Privacy Policy
Last updated: August 26, 2026
At SplashPlay we take the privacy of your data seriously. This policy explains what information we collect when you book a session, buy a gift card, or browse splashplay.es, what we use it for, who we share it with, and what rights you have over it.
1. Who is responsible for your data
The data controller for your personal data is Aleksandra Lopina, a self-employed professional (autónoma) trading as "SplashPlay Studio", with address at Carrer del Concili de Trento, 7, 08018 Barcelona, Spain.
For any question about this policy or your personal data, you can write to us at [email protected].
2. What data we collect and where it comes from
We do not keep our own customer database. The data we collect is stored directly in the third-party services described below, which act as our data processors.
Giving us your name, email and phone number is necessary to complete a booking — without them we can't confirm your session, contact you about it, or process payment.
Booking and payment (Stripe)
When you book and pay for a session, the payment form (Stripe Checkout) collects your name, email, phone number and your card or payment method details. Stripe processes the payment and stores this data on our behalf; we never see or store your full card number.
Choosing a date and time (Calendly)
Once payment is confirmed, your name, email, phone number and any comment you leave are sent to Calendly to book your slot in the studio's schedule.
Bookings made through partners
If you reach SplashPlay through a partner's link (for example, another business that recommends our sessions), we share your name, the session date, activity type, price and number of guests with that partner, so it can confirm the booking it referred. We also store, in a technical store hosted by our hosting provider (Netlify), the payment transaction ID together with the partner, price and number of guests — without your name or contact details — to reconcile that relationship with the partner.
Internal booking notifications
When a booking is created, changed or cancelled, a message with your name, email, phone number and (if you cancel) the cancellation reason is automatically sent to an internal Telegram chat that we use solely to run the studio.
Analytics and advertising
We use Amplitude to understand how the website is used (pages viewed, clicks, booking-flow steps) and its session-replay feature, which can record how you interact with the page. We also use Google Tag Manager, Google Ads and the Meta (Facebook/Instagram) Pixel to measure the performance of our ads and, based on your on-site behaviour, to build remarketing audiences (showing you ads after your visit) and lookalike audiences on Google and Meta — in other words, these tools carry out profiling for advertising purposes. These tools may collect your IP address, device/browser identifiers and on-site activity through cookies or similar technologies. These tools currently load when you visit the site, without asking for your consent first; we are building a cookie-consent control that will let you accept or reject this advertising profiling before it runs.
Hosting and technical logs
Our website and server functions are hosted on Netlify, which generates temporary technical logs (for example, of errors or function traffic) that may include IP addresses or other data included in requests.
3. Why we process your data (legal basis)
We process your personal data under the following GDPR legal bases:
- Performance of a contract (Art. 6.1.b): to manage your booking, process payment and provide the service.
- Legal obligation (Art. 6.1.c): to comply with tax and accounting obligations.
- Legitimate interest (Art. 6.1.f): to prevent fraud, manage partner bookings and improve the website.
- Consent (Art. 6.1.a): for non-essential analytics and advertising, where required by applicable law.
4. Who we share your data with
We only share data with the providers needed to run the service, all acting as data processors (or, in the case of partners, as independent controllers of the data they receive):
- Stripe Payments Europe, Ltd. — payment processing and customer data.
- Calendly, LLC — booking schedule management.
- Amplitude, Inc. — product analytics and session replay.
- Google Ireland Ltd. (Google Tag Manager, Google Ads, Google Maps) — ad measurement and the studio map on the Contact section.
- Meta Platforms Ireland Ltd. (Meta Pixel) — ad measurement.
- Netlify, Inc. — website hosting, server functions and technical storage.
- Telegram Messenger Inc. / Telegram FZ-LLC — internal booking notifications.
- Partner businesses that referred you to SplashPlay, only when you book through their link.
We do not sell your personal data to third parties.
We have a data processing agreement (DPA) under Art. 28 GDPR in place with each of these providers, incorporated into their standard terms of service — with the exception of Telegram (see section 5).
5. International data transfers
Some of our providers process data outside the European Economic Area, mainly in the United States. Here is the specific safeguard each one relies on:
- Stripe (Stripe Payments Europe, Ltd. in the EU; Stripe, Inc. in the US as sub-processor) — EU-U.S. Data Privacy Framework.
- Calendly, LLC — EU-U.S. Data Privacy Framework, plus the UK Extension and the Swiss-U.S. DPF.
- Amplitude, Inc. — EU-U.S. Data Privacy Framework.
