Privacy Policy
Last updated: 1 October 2026
This notice explains what personal information Ninja Kidz Action Park collects about you and your family, why we collect it, who we share it with, how long we keep it, and your rights. It covers our website, our booking system, and visits to our parks in Dundee and Edinburgh.
There is a short version written for children: Your privacy (for kids).
Who is responsible for your information
Each park is run by its own company, which is the controller of the personal data collected by or for that park:
Ninja Kidz Action Park Dundee
- Company
- Ninja Kidz Parks Dundee Ltd (formerly Ryze Dundee Limited)
- Company number
- SC529147 (registered in Scotland)
- Registered office
- Unit 23 Mayfield Industrial Estate, Dalkeith, Midlothian, EH22 4AD, United Kingdom
- ICO registration number
- ZB861516
Ninja Kidz Action Park Edinburgh
- Company
- Ninja Kidz Parks Edinburgh Ltd (formerly Ryze Edinburgh Limited)
- Company number
- SC478281 (registered in Scotland)
- Registered office
- Unit 23 Mayfield Industrial Estate, Dalkeith, Midlothian, EH22 4AD, United Kingdom
- ICO registration number
- ZB868387
The company that runs the park you book or visit shares responsibility for your information with Wonderment, LLC, a US company in our group that runs our website, bookings and marketing. We are “joint controllers”. We have agreed that Wonderment, LLC writes this notice, runs our privacy contact point and handles your requests and complaints. The park company runs its CCTV and on-site systems and leads any report to the Information Commissioner’s Office if something goes wrong. Each of us keeps the information we handle secure. You can contact either of us to use your rights, and we will make sure your request reaches the right place.
Wonderment, LLC’s UK representative is Ninja Kidz Parks Edinburgh Ltd, Unit 23 Mayfield Industrial Estate, Dalkeith, Midlothian, EH22 4AD, legal@ninjakidzparks.com.
How to contact us about your information
Email legal@ninjakidzparks.com, or write to Data Protection, at the address of the park company shown above: Unit 23 Mayfield Industrial Estate, Dalkeith, Midlothian, EH22 4AD. You can also ask at reception in either park. This contact covers both the park companies and Wonderment, LLC.
What information we collect
- Booking details: your name, email address, phone number, what you booked and when. Card payments are taken by our booking system’s payment provider; we don’t store your full card number.
- Waiver details: the name, date of birth, phone number, home address and email address of the person signing (who must be 16 or over), and the names and dates of birth of any children they sign for. The person signing can choose to give their gender.
- Party and group details: for example the birthday child’s name and age and the number of guests.
- Messages: what you tell us when you email, phone or message us (including on WhatsApp), or fill in a form on our website.
- Marketing records: whether you agreed to hear from us, when and how; and whether you open or click our emails and texts.
- Website use: the pages you visit, your device and browser, and your approximate location from your IP address. Cookies that aren’t essential are only used if you agree — see our Cookie Policy.
- Safety records: details of any accident or incident in the park.
- CCTV: both parks use CCTV cameras, so we record images of people in and around the park.
Why we use your information, and our lawful basis
UK data protection law says we must have a lawful basis for each use:
- To take and manage your bookings, tickets, parties and memberships, and send you confirmations and visit information. Basis: contract — we need it to provide what you booked.
- To run the park safely, check that everyone taking part has a signed waiver, and record and deal with accidents. Basis: legitimate interests (keeping guests safe and handling claims) and legal obligation (health and safety law, including reporting some injuries).
- To keep people and property safe with CCTV, and to prevent and investigate accidents and crime. Basis: legitimate interests.
- To send marketing emails and texts. If you opt in when you book or sign a waiver, you’ll hear from both of our UK parks, Dundee and Edinburgh (basis: consent). If you have booked with a park and didn’t opt in, that park may still send you offers about similar things from that park only, unless you said no when you booked — every message lets you opt out (PECR regulation 22(3), the “soft opt-in”; basis: legitimate interests).
