Maintaining your privacy is really important to us. You entrust us with your information, and we take that responsibility seriously.
We may modify or update this Privacy Policy from time to time to reflect the changes in our business and practices, and so you should review this page periodically. When we change the policy in a material manner we will let you know and update the 'last updated' header as below.
This Privacy Policy was last amended on 12/05/2026
This policy was last updated on 15/05/2026 in line with UK GDPR and Data Protection Act 2018 requirements. It may be updated in the future and we will post the new version here on our website. We will never deviate from our overall philosophy of maintaining your privacy, though.
We take security and privacy seriously. This Privacy Policy explains how we collect, store and use personal data when you browse our website or otherwise provide your personal data to us. Please read this Privacy Policy carefully to understand how we will treat your personal data.
Data controller: The data controller for the personal information collected via this website is Black Dingo Limited (trading as Nerdvana), a company registered in Scotland under number SC706416, with registered office at 32 Loanfoot Crescent, Uphall, Broxburn, West Lothian EH52 6DN. VAT registration number GB 451 4494 92. You can reach us using the contact details at the end of this policy.
When we say your "personal data", we mean any information that identifies any person that you provide to us.
Your "personal data" may also be contained in information that we collect about you in connection with your order or otherwise interact with us for example by electronic mail.
When it comes to your personal data, we comply with our obligations under the General Data Protection Regulation and any other applicable data protection legislation from time to time.
Your personal data includes the information you provide on our website (including any forms you complete), or during an electronic mail enquiry about you.
Examples of this personal data include your name, your email address, address including postcode which you provide to us when you set up an account and subsequently amend in the My Account section when you go to checkout; and any correspondence when you contact us.
We do not knowingly collect or solicit any personal data from anyone under the age of sixteen or knowingly allow such persons to purchase goods from us. Our website is not directed at children under the age of sixteen. In the event that we learn that we have collected personal data from a child under age sixteen without verification of parental consent, we will delete that information as quickly as possible.
We collect information about your website usage, to improve our service and to understand trends to enhance and customise our website. Some of this data may be "personal data", where it identifies a person. Here's the information that we collect and how we use it:
We use your personal data for legitimate business reasons, for example emailing you when your order has been received or when a booking is confirmed. It also lets us contact you by email, post, SMS or telephone where necessary about an order or booking you have placed, record your personal preferences, and personalise our services (such as pre-populating fields so you don't have to re-enter them). It enables us to produce reports you request as part of the services we provide.
We may use your personal data to contact you by email about our own services, content, offers or product ranges that may be of interest to you. We only send you marketing messages where you have given us consent (for example by ticking the "marketing updates" box during registration or on your Manage My Data page) and you can withdraw that consent at any time using the same controls or by emailing us.
We may use your personal data to comply with any legal obligations to which we are subject.
Under UK GDPR we must have a specific lawful basis for every way we use your personal data. The basis depends on what we're doing:
Except as described in this policy, we do not divulge any personal information gathered via our services to third parties.
We may share your personal data with third parties in certain circumstances:
| Name | Service Provided | Location | Link |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, and application infrastructure | EU (Ireland) | Privacy Policy |
| Square | Payment processing (PCI-DSS compliant). We also mirror your account into Square's Customer Directory — name, email, and phone number where provided — so staff at our in-store till can identify you when you visit. This applies even if you have never paid through Square (i.e. registration alone is enough for the mirror to be created). You can ask us to delete this mirror at any time via your account or by contacting us; we will also remove it as part of any account-erasure request. | USA (adequate safeguards) | Privacy Policy |
| OAuth authentication (optional), email hosting, Google Analytics 4 (website analytics — only with your consent) | USA (adequate safeguards) | Privacy Policy | |
| Google reCAPTCHA Enterprise | Bot / automated-signup protection on our registration form. Processes your IP and basic behavioural signals to score the request. | USA (adequate safeguards) | Privacy Policy |
| Google Maps | Embedded map on our contact page so you can find the store. | USA (adequate safeguards) | Privacy Policy |
| Discord | OAuth authentication (optional, account linking) — if you link your Discord account we receive your Discord user ID, username, and avatar via the Discord identify scope. We do not request or receive your Discord email or any other Discord data. | USA (adequate safeguards) | Privacy Policy |
International Transfers: Some processors are located outside the UK/EEA. We ensure adequate safeguards are in place through Standard Contractual Clauses (SCCs) and processor certifications.
