Data & Security Policy

    Last updated: 9 September 2026

    Acceptance of This Policy

    By accessing or using the Unofficial Alton Towers website or any associated application (collectively, the "Service"), you acknowledge that you have read, understood, and agree to be bound by this Data & Security Policy. If you do not agree with any part of this policy, you must not use the Service.

    Your continued use of the Service constitutes ongoing acceptance of these terms, including any future updates we may make to this policy.

    1. GDPR Compliance

    We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. As a data controller, we process personal data lawfully, fairly, and transparently.

    1.1 Lawful Basis for Processing

    We process your personal data under the following lawful bases:

    • Consent โ€” When you subscribe to our newsletter, create an account, or store pass/ticket data in your wallet.
    • Legitimate Interest โ€” To operate, maintain, and improve the Service, and to protect the security of our systems.
    • Contractual Necessity โ€” To provide features you have signed up for, such as account access and pass management.

    1.2 Your Rights Under GDPR

    Under GDPR, you have the following rights regarding your personal data:

    • Right of Access โ€” Request a copy of the personal data we hold about you.
    • Right to Rectification โ€” Request correction of inaccurate or incomplete data.
    • Right to Erasure โ€” Request deletion of your personal data ("right to be forgotten").
    • Right to Restrict Processing โ€” Request we limit how we use your data.
    • Right to Data Portability โ€” Receive your data in a structured, machine-readable format.
    • Right to Object โ€” Object to processing based on legitimate interest.
    • Right to Withdraw Consent โ€” Withdraw your consent at any time without affecting the lawfulness of prior processing.

    To exercise any of these rights, please contact us at unofficialaltontowers@gmail.com. We will respond within 30 days.

    2. Data Sharing & Third Parties

    2.1 What We Share

    We do not sell your personal data to any third party. We may share limited data with the following categories of processors:

    • Hosting & Infrastructure โ€” Our backend infrastructure provider stores account data, pass information, and chat messages using industry-standard encryption at rest and in transit.
    • Email Services โ€” If you subscribe to our newsletter, your email address is shared with our email delivery provider solely to send you the content you requested.
    • Analytics โ€” We may collect anonymised usage data (pages visited, device type) to improve the Service. This data cannot identify you personally.

    2.2 Affiliate Links

    This Service contains affiliate links to Alton Towers (altontowers.com), Merlin Annual Pass, and partner websites. When you click these links, those third-party sites may collect data under their own privacy policies. We have no control over, and accept no responsibility for, data collected by third-party websites.

    2.3 Law Enforcement

    We may disclose your personal data if required to do so by law or in response to valid requests by public authorities (e.g. a court or government agency).

    3. Data Storage & Retention

    • Account data (email, profile information) is retained for as long as your account is active.
    • Pass and ticket barcode data you enter is stored in encrypted form and is accessible only to you when authenticated.
    • Chat messages are retained for up to 90 days for support purposes and then automatically purged.
    • Newsletter subscriber data is retained until you unsubscribe.
    • Upon account deletion, all associated personal data is permanently removed within 30 days.

    4. User Responsibility & Data Security

    By using this Service, you accept full responsibility for the security of your own data, account credentials, and any information you choose to store, display, or transmit through the Service.

    This includes, but is not limited to:

    • Account Credentials โ€” You are solely responsible for maintaining the confidentiality of your password and login details. You must not share your credentials with any other person.
    • Pass & Ticket Data โ€” Any barcode, pass number, or ticket information you store in the Pass Wallet is your responsibility. You must ensure your device is secure and your screen is not visible to others when displaying sensitive information.
    • Device Security โ€” You are responsible for securing the device(s) you use to access the Service, including keeping your operating system and browser up to date, using screen locks, and not leaving sessions unattended.
    • Public & Shared Devices โ€” If you access the Service from a public or shared device, you must log out when finished. We accept no liability for unauthorised access resulting from failure to do so.
    • Location Data โ€” The Service may request access to your location to enable park-specific features (such as the Quick Access Wallet). You control whether to grant this permission via your device settings.
    • Chat & User-Generated Content โ€” Any information you share via live chat, profile bios, or other user-generated content is your responsibility. Do not share personal, financial, or sensitive data through these features.

    We implement reasonable technical and organisational measures to protect data stored on our systems, including encryption at rest and in transit, role-based access controls, and automatic session timeouts. However, no system is 100% secure. You acknowledge and accept the inherent risks of transmitting data over the internet.

    5. Our Security Measures

    We take the following steps to protect your data:

    • All data is transmitted over HTTPS (TLS 1.2+) encryption.
    • Passwords are hashed using industry-standard algorithms and are never stored in plain text.
    • The Pass Wallet requires password re-authentication before displaying sensitive barcode data.
    • Quick Access Wallet includes geofencing (park-only unlock) and automatic timeout locks.
    • Administrative access is restricted via role-based access control (RBAC).
    • Database access is governed by row-level security policies ensuring users can only access their own data.

    6. Limitation of Liability

    To the fullest extent permitted by applicable law, Unofficial Alton Towers and its operators shall not be liable for any loss, damage, or unauthorised access to your data arising from:

    • Your failure to maintain the security of your account credentials or device.
    • Your decision to store sensitive data (e.g. pass barcodes) within the Service.
    • Unauthorised access to your account due to weak, reused, or compromised passwords.
    • Actions taken by third-party websites accessed via affiliate links on this Service.
    • Any data breach caused by circumstances beyond our reasonable control.

    7. Children's Data

    The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided us with personal data, please contact us and we will delete it promptly.

    8. International Data Transfers

    Your data may be processed on servers located outside the United Kingdom. Where this occurs, we ensure appropriate safeguards are in place, including standard contractual clauses approved by the UK Information Commissioner's Office (ICO).

    9. Data Breach Notification

    In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach, and will inform affected users without undue delay, in accordance with GDPR Article 33 and 34.

    10. Changes to This Policy

    We reserve the right to update this policy at any time. Material changes will be communicated via a notice on the Service or by email where appropriate. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

    11. Contact & Complaints

    For any questions about this policy or to exercise your data rights, contact us at unofficialaltontowers@gmail.com.

    If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

    See also: Privacy Policy ยท Terms of Use