Privacy
Privacy Policy
This policy explains how Ramen Club collects and uses personal data across our public website, Ramen Space services and the Members Hub.
Who we are
Ramen Club Ltd is the controller responsible for the personal data described in this policy.
Ramen Club LtdCompany number 11968201
71-75 Shelton Street
Covent Garden
London WC2H 9JQ
United Kingdom
charlie@ramenclub.com
What this policy covers
This policy covers ramenclub.com, members.ramenclub.com, Ramen Club membership, Ramen Space enquiries and bookings, our events, workshops, forms and direct communications.
Other websites and services you choose to visit, including Slack, Luma and social networks, have their own privacy policies. Their policies apply when you use those services directly.
Information we collect
Information you give us
This can include:
- Your name, email address, company and contact details.
- Membership applications, trial bookings, event registrations, survey answers and other information you enter into our forms.
- Messages, attachments and other information you send through email, forms, support chat or community channels.
- Your email and marketing preferences.
Membership and account information
For Members Hub access we process your member email, authentication and session information, account status and security records. We use this information to confirm that you are an eligible member and to keep the hub private.
Billing and transaction information
We process subscription, invoice, payment-status and billing-contact information needed to manage membership and other purchases. Stripe collects and processes payment-card details. Ramen Club does not store full payment-card details.
Starting a Remote membership
When you press “Continue to payment”, we save your account email, name, selected membership, optional billing email and marketing choice in a private signup record in Supabase. We do not save these details merely because you type them into the form. Your billing email defaults to your account email unless you choose a different one. Changes to billing details in Stripe do not change your account email.
If you opt in to email tips, the Ramen Club newsletter and membership updates, we may add your account email and name to Loops before payment. You can receive those emails even if you do not complete your purchase. This optional choice is separate from analytics consent and from service emails needed to verify your account or provide a membership you paid for. You can unsubscribe from marketing at any time. Existing unsubscribe and suppression choices are not automatically reversed when you submit a form.
We do not send abandoned-checkout reminders. If you pay but do not verify your account email, we may send one service reminder to help you access your membership. Payment alone does not verify ownership of an email address or sign you into the Members Hub.
Technical and usage information
When you use our websites and online services, we and our providers may receive your IP address, browser and device information, pages viewed, dates and times, referring pages, campaign information, interactions, cookie or storage identifiers and diagnostic or security data.
How and why we use information
- To provide services and take requested steps. We use information to handle applications and bookings, provide membership, authenticate members, manage billing, deliver events and respond to enquiries. We rely on performance of a contract or steps requested before entering a contract.
- To operate, secure and improve Ramen Club. We use information to prevent misuse, diagnose problems, provide support, understand service performance and improve the experience. We rely on our legitimate interests in operating a safe and useful service.
- To communicate. We send service messages needed for membership, authentication, bookings, purchases and events. We send marketing where you have consented, or where another lawful permission applies, and provide an unsubscribe option.
- To measure and market our services. We use analytics, referral and advertising technologies to understand visits and campaigns. We rely on legitimate interests where permitted and on consent where the law requires it for cookies or similar storage.
- To meet legal obligations. We may retain and use information for accounting, tax, fraud prevention, disputes, legal claims and valid requests from public authorities.
We do not use personal data to make decisions based solely on automated processing that have legal or similarly significant effects on you.
Services that process information
We share information only where it is needed to run Ramen Club, provide a requested service, comply with law or protect our rights. Our principal providers include:
- Cloudflare for website and Worker hosting, delivery, security and operational analytics.
- Supabase for Members Hub authentication, session management, private signup records and membership access records.
- Loops for transactional and marketing email.
- Stripe for payments, subscriptions, invoices and the member billing portal.
- Tally for forms, applications, bookings and surveys.
- Cal.com for Ramen Space trial bookings, calendar invitations, confirmations and reminder emails.
- Fathom Analytics for privacy-focused audience measurement on the public site and Members Hub.
