Privacy Policy

Last updated: 23 April 2026
Data Controller: Caledonia TX Ltd, trading as ROCK.SCOT
Company Registration: SC646223 — VAT: 491589639
Address: 19 Hogg Avenue, Johnstone, PA5 0EZ, Scotland
Email: studio@rock.scot — Phone: 0141 459 7625
ICO Registration Number: ZC129857 — Caledonia TX Limited, registered as a data controller with the Information Commissioner's Office on 21 April 2026

1. Introduction

Caledonia TX Ltd, trading as ROCK.SCOT, is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, how we use it, and your rights under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

This policy applies to all users of our website at rockdotscot.com (and rock.scot), our DAB+ radio service, our merch store, our mailing list, and our advertising services.

2. What Data We Collect and Why

2.1 Merch Store Customers

DataPurposeLawful Basis
Name, email addressOrder confirmation, delivery updatesContract
Shipping addressFulfilment via GelatoContract
Order details (items, size, colour)Fulfilment, returnsContract
Payment dataPayment processing (via Stripe — we never see card numbers)Contract
Order historyHMRC accounting requirementsLegal obligation

Right to cancel: Our merch products are custom print-on-demand items manufactured to your specific order. Under the Consumer Contracts Regulations 2013, the 14-day right to cancel does not apply to goods made to a consumer's specification. We will replace or refund faulty or damaged items — see our returns process at studio@rock.scot.

2.2 Mailing List Subscribers

DataPurposeLawful Basis
Email addressSending newsletters, station news, merch updatesConsent (double opt-in)
Subscription date and confirmation tokenProof of consentLegal obligation (PECR)

You can unsubscribe at any time using the link in every email or by emailing studio@rock.scot. We will process unsubscribe requests within 5 working days.

2.3 Advertising Clients

DataPurposeLawful Basis
Name, email, phone, companyCampaign management, invoicingContract
Campaign and billing recordsAccounting, HMRCLegal obligation

2.4 Listener Messages (Message the DJ)

DataPurposeLawful Basis
Name (optional, self-provided)Personalising on-air responseConsent
Message textDelivering to on-air presenterConsent
Hashed IP addressRate limiting, abuse preventionLegitimate interests
Plain IP address (flagged messages only)Safety — evidence of threats or abuseLegitimate interests / Legal obligation
TimestampMessage routing to correct DJLegitimate interests

Messages are automatically moderated for threatening or abusive content. Flagged messages may be retained and disclosed to police if they contain credible threats. Non-flagged messages are anonymised after 90 days.

2.5 Website Visitors

DataPurposeLawful Basis
Essential cookies (session, consent record)Site operation, remembering your cookie choiceLegitimate interests
Analytics cookies (if consented)Understanding how the site is usedConsent
General location (country/region from IP)Aggregate audience analyticsLegitimate interests

You can manage your cookie preferences at any time via our Cookie Policy page.

3. Data Retention

Data TypeRetention PeriodReason
Order records (name, address, items, payment ref)7 years from order dateHMRC statutory requirement
Mailing list subscriptionsUntil unsubscribed, or 2 years of inactivityPECR / consent basis
Advertising client records7 years from last invoiceHMRC statutory requirement
Listener messages (non-flagged)90 days then anonymisedOperational necessity
Listener messages (flagged / threatening)Up to 7 yearsLegal obligation / safety
Website analytics13 months then deletedICO guidance on PECR
Session tracking (sessionStorage)Current session only, cleared on browser closeLegitimate interests
Visitor fingerprinting (localStorage)12 monthsLegitimate interests — to track returning visitors and improve analytics
Device type detection13 months with other analyticsLegitimate interests
Stream connection logs90 daysOfcom technical records requirement
General correspondence3 years from last contactLegitimate interests

4. Who We Share Your Data With

We do not sell your data. We share it only with the following data processors who act under our instructions and are bound by data processing agreements (DPAs) compliant with UK GDPR:

