Skip to content
Logo de FlipoPark

Privacy Policy

Content pending review by a lawyer before its final publication. The data described, the categories, the retention periods, and the legal bases reflect what the application actually collects, but the final wording of this page must be reviewed by a legal professional before we operate with real personal data.

Data Controller

The controller responsible for the personal data collected on this site is Victoria García García, with NIF (Spanish tax ID) 77422591Z and registered address at Rúa Echegaray 26, 36002 Pontevedra, owner of FlipoPark, a children’s ball pit park in Pontevedra.

What data we collect

The booking form on this site collects only the data needed to handle your request:

  • Name
  • Contact phone number
  • Email address
  • Number of children
  • Message or additional comments about the celebration
  • The child’s allergies or intolerances, if you choose to provide them
  • The age of each birthday child, if the event is a birthday party
  • The name of each birthday child, if you choose to provide it and the event is a birthday party

Allergies and intolerances have their own fields in the form — a closed list of the 14 allergens subject to mandatory declaration under Regulation (EU) 1169/2011 to tick, plus a text field for anything not on it — separate from the message field, and optional: we do not ask for them as a requirement. If you do provide them, we process them because you have chosen to share them and have given us your explicit consent to do so via a specific checkbox.

In addition to allergies, the wizard includes a special diets section (vegetarian, vegan, halal, kosher, pork-free, among others). If your child follows a halal or kosher diet, that information reveals a religious belief and is therefore also special category data under Article 9 GDPR, just like allergies. That is why, in the same work cycle as this page, we are adding a specific explicit consent checkbox for diets, separate from the allergy one and from the general acceptance of this policy.

If the event is a birthday party, we also ask for the age each child is turning (only the number, never the date of birth), so we can offer the correct time slot and price. This is data about your child that you, as the parent or legal guardian, provide to us — the form is not filled in by the minor.

If the event is a birthday party, you can also tell us the name of each child having a birthday (up to 60 characters, up to 10 birthday children). This is an optional field: the booking works the same whether you fill it in or not. As with the age, this is data about your child that you, as the parent or legal guardian, provide to us — the form is not filled in by the minor.

In addition to the website form, we collect the following other data at the venue itself:

  • Customer record (name and phone number only): we create this when you book a birthday party or when you drop off a child at the park without staying yourself. If you stay at the park, we do not ask you for any data: you pay and enter just as before. We do not ask for an email address or ID card for this record.
  • Payment log: amount, payment method (cash, card, bank transfer, or Bizum), whether it is a deposit or the balance, the date, and which staff member recorded it. Most open-play payments have no customer attached, because most accompanying adults stay at the park.
  • Internal change log: when a payment or a customer record is edited, we store what changed, who made the change, and when. This is an internal business control, not additional data about you.
  • First names of the children attending a birthday party: when the party starts, staff write down each child’s first name at the front desk next to their wristband code and their locker code. First name only, up to 30 characters: never surnames and never date of birth.

Contact, event, and after-school activity forms

In addition to the birthday booking wizard, this website has other forms that also collect your data and are processed differently:

  • The general contact form, with your name, phone number, email address, and the message you write.
  • Event requests: in addition to that contact data, the type of event, the preferred date, and the number of children and adults.
  • After-school activity enrolment requests: in addition to the contact data, the child’s age and the chosen workshop.

These forms are not processed on this website itself — which is a static site, with no server of its own: your data travels directly to FlipoPark’s management platform, through an endpoint dedicated to contact requests.

The after-school activities form may include, within the free-text message, information about the child’s allergies — this is health data even when written as free text. In the same work cycle as this page, we are adding a specific explicit consent checkbox for that information, just like the one in the birthday wizard.

For the other cases — a contact enquiry or an event quote request — we ask for your general, mandatory consent when you submit the form.

Purpose

We use this data exclusively to handle your booking request: to contact you, confirm date availability, and answer your questions about the birthday party or event. If you tell us about allergies or other health information, we use it solely to make the celebration safe for your child (for example, to alert the kitchen or adapt the menu).