- To send you birthday offers. We use the first names and birthdays of the children on your booking or waiver to send you — the adult — party and birthday offers around their birthday. We never send marketing to children. Basis: the same as for our other marketing above; you can stop at any time.
- To measure and improve our website and advertising with cookies Google Analytics needs your consent to statistics cookies; Google Ads, the Meta Pixel and RudderStack need your consent to marketing cookies. Basis: consent — these stay off unless you allow them. On our UK park pages, Google’s tag doesn’t load at all until you accept statistics or marketing cookies.
- Site statistics. We use Vercel Web Analytics and Speed Insights to count visits, see which pages work well and how quickly they load, so we can improve our website. They don’t use cookies. A visit is identified by a code that is deleted after 24 hours, and we only see overall figures, not information about you. Vercel processes this for us and can’t use it for anything else. UK law allows this kind of statistics without asking first, as long as you can object: choose “Necessary only” or switch off “Statistics” in our cookie settings. Basis: legitimate interests in running and improving our website.
- To keep our website working and secure. Our error monitoring (Sentry) records technical details when something breaks, and a replay of the page with anything typed into forms hidden. Basis: legitimate interests.
- To answer your questions and complaints. Basis: legitimate interests, or contract where it’s about a booking.
- To reply to WhatsApp messages with an AI assistant. If you message a park on WhatsApp, you may be talking to an AI assistant rather than a person. It answers questions about visits and bookings and hands over to a member of staff when it can’t help. It doesn’t make decisions about you. Basis: legitimate interests (answering you quickly), or contract where it’s about a booking.
- To keep accounting and tax records. Basis: legal obligation.
We group customers by things like which park they visit, when they last came and when their children’s birthdays are, so that offers are relevant. We don’t make decisions about you that have legal or similarly significant effects using automated means alone.
Who we share your information with
Wonderment, LLC, as joint controller (see above). We also use other companies to provide our services. They act on our instructions (they are “processors”) and may not use your information for their own purposes:
- ROLLER — our booking, ticketing, waiver and till system. It holds your bookings, waivers and payment records.
- Klaviyo — sends our marketing emails and texts, and keeps your marketing preferences.
- Twilio — sends and receives text messages.
- Google Analytics — measures how our website is used, only if you allow statistics cookies.
- RudderStack — passes what you do on our website to our marketing and advertising tools, only if you allow marketing cookies.
- Cookiebot (Usercentrics) — records your cookie choices.
- Vercel — hosts our website and provides our site statistics.
- Sentry — monitors our website for errors.
- Jotform — runs the forms on our website.
- Snowflake — our data warehouse. It holds booking, visit and marketing records for reporting and to carry out the deletion schedule below.
- Amazon Web Services (AWS) — stores files used by our data systems.
- Astronomer — runs the data pipelines that move information between our booking, warehouse and marketing systems.
- Zendesk — manages our guest-service emails and messages, including WhatsApp conversations.
- WhatsApp — carries your messages if you contact a park on WhatsApp.
- Anthropic — provides the AI (Claude) behind our WhatsApp assistant.
- Google Workspace — our email, documents and file storage.
If you allow marketing cookies, Google (Google Ads) also receives information about your visit to measure and personalise our adverts, and decides how it uses it under its own privacy policy.
Meta (Facebook and Instagram). If you accept advertising cookies, the Meta Pixel on our website sends information about your visit, such as pages viewed and bookings made, to Meta Platforms, Inc. in the US. We use it to measure our adverts and show them to the right people. For collecting and sending this information, we and Meta are joint controllers. We and Meta have agreed in writing who is responsible for what. We give you this information. Meta is responsible for letting you access, correct, delete or move the information it holds after we send it. You can read how Meta uses it, and how to use your rights with Meta, in Meta’s Privacy Policy.
We also share information with the police, regulators or courts where the law requires it or to protect people’s safety, with our insurers and advisers if there is a claim, and with a buyer if a park or business is sold. We never sell your information.
