Last updated: Monday, 7 September 2026

This Privacy Policy explains how we collect, store and use personal data when you visit Drunken Knitwits (the "Website") and when you register as a member and use the features it offers (together, the "Services"). It sets out what personal data we collect, why we collect it, who we share it with, and the rights you have over it. Please read it carefully.

We are the data controller for the personal data held in the Services. That means we decide what may be collected and what it is used for, how long it is kept and how it is protected, and we are responsible to you for it. Section 4 sets out the part a group's organisers play in that, and the position where they hold your details outside the Services.

1. Who we are

If you have any question about this policy, or you want to exercise any of the rights described in it, contact us at privacy@drunkenknitwits.com.

2. The personal data we collect

We collect the following personal data about you:

  • Your account details - your first and last name, your e-mail address, and your password. Your password is stored only as a salted hash, so we never hold the password itself and cannot recover it.
  • Your preferences - your time zone, your preferred date and number formatting, and your preferred distance units. We take these from your browser when you first visit and keep them up to date as you use the Services.
  • Your profile - the profile photo you upload, and the answers you give to the profile questions asked by the groups you join.
  • Your location - an approximate location and place name, where you choose to give one, so that we can show you groups and events near you. This is the location you enter or agree to share; we do not track your device. Before you have given us one, we guess a town from your IP address in order to suggest groups near you and to choose between miles and kilometres. That guess is worked out on our own servers, from a database we hold: your IP address is not sent to anybody else for it, and the guess is not stored unless you save it as your location.
  • Your topics of interest - the topics you select to help us suggest relevant groups.
  • Your group memberships - which groups you belong to, when you joined each one, whether your membership has been approved, and the status and expiry date of any membership subscription.
  • Your events - the events you respond to and whether you said you were attending.
  • Your messages - messages you send to a group's organisers, and messages you send to us through the Website.
  • Your payments - a record of payments you make through the Services, including the amount, the currency, the date and what the payment was for. We never see or store your card details; these are handled entirely by our payment provider (see section 5).
  • Technical data - your IP address, the pages you request and your browser's identifying information, recorded in our server logs. We also store the score our anti-automation check returned when your account was created.

Where a group's organisers invite or import you, we may receive your name and e-mail address from them before you have any account with us. If you never take the invite up, both are deleted - see section 7.

3. How we use your personal data

We only use your personal data where the law allows us to. In each case below we say what we do and the lawful basis we rely on.

  • To provide the Services to you - creating and maintaining your account, showing you to the groups you have joined, managing your memberships and event responses, and delivering the e-mails the Services depend on, such as account activation, password resets and notices about your membership. Lawful basis: performance of our contract with you.
  • To take and record payments - processing membership payments and keeping the records of them. Lawful basis: performance of our contract with you, and our legal obligation to keep financial records.
  • To keep the Services secure - detecting and preventing automated sign-ups, checking that an e-mail address is deliverable, warning you if the password you have chosen has appeared in a known data breach, and investigating faults and abuse using our server logs. Lawful basis: our legitimate interest in keeping the Services safe and working.
  • To send you group and event e-mails - so the groups you belong to can tell you about their events and news. Lawful basis: your consent, which you can withdraw at any time from your account settings without affecting your membership.

We do not use your personal data to make any decision about you by automated means alone, and we do not profile you for advertising.

4. What group organisers can see

Groups on Drunken Knitwits are run by their own organisers. When you join a group, its organisers can see the following about you, for that group only:

  • Your name and profile photo;
  • Your answers to that group's profile questions, including any answers the group asks for on application and does not show to its other members;
  • The date you joined, and whether your account has been activated;
  • Your membership type, subscription status and expiry date, and the payments you have made to that group;
  • The events of theirs you have responded to;
  • Your conversations with that group's organisers;
  • Whether you have chosen to receive that group's e-mails.