We use the age only to work out the party category (children’s or teen) and the applicable price, never for any other purpose.

The name of each birthday child, if you provide it, is used only to personalize the celebration and the confirmation we send you (for example, to address each child by name); we do not use it for anything else, and the booking is handled the same way if you leave it blank.

We use the customer record so we can call the responsible adult if needed while a child is at the park without them, and so we don’t have to ask you for your details again if you come back another day. We use the payment log to keep the business’s accounts and balance the till each day. We use the internal change log only so we can review, if ever needed, who changed a payment or a record and when.

The first name we write down at the front desk when a birthday party starts is used only during the party and for two things: matching each child’s wristband and locker to them, and being able to answer a parent who asks at the desk who has already arrived. That list is checked by staff only: there is no screen, link, or access available to families.

Legal basis

The processing is based on your consent, given by voluntarily filling in and submitting the booking form. For the child’s health information (allergies or intolerances), the legal basis is your explicit consent, given by ticking a specific checkbox separate from the general acceptance of this policy. That checkbox only appears if you mark an allergen or fill in the free-text field.

We only ask for the customer record when you drop off your child at the park without staying: in that case the legal basis is the safety of the minor, not your consent — precisely so it does not depend on whether you agree to provide your data. If you stay, we ask for nothing. The payment log is based on a legal obligation: the Spanish Commercial Code (Código de Comercio) requires us to keep records of amounts charged.

The first names of the children at a birthday party are processed to perform the birthday service you have already contracted (Article 6(1)(b) GDPR), not on the basis of your consent. We do not ask for a checkbox for this, and that is deliberate: without that data we cannot tell which wristband and locker belong to which child, so a checkbox would not give you a real alternative. Nor is it health data or any other special category under Article 9 — a first name reveals nothing of that kind — which is why it does not share a checkbox or a legal basis with the allergy data.

In general terms: ordinary contact and booking data (name, phone number, email, message, event type, date, number of attendees) are processed because they are necessary to manage the pre-contractual or contractual relationship with you — the same contract-performance basis explained above — and, on forms where an acceptance checkbox is requested, also with your consent (Article 6(1)(a)). A minor’s health data (allergies) and religious belief data (halal or kosher diets) are always processed with the explicit and specific consent of whoever holds parental responsibility (Article 9(2)(a) GDPR), via a checkbox separate from any other consent.

Retention

The child’s health information has its own, much shorter retention period: we delete it 30 days after the event date, because its sole purpose — making the celebration safe — is fulfilled once the celebration is over. It does not wait for the general period described below.

The age of each birthday child has that same period: we delete it 30 days after the event date. It is not health data, but its purpose — choosing the time slot and price — is likewise fulfilled once the celebration is over, so there is no reason to keep it any longer. It is not part of the historical statistics described below. If you also gave us the name of each birthday child, we delete it in that same operation, together with the age — it shares the process and the period, not a period of its own.

We keep your data for as long as we are handling your booking and, where applicable, for as long as there is an ongoing relationship with FlipoPark (for example, if you hold the event and we need to reach you about any incident). Once 5 years have passed since the event date, FlipoPark’s own policy is to anonymize the booking record: we delete the name, phone number, email, message, and any internal notes. We keep only the date, the time slot, the type of event, the number of children, and the booking status, so we can keep historical accounts for the business. From that point on, that information no longer identifies anyone and is kept indefinitely as statistics.

Payments and the customer record are kept differently, because they are not the same thing. We keep the payment log for 6 years, because the Spanish Commercial Code (art. 30) requires accounting books and supporting records to be kept for six years: this is not a figure we can shorten. The customer record, by contrast, is a convenience so we don’t have to ask you for your details again, not an accounting document: if after 3 years you have not returned to the park, we anonymize your record (deleting your name and phone number) and your payments remain as unnamed lines, with the amount intact to preserve the accounts.

The first names of the children at a birthday party have the shortest retention period of all: we delete them when the party ends and, in any case, at most 24 hours after it started, even if no one closes it out. This does not rely on staff remembering: an automatic process deletes it regardless. What we do keep is the wristband code, the locker code, and the check-in and check-out times, which are the record of the event and do not by themselves identify any child.

