 1 certified systems and are never stored on, or transmitted through, our own servers. Stripe acts as an independent data controller for payment processing, fraud prevention and regulatory compliance. Our contracting Stripe entity is Stripe Payments Europe, Limited; payment services in the UK are provided by Stripe Payments UK Limited, an electronic-money institution authorised and regulated by the Financial Conduct Authority. Where Stripe transfers data internationally it relies on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum under its own data-processing agreement. Strong Customer Authentication is handled by Stripe.
- Infrastructure (Cloudflare) and email (Resend). Cloudflare provides our content delivery, security and serverless hosting (with UK points of presence), and Resend delivers our transactional and confirmation emails (Resend uses Amazon Web Services and may process email data in the United States). Each processes your data on our behalf under a data-processing agreement, and where data is transferred internationally it is protected by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
- Media hosting (Cloudways). Images you or a business upload (avatars, business logos and photos) are stored with our media host, Cloudways, at data.welovesoho.co.uk. They process this content on our behalf under a data-processing agreement.
- Error monitoring (Sentry). To keep the service reliable we use Sentry to capture technical error reports. When an error occurs while you are signed in, the report may include your user ID and email address so we can trace and fix the problem; passwords, payment details, authentication tokens and other secrets are stripped out before the report is sent. Sentry processes this on our behalf under a data-processing agreement, and any international transfer is protected by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
- Business bank transfers. Where a business chooses to pay by bank transfer, the payment is made to our Barclays business account and reconciled manually; your business and invoice details are processed for that purpose and kept as part of our financial records.
We will publish a fuller, in-app privacy notice as the app rolls out. If you are reading this before that notice is live, the providers and safeguards above are the ones that already apply to any account or payment data we hold.
How long we keep it
We hold signup data until the earlier of:
- You unsubscribe, in which case we delete your email from the active list within 14 days and keep a hashed record of the unsubscribe itself (so we don't accidentally re-email you) for 24 months;
- 24 months of inactivity on the mailing list, after which we'll either confirm you still want to hear from us or delete the record.
Raw technical metadata (IP-derived country, referrer, UTM parameters) collected at signup is retained for 12 months for signup-source analysis and then permanently deleted. Aggregate, non-identifying statistics (e.g. "we had X signups from Y country") may be retained indefinitely.
Account and payment records. Once you hold a paid membership, we keep your billing and invoice records for 6 years after the end of the relevant tax year, because UK tax and company law require us to. We keep the rest of your account data for as long as your account is active, and delete or anonymise it within a reasonable period after you close your account, except where we must keep the financial records above.
Cookies and analytics
We keep this simple, and we ask before we measure. Here is what runs on our website:
- Essential cookies and stored preferences. A small number of first-party items keep the site working and remember your choices, for example your theme, your cookie choice, and keeping you signed in to your account. These do not need consent under UK law because the site cannot work properly without them.
- Google Analytics 4, used only with your consent. We use Google Analytics (measurement ID G-NYGSFYMS6P) to understand how the website is used so we can improve it, but only if you accept analytics in the cookie notice. We use Google Consent Mode v2: analytics storage, and all advertising-related storage, default to denied. Google Analytics loads but sets no analytics cookies and sends no measurement about your visit until you accept. If you accept, we record your choice in your browser (localStorage key
wls.cookies) so that on later visits we can honour it without asking again; if you decline, or take no action, analytics stay off. You can change or withdraw your choice at any time, see the cookie policy. - No third-party advertising cookies and no Google ad personalisation. Our Google consent settings leave advertising storage, ad user data, and ad personalisation switched off, and we do not use Google Ads or share your data with advertising networks. Any remarketing we do runs inside our own app using your in-app activity, and is described in the "In-app personalisation and remarketing" section below.
- No cross-site trackers and no social-network pixels (no Facebook pixel, no LinkedIn Insight, no TikTok pixel, or similar).
