Last updated: 9 September 2026
This is the detailed companion to our Privacy Policy — it sets out exactly what we hold, why, for how long, and who it's shared with.
Data categories we hold
| Category | Examples | Why |
|---|---|---|
| Membership & contact | Name, email, phone, DOB, address, postcode | Run your account and membership |
| Financial | Full account balance, spend and visit history, tab history, complete payment history (card, bank transfer, in person), card-on-file (via Stripe), signed tab agreements (name, date, IP address) | Manage your account and any tab/credit facility, take payments, and assess or review a credit request |
| Marketing preferences | Consent status, preferred contact channel | Only contact you the way you've agreed to |
| Messaging records | WhatsApp/SMS/email/push notification log | Keep a record of what we've sent and when |
| Loyalty | Points balance, rewards issued/redeemed | Run the rewards scheme |
| Staff & employment | Bank details, SIA licence numbers, shift/pay records | Payroll and licensing compliance (staff only, not customers) |
| Door & venue security | CCTV, entry and incident records, banned-persons list | Venue safety and licensing compliance — handled in line with GDPR, including where it involves sensitive information |
How long we keep it
- Active membership/account data: for as long as your account is active, plus up to 2 years of inactivity before review.
- Financial & payment records (including signed tab agreements): up to 6 years, in line with UK tax record-keeping requirements.
- Messaging logs: up to 2 years.
- Door & venue security records: retained as long as necessary for venue safety and licensing purposes, in line with GDPR.
- Staff/employment records: duration of employment plus up to 6 years, per HMRC requirements.
These are working guidelines, not fixed rules — where we no longer have a reason to keep something, we delete it sooner.
Who we share data with
Our data processors: our till/operations system (used for trend analysis, stock control and understanding customer preferences), Stripe (payments — PCI DSS Level 1 compliant), Meta/WhatsApp Business (messaging), our website host, and our membership sign-up form provider. Each is bound by its own data protection terms and receives only what it needs to provide its service. Where a provider processes data outside the UK, it relies on standard contractual clauses or an equivalent approved safeguard.
Who can access this internally
Pulse Southend, as data controller, has full access to all categories above — in practice, the owner. Beyond that, access is granted individually, per member of staff, based on what their role actually needs — not given to all staff by default:
- Financial & account records (balance, spend history, tab, payments): the owner, plus staff individually granted account-management access.
- Approving/declining a tab request, editing a credit limit, or viewing the full activity log: the owner only.
- Door & venue security records: the owner and on-duty Door Supervisors.
- Staff/employment records: the owner only.
Security measures
- All web traffic is encrypted (HTTPS).
- Passwords and door-access PINs are stored using one-way cryptographic hashing, never in plain text.
- Payment card details are never handled or stored on our own systems — Stripe handles this directly.
- Access to customer, financial and incident records is restricted to authorised staff, based on their role.
Your rights & contact
See our Privacy Policy for your rights and how to exercise them, or email info@pulsesouthend.co.uk directly.
