Privacy policy
Draft — under review
This page reflects UK ICO (data-protection regulator) guidance and how comparable UK charities and directories write theirs. It is not legal advice, has not been checked by a solicitor, and will be reviewed and amended by Pete before launch.
No ad-tech, no tracking pixels, no user accounts — just an honest account of what data this directory handles, and why.
Who we are
directory.lgbt is an independent, UK-wide directory of LGBTQIA+ groups, services and spaces. It's currently run by one person (Pete), who is the "data controller" for the personal data described on this page — the person legally responsible for deciding how and why it's used. Our ICO (Information Commissioner's Office) registration reference will be added here once registration is complete. You can contact us about anything on this page at [email protected].
What data this directory publishes
The core of this site is a directory of organisations, not individuals: names, descriptions, services offered, categories, locations and contact details for LGBTQIA+ groups, charities and services across the UK. This information comes from public registers (the Charity Commission for England & Wales, the Scottish Charity Regulator OSCR, the Charity Commission for Northern Ireland, and Companies House), from organisations' own websites, and occasionally from Google Places. An organisation's own name, mission and services aren't personal data under data protection law — they describe an organisation, not an identifiable individual — but where a listing includes a named individual's own contact details (for example, a charity's registered complaints contact), that detail is personal data, and this policy applies to it.
Special category data — how we handle it
Because this directory is about LGBTQIA+ organisations, some of what we publish sits close to "special category data" under Article 9 of UK GDPR — information that could reveal someone's sexual orientation or gender identity. An organisation's own published mission and services aren't personal data about a specific person, so Article 9 doesn't apply there. It does apply, narrowly, where a specific named individual's own sexual orientation or gender identity is disclosed alongside their name — for example, in a free-text report or a register filing. Our policy is that content like that should not be published without redacting the individual's identity or attribute, and we review submissions with this in mind before anything goes live.
Why we're allowed to process this data (our lawful basis)
For publishing organisation and listing data, our lawful basis under UK GDPR Article 6 is "legitimate interests": running a public-interest directory that helps people find genuinely LGBTQIA+ services, republishing information the organisations themselves already make public (their own charity filings, their own websites), with a straightforward way for an organisation to ask us to correct or remove a listing if they object. For handling a report or a suggested correction you send us, our lawful basis is the same — legitimate interests in keeping the directory accurate and dealing with problems people flag.
Search, location and cookies
Searching the directory doesn't create an account and isn't logged against your identity. If you tap "Use my location", your device's location is used to find nearby services for that one search and is never stored. If you type a postcode instead, only the first part of it (the outward code, like "SW9") ever leaves your browser — never the full postcode. Our own server turns that into an approximate location using postcodes.io, a free government-open-data-backed lookup service; because we look each area up through our server rather than directly from your device, postcodes.io never sees your personal IP address, and we cache each area so it's only ever looked up once. The only cookie this site sets is a simple, non-tracking preference for light/dark theme — see our short Cookies page for the detail. We use Plausible, a privacy-friendly analytics service run from the EU that doesn't use cookies and doesn't build a profile of you across visits. It counts page views, and when you search it records only a general region or radius band and a rough range for how many results came back — the words you actually typed are never sent to Plausible at all, so there's nothing search-text-shaped for a third party to hold, however long its retention period runs. Visits to our Need help now page (/help-now) are never sent to Plausible at all — we filter those out on our own server before they'd ever reach it, so nothing about that visit is recorded by Plausible or kept anywhere in our own logs.
If you report a problem or suggest a correction
If you use the "Report a problem" or "Suggest an edit" link on a listing, we collect what you type — an optional email address (only if you'd like a reply), a reason, and any free-text description or suggested correction. We use this to fix the listing and, if you left an email, to follow up with you. We don't require an account to do this, and we don't ask for more than we need in order to act on your report.
Who else sees this data (our processors)
We use a small number of specialist companies to run the site, and none of them get more of your data than they need to do their job: Railway hosts the website and its database infrastructure; Supabase is our database and enforces who can see what; Meilisearch (which we run ourselves on Railway) powers on-site search using only already-published listing data; Cloudflare sits in front of the site for security and performance and screens public forms for automated abuse; Plausible (EU-based) provides the cookieless analytics described above; and Sentry helps us notice when something on the site breaks. On the admin side — never visible to the public — we also use the Charity Commission, OSCR, Companies House, CharityBase, Google Places, Firecrawl and Ideal Postcodes to source, check and validate organisation data, and Google's Vertex AI (Gemini) to help sort new organisations into the right category before a person reviews them.
How long we keep data
Published listing data is kept for as long as the organisation is listed, since that's the whole point of the directory; if an organisation closes or asks to be removed, we take it down. Behind the scenes, our policy is to keep records of changes and admin activity (our audit trail) for up to 24 months, ingestion run logs for up to 6 months, and reports or suggested edits you send us for up to 18 months. We don't send the words you type into search to Plausible at all (see "Search, location and cookies" above), so there's no separate third-party retention question for it. The general region/radius band and result-count range we do record with Plausible are ordinary analytics data, kept for as long as our Plausible plan's standard retention period runs (currently several years) — the same as our page views — and we can delete it all in one go, for that data specifically or for the whole site, at any time. We're building automatic clean-up to enforce the other limits above; until that's in place, a person removes data past its window, and you can ask us to erase yours sooner at any time (see "Your rights"). Backups of the whole database are kept for up to 30 days before being automatically overwritten.
Your rights
Under UK GDPR you can ask us to: confirm what personal data we hold about you and get a copy of it (a "subject access request"); correct it if it's wrong; ask us to erase it; and object to how we're using it. Because this site has no user accounts, most of these rights concern things like a report you sent us, or a personal contact detail (not an organisation's general listing) that appears somewhere in the directory. To make any of these requests, email [email protected] — we aim to respond within one month, as UK GDPR requires. You also have the right to complain to the Information Commissioner's Office (ico.org.uk) if you think we've got something wrong.
Organisations: correcting or removing your listing
If you run an organisation listed here and want to correct, update or remove your entry, that's not a data protection request (an organisation isn't a "data subject" under GDPR) — it's a straightforward listing change, and we'll action it quickly. Use the "Suggest an edit" link on your listing, or email [email protected].
Changes to this policy
We'll update this page whenever what we do with data changes materially — for example, if we add analytics, a new external service, or user accounts. We don't expect to make changes without saying so here first.