ProcessorPurposeLocationDPA
Supabase Inc.Database hosting — stores orders, subscribers, messages, DJs, anonymous website analyticsEU (Frankfurt)Yes — supabase.com/privacy
Stripe Inc.Payment processing — handles all card transactionsEU / US (SCCs)Yes — PCI DSS compliant. We never see card numbers.
Gelato ASPrint-on-demand fulfilment — receives name and shipping address for merch ordersEU (Norway)Yes — gelato.com/privacy
SMTP2GOTransactional email — order confirmationsEU / AU (SCCs)Yes — smtp2go.com/privacy
Resend Inc.Mailing list confirmation emailsUS (SCCs)Yes — resend.com/privacy
Supabase Inc. (Analytics)Anonymous website visit data (page, device type, visitor ID) — no personal data storedUS (SCCs)Yes — supabase.com/privacy
Amazon EU S.à.r.l.Affiliate programme (Amazon Associates) — we earn commission on qualifying purchases via links on our siteLuxembourg/US (SCCs)Yes — Amazon Privacy Notice
Pusher Ltd.Real-time message delivery to DJ loungeEU (Ireland)Yes — pusher.com/legal
Broadcast.RadioAudio stream deliveryUKYes
IONOS SEDomain registrationEU (Germany)Yes — ionos.co.uk/privacy

Legal Disclosure

We may also disclose your data where required by law to: Ofcom, Police Scotland or other law enforcement, HMRC, courts or tribunals. We will only do so in response to valid legal requests.

5. International Data Transfers

Some processors operate outside the UK/EEA, including Stripe (US), Resend (US), Supabase (US), and Amazon (Luxembourg/US). All such transfers are protected by Standard Contractual Clauses (SCCs) approved by the UK ICO, ensuring your data receives equivalent protection to that provided under UK GDPR.

Affiliate Disclosure

ROCK.SCOT participates in the Amazon EU Associates Programme, an affiliate advertising programme that allows sites to earn advertising fees by linking to Amazon.co.uk. When you click an Amazon link on our site and make a purchase, we may receive a small commission at no extra cost to you.

Affiliate links are clearly identified on our site. We only link to products we believe are relevant to our audience. The commission we earn helps support the running of ROCK.SCOT as an independent Scottish rock radio station.

Amazon may set cookies when you click our affiliate links. See Amazon's Privacy Notice for details.

6. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Right of Access — request a copy of all data we hold about you
  • Right to Rectification — correct inaccurate or incomplete data
  • Right to Erasure — request deletion (subject to legal retention obligations)
  • Right to Restrict Processing — limit how we use your data
  • Right to Data Portability — receive your data in a machine-readable format
  • Right to Object — object to processing based on legitimate interests or direct marketing
  • Rights re: Automated Decisions — we do not use automated profiling or decision-making
  • Right to Withdraw Consent — for any processing based on consent (e.g. mailing list, analytics cookies) at any time

To exercise any right, email studio@rock.scot. We will respond within 30 days. No fee is charged for reasonable requests.

7. Security

We protect your data through: HTTPS encryption on all web traffic • encrypted database storage with row-level security • access controls and authentication • API key management (keys stored in secured server files, not in code) • rate limiting on all public-facing forms • content moderation on user-submitted messages.

In the event of a data breach affecting your rights, we will notify the ICO within 72 hours and affected individuals without undue delay, as required by UK GDPR Article 33-34.

8. Children

Our services are not directed at children under 16. We do not knowingly collect data from children. If you believe we have collected data from a child under 16, contact us immediately at studio@rock.scot and we will delete it.

9. Regulatory Licences

As an Ofcom-licensed DAB+ broadcaster, ROCK.SCOT complies with: the Communications Act 2003 • the Ofcom Broadcasting Code • PRS for Music (performance rights licence) • PPL (Phonographic Performance Limited — recording rights licence) • Ofcom logging and record-keeping requirements.

10. Changes to This Policy

We may update this policy as our services evolve or when required by law. The "Last updated" date at the top will always reflect the current version. For significant changes we will notify mailing list subscribers by email.

11. Complaints

If you are unhappy with how we handle your data, please contact us first at studio@rock.scot. If you remain unsatisfied, you have the right to complain to the Information Commissioner's Office (ICO):

Website: ico.org.uk • Phone: 0303 123 1113 • Post: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

ROCK.SCOT

Scotland's rock station on DAB+ digital radio. Broadcasting Metal, Alt, Punk and Classic Rock 24/7 across West Scotland.

Ofcom Licensed · SC646223 · VAT 491589639

Legal

Privacy Policy Terms of Service Cookie Policy

Navigate

Home The Wire Coverage Advertise

Contact

0141 459 ROCK studio@rock.scot advertise@rock.scot
© 2026 ROCK.SCOT · Caledonia TX Ltd · SC646223 · VAT 491589639 · Ofcom Licensed