Privacy Notice
What we collect, why, and how to get rid of it. No analytics, no advertising, no tracking cookies.
The short version
There is no analytics, no advertising, and no tracking of any kind on this site. We do not use Google Analytics or any equivalent, we run no ad network, we set no cookies to follow you, and we do not sell personal data to anyone.
What we do hold is small and boring: an email address if you have an account, and your IP address for a few minutes so that one visitor cannot exhaust the free API for everybody else. That is very nearly the whole story, and the rest of this page is just that in detail.
Who we are
ThemeParks.wiki is operated by Jamie Holding (James Holding on the paperwork), a sole trader based in the United Kingdom. We are the "data controller" for the personal data described on this page, which means we are the ones responsible for it, and here is where to find us on the record:
- Postal address: James Holding, ThemeParks.wiki, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom. Post needs the name James on it to reach us.
- ICO registration: ZC215410, on the Information Commissioner's Office register of fee payers. It is a public entry, so you can check it without asking us.
Contact us about anything here, including to exercise any of your rights: cube@themeparks.wiki. Email reaches us faster than post does.
What we collect, and why
If you use the site or API without an account, we process:
- Your IP address, to count requests against the rate limit and to block scanners and abusive traffic. It is held in a short-lived cache, not a database of visitors — see how long we keep things, below.
- The site your browser says you came from, and only the site. We keep
https://example.com, never the particular page you were on or anything after it. We count those in aggregate to see who links to the API, and we do not attach the count to you or to your IP address.
If you create an account, we additionally store:
- Your email address — to verify the account, let you reset your password, and contact you about the service or your API keys.
- Your username and display name.
- A one-way hash of your password. We never store the password itself and cannot recover it.
- One-way hashes of your API keys. We cannot show you a key again after you create it, because we do not have it.
- If you sign in with Discord or GitHub: the account identifier and display name they give us, plus access tokens, which are encrypted at rest. We ask those services for the minimum they will give us, and we never receive your password for them.
We do not ask for your name, address, phone number, date of birth or payment details, because we do not need them. If paid subscriptions launch, billing will be handled by a payment provider and this page will be updated before that happens.
There is no automated decision-making and no profiling. Nothing about you is decided by an algorithm here.
Our lawful bases
Data protection law requires us to have a specific reason for each use. Ours are:
- Performance of a contract — everything account-related. You asked us for an account and API keys; we cannot provide them without an email address and a password hash.
- Legitimate interests — rate limiting and abuse prevention using IP addresses, and the aggregate counts of which sites link to us. Our interest is keeping a free service available and not letting one client degrade it for everyone. We have weighed this against your privacy: the data is held briefly, used for nothing else, never enriched, never combined into a profile, and never shared for marketing.
We do not currently rely on consent for anything, which is why you are not being asked to click a banner.
How long we keep it
- IP addresses: minutes. A rate-limit counter lasts about a minute, and a block on abusive traffic lasts up to 30 minutes, after which it expires by itself. We do not keep a log of which addresses visited us.
- Account data: for as long as you have an account. Ask us to delete it and we will.
- Referrer counts: kept as running totals per linking site. There is nothing personal in them and nothing to tie one back to a person.
Separately, our hosting provider keeps short-lived server logs as part of running the platform, in the ordinary way.
Who else touches it
We use a small number of suppliers to run the service. They process data on our instructions only, under contract, and none of them are permitted to use it for their own purposes:
- Cloudflare — the website, DNS, and protection against attacks.
- Heroku (Salesforce) — application hosting and the database.
- Amazon Web Services — our data archive, in the London region.
- Mailgun — sending account emails, via its EU service.
- GitHub and Discord — only if you choose to sign in with them, or sponsor us through GitHub.
- Better Stack — monitoring whether the service is up.
We do not sell personal data, share it with advertisers, or hand it to data brokers. We would disclose data if we were legally required to, and we would tell you unless we were prohibited from doing so.
Where it is held
We keep data in the UK or EU where the choice is ours: our archive is in London and our email provider runs on its EU service. Some of our suppliers are US companies. Where personal data is transferred outside the UK or the EEA, that transfer is covered by the supplier's data processing agreement together with the UK's International Data Transfer Addendum or the EU standard contractual clauses, which are the safeguards the law provides for this.
Cookies and your browser
We set no cookies. Not for analytics, not for advertising, not for anything.
If you log in, the site keeps your session in your browser's local storage so you are not signed out on every page. It also briefly remembers two things to stop the site annoying you: whether a page needed reloading after an update, and whether you have dismissed the "create an account" prompt. All of that is necessary for features you asked for, none of it identifies you to anyone else, and none of it leaves your browser except to sign your requests to our own API.
That is why there is no cookie banner on this site. A banner exists to ask consent for tracking, and there is nothing here to consent to. If that ever changes, we will ask properly rather than assume.
Your rights
You can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything that is wrong.
- Delete your account and its data.
- Restrict or object to how we use it, including objecting to anything we do on the basis of legitimate interests.
- Port it — receive it in a machine-readable form.
Email cube@themeparks.wiki. We do not charge for this and we will not ask you why. We aim to respond within one month, which is the deadline the law sets, and we will tell you if a request is complex enough to need longer.
If you are unhappy with how we have handled your data, you can complain to the UK's data protection regulator, the Information Commissioner's Office (ico.org.uk/make-a-complaint), or to your own country's supervisory authority if you are in the EU. We would rather you told us first so we can put it right, but you do not have to.
Changes to this notice
If we change what we collect or why, we update this page and record it in the changelog below. Material changes are announced on the status page and, for account holders, sent by email. See also our Terms & Acceptable Use.
Changelog
- 9 August 2026 — added our postal address and ICO registration number, and corrected the referrer description: we only ever stored the linking site, never the page. No change to what we collect or why.
- 29 July 2026 — first published.