- Google (Google Ireland Ltd. as our contracting party; Google LLC in the US) — EU-U.S. Data Privacy Framework, for Google Ads, Google Tag Manager and Google Maps.
- Meta (Meta Platforms Ireland Ltd. as our contracting party; Meta Platforms, Inc. in the US) — EU-U.S. Data Privacy Framework.
- Netlify, Inc. — EU-U.S. Data Privacy Framework plus the European Commission's Standard Contractual Clauses.
- Telegram (Telegram FZ-LLC, Telegram Group Inc.) — Telegram acts as an independent controller for the messages we send it, and states it stores EU/UK users' data in data centres in the Netherlands, with an EU representative appointed under Art. 27 GDPR. Telegram does not offer a data processing agreement, so we cannot point to a formal Art. 46 GDPR safeguard for this channel; that is why we limit what we send there to the minimum needed to manage your booking.
You can check each provider's own policy for their current DPF certification details.
6. How long we keep your data
Since we don't store data in our own systems, retention depends mainly on each provider and our legal obligations:
- Payment and billing data (Stripe): for as long as the relationship lasts, and afterwards for the period required by Spanish tax and accounting law (currently up to 6 years).
- Booking data (Calendly): for as long as the booking stays on our calendar; we manually clear completed or cancelled Calendly events, typically within 12 months of the session, unless we need to keep them longer for a payment dispute or claim.
- Partner data (Netlify Blobs, no name or contact details): 365 days from the booking, then automatically deleted by a daily scheduled job.
- Session Replay recordings (Amplitude): 30 days from recording, Amplitude's default retention.
- Other analytics events (Amplitude, beyond Session Replay): per our Amplitude account's retention setting, which we currently have not shortened from the platform default.
- Advertising cookies (Google Ads, Meta Pixel): the `_gcl_au` (Google Ads) and `_fbp`/`_fbc` (Meta Pixel) cookies expire by default 90 days after your last visit.
- Internal notifications (Telegram) and technical logs (Netlify): we keep messages in the internal chat only for as long as operationally useful to manage the booking, typically a few weeks; Netlify's technical logs are kept for a limited period under our hosting provider's own settings.
- Google Maps (Contact section): Google may set its own cookies when the map loads; retention is set by Google (see Google's cookie policy).
7. Your rights
You can exercise the following rights at any time by writing to [email protected]:
- Access: find out what data of yours we process.
- Rectification: correct inaccurate data.
- Erasure: ask us to delete your data (note that some billing data must be kept by law even if you request deletion).
- Objection and restriction: object to certain processing or ask us to restrict its use.
- Portability: receive your data in a structured format.
- Withdraw consent: where processing is based on your consent, at any time, without retroactive effect.
If you believe we haven't handled your data correctly, you can also file a complaint with the Spanish Data Protection Agency, the AEPD (www.aepd.es).
8. Cookies and similar technologies
Our website uses cookies and similar identifiers mainly for analytics and advertising, through the services listed in section 2:
- Amplitude — usage analytics and session replay (recordings kept 30 days by default).
- Google Tag Manager and Google Ads — campaign measurement and building remarketing/lookalike audiences from your on-site activity (advertising profiling); `_gcl_au` cookie, expires after 90 days.
- Meta Pixel — campaign measurement and building remarketing/lookalike audiences on Facebook/Instagram from your on-site activity (advertising profiling); `_fbp`/`_fbc` cookies, expire after 90 days.
- Google Maps — the interactive map embedded in the Contact section loads directly from Google and may set its own cookies; for EU visitors, Google shows its own consent prompt inside the map before loading them.
You can block or delete these cookies from your browser settings; blocking them does not affect your booking or payment, which are handled directly with Stripe and Calendly. These tools currently load without asking for your consent first — we are building a consent panel that will let you accept or reject analytics and advertising (including the profiling described above) before they run.
9. Security
We apply reasonable technical and organisational measures to protect your data, and we entrust payment processing to Stripe, a PCI-DSS certified platform, so your card details never pass through our own servers.
10. Children
Our sessions may include children accompanied by an adult, but booking and payment must always be made by an adult. We do not knowingly collect personal data from children through the booking form.
11. Changes to this policy
We may update this policy if our services or applicable law change. We will always publish the current version on this same page, with the last-updated date.
12. Contact
For any question about this policy or your personal data:
Email: [email protected]
Address: Carrer del Concili de Trento, 7, 08018 Barcelona, Spain