Sending your information outside the UK
- ROLLER stores guest information for its UK venues in a data centre in the European Union. UK law recognises the EU as giving adequate protection, and ROLLER’s data processing agreement includes the UK’s standard contractual clauses for any transfer beyond that.
- Klaviyo stores information in the United States. Klaviyo, Inc. is certified under the UK Extension to the EU–US Data Privacy Framework (the “UK–US data bridge”) — you can check its certification. If Klaviyo ever can’t rely on that, its data processing agreement applies the standard contractual clauses with the UK Addendum.
- Twilio, Google (including Google Workspace), RudderStack, Vercel, Sentry, Jotform, Snowflake, Amazon Web Services and Zendesk are also in the United States, and are each certified under the UK Extension to the EU–US Data Privacy Framework. You can check any of them on the Data Privacy Framework list.
- Meta protects its transfer of Meta Pixel information to the US with the UK International Data Transfer Addendum to the EU standard contractual clauses, approved by the ICO.
- Astronomer, WhatsApp and Anthropic are in the United States. Their data processing terms protect the transfer with the EU standard contractual clauses and the UK International Data Transfer Addendum, approved by the ICO.
- Wonderment, LLC is in the US, so the park companies send your information there to run bookings, marketing and reporting. To protect it, each park company has signed the International Data Transfer Agreement issued by the UK Information Commissioner with Wonderment, LLC. You can ask us for a copy at legal@ninjakidzparks.com.
How long we keep your information
- Marketing: if you haven’t visited or booked for 2 years (730 days), we delete your marketing profile. If you unsubscribe, we keep just your email address or phone number on a “do not contact” list, so that we don’t message you again.
- Bookings and payment records: 6 years after the end of the financial year in which you booked, as tax law requires.
- Waivers and accident records: 3 years after your visit or, for a child, until they turn 19 if that is later — the time limits for injury claims in Scotland. If a claim is made, we keep the records until it is settled.
- CCTV: 180 days, as our insurer requires. If footage shows an accident or incident, we keep it with that record instead.
- Website analytics: 14 months in Google Analytics.
- Website error logs: 90 days in Sentry.
- Emails, messages and enquiries: 2 years after our last contact with you, or longer if they form part of a booking or claim record above.
Your rights
You have the right to:
- Access — get a copy of the information we hold about you.
- Correct — have anything wrong or incomplete put right.
- Delete — ask us to erase your information (see how to ask us to delete your data).
- Restrict — ask us to pause using your information while a concern is checked.
- Object — to our use of your information based on legitimate interests. You can always object to marketing, and we will stop.
- Portability — get information you gave us in a format you can reuse.
- Withdraw consent — at any time, as easily as you gave it: use the unsubscribe link in any email, reply STOP to any text, or change your cookie choices on our Cookie Policy page. See Marketing Preferences. Withdrawing doesn’t affect anything we did before.
To use any of these rights, contact us using the details above. It’s free. We’ll reply within one month, or tell you within that month if we need up to two more months because your request is complex. We may ask you to confirm your identity first.
Complaints
If you’re unhappy with how we’ve handled your information, please tell us using our data protection complaint form, or email legal@ninjakidzparks.com. We’ll acknowledge your complaint within 30 days and tell you what we’re doing about it.
We’d like the chance to put things right first, but you can complain at any time to the Information Commissioner’s Office (ICO), the UK’s data protection regulator: ico.org.uk/make-a-complaint, or call 0303 123 1113.
Children
Waivers must be signed by someone aged 16 or over. We use children’s names and birthdays to run their visit safely and, if you’ve agreed to hear from us, to send you birthday offers. We never send marketing to children themselves. Our children’s privacy page explains this in a way children can understand.
Changes to this notice
We’ll update this page when our practices change and change the date at the top. If a change matters to how we use your information, we’ll tell you before it happens.

