1. Overview
WITHINDLENS ("we", "our", or "us") operates the website at withindlens.com. This Privacy Policy explains what personal information we collect when you use our platform, why we collect it, and how we safeguard it.
By accessing or using WITHINDLENS you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the platform.
2. Information We Collect
We collect only the minimum information necessary to operate the platform:
- Account data — When you register, we collect your full name, email address, and a securely hashed version of your password. We never store your password in plain text.
- Usage data — We may log general information such as pages visited, content interacted with, and approximate session duration. This data is aggregated and not linked to your identity.
- User-generated content — Any reviews or comments you submit are stored and publicly displayed alongside your display name.
- Contact enquiries — If you contact us via email, we retain your message to respond to your enquiry and, where appropriate, follow up.
We do not collect payment information, government-issued IDs, or any sensitive personal data.
3. How We Use Your Data
We use the information we collect to:
- Authenticate your account and maintain a secure login session.
- Display your name alongside reviews and comments you submit.
- Respond to support requests and enquiries.
- Monitor platform performance and diagnose technical issues.
- Improve the quality and relevance of content we feature.
We will never use your email address to send unsolicited marketing communications without your explicit consent.
4. Cookies
WITHINDLENS uses a single, essential session cookie to keep you logged in while you browse. This cookie is:
- Stored only for the duration of your browsing session (or a maximum of 2 hours of inactivity).
- Not used for advertising or tracking across other websites.
- Not shared with any third party.
We do not use analytics cookies, advertising cookies, or any form of cross-site tracking. You can disable cookies in your browser settings, but doing so will prevent you from logging in.
5. Third-Party Services
To deliver our service, we use the following trusted third-party providers:
- Google Fonts & Font Awesome — for typography and icons. These providers may log your IP address as part of serving these assets.
- Firebase Storage (Google) — we store movie files, music tracks, and user-uploaded images on Google Firebase. Data is subject to Google's Privacy Policy.
- External ticketing partners — if you click a "Get Tickets" link you will be taken to a third-party website. That site's own privacy policy will apply from that point forward.
We have no control over and assume no responsibility for the content or privacy practices of any third-party websites.
6. Data Security
We implement reasonable technical and organisational measures to protect your personal data, including:
- Passwords are hashed using PHP's
password_hash()(bcrypt) before being stored. Even in the event of a data breach, your plain-text password is not exposed. - Sessions are managed server-side with automatic expiry after 2 hours of inactivity.
- Database access is restricted to the application server and is not publicly accessible.
No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security. In the unlikely event of a data breach affecting your personal information, we will notify you promptly.
7. Your Rights
You have the following rights regarding your personal data:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may ask us to correct inaccurate data.
- Right to erasure — you may request that we delete your account and all associated data.
- Right to object — you may object to certain uses of your data.
To exercise any of these rights, please contact us. We will respond within 7 business days.
8. Data Retention
We retain your account information for as long as your account remains active. If you request account deletion, we will remove your personal data within 7 business days. Anonymised, aggregated usage statistics may be retained indefinitely.
Reviews submitted under your account may be removed or anonymised upon account deletion, at our discretion.
9. Children's Privacy
WITHINDLENS is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal information without parental consent, please contact us and we will delete that information promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make significant changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Continued use of the platform after any changes constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your data, please reach out to us: