Privacy Policy
Last updated: April 2026
- Who we are
- What data we collect
- Where data is stored
- How we use your data
- Lawful basis for processing
- Shared account with Latitude Film School
- Third-party processors
- International data transfers
- Cookies and local storage
- Data retention
- Your rights under UK GDPR
- Institution access
- Children
- Changes to this policy
- Contact us
Who we are
Latitude Footprint is a carbon tracking tool for film and TV productions, operated by Aram Atkinson (trading as Latitude Film School), based in the United Kingdom.
For the purposes of UK data protection law, the data controller is Aram Atkinson, trading as Latitude Film School.
Website: latitudefootprint.com
Email: privacy@latitudefootprint.com
What data we collect
We may collect and process the following personal data:
- Account information: your email address, encrypted password (stored as a cryptographic hash - we never store or see your plain-text password), and display name (optional).
- Production data: project names, shoot days, equipment selections, energy calculations, catering logs, transport logs, accommodation logs, and battery logs.
- Subscription information: your subscription tier level and payment status, managed via Paddle. We never see or store your card details.
- Technical data: IP address (processed by Cloudflare Turnstile for CAPTCHA verification only) and browser type (for PWA compatibility).
- Institution codes: if you redeem an institution access code, your email domain is validated against the institution's domain to confirm eligibility.
Where data is stored
- Account data and production data: Supabase, United Kingdom (London, eu-west-2 region).
- Local device: localStorage in your browser stores projects, kits, session data, and app preferences. This data stays on your device unless you sync to cloud.
- Payment data: Paddle (UK/EU entity). We never see or store your card details.
- CAPTCHA: Cloudflare Turnstile processes your IP address to verify you are human. No personal data is stored.
- Website hosting: Vercel (global CDN). No personal data is stored by Vercel.
How we use your data
We use your personal data for the following purposes:
- Providing the service: account creation, project management, energy tracking, and report generation.
- Processing payments: subscription management via Paddle.
- Security: CAPTCHA verification and fraud prevention.
- Service improvement: aggregated, anonymised usage patterns. We do not perform individual tracking.
- Legal compliance: tax and accounting requirements.
- Aggregated statistics: we may compile anonymised, aggregated statistics about overall platform usage (such as total reports generated or total CO₂e tracked). This data cannot identify individual users and is used to improve the service and demonstrate impact.
Lawful basis for processing
Under UK GDPR, we rely on the following lawful bases for processing your personal data:
- Contract: processing necessary to provide your account and access to the service.
- Legitimate interest: security measures (CAPTCHA verification, fraud prevention) and service improvement through anonymised analytics.
- Legal obligation: financial record-keeping as required by UK law.
Important: We do NOT send marketing emails from account creation. If you wish to receive updates, you must subscribe to the Latitude Film School newsletter separately - this is an entirely different sign-up process and is not connected to your Footprint account.
Third-party processors
We share your data with the following third-party service providers who process data on our behalf:
- Supabase (authentication and database) - stores your account data and production data in the UK (London, eu-west-2 region). Supabase Privacy Policy
- Paddle (payment processor) - handles all payment transactions. We never see or store your card details. Paddle is a UK/EU-based entity. Paddle Privacy Policy
- Cloudflare Turnstile (CAPTCHA/bot protection) - processes your IP address to verify you are human during sign-up. No personal data is stored. Cloudflare Privacy Policy
- Vercel (website hosting) - serves our website via a global content delivery network. No personal data is stored by Vercel. Vercel Privacy Policy
- YouTube (embedded videos) - we use YouTube's privacy-enhanced mode (youtube-nocookie.com) which does not set cookies until you play a video. When you play a video, YouTube may collect viewing data. Google Privacy Policy
- Vimeo (embedded course/tutorial videos) - may collect viewing data when you play a video. Vimeo Privacy Policy
We do not sell your personal data to any third party.
International data transfers
Your account data and production data are stored in the United Kingdom (Supabase, London region).
The following processors may transfer data outside the UK:
- Cloudflare - processes IP addresses globally under Standard Contractual Clauses (SCCs).
- YouTube / Google - when you play an embedded video, viewing data may be processed in the United States. We use privacy-enhanced mode to minimise data collection. Google operates under SCCs and the EU-US Data Privacy Framework.
- Vimeo - when you play an embedded video, viewing data may be processed in the United States. Vimeo operates under SCCs.
Cookies and local storage
We do not use tracking cookies.
We use localStorage (not cookies) to store the following data on your device:
- Session token
- Projects and production data
- Equipment kits and state
- App preferences
localStorage is not transmitted to any server - it stays on your device.
Cloudflare Turnstile may use cookies for bot detection during the sign-up process only.
Data retention
We retain your personal data only for as long as necessary:
- Account data: retained while your account is active.
- Production data: retained until you delete it, either via the in-app "Clear All Data" function or by requesting full account deletion.
- Payment records: retained as required by UK tax law (6 years).
- CAPTCHA data: not retained. Processed in real-time only by Cloudflare Turnstile.
Your rights under UK GDPR
Under the UK General Data Protection Regulation, you have the following rights:
- Right to access: export all your data via the app's "Export All Data" function.
- Right to rectification: edit your profile and project data at any time within the app.
- Right to erasure: There are two levels of data deletion:
- Clear local data only: The "Clear All Data" button in the app's Account page removes all data stored on your device (localStorage). This includes projects, kits, and session data stored in your browser. This does NOT delete your Supabase account or any data synced to the cloud.
- Full account deletion: To permanently delete your account and all associated cloud-stored data (including your authentication record, profile, and any synced projects), email privacy@latitudefootprint.com. We will delete all your data from our servers within 30 days and confirm by email.
- Right to data portability: export your data via the app's Export All Data function (JSON format containing all projects, kits, and settings) or export individual reports as PDF or CSV.
- Right to restrict processing: contact us at the email below.
- Right to object: contact us at the email below.
- Right to withdraw consent: We process your data under Contract (you signed up for a service) and Legitimate Interest, not under Consent. This means your data processing is tied to your use of the service. If you no longer wish your data to be processed, you can delete your account and all associated data will be removed.
To exercise any of these rights, please contact us at privacy@latitudefootprint.com. We will respond within one month.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk
Telephone: 0303 123 1113
Institution access
If your university or film school has arranged group access to Latitude Footprint:
- If your institution requests usage information, we may share the number of active seats (a count only). We do not share individual user names, email addresses, or production data with institution administrators. Institutions cannot access your account or view your work.
- Your email domain is validated to confirm you belong to the institution.
- Your individual production data is never shared with the institution.
Children
Our service is not directed at children under the age of 16. If you are under 16, you may only use the service with parental or guardian consent.
If you believe we have inadvertently collected data from a child under 16, please contact us immediately and we will take steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
Contact us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us:
Aram Atkinson (trading as Latitude Film School)
Email: privacy@latitudefootprint.com
Location: United Kingdom
Enterprise and team accounts are on our roadmap - contact hello@latitudefootprint.com for more information.