This page explains what data themepark.com collects, why, and how it's handled. The short version: very little. We count visits without recording your IP address, we receive your name and email address only when you write to us, and your data is never sold or shared with advertisers.
Last updated: 28 September 2026
Who we are
Theme Park AG, a Swiss Aktiengesellschaft registered in the Commercial Register of the Canton of Zürich (UID CHE-420.189.003). Full company details and registered office are in the imprint. Contact: via the contact form.
What we collect
We only collect what we need to run a website and respond to people who contact us.
- Contact form submissions. When you send a message, we receive your name, email address, and the content of your message.
- Billing enquiries. If you use the form on the billing page, we receive your name, email address, the text on your statement, the charge date if you give it, and your message. They are stored as a support ticket in Zendesk (Zendesk, Inc.), which we use to identify the charge and answer you.
- Server logs. Our web server records standard request data — IP address, timestamp, requested URL, browser user agent, referrer. Used for operating and securing the site.
- Traffic statistics. We count visits to this website to know how much traffic it gets: which page was requested and when, which website or search engine the visit came from, and the type of browser. The count is made on our own server from a separate log that contains no IP address, sets no cookie and uses no identifier, so visits can't be linked to each other or to you. We monitor traffic numbers only — we don't analyse or track individual visitors, build profiles, or use any third-party analytics service. Once a day the log is copied to our own statistics database on another of our servers, in Strasbourg, France; it is shared with no one.
- Technical cookies. The software that runs this site sets two cookies on every page:
statamic-session, which holds a short technical session, and XSRF-TOKEN, a security token against requests forged by other websites. They contain no personal details, aren't used to recognise or follow you, and expire after two hours. There are no other cookies. You can block or delete cookies in your browser; our contact and billing forms don't rely on them.
What we don't do
- No third-party analytics, no tracking pixels, no tracking of individual visitors.
- No third-party advertising scripts.
- No selling, renting, or sharing your data with advertisers or data brokers — ever.
Why we collect it
- Contact form: to read and respond to your message. Legal basis: pre-contractual measures (GDPR Art. 6(1)(b)) and our legitimate interest in responding to inbound communication.
- Billing form: to identify the charge you ask about and answer you. Legal basis: the contract the charge belongs to (GDPR Art. 6(1)(b)) and our legitimate interest in answering billing questions (GDPR Art. 6(1)(f)).
- Server logs: security, abuse prevention, and reliable operation of the site. Legal basis: legitimate interest (GDPR Art. 6(1)(f)) under Swiss FADP equivalents.
- Traffic statistics: knowing how much the site is used. Legal basis: our legitimate interest (GDPR Art. 6(1)(f)). The log holds no IP address or other identifier.
- Technical cookies: secure operation of the site software. Legal basis: our legitimate interest (GDPR Art. 6(1)(f)).
Where data goes
The site is hosted by OVH SAS (France) on a server in Warsaw, Poland, in the European Union. The traffic log is copied to our own statistics database on another OVH server, in Strasbourg, France.
Contact form messages are delivered by Mailgun (Mailgun Technologies, Inc.), using its European region, so the sending and the delivery records stay in the EU. They land in our mailbox at Google Workspace.
Billing enquiries are stored in Zendesk (Zendesk, Inc.), our support ticket system.
Cloudflare (Cloudflare, Inc., United States) answers the domain-name lookups for themepark.com; your page requests go directly to our server and do not pass through Cloudflare.
We do not pass your data to anyone else.
How long we keep it
- Contact form messages: retained in our inbox for as long as needed to handle your request and any follow-up. Older correspondence is archived or deleted on a periodic basis.
- Server logs: rotated daily and deleted after 52 days.
- Traffic statistics: the log is rotated daily and deleted after 52 days; the copy in our statistics database, still without any IP address, after 90 days. Only daily totals (counts per day, page, source and browser type) are kept longer.
- Technical cookies:
statamic-session and XSRF-TOKEN expire after two hours.
Your rights
Under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU GDPR, you have the right to:
- Request access to the personal data we hold about you
- Have inaccurate data corrected
- Have your data deleted (subject to legal retention requirements)
- Object to or restrict processing based on legitimate interest
- Receive your data in a portable format
- Lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local EU supervisory authority
To exercise any of these rights, send a request via the contact form.
Security
The site is served exclusively over TLS. Form submissions travel encrypted end-to-end. Access to the inbox where messages are received is restricted to authorized personnel and protected by strong authentication.
Changes to this policy
If we make material changes to this policy, we'll update the date at the top and, where the change affects how we use existing data, take reasonable steps to notify affected individuals. The current version always lives at this URL.