Contact, event, or after-school activity requests that do not turn into a booking or an enrolment are anonymized after 12 months. Any health data that may appear in them — for example, allergies mentioned in the message of an after-school activities request — is deleted sooner, after 30 days, just as in the birthday wizard.

From request to after-school activity enrolment

If an after-school activity enrolment request turns into an actual enrolment, that process moves to FlipoPark’s internal management platform, which is not part of this website. To be honest about the data’s full journey in this policy: once enrolled, the child has a record with name, age, allergies or diets — the same type of special category data and the same type of consent described above — and an emergency contact. The health data in that record is kept for 6 months after all of the child’s enrolments have ended, and the rest of the record for 12 months, with automatic anonymization once that period has passed.

FlipoPark customer area (ClubFlipo)

In addition to this website, FlipoPark offers its customers a private area at club.flipopark.es ("ClubFlipo"), where you can check your bookings, your children’s records, your payments, and your passes. You sign in without a password, through a sign-in link ("magic link") sent to your email — we do not store any password of yours. This section describes what data ClubFlipo processes, for what purpose, on what legal basis, and for how long; the rest of this policy — providers, your rights and the contact channel — applies to ClubFlipo too.

Your customer account data

To give you access to ClubFlipo and manage your account, we process:

  • Your name, phone number, and email address, the same ones already on your customer record or your bookings.
  • Your notification preferences: whether you want to receive operational notices, marketing notices, or both.
  • The sign-in identifier generated by your access link, to keep you identified while you use the app. It is stored in the browser itself (local storage), not in a cookie — see the cookie policy for the technical detail.

Your children’s data

ClubFlipo shows the record for each child you have registered with FlipoPark: name, date of birth, allergies and intolerances, special diets, and notes. These are the same types of health and belief data already described in the "What data we collect" section of this policy, now also visible and editable by you in ClubFlipo. You can edit your children’s allergies and diets directly from the app; the rest of the record is managed by park staff. The record also includes the people you authorise to pick up your child (name, relationship, phone number and identity document): before giving us another person’s data you must have informed them and obtained their agreement; we use it only to verify their identity at pick-up, as a safety measure for the child, and keep it while the authorisation is in force and, at most, for the same period as the child’s record.

Bookings, payments, passes, and after-school activities

ClubFlipo shows you, in read-only mode, the history and status of your birthday bookings, your payments (amount, payment method, and date), your entry passes, and your children’s after-school activity or playroom enrolments, including their monthly attendance. FlipoPark does not process card payments within this app: payments are recorded at the park at the time they are made — in cash, by card, bank transfer, or Bizum — and ClubFlipo only displays that record; if you pay by card, your card data is processed by the park’s card terminal, not by FlipoPark. If online payment from within the app is activated in the future, the card number will be processed directly by whichever payment gateway is contracted at that time, never by FlipoPark — see the recipients section below.

Purpose

We use this data to give you access to your own information as a FlipoPark customer, so you can check it without having to call or write to the park, and so you can keep your children’s allergies and diets up to date. We also use it to send you the operational notifications you have accepted, for example that a payment has been recorded or that a pass is about to expire.

Legal basis

Processing your account, booking, payment, pass, and after-school-activity data is based on the performance of the contract you already have with FlipoPark as a customer (Article 6(1)(b) GDPR): it is the same data that relationship already generates, now accessible to you in a private area. Your children’s health and belief data (allergies, diets) is processed under the explicit consent you already gave as parent or legal guardian when you provided it (Article 9(2)(a) GDPR); if your child is under 14, it is your consent as their legal representative that legitimizes that processing (Article 7 LOPDGDD, the Spanish data protection act), never the child’s own.

Retention

Each child’s record is kept for as long as any enrolment or admission remains active; once the last one has ended, it is anonymized after 12 months, except for health data (allergies, diets), which is anonymized sooner, after 6 months. Payments and accounting records follow the same 6-year period explained in the "Retention" section of this policy, under the same Spanish Commercial Code obligation. You can request to close your ClubFlipo account, and to have your data deleted, at any time from within the app itself (personal data section). That request is reviewed by FlipoPark staff and does not necessarily mean the immediate deletion of data we must keep under a legal obligation, such as accounting records.