We only store your data for as long as necessary for the purposes of processing set out in this policy. Our full Data Retention Policy is available in our technical documentation.
| Category | What personal information is kept? | How long is it kept for? |
|---|---|---|
| Active Account | Name, email, address, phone | Until account deletion requested |
| Inactive Account | Name, email, address | 3 years (then automatically deleted) |
| Order Records | Name, email, address, purchase details | 7 years (tax law requirement) |
| Booking Records | Name, email, phone, table / room / event booking details | Anonymised 2 years after the booking date. Paid bookings keep a financial record for tax (as Order Records); free / unpaid bookings are deleted. |
| Payment Logs | Transaction ID, amount, timestamp | 7 years (PCI DSS requirement) |
| Security Logs (Low/Medium) | IP address, user agent, login attempts, actions | 90 days (fraud prevention) |
| Security Logs (High/Critical) | IP address, failed logins, security events | 365 days (security investigation) |
| Marketing Consent | Email address | Until you unsubscribe |
What happens when you delete your account: we run a single transaction that (1) anonymises records we're legally or operationally required to keep — orders (kept for 7 years for HMRC), paid table / room bookings (kept as a financial record with your name, email and phone removed), gift cards (purchaser and recipient sides), gift-card transactions, and admin / audit log entries that referenced you as the actor; and (2) deletes everything else — your account row, addresses, password reset tokens, abandoned cart, plus any bookings (unpaid or free ones only), booking-modification requests, invites you sent, and waitlist entries. Anonymised records have your name, email, postal address, and any free-text PII fields stripped or replaced with a deterministic placeholder so the financial totals still reconcile but you can no longer be identified from them. If you also want a copy of your data first, use the Export Your Data button on the Manage My Data page before you delete.
You are free to change your personal details in the My Account section of your account at any time, if you have set up an account with us.
You can also ask us for a copy of your personal data that we hold. We may ask for proof of your identity before providing any information and reserve the right to refuse to provide information requested if identity is not established.
You can ask us to confirm if we are processing your personal data and you may request a copy of your personal data by contacting us.
Where you have given us consent to make use of your personal data for any of the purposes outlined in this policy, you may withdraw that consent at any time by contacting us.
You may ask us to update out of date or inaccurate information we hold about you. To do so, please log on to your account and update your information or get in touch using the contact details below.
In certain circumstances you may ask us to erase your Personal Data. If you would like us to erase the personal data we hold about you, please get in touch using the contact details below.
In certain circumstances you may ask us to provide you with the personal data that we hold about you in a structured, commonly used, machine readable form, or ask for us to send such personal data to another data controller.
In certain circumstances you may object to our processing of your personal data. Please get in touch using the contact details below.
You can ask us to restrict the processing of personal data we hold about you in certain circumstances. Please get in touch using the contact details below.
You may make a complaint about our data processing activities, please contact us using the details below.
We take security and privacy seriously. We will endeavour to take all reasonable steps to keep your personal data secure once it has been transferred to our systems. We adopt appropriate, industry standard data collection, storage and processing practices and security measures to protect against unauthorised access, alteration, disclosure or destruction.
In the unlikely event of a data breach that may affect your personal data, we will:
If you believe your personal data has been compromised, please contact us immediately at hello@nerdvanalivingston.co.uk with the subject line "Data Security Concern".
If you have any queries relating to this Privacy Policy or how Black Dingo Limited (trading as Nerdvana) uses your personal or financial data, please contact:
Email: hello@nerdvanalivingston.co.uk
Postal address (visit us / general post): Unit 11 Grampian Court, Beveridge Square, Livingston, West Lothian EH54 6QF
Registered office: Black Dingo Limited (trading as Nerdvana), 32 Loanfoot Crescent, Uphall, Broxburn, West Lothian EH52 6DN. Company number SC706416. VAT GB 451 4494 92.
You also have the right to lodge a complaint with the Information Commissioner's Office (the UK supervisory authority for data protection) — see ico.org.uk/make-a-complaint for how to do that. We'd ask that you raise the concern with us first so we have the chance to put it right.