Privacy Policy — BaseCamp OS
BaseCamp OS

Privacy Policy

Last updated: 11 August 2026

1. Who we are

BaseCamp OS is operated by HowMedia UK ("we", "us", "our"), a company registered in England and Wales. We provide an operations management platform for outdoor activity businesses.

For data protection purposes we are the data controller in respect of the personal data of our business customers (and their staff) who use the BaseCamp OS platform. In relation to the personal data of the end customers and participants of those businesses, we act as a data processor on behalf of our business customers, who are the data controllers.

Contact: privacy@basecampos.co.uk

2. What personal data we collect

Business account holders and staff

  • Name, email address, and password (hashed)
  • Business name, email address, and Stripe payment account identifiers
  • IP address at account creation and DPA acceptance
  • Staff certifications, roles, and profile information entered by account administrators

End customers and activity participants (processed on behalf of business customers)

  • Name, email address, and phone number
  • Date of birth (where collected for age-restricted activities)
  • Health declaration acknowledgements and the declaration text agreed to
  • Signed waiver records — including the waiver content, typed name, timestamp, IP address, and browser user agent string. IP address and user agent are stored as part of the waiver audit trail (see section 3 for lawful basis)
  • Booking details and payment records

Website visitors

  • Analytics data (page views, referral source, approximate location) — only with your consent
  • Cookie consent preference (stored in a browser cookie)

3. Lawful basis for processing

Purpose Lawful basis (UK GDPR)
Providing the platform to business customers Contract (Art. 6(1)(b))
Processing participant bookings, waivers, and payments on behalf of business customers Legitimate interests of the data controller (Art. 6(1)(f)) / Contract
Recording IP address and browser user agent when a waiver is signed Legitimate interests (Art. 6(1)(f)) — establishing audit evidence that a specific person signed a safety waiver, which has legal value in the event of an incident or dispute
Analytics cookies Consent (Art. 6(1)(a))
Sending billing and service emails Contract / Legitimate interests
Special category data (health declarations) Explicit consent of the data subject (Art. 9(2)(a))

4. How we share your data

We share personal data only with the following third parties, all of whom are bound by appropriate data processing agreements:

  • Stripe — payment processing (Stripe processes card data directly; we store only payment identifiers)
  • Mailgun / Laravel mail service — transactional email delivery
  • Google Analytics — website analytics (only if you have consented to analytics cookies)
  • Hostinger / server infrastructure — cloud hosting within the EEA or UK-adequate jurisdictions

We do not sell personal data to third parties.

5. How long we keep your data

  • Business account data: retained for the duration of the subscription and for 6 years after account closure (for legal and financial record-keeping)
  • Booking and payment records: 6 years from the booking date
  • Waiver records: 6 years from the date of signing
  • Analytics data: as per Google Analytics' retention settings (default 14 months)
  • Cookie consent: 12 months (stored as a cookie in your browser)

6. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten"), subject to legal retention obligations
  • Restrict how we process your data
  • Data portability in a structured, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time where we rely on consent

To exercise any of these rights, contact us at privacy@basecampos.co.uk. We will respond within one calendar month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

7. Cookies

We use a small number of cookies:

  • Session cookie (essential) — keeps you logged in
  • CSRF token (essential) — protects form submissions
  • cookie_consent (functional) — remembers your analytics cookie preference for 12 months
  • Google Analytics cookies (analytics) — only set if you accept analytics cookies via our consent banner

You can change your analytics cookie preference at any time by clearing the cookie_consent cookie from your browser settings.

8. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), hashed passwords, and access controls. No system is completely secure; if you become aware of any security concern, please contact us immediately.

9. Changes to this policy

We may update this Privacy Policy from time to time. We will notify business account holders of material changes by email. Continued use of the platform following notification constitutes acceptance of the revised policy.