Privacy Policy
Last updated: 1 July 2026
This policy explains what personal data ralph.world collects about you, why we collect it, how long we keep it, and the rights you have over it. It applies to everyone who visits the site, has an account, or subscribes.
1. Who's responsible (the data controller)
Ralph Creative Limited (“Ralph”, “we”, “us”), company number 05638038, registered at 27-33 Bethnal Green Road, London, E1 6LA. We're the “controller” of your data under UK GDPR.
2. What data we collect, why, and the lawful basis
| What | Why | Lawful basis | Retention |
|---|---|---|---|
| Email, name, hashed password | Account creation and sign-in | Contract | Until account deletion |
| Subscription status, Stripe customer ID, billing period | Manage your subscription | Contract | Until account deletion + 6 years (UK tax retention) |
| Shipping address | Post the magazine to you | Contract | Until account deletion |
| Marketing opt-in flag + consent log | Newsletter sends (opt-in only) | Consent | Consent log: indefinite (legal record); opt-in flag: until withdrawn or account deleted |
| Cookie preferences | Remember your choice | Consent (for analytics) / Legitimate interest (for necessary) | 12 months |
| Event RSVP records | Confirm you're on the guest list | Contract / Legitimate interest | Until 6 months after the event |
| Error reports (Sentry) | Diagnose bugs | Consent (cookies_all only) | 90 days |
| IP address, device/browser data, security and audit logs | Detect and prevent fraud, abuse, and security incidents; keep an audit trail of sensitive account actions | Legitimate interest | 12 months from collection |
| Support correspondence (emails to hello@ralph.world) | Respond to your questions and rights requests | Legitimate interest | 24 months after the issue is resolved |
3. Who we share it with
We share personal data with the service providers below, who process it on our behalf and under our instructions (as “processors” under UK GDPR), each bound by a data processing agreement.
- Stripe — subscription billing. stripe.com/privacy
- Shopify — shop orders and magazine fulfilment. shopify.com/legal/privacy
- Resend — transactional email delivery (verification, receipts, RSVP confirmations).
- Mailchimp — marketing newsletter (only if you opted in).
- Cloudflare R2 — image storage and CDN.
- Railway — application hosting + database.
- Sentry — error reporting (only if you accepted analytics cookies).
- Google OAuth — sign-in if you choose Google.
- Newsstand — magazine printing and distribution.
We don't sell your data. We don't share it with anyone else unless required by law.
4. International transfers
Several of our processors operate outside the UK, including Stripe, Sentry, Resend, Mailchimp, Cloudflare, Railway, and Google. Where we transfer your data outside the UK, we rely on the UK's adequacy regulations (for transfers to the EU) or on Standard Contractual Clauses / the International Data Transfer Addendum (for transfers elsewhere, including the US) which require the recipient to protect your data to UK standards.
5. Your rights under UK GDPR
You have the right to:
- Access — get a copy of the data we hold about you. Use “Download my data” in your account, or email hello@ralph.world.
- Rectify — correct anything wrong. Edit in your account or email us.
- Erase — delete your account from your account page. Subscription billing history and consent records are kept under the lawful bases above; everything else is removed.
- Restrict / object — pause specific processing (e.g. marketing) without deleting your account.
- Portability — get the data you've given us in a structured, commonly used, machine-readable format, or ask us to send it directly to another provider where that's technically feasible.
- Automated decisions — we don't make any decisions about you based solely on automated processing that have a legal or similarly significant effect on you.
- Withdraw consent — unsubscribe from marketing or revoke cookies at any time via the account page or the “Cookie preferences” link in the footer.
- Complain — to the UK ICO at ico.org.uk.
We'll respond to rights requests within 30 days. To exercise any of these, email hello@ralph.world.
6. Children's privacy
If you're under 13, a parent or guardian needs to confirm they're aware of and consent to your use of ralph.world before you create an account, as set out in our Terms of Service. We may ask for that confirmation directly. We don't collect additional categories of data from children, use children's data for marketing, or show them targeted advertising. A parent or guardian can exercise any of the rights in section 5 on a child's behalf by emailing hello@ralph.world.
7. Cookies
See our Cookies page for the full list and how to change your preferences.
8. Security
Passwords are hashed (bcrypt). Database access is role-segregated. All traffic is TLS. Production data is encrypted at rest by our hosting provider. We log sensitive actions to an append-only audit trail. We don't store payment card details — Stripe handles those directly. If a security incident puts your personal data at risk, we'll notify the ICO within the timescales UK GDPR requires and tell affected users without undue delay where there's a high risk to your rights and freedoms.
9. Changes to this policy
Material changes are flagged on this page and (for account holders) emailed in advance. Minor wording fixes don't trigger a notice.
10. Contact
Privacy questions, rights requests, or anything you'd like clarified: hello@ralph.world. If you have a complaint about how we've handled your data, email us there first and we'll try to resolve it directly before you escalate to the ICO.