Group organisers do not see your e-mail address. They can write to you through the Services, and we deliver the message on their behalf, but the address itself is not shown to them and is not included in the member list they can download.

There are two exceptions to that. If an organiser added your e-mail address themselves in order to invite or import you, they already hold it. And if a group takes payments, it holds its own account with our payment provider, and the details you give when paying - including your e-mail address and billing information - are visible to that group in that account.

Other members of a group you have joined can see your name, your profile photo, the date you joined and your answers to that group's profile questions, other than those the group has marked as being for organisers only. Your profile is not visible to anybody who is not signed in.

Everything described above is held by us, and we are the data controller for it - including the answers you give to a group's questions. A group's organisers choose what their group asks and decide who joins it, but they do so inside the Services: they cannot take a copy of your answers or of your e-mail address, we decide how long any of it is kept and how it is protected, and a request to see, correct or delete it comes to us. Your rights under section 8 cover what a group holds about you here, and you exercise them with us.

Where a group's organisers hold your details outside the Services, they are a data controller in their own right, and what they do with them is their responsibility rather than ours. That covers the two exceptions above - an e-mail address an organiser already had and used to invite or import you, and the details held in the group's own account with our payment provider - together with anything an organiser notes down or copies elsewhere. For any of those, contact the group's organisers, and tell us if you cannot resolve it with them.

5. Who else we share your data with

We do not sell or rent your personal data to anybody, and we do not share it for anybody else's marketing.

We use a small number of providers to run the Services, and they do not all stand in the same relationship to your data. The difference is worth knowing, because it decides who answers to you for what:

  • A processor may use your data only to provide its service to us, on our instructions. We remain answerable to you for it, and a request about it comes to us.
  • A controller decides for itself what it does with what it receives, under its own privacy policy and its own responsibilities. Where a provider is one, its own policy is the place to look.

Each provider's name below links to its own privacy policy. Where the data is held is the country the data sits in, which is not always the country the provider comes from.

Provider Their role What they do for us What they receive Where the data is held
Stripe Controller and processor Takes and processes payments Your name, e-mail address, and the payment and card details you enter Ireland, and the United States
Brevo Processor Delivers our e-mails Your name, e-mail address and the content of the e-mail France, Germany and Belgium
Google Controller Maps and place look-up, and sign-in with Google where you choose it Your IP address and browser information; a location you search for; and, if you sign in with Google, your name and e-mail address from your Google account Ireland, and the United States
Google reCAPTCHA Processor The check that protects our sign-up form from automated abuse Your IP address and browser information Ireland, and the United States
Have I Been Pwned Neither - receives nothing that identifies you Tells us whether a chosen password is known to have been breached The first five characters of a hash of the password only. Your password, and your identity, are never sent Not applicable
Better Stack Processor Stores our server logs so we can diagnose faults, for 3 days Technical data, including your IP address European Union

Stripe is both, which is why it is listed as both. When it takes a payment for us it does so on our instructions, and there it is our processor. It also uses what it learns to prevent fraud and to meet the duties any payment company has under financial law, and for that it decides for itself and answers for itself.

A group that takes payments holds its own account with Stripe, as section 4 explains. What that group does with the details in its own account is a matter for the group, not for us.

We may also disclose your personal data where we are required to by law, or where it is necessary to establish, exercise or defend legal claims.

6. Cookies

Cookies are small data files a website places on your device. We use only the cookies the Services need in order to work:

  • A sign-in cookie, so that you stay signed in as you move around the Website. It lasts up to 30 days, or until you sign out.
  • A security cookie, which protects the forms on the Website against being submitted from somewhere else on your behalf.

We do not use any advertising, analytics or tracking cookies, and we do not allow anybody else to track you across other websites through ours.

Some pages include services provided by Google - a map, or the reCAPTCHA check on our sign-up form - and these may set cookies of their own when those pages load. A cookie a map sets is Google's own, and what Google does with it is governed by Google's privacy policy. A cookie reCAPTCHA sets is not: Google provides that check to us as our processor, so what it collects may be used to run and secure the check and for nothing else of Google's own.