- PostHog for public-site and Members Hub support, product analytics, web performance measurement and privacy-bounded Session Replay, including Replay Vision analysis of consented recordings using Google's Gemini model as PostHog's sub-processor.
- Google, including Google Tag Manager, Google Analytics and Google Ads, for measurement, attribution and advertising.
- Google Drive for playing Hub event recordings. Pressing Play loads Google's player, and Google then receives the viewer's usual browser data, such as their IP address and browser information. The player does not load when you simply browse recordings.
- Meta for advertising measurement through Meta Pixel.
- Promptwatch for visitor and referral analytics, loaded only after you allow optional tracking.
Some pages include content or tools from Senja, YouTube, Airtable or Tiiny Host. When that content loads, the provider may receive technical information such as your IP address, browser and the page you visited.
We may also disclose information to professional advisers, courts, regulators, law-enforcement bodies or a buyer or successor where this is necessary and lawful.
Ramen Club does not sell personal data.
Members Hub support chat
PostHog Support is available on the rendered Members Hub sign-in and access-unavailable pages and on the rendered authenticated homepage, event calendars and Ramen Space page. If you use it, PostHog may receive information you voluntarily provide in the chat, browser and device information, and the current rendered page address, including ordinary query parameters. IP anonymisation is enabled for the project. The widget is not loaded on authentication callbacks, billing actions, redirects, feedback redirects, 404 pages or other non-rendered responses.
Before authentication, the Members Hub supplies only the public PostHog
project key and service address. It does not supply your entered or
pending email, one-time code, Supabase user ID, identity hash or
membership information, does not call identify, creates no
person profile and drops every analytics event. Anonymous Session Replay
may still record the rendered sign-in or access-unavailable page as
described below.
After authentication, PostHog receives the validated Supabase user ID,
authenticated email address and an HMAC-SHA256 identity-verification
hash derived on the server. We also supply the
membership_access label as Club-only or Club-and-Space and
the fixed app_surface value members. The secret
used to derive the hash never reaches the browser or PostHog. We do not
send payment data, Stripe Customer IDs, Supabase session tokens or
one-time codes. Support chat is not used by itself to approve billing,
authentication, entitlement or account changes.
PostHog is the Members Hub support provider. Crisp, our previous support provider, was retired on 28 September 2026: its account was closed and all of its historical conversations were deleted.
Public-site support and optional analytics
PostHog Support is available on pages rendered at
ramenclub.com. If you open it,
PostHog may receive information you voluntarily provide in the chat,
browser and device information and the canonical page address without
query parameters or fragments. Providing an email address is optional.
The public site does not call identify, use the Members Hub
identity-verification hash or itself create a PostHog person profile.
The widget can operate before you choose optional analytics. Until you
select “Allow optional tracking”, the public PostHog client uses page-memory
persistence, drops analytics events and does not record Session Replay.
If you allow analytics, PostHog receives one canonical pageview per
rendered page, anonymous browser and device context and the fixed
app_surface value marketing. The anonymous
analytics identifier uses separate local storage for return visits. We
retain the landing page, referring domain and named source, medium and
campaign slugs, but not arbitrary query values or full referrer URLs.
We do not send public form values or support messages in analytics.
PostHog also receives a fixed set of named clicks on booking and signup
links, such as opening the free trial form or choosing a day pass, with
only a fixed label for where on the page the link sits. To spot broken
or confusing controls, it receives repeated clicks on the same spot and
clicks that produce no visible change, limited to the clicked element's
type, CSS classes, up to 60 characters of its visible text and, for a
link, its path on this site or the other site's domain. It also receives
JavaScript errors from the page, limited to the error type, a shortened
message without query strings and the script files and lines involved.
Clicks inside the Support chat or this consent panel are not sent.
With analytics permission, submitting Remote signup details also sends
an anonymous event containing the selected plan and submission time,
not your email, name, marketing choice or payment details.
A verified Remote payment sends a purchase event with the plan and
original payment time, even if email verification is not completed.
Only after authenticated sign-in, with both public measurement and Hub
usage and recordings permission, can that anonymous history be connected
to your Members Hub user ID through PostHog's native identity linking.
