This is a translation for your convenience. The binding version of this Privacy Policy is the Spanish one, available at qlesspark.com/politica-privacidad. In the event of any discrepancy or conflict between the two, the Spanish version prevails.
This Policy explains what personal data we process at Qless Park (https://www.qlesspark.com), what we use it for, who we share it with, and what you can do about it. It is written in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Qless Park is an independent visit-planning service. We have no relationship with Disneyland Paris or with The Walt Disney Company: we do not sell tickets, we do not manage hotel or restaurant bookings, and we are not agents of the park.
Who the controller is
Data controller: Pol Naranjo, a sole trader registered in Spain as an empresario individual (autónomo), trading under the commercial name Qless Park.
Spanish tax number (NIF): 38877085R.
Contact address: info.qlesspark@gmail.com
We have not appointed a Data Protection Officer: given the volume and nature of the processing, none of the circumstances in Article 37 GDPR applies. For any privacy matter, write to the address above.
What we collect
Only what you give us, and only what serves to build your itinerary. We do not buy data, we do not enrich it from outside sources, and we do not build advertising profiles.
- Contact: your name, your surname if you give it, your email address and, optionally, a phone number. Also the language you are using the site in.
- The trip: arrival date, number of park days, the entry and exit time for each day, whether you are staying in a Disney hotel and which one, the board type, and any restaurant bookings you tell us about (place, day and time).
- The group: one row per person with their age band and height band, and how many pushchairs you have. These are bands, not dates of birth or exact measurements.
- Preferences: which attractions you consider unmissable, how much queueing you will accept for Mickey and for the Pavillon des Princesses, whether the parade is a priority, whether anyone has an accessibility pass, and the free text you write in the comments box.
- Payment: your purchase reference, the amount, the currency and the identifiers Stripe returns to us. We never receive or store your card number: payment details are entered directly into Stripe and we have no access to them.
- Consents: for every box you tick we store which one it was, the exact text you were shown, the language you read it in, and when you accepted it. It is the evidence of what you agreed to and when.
- Technical data: the usual web server records (IP address, browser, pages visited and time of visit), which we use to keep the service running and to detect abuse.
Health data: only with your explicit consent
Two of the questions in the client area can reveal health data, which Article 9 GDPR treats as a special category:
- Food allergies and intolerances, including the free-text note where you explain whose they are and how strict.
- Reduced mobility and the group's accessibility passes.
We do not require either of them in order to sell to you. If you choose to give them, we first ask for separate, explicit consent using a box that does not come pre-ticked, and we store the text you were shown. We use them for one purpose only: not to suggest a restaurant with nothing you can eat, and to work out the day's pace and distances realistically.
You can withdraw that consent at any time by writing to us, and you can give us every other answer without giving us these. Withdrawing does not affect the lawfulness of earlier processing, but it does affect what we can take into account when building the Route.
Children
This service is bought by an adult. It is not aimed at children and we do not allow a child to purchase.
We do process data about the children travelling with you — their age band and height band — because that is what decides which attractions they can ride and how fast the group moves. It is provided by the adult who buys, it consists of bands rather than identifiers, and it is used for nothing else.
What we use it for, and on what legal basis
- Working out and delivering your itinerary, and supporting you — performance of the contract (Art. 6(1)(b) GDPR). Without this data there is no service to provide.
- Allergies, intolerances and mobility — your explicit consent (Art. 9(2)(a) GDPR), in addition to the contract.
- Taking payment and keeping accounting and tax records — performance of the contract and legal obligation (Art. 6(1)(b) and 6(1)(c)).
- Service emails (your access code, notices about your trip, delivery of the Route) — performance of the contract. These are not marketing and you cannot unsubscribe from them without ceasing to receive the service.
- Measurement cookies — your consent (Art. 6(1)(a)), which you give or refuse in the banner and can change whenever you like.
- Site security and abuse prevention — legitimate interest (Art. 6(1)(f)).
We do not take automated decisions with legal effects concerning you. The itinerary is calculated by an algorithm, but it is a proposed plan for a visit: it decides nothing about your rights, and a person reviews it before we send it to you.
Who we share it with
We do not sell your data and we do not pass it to anyone for their own use. The following process it with us, as processors and only for what is necessary:
- Supabase — the database where your answers are stored.
- Netlify — the hosting for the site and for the functions that process the form.
- Stripe — the payment gateway. It receives your payment details directly; we receive only the confirmation and the transaction identifiers.
- Google — the outgoing mail we write to you with and, if you accept measurement cookies, Google Analytics.
- consentmanager — the cookie banner provider.
We will also disclose it to courts, tribunals and public authorities where a legal rule requires us to.
International transfers
Some of those providers are based in the United States and may process data outside the European Economic Area. Where that happens, the transfer relies on the EU-US adequacy framework or on the Standard Contractual Clauses approved by the European Commission, depending on the provider. You can ask us for a copy of the applicable safeguards.
How long we keep it
- Your answers and your itinerary: while your trip is active and for up to a year afterwards, in case you need to retrieve it or raise a complaint.
- Allergies, intolerances and mobility: deleted when your trip ends. They are the most sensitive data we hold and the data we keep for the shortest time.
- Invoicing and consent records: for the period required by tax and commercial law, and for as long as they may serve as evidence of an obligation.
- Technical logs: twelve months at most.
After those periods we delete or anonymise the data. Note that a backup may take a little longer to rotate; in the meantime it is out of use.
Cookies
We use the technical cookies the site needs in order to work and to remember your session — the code you use to get into your trip — and those do not require your permission.
Measurement cookies, which tell us which pages are read and where people abandon the process, are only switched on if you accept them in the banner that appears the first time. You can change your mind at any point from that same banner. If you refuse them, the site works exactly the same.
Your rights
You may at any time exercise your rights of access, rectification, erasure, restriction of processing, objection and portability, and withdraw any consent you have given us.
Write to info.qlesspark@gmail.com saying which right you wish to exercise. We will reply within one month. If we have reason to doubt it is you, we may ask you to prove it, and we will not ask for more data than we need in order to do so.
If you believe we have not handled your request properly, you may complain to the Spanish Data Protection Agency (www.aepd.es). We would be grateful if you told us first, so that we can try to put it right.
How we protect your information
Access to the database is restricted and credential-protected, traffic to the site is encrypted, and getting into your trip is done with a code we email you rather than with a password you would have to invent and reuse.
That code is order-lookup grade: it retrieves your trip, like a booking reference. Keep it and do not share it. No system is infallible; if a breach ever occurred that could pose a risk to your rights, we would tell you and notify the supervisory authority in accordance with Articles 33 and 34 GDPR.
Changes to this policy
If we change anything material we will publish it here and, where the change affects you significantly, we will tell you by email before it takes effect. Each version is identified by its date, and for every consent we store which version you were shown.
Contact
For any question about this Policy: info.qlesspark@gmail.com
Last updated: 3 September 2026