Skip to main content

Privacy Policy

Last updated: 21/7/2026

Who we are

FA Improv Limited (“FA”, “we”, “us”), company number 09448430, operates an improv comedy theatre and training school in London, and is the data controller for the personal data described in this policy. It explains what we collect when you use thefreeassociation.co.uk, buy tickets, join as a member, book classes, apply to perform, contact us, or sign up to our emails - and what we do with it.

For any privacy question, or to exercise any of the rights below, email hello@thefreeassociation.co.uk.

The data we collect

Things you give us

  • Account and contact details - your name, email address and postcode when you create an account or check out. If you set a password we store only a secure one-way hash of it, never the password itself. A small number of longstanding records also hold a date of birth inherited from a previous box-office system; our current forms don’t ask for it.
  • Orders and tickets - your purchase history with us: shows, classes, memberships and donations, plus the tickets issued against them (including their entry QR codes and when they were scanned at the door).
  • Payment details - payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers; we hold a payment reference and, for auto-renewing memberships, a reference to your Stripe subscription and saved payment method.
  • Enquiries and applications - what you submit through our contact, corporate-enquiry and performer-application forms: your name, email address and message, plus - where the form asks - a phone number, company name, and anything you choose to share (such as pronouns on performer applications).
  • Marketing preferences - which of our email lists you’ve joined or left, when, and the exact consent wording you agreed to.

Things generated when you use our services

  • Security data - we log the IP address alongside sign-in attempts, login-code requests and form submissions, and rate-limit those actions to protect accounts from abuse. Our web servers keep standard access logs (IP address, pages requested, browser type) for around two weeks.
  • Email activity - we send email through Resend and record delivery events (bounces, complaints) plus, for marketing email, opens and link clicks - so we stop mailing addresses that can’t or don’t want to receive mail, and can see which emails are worth sending.
  • Analytics - only with your consent (see Cookies below), Google Analytics data about how the site is used. The purchase statistics we send to analytics contain order values and items, never your name or email address.

Things we receive from others

  • Ticketing partners - where a show is sold through a ticketing partner (currently Ticket Tailor), we receive the order, your name and email address, and your answer to their marketing question, so your tickets and history are in one place. We don’t send your details back to them.
  • Class registrations - classes are administered on our course-management platform, Arlo. To show your class history or check student-discount eligibility we look up your registrations in Arlo by your email address.

How we use it (lawful bases)

  • Performance of a contract - taking payment, issuing tickets, running your membership, delivering classes, and sending service emails such as booking confirmations, receipts and login codes.
  • Legitimate interests - keeping accounts secure and preventing fraud (the IP logging and rate limits above), answering enquiries, keeping sales records, measuring email engagement, and maintaining a do-not-contact list so opt-outs stick.
  • Consent - marketing email and analytics cookies. You can withdraw consent at any time: every marketing email has an unsubscribe link, your account has marketing preferences, and the “Manage cookies” link in the site footer reopens the cookie choice.
  • Legal obligation - keeping transaction records for tax and accounting purposes.

Marketing emails

We run two email lists - FA shows and FA classes. You join them by choice: signing up on our website (we send a confirmation link first and only add you once you click it), ticking the marketing preferences in your account, or answering yes to the marketing question when buying through a ticketing partner. Where you’ve bought from us, we may also email you about similar FA shows and classes under the PECR “soft opt-in” rules - we tell you this at checkout, and every such email includes an unsubscribe link.

Every marketing email includes a one-click unsubscribe. You can leave a single list or all of them; unsubscribing from everything adds your address to a suppression list so a later import or sign-up mistake can’t re-add you without your explicit say-so. Service emails (receipts, tickets, login codes) are separate and are sent regardless of marketing preferences.

Who we share it with

We never sell your data. We share it only with the service providers who run parts of our operation, each acting under contract:

  • Stripe - payment and subscription processing (receives your name and email; your card details go to Stripe directly).
  • Resend - sending our email.
  • Arlo - class administration and registrations.
  • Ticket Tailor - where a show is sold through them.
  • Square - card payments at our venue box office and bar. Square processes your card as a payment provider; we don’t send Square your identity.
  • Cloudflare - bot protection on our forms (a check that includes your IP address).
  • Google - analytics (only with your consent), the fonts our pages load, and embedded maps and YouTube videos - your browser requests that content from Google’s servers.
  • Tally - some of our forms are embedded from Tally; what you type in those goes to Tally in order to reach us.
  • DigitalOcean - our hosting provider; our servers, databases and uploaded media are in their London region.
  • Amazon Web Services - encrypted off-site backups, stored in the EU (Stockholm).

We may also disclose data where the law requires it - for example to HMRC, or to law enforcement with a valid request.

International transfers

Some of these providers are US-headquartered and may process personal data outside the UK and EEA. Where they do, the transfer is protected by safeguards recognised under UK law - the UK Extension to the EU–US Data Privacy Framework and/or the UK International Data Transfer Agreement or Addendum (standard contractual clauses). Details of the safeguard for a specific provider are available on request.

How long we keep it

  • Orders and payment records - 6 years after the transaction, as required for tax. If you ask us to erase your data we anonymise these records rather than delete them (see Your rights).
  • Account details - for as long as your account is active, or until you ask us to erase them.
  • Marketing preferences - while you’re subscribed. Records of opt-outs and suppressed addresses are kept indefinitely so we don’t contact you again.
  • Form submissions (contact, corporate, applications) - deleted after 12 months.
  • Raw payment and ticketing notifications from our providers - personal data redacted after 90 days.
  • Login codes and links - they expire within minutes to hours and are routinely purged; records of sign-in attempts (including IP addresses) are kept for around 7 days.
  • Server access logs - around 14 days.
  • Backups - encrypted backups are kept on a rolling schedule and deleted automatically as they age out.

How we protect it

All traffic to the site is encrypted (HTTPS). Passwords are stored only as secure one-way hashes. Card details never reach our servers. Database backups are encrypted before they leave our infrastructure, with the decryption key held offline. Access to customer data is limited to the people who need it to run FA.

Your rights

Under UK GDPR you can ask us to: access the data we hold about you; correct it; erase it; restrict or object to processing; and port it to another provider. You can also withdraw consent at any time where consent is the basis we rely on.

If you ask us to erase your data, we anonymise your account and order history (we’re required to keep transaction records for tax, so they’re stripped of your details rather than deleted), cancel any active membership, delete pending login codes and links, and add your email address to our do-not-contact list so we don’t email you again.

Email hello@thefreeassociation.co.uk and we’ll respond within one month. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk).

Cookies and similar technologies

Essential cookies - always on, because the site doesn’t work without them:

  • A session cookie that keeps your basket and login working; it expires when you close your browser.
  • A “remember me” cookie (fa_remember) set when you sign in, so you stay signed in on that device for up to 30 days. Signing out removes it.
  • Stripe sets its own cookies on checkout pages for payment processing and fraud prevention.
  • A long-lived cookie on FA staff devices only, used for ticket scanning at the door.

Analytics cookies - set only if you choose “Accept” on our cookie banner. We use Google Consent Mode: until you accept, analytics and advertising storage stays switched off. You can change your choice at any time via the “Manage cookies” link in the footer.

Embedded content - pages containing YouTube videos, Google Maps or Tally forms load content from those providers, which may set their own cookies governed by their policies.

We also use your browser’s local storage (which stays on your device) to remember your cookie choice, show your basket count in the header, and avoid double-counting a purchase in our analytics.

Changes to this policy

We’ll post any changes on this page and update the date at the top. Significant changes will be flagged by email where appropriate.