Additional ClubFlipo recipients

In addition to the providers already named in the "Recipients" section of this policy, ClubFlipo uses: the hosting provider for the server the app runs on — a VPS at OVH, the same one that hosts the rest of FlipoPark’s systems; an email provider to send you the sign-in link and operational notices; and, if you enable browser push notifications, the push notification services of Google, Mozilla, or Apple, depending on the browser or device you use, to which only the technical identifier of your subscription is sent, never the content of your personal data. All of them act on FlipoPark’s instructions, solely to provide that service.

Recipients

We do not sell your data, we do not use it for advertising purposes, and we do not hand it over to anyone to use for their own purposes. It does pass through the technical providers that make the booking system itself possible: the form is sent to the platform that hosts and processes FlipoPark’s requests, and the notification of a new booking is sent by email through an email provider. Both act on FlipoPark’s instructions, solely to provide that service, and not for their own purposes.

There is also a known limitation that does not yet have a definitive solution: when someone fills in a form on this website, in addition to being saved on the management platform, a notification containing that data is also delivered to an internal FlipoPark mailbox. An email that has already been sent cannot technically be withdrawn. This point is pending confirmation from the lawyer on how it should be recorded in the record of processing activities — we do not yet have a definitive solution to offer here.

If you choose to write to us through this website’s WhatsApp link or button, you are the one who initiates that contact voluntarily: a WhatsApp conversation opens with your number and the message you wrote. We do not send or share your data via WhatsApp automatically — it only happens if you choose that channel. From the moment that conversation opens, the processing of your data is governed by WhatsApp’s own privacy policy (WhatsApp Ireland Limited, a Meta subsidiary), not by this one.

International transfers

Some of the technical and analytics providers named in this policy may involve a transfer of data outside the European Economic Area. Here is what we know about each one:

  • Google Analytics (Google Ireland Limited): browsing data may be transferred to Google LLC in the United States, certified under the EU-US Data Privacy Framework.
  • PostHog (PostHog Ireland Ltd): this website’s data is processed on PostHog’s European infrastructure, so in principle it should not involve a transfer outside the European Union.
  • Contentsquare: if any transfer of data outside the European Economic Area were to occur, it would take place under Standard Contractual Clauses (SCCs) or another transfer mechanism recognized under European law.
  • WhatsApp (WhatsApp Ireland Limited, a Meta subsidiary): only if you choose to write to us through that channel, as explained in the recipients section above. From that point on, any international transfers of your data are governed by WhatsApp’s own privacy policy.
  • Browser push notification services (Google, Mozilla, or Apple, depending on the device): if you enable push notifications in ClubFlipo, the technical identifier of your subscription may be transferred to these providers — based outside the European Union in the case of Google (Google LLC, United States, certified under the EU-US Data Privacy Framework) and Apple (Apple Inc., United States, subject to its own contractual safeguards); Mozilla provides this service from European infrastructure.

When we cannot state the exact transfer mechanism used by one of these providers, our general safeguard is that any transfer, if it occurs, takes place under Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework.

Cookies and analytics

This website uses Google Analytics, PostHog, and Contentsquare to find out how many people visit it, which pages interest them, and how they navigate the interface, but only if you give us your consent in the cookie banner: until you accept it, none of the three is activated. All three providers act as processors over that browsing data. You can see the details for each, and how to withdraw your consent, in the cookie policy.

Data Protection Officer

FlipoPark has not, at this time, appointed a Data Protection Officer (DPO). If you have any questions or wish to exercise your rights, the contact channel is the one indicated below.

Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction of processing, and data portability at any time, by writing to FlipoPark through the email address reservas@flipopark.es or through the contact form. You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es) if you believe the processing of your data does not comply with the regulations.

If you are a ClubFlipo customer, you can also request deletion of your account directly from within the app, in the personal data section.