Privacy notice
Last updated 18 July 2026
Timeless North Ltd, trading as Scottish Luxury Experience (“SLE”, “we” or “us”), is the controller for personal data used in the Scottish Luxury Experience app and the Timeless North guide app. MOD Digital Limited develops and publishes both apps and processes app data on behalf of Timeless North Ltd to operate and support them. The apps provide invited guests and contracted Guides with the information and communication needed to deliver a booked trip.
Information we use
- Identity and contact details, including name, verified email address and account identifier.
- Trip information, itineraries, bookings, tickets, arrival and departure details and travelling-party information.
- Dietary, accessibility, mobility and emergency-contact information supplied for safe trip delivery.
- Messages, voice notes, photographs and documents deliberately shared through trip chat.
- For guides: availability, assignments, vehicle details, mileage, expense receipts and compliance documents.
- Device push token, app version, operating system and security/audit events. The current mobile release does not include crash, analytics or performance-monitoring diagnostics; those would be used only if diagnostic reporting is enabled in a later release.
- A user-scoped offline copy of opened trip information stored inside the app sandbox for up to seven days, or until the user signs out or clears downloaded data.
Why we use it
We process this information to perform and administer booked travel services, coordinate guides and suppliers, protect guests, answer support requests, keep records required by law, prevent misuse and improve the reliability of the apps. We do not sell personal information or use app data for cross-app advertising.
Service providers and international processing
Authorised data may be processed by providers that operate the service, including Clerk for authentication; Railway and PostgreSQL for application hosting; private S3-compatible object storage; Expo, Apple Push Notification service and Firebase Cloud Messaging for notifications; email delivery providers; and Sentry if production diagnostics are enabled. Some providers process data outside the United Kingdom under their contractual transfer safeguards.
Sharing
Trip information is shown only to the SLE operations team, guests authorised for that trip, currently assigned guides, and suppliers or professional advisers who need it to provide the service or meet a legal obligation. Access is withdrawn when an assignment or trip entitlement ends.
Retention and security
Authentication records, push tokens and app access are removed when an account is deleted. Messages and uploaded app files are deleted or anonymised unless they form part of a booking, safety, accounting or legal record that must be retained. Booking and accounting records may be kept for up to seven years. Short-lived recovery records may contain generated itinerary, Guide tender, debrief or guest packet output; exact prior versions of a proposal workspace; and redacted prior versions of operational records such as identity and contact details, trips, bookings, Guide assignments, payments, support records and chat. Credential-like values and specifically excluded provider or high-churn fields are not copied into operational recovery records. Live recovery copies expire at 90 days and are automatically purged within 24 hours. Restricted primary disaster-recovery copies use a finite tiered schedule: hourly copies for seven days, daily copies for 35 days, weekly copies for 13 weeks and monthly copies for up to 12 months. Where the independent immutable disaster-recovery destination is enabled, it keeps hourly copies for up to 36 days, daily copies for up to 90 days, weekly copies for up to 52 weeks and monthly copies for up to 12 months. Short-lived recovery journals are excluded from the separate pre-deployment JSON archive, and an isolated restore removes already-expired recovery records before general access. Data is encrypted in transit, stored in access-controlled systems and protected by tenant, user and trip-level authorisation.
Your choices and rights
You may ask for access, correction, restriction, portability, objection or deletion where applicable. Notification permission can be changed in device settings. Downloaded app data can be cleared from Profile. Account deletion can be initiated inside either app or through the web deletion request.
Contact
Privacy enquiries: contact@timelessnorth.com. You may also complain to the UK Information Commissioner’s Office.