Payment recovery and welcome pages do not load analytics or replay.
Consented public Session Replay records 100% of eligible sessions and is retained for 30 days. Every input is masked. Forms, iframes, the Support transcript and the PostHog configuration bootstrap are blocked from snapshots. We do not record console logs, network headers or request or response bodies, canvas content or cross-origin iframes.
Consented public Session Replay recordings may be analysed by PostHog Replay Vision, which uses an AI model that Google provides to PostHog (Gemini) to flag usability problems, such as a booking step that is hard to find or does not respond. It sees only the masked and blocked recordings described above, and its written observations are stored in our PostHog project. We use them to improve the site, not to make decisions about individual visitors.
Cookies and browser storage
The Members Hub uses necessary cookies for authentication, pending sign-in state and cross-site request forgery protection. PostHog Support uses one dedicated local-storage entry for its widget-session ID, ticket ID, launcher state and any traits you voluntarily enter into the Support identification form. The Hub also stores a browser-wide mode and pseudonymous member marker for conversation ownership, plus a per-tab member marker. Authenticated user ID, email and access traits and analytics continuity use PostHog's tab-scoped session storage. Unread state is fetched at runtime rather than retained in local storage. These entries are cleared on incompatible identity transitions and sign-out.
The public optional-tracking preference uses a versioned local-storage key and
a first-party cookie shared for the signup hand-off for up to one year.
The separate “Hub usage and recordings” permission uses a Members Hub-only
cookie and local storage, remembered on that browser for one year.
Closing an unanswered Hub prompt keeps tracking off and remembers the dismissal.
A still-valid earlier explicit choice is carried forward only where it covered
the same or broader purposes. Missing choices, refusals and dismissals never
become acceptance. Use public “Analytics preferences” or “Hub usage and
recordings preferences” in the Hub to change the relevant choice.
Hub permission alone never enables public advertising or acquisition tracking.
When allowed, anonymous PostHog continuity
uses a separate ramen-marketing local-storage namespace and
a 30-day first-party identifier cookie shared for the signup hand-off.
Withdrawing public consent stops optional public Google, Meta and PostHog
measurement and clears their accessible first-party analytics cookies.
Withdrawing Hub permission stops member usage events and recordings.
Neither choice disables support chat or Fathom. The public site and Members Hub use separate
browser origins and persistence names. Conversation and replay-session
storage is never shared. Withdrawal also suppresses pending purchase
exports and identity links once the server receives it; a failed request
is retried from this browser. Requests already sent cannot be recalled.
Newsletter subscription consent is separate and unchanged.
The public site and authenticated Members Hub use Fathom's cookie-free analytics in combined and domain-filtered reports. On the authenticated Hub homepage, Events and Space pages, Fathom receives one canonical pageview and fixed action-selection event names, without a referring address supplied by our Hub code. It does not measure authentication or billing actions. On the public site, browser referrers may include query strings depending on the referring site's settings. We do not attach a member's email, name, user ID, authentication or Support identity hash, Members Hub query parameters, destination URLs or event properties.
The authenticated Members Hub homepage, event calendars and Ramen Space page use PostHog's EU service for product analytics and Core Web Vitals only with Hub usage and recordings permission. PostHog receives the member's Supabase user ID, whether their access is Club-only or Club-and-Space, the fixed Members Hub app-surface label, canonical pageviews, fixed action-selection event names, browser and device context and performance measurements. IP anonymisation is enabled. Its analytics browser identifier is stored in session storage for the current tab and is reset on sign-out. We use observed activity for manual member-support reviews. A resource click is not proof of a Slack join or introduction, and missing telemetry means activity is unknown, not that a member is inactive. This does not trigger automated follow-up messages.
Product analytics is limited to canonical query-free Members Hub routes. The current page address and ordinary query context available to Support is not copied into analytics events. A member's email is available to verified Support tickets and a controlled PostHog person update, but is removed from ordinary analytics events. PostHog is configured without autocapture, heatmaps, surveys, feature-flag evaluation or exception capture. We do not send ordinary events a member's name, one-time code, authentication token, identity hash, payment data, support messages, query strings, destination URLs or Ramen Space operational values.
