🇬🇧London:--:--:--🇳🇵Kathmandu:--:--:--
💱

Legal

Privacy Policy

Last updated: 21 May 2025

Nepalese Business Directory Ltd (“we”, “us”, “our”) operates https://nepalesebusinessdirectory.co.uk. We are committed to protecting your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

Nepalese Business Directory Ltd is the data controller responsible for your personal data collected through this website.

Contact: info@nepalesebusinessdirectory.co.uk

If you have concerns about how we handle your data, you may also contact the Information Commissioner's Office (ICO) at ico.org.uk.

2. Data We Collect

We collect the following categories of personal data:

Account & Identity

Full name, email address, hashed password, profile photo, city, and account type.

Business Listing Data

Business name, address, phone, website, opening hours, category, description, and images.

Payment Data

Stripe customer ID, transaction reference, amount, and status. We do NOT store card numbers — these are held by Stripe.

Event & Ticket Data

Name, email, ticket quantity and type for event bookings.

Job & Room Listings

Listing details, CVs, cover letters, and answers to custom application questions.

User-Generated Content

Reviews, community posts, questions, comments, and saved businesses.

Communications

Emails, enquiry forms, and direct messages sent through the platform.

Technical & Usage Data

IP address, browser type, device, pages visited, and analytics data.

Marketing Preferences

Whether you have opted in or out of newsletter and email marketing.

3. How We Use Your Data

We use your personal data to:

  • Create and manage your account
  • Display business listings, jobs, and rooms to other users
  • Process event ticket purchases and send booking confirmations
  • Process payments via Stripe and manage subscriptions
  • Send transactional emails (confirmations, password resets, listing approvals)
  • Send marketing emails where you have opted in
  • Display reviews and community content
  • Verify business ownership claims
  • Prevent fraud, abuse, and spam
  • Improve the platform through analytics
  • Comply with our legal obligations
  • Respond to enquiries and support requests

5. Sharing Your Data

We do not sell your personal data. We share data with:

  • Supabase — database and authentication provider (EU/UK data storage).
  • Stripe — payment processor, PCI-DSS compliant.
  • Netlify — hosting and CDN provider.
  • GoHighLevel — CRM and email marketing platform for business contacts.
  • Google Analytics / Meta Pixel — analytics tools (only where consent has been given).
  • Business owners — your name and email when you submit an enquiry through a listing.
  • Event organisers — your name and email for check-in when you buy a ticket.
  • Legal authorities — where required by law, court order, or to protect safety.

6. Data Retention

  • Account data: Until you delete your account, plus 30 days for recovery.
  • Payment records: 7 years (UK financial regulation requirement).
  • Event ticket data: 2 years after the event date.
  • Job applications: 6 months after the closing date.
  • Analytics data: Up to 26 months; aggregated data indefinitely.
  • Newsletter subscribers: Until you unsubscribe.

7. Your Rights

Under UK GDPR you have the right to:

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your data (subject to legal obligations).
  • Restrict processing — limit how we use your data.
  • Data portability — receive your data in a machine-readable format.
  • Object — object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent — unsubscribe from marketing at any time.

Email info@nepalesebusinessdirectory.co.uk to exercise any of these rights. We will respond within 30 days.

8. Cookies

We use cookies to operate the site and, with your consent, to analyse traffic and deliver personalised advertising. See our full Cookie Policy.

9. Security

We implement HTTPS encryption, hashed passwords, row-level database security, and restricted access to production systems. No system is 100% secure. If you believe your data has been compromised, contact us immediately at info@nepalesebusinessdirectory.co.uk.

10. Children's Privacy

Our services are not directed at individuals under 13. We do not knowingly collect data from children. If you believe a child has provided us with their data, contact us and we will delete it promptly.

11. International Data Transfers

Some service providers (Supabase, Stripe, Netlify) may process data outside the UK. We ensure appropriate safeguards including Standard Contractual Clauses (SCCs) or UK adequacy decisions are in place.

12. Changes to This Policy

We may update this policy periodically. Significant changes will be communicated by email or a prominent site notice. The “Last updated” date at the top reflects the most recent revision.

13. Contact Us