- Cloudflare Turnstile for stopping bot signups. Turnstile is privacy-friendly by design and is not used for ad tracking.
What Google Analytics processes. When analytics are on, Google Analytics processes usage data such as the pages you view, approximate location derived from your IP address, device and browser type, and the source that brought you to the site. Google (Google Ireland Limited, with Google LLC) acts as our data processor for this, under Google's data-processing terms. Our lawful basis is your consent under the UK GDPR and PECR.
International transfers. Using Google Analytics may involve transferring some data to Google outside the UK, including to the United States. Google states that it relies on safeguards for such transfers, including the UK extension to the EU-US Data Privacy Framework and the EU Standard Contractual Clauses with the UK International Data Transfer Addendum.
Retention. Google Analytics keeps user-level and event-level data for 14 months, after which Google deletes it. We chose 14 months so we can compare usage year on year while keeping data no longer than necessary. Aggregate, non-identifying reporting may be kept longer.
In-app personalisation and offers
Inside the We Love Soho app we use your in-app activity, such as the offers you view, save, and redeem, together with general information like the area you use the app in, to personalise what you see and to show you relevant offers and reminders from We Love Soho and participating businesses. This helps us surface the offers most useful to you.
This personalisation runs entirely within our own systems. We do not sell your data, we do not share it with third-party advertising networks, and we do not use it for advertising outside the app. Reporting we share with participating businesses is aggregated, so a business sees patterns such as how many members redeemed an offer, not identifiable individuals.
Our lawful basis for this personalisation is our legitimate interest in running a useful membership service and helping local businesses reach members, balanced against your interests. You can object to it, and manage your marketing and notification preferences, at any time in the app or by contacting us. We keep the activity data behind this only as long as needed for the service and our retention schedule.
Business advertising and promoted placements
If you use We Love Soho as a business, you can pay to promote your offers to members through our advertising tools, funded from an advertising balance ("ad credit") held on your account. This section explains the data involved.
When you run a promoted placement, we process your business account and billing details to charge for it, and we generate performance data about the placement itself, such as how many members saw it (impressions) and how many acted on it (clicks or redemptions). We use this to run the advertising, bill it correctly, prevent abuse, and show you reporting on how your promotion performed.
The reporting we give an advertising business is aggregated: it shows counts and patterns (for example how many members viewed or redeemed a promoted offer), not the identity of individual members. Promoted placements are decided inside our own systems using members' in-app activity and general area, as described in the section above; we do not hand member data to the advertising business, and we do not share it with third-party advertising networks or use it to target members outside the We Love Soho app. Our lawful basis is performance of the advertising business's contract with us (to run and bill the placement) and our legitimate interest in operating the advertising service. Advertising billing and performance records are kept in line with the retention periods above.
Your rights
You have the rights you'd expect under UK GDPR:
- To access the personal data we hold about you;
- To correct it if it's wrong;
- To delete it (yes, even after you've confirmed, just ask);
- To restrict or object to our processing of it;
- To get a portable copy in a machine-readable format;
- To withdraw consent at any time, the unsubscribe link in any email does this in one click.
If you'd like to exercise any of these, email privacy@welovesoho.co.uk and we'll respond within 30 days (usually much faster). You also have the right to complain to the Information Commissioner's Office, but we'd prefer the chance to make it right first, so please contact us before going to the ICO.
Changes to this policy
We'll update this notice as the product evolves or the law changes. If we make changes that materially affect how we use your data, we'll give you reasonable notice (for example by email or a notice in the app) before they take effect. The effective date at the top shows when the current version came into force.
Getting in touch
For anything privacy-related, questions, requests, complaints, or just to tell us we got something wrong, the email below reaches a real human at We Love Soho.
Talk to us about your data.
We aim to reply within two working days. If something's urgent, say so in the subject line.
- Email privacy@welovesoho.co.uk
- Post We Love Soho Limited, Soho, London W1 (full address at launch)
- ICO ico.org.uk — 0303 123 1113 (please contact us first)