This policy explains how Mr Gig Studios collects, uses, and protects your personal data when you use our website or make a booking. We are committed to handling your information transparently and in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Last updated: September 2026
Mr Gig Studios is a rehearsal and recording studio based in Bletchley, Milton Keynes. We are the data controller for the personal information collected through this website. You can reach us at [email protected].
We collect personal data in the following ways:
When you make a booking or create an account, we collect your name, email address, and phone number. Your password is stored in an irreversibly hashed form. Booking records also include the studio booked, your session dates and times, the total price, the amount you have paid to date, and a booking reference number. Where a deposit option is offered, we also record whether you chose to pay in full or by deposit, and the date and time you confirmed you understood that part of your payment is non-refundable.
When you send us a message through the contact form, we collect your name, email address, an optional phone number, and your message. This information is emailed to us and used solely to respond to your enquiry.
We do not store your card details. Payments are processed securely by Stripe. We only retain a reference to the Stripe checkout session used to confirm and reconcile your booking. If you pay a deposit followed by a balance payment, we retain a reference to each checkout session, along with the date the balance becomes due and the date it is paid.
For confirmed bookings, we generate a single numeric door access code each day, which is shared by everyone with a confirmed booking on that day and is valid only for that day. We store the code, its activation time, and its expiry time alongside your booking record, and email it to you ahead of your session.
Our legal basis for processing this data is the performance of a contract (your booking) and our legitimate interest in communicating with you about services you have enquired about.
We use the following third-party services, each of which may process some of your data:
Used to process payments securely. When you complete checkout, you are directed to Stripe's hosted payment page. Stripe collects your card details and billing information directly. We never see or store your card number. Stripe is PCI DSS compliant. stripe.com
Used on the contact form to distinguish human users from automated bots. When you submit the form, Cloudflare Turnstile collects information about your browser and interaction with the page (including your IP address) and sends it to Cloudflare for verification. This is governed by Cloudflare's Privacy Policy. cloudflare.com/products/turnstile
An embedded Google Map is shown on our contact page to help you find us. Loading the map may cause Google to collect data about your visit in accordance with Google's Privacy Policy. maps.google.com
We use Google Fonts to serve typefaces used across the site. When fonts are loaded your browser may send a request to Google's servers. fonts.google.com
We use a session cookie to keep you logged in to your customer account and to maintain your booking flow. This cookie is essential for the site to function and is deleted when you close your browser or log out. We do not use advertising or tracking cookies.
Booking records are retained for a minimum of six years to comply with financial record-keeping obligations. Your customer account information is kept for as long as you maintain an account with us. Contact form submissions are retained only as long as necessary to resolve your enquiry. Door access codes are automatically deactivated after your session ends.
Under UK GDPR you have the right to:
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
All data is transmitted over HTTPS. Passwords are stored using a one-way hash and are never stored in plain text. Access to our systems is restricted to authorised personnel only.
We may update this privacy policy from time to time. Any changes will be published on this page with a revised date at the top. Continued use of the site after changes are posted constitutes your acceptance of the updated policy.