Privacy Policy

Last updated: 2026-06-11

This Privacy Policy explains how Unlock Sweden (“we”, “us”, “our”) collects, uses, shares, and protects personal data when you use our website and related services (the “Service”), including when you buy and play our self‑guided outdoor/city quests delivered through the Actionbound app.

If you do not agree with this Privacy Policy, please do not use the Service.

Who we are (Data Controller)

Unlock Sweden is the controller for the personal data described in this Privacy Policy.

Contact (privacy): support@unlocksweden.se Postal address: Hamnvägen 1, 1405, Norrtälje 76134, Sweden Supervisory authority (Sweden): Integritetsskyddsmyndigheten (IMY) — https://www.imy.se/

We are currently operated by an individual (sole operator) in Sweden and do not yet have a registered legal entity or organisation number. If you need our legal name for the purpose of exercising your GDPR rights or for regulatory correspondence, we will provide it upon request after verifying your identity.

What personal data we collect

We collect only the data we need to deliver access to quests, provide support, and run the Service.

Data you provide to us

  • Contact details: email address and, if provided, name.
  • Purchase and access information: information needed to deliver your access code and troubleshoot issues (for example, order identifiers, product/quest identifier, language/locale, time of purchase).
  • Support communications: information you include when contacting support (for example, messages and any screenshots you send).

Data collected automatically (Usage Data)

When you visit the website, we may automatically collect:

  • IP address (typically in logs), device and browser type, operating system,
  • pages visited, timestamps,
  • diagnostics and performance data.

Cookies and similar technologies

We may use cookies and similar technologies for:

  • essential site functionality and security,
  • remembering preferences (for example, language),
  • measuring site performance and usage.

We do not use marketing cookies or cross‑site tracking cookies. We also do not sell personal data.

Where required by law (including Swedish ePrivacy/cookie rules), we will ask for consent before placing non‑essential cookies (such as analytics cookies). You can control cookies through your browser settings and, where available, our cookie settings banner.

Actionbound (third‑party app)

Your quest gameplay runs in the Actionbound app. Actionbound may process personal data under its own privacy policy (for example, device identifiers and location permissions, depending on your device/app settings).

We do not receive and do not have access to your precise GPS location or media uploaded within the Actionbound app, unless you voluntarily share it with us (for example, by sending screenshots to support).

Why we process personal data (purposes)

We use personal data for the following purposes:

  • To provide the Service (deliver access codes, provide instructions, and ensure you can start the quest).
  • To perform our contract with you (process purchases and deliver the purchased digital experience).
  • To provide customer support (answer