Session Replay records 100% of eligible anonymous and authenticated sessions on the rendered Members Hub pages listed above, including code-entry, validation-error, reset, ordinary query and billing-error states, only with Hub usage and recordings permission. Recordings are retained for 30 days. Every input is masked, and credential-bearing elements, Ramen Space door and Wi-Fi credentials, Slack invitation links, the Support transcript and the identity bootstrap are blocked from snapshots. Ordinary page text remains visible. We do not record console logs, network headers or request or response bodies, canvas content or cross-origin iframes. Recordings made with Hub usage and recordings permission may be analysed by PostHog Replay Vision, which uses an AI model that Google provides to PostHog (Gemini) to flag Members Hub tasks that members could not complete. It sees only the masked and blocked recordings described here, and its written observations are stored in our PostHog project. We use them to improve the Members Hub, not to make decisions about individual members.
If you allow optional tracking, the public site loads Google and Meta measurement or advertising technologies. These technologies may set identifiers such as Google Analytics, Google Ads, DoubleClick and Meta Pixel cookies. Until you allow them, Google Tag Manager and the Google and Meta tags inside it do not load. The site also uses local or session storage for referral, conversion and event-deduplication state. Embedded forms or media may use their own storage.
You can remove or block cookies through your browser. Blocking necessary Members Hub cookies will prevent sign-in. The public “Analytics preferences” control records consent for optional Google, Meta, PostHog and Promptwatch measurement, including PostHog Session Replay. It does not change Fathom or embedded-service storage. A browser Do Not Track signal prevents the optional Google, Meta, PostHog and Promptwatch measurement.
International transfers
Some providers process information in the United Kingdom or European Economic Area, and others may process it elsewhere. Where data is transferred to a country without an adequacy decision, we require an appropriate safeguard where applicable, such as approved contractual clauses or a recognised data-transfer framework. Contact us if you would like more information about the safeguards relevant to your data.
How long we keep information
We keep personal data only for as long as it is needed:
- Membership, account and service records are kept while the relationship is active and afterwards where needed for support, disputes or legal obligations.
- Transaction and accounting records are kept for the periods required by tax, accounting and company law.
- Marketing information is kept until you unsubscribe or we no longer need it. We may retain a suppression record so we respect your choice.
- We aim to remove expired, unpaid Remote signup records after 90 days. Records with an unresolved payment, identity or support issue are held for review. This does not delete paid membership or accounting records. Newsletter subscriptions are managed separately. We retain minimal consent evidence and suppression records for as long as needed to demonstrate and respect your email choices.
- Form responses, support messages and event records are kept while they remain useful for the purpose collected, then deleted or anonymised.
- Technical, security and analytics data is kept according to operational need and the applicable provider settings.
Your rights
Depending on the circumstances, UK and EEA data-protection law may give you rights to access, correct or erase your personal data; restrict or object to its use; receive portable data; and withdraw consent. These rights can be limited by law and depend on the reason we process the data.
You can object to direct marketing at any time by using the unsubscribe link in an email or contacting us. To make another privacy request, email charlie@ramenclub.com. We may need to verify your identity before acting on a request.
You can complain to the UK Information Commissioner's Office. Visit the ICO complaint guidance for details. If you are in the EEA, you may also contact your local supervisory authority.
Security
We use access controls, encryption in transit, restricted secrets and other technical and organisational measures intended to protect personal data. No online service can guarantee absolute security.
Children
Ramen Club, Ramen Space and the Members Hub are intended for adults. We do not knowingly collect personal data from anyone under 18. Contact us if you believe a child has provided personal data to us.
Changes and contact
We may update this policy when our services or legal obligations change. We will publish the new version here and update the date above. We will provide a more prominent notice where a change materially affects how we use personal data.
Questions or requests can be sent to charlie@ramenclub.com.