1. Scope
This policy explains how the BlackStone RP website may handle personal information. It is written for a UK audience and is intended to reflect UK data-protection concepts, including transparency, data minimisation and individual rights. It is not a claim of legal certification or solicitor review.
2. Information the website may process
Public visitors are not required by this website version to create an account. The site may process basic technical information needed to deliver and secure the website, such as request information, device/browser details and service logs generated by the hosting platform.
If a person voluntarily contacts BlackStone through a configured community, support or payment provider, that provider may process information under its own privacy terms.
3. Admin authentication
Authorised administrators use Supabase Authentication. Supabase may process account identifiers, authentication events and session data needed to sign administrators in securely. Admin role records are stored in the site database.
4. Gallery administration
Gallery images, titles, descriptions, publication status, ordering information, timestamps and the ID of the administrator who created an entry may be stored in Supabase. Public visitors only receive gallery entries marked as published.
5. Cookies and local storage
Authentication cookies may be used for administrator sessions. The public marketing pages do not intentionally require advertising or tracking cookies in this version. If analytics or other integrations are added later, this policy should be updated before deployment.
6. Third-party services
The site is designed to use Supabase for database, authentication and gallery storage, and Vercel for web hosting. Links may also direct users to Discord and, if configured later, third-party store or payment providers. Those services operate under their own terms and privacy notices.
7. Lawful handling and retention
BlackStone should only retain information for as long as it is reasonably needed for website operation, security, administration, dispute handling or legal obligations. Actual retention periods should be reviewed when real contact, payment, analytics or moderation workflows are connected.
8. Security
The website uses server-side admin access checks, Supabase authentication and database access controls. No online system can be guaranteed completely secure, so administrators should use strong unique passwords and keep credentials private.
9. Your rights
Depending on the circumstances and applicable UK data-protection law, individuals may have rights to request access, correction, deletion, restriction or other information about personal data relating to them. Requests should be sent to the configured BlackStone contact address.
10. Contact
A privacy contact email has not yet been configured. Add one in src/config/site.ts before public launch.
11. Changes
This policy may be updated as BlackStone’s website, integrations or legal obligations change. The current revision date is shown at the top of this page.