You can set your browser to refuse cookies, but if you refuse the two cookies above you will not be able to sign in or submit forms. Each browser is different, so please see your browser's "Help" menu for how to change your cookie preferences.

7. How long we keep your data

We keep your personal data for as long as you have an account with us. You can delete your account at any time from your account settings, and doing so removes your personal data from the Services.

If you leave a single group, we remove your membership of that group and the answers you gave to that group's questions, and your account itself is unaffected.

Where a group's organisers gave us your name and e-mail address in order to invite you, we delete those details 90 days after we received them from the organiser, unless by then you have accepted the invite or activated the account it raised. That period runs from when we received your details, so it does not depend on when - or whether - the group sent the invite. You do not have to wait for it either: every invite e-mail carries a link that declines the invite and deletes those details straight away.

Two things outlive your account. We keep records of payments for as long as tax and accounting law requires us to, currently six years. And our server logs, which record technical data rather than your profile, are kept for 90 days and then deleted. A copy is also held by our logging provider for 3 days, as set out in section 5.

8. Your rights

You have the following rights over your personal data, free of charge:

  • Access - to ask us for a copy of the personal data we hold about you;
  • Correction - to have inaccurate or out-of-date data corrected. Most of it you can correct yourself in your account settings;
  • Erasure - to ask us to delete the personal data we hold about you;
  • Restriction - to ask us to stop using your data while a question about it is resolved;
  • Portability - to receive the data you gave us in a common, machine-readable format, or to have us send it to somebody else;
  • Objection - to object to our using your data where we rely on our legitimate interests;
  • Withdrawing consent - to withdraw your consent to group and event e-mails at any time, without affecting your membership or anything done before you withdrew it.

To exercise any of these, write to privacy@drunkenknitwits.com. We will respond within one month.

If you are not satisfied with how we have handled your personal data, you can complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113. We would be grateful for the chance to address your concern first.

9. Security

We take appropriate technical and organisational measures to protect your personal data. The Website is served over an encrypted connection, passwords are stored only as salted hashes, and card details never reach our systems.

No transmission over the Internet can ever be guaranteed completely secure, so we cannot promise absolute security for data you send us over the Internet. If a breach of your personal data occurs that is likely to result in a risk to your rights, we will notify the Information Commissioner's Office, and you, as the law requires.

10. Where your data is held

Your personal data is held in the United Kingdom and the European Economic Area, except where the table in section 5 names somewhere else. That table gives the country for every provider, so it is the place to look rather than this section.

Two of those providers hold data outside the UK and the EEA: Stripe and Google. We deal with the Irish company in each case, and each transfers onward to the United States. Where personal data goes to the United States, the transfer relies on the UK Extension to the EU-US Data Privacy Framework where the receiving company is certified under it, and otherwise on the International Data Transfer Agreement or the UK Addendum to the standard contractual clauses. Each of those binds the recipient to protect your data to the UK standard, and leaves you able to enforce it.

Not every transfer in the chain is ours to make. A provider we send your data to inside the UK or the EEA may itself use another company further down the line, and where that company is outside the UK and the EEA, the transfer is one our provider makes under the contract it holds with us - it is not a transfer we make ourselves, and it is that provider's to account for. We require our providers to hold those onward transfers to the same standard we hold our own to, and the privacy policies linked in section 5 name the companies each of them uses.

11. Children

The Services are not intended for children, and you must be at least 16 years old to register as a member. We do not knowingly collect personal data about anybody younger. If you believe a child has given us their personal data, contact us at privacy@drunkenknitwits.com and we will delete it.

12. Changes to this Privacy Policy

Any changes we make to this Privacy Policy will be posted on this page, and the date at the top will be updated. Where a change materially affects how we use your personal data, we will tell you by e-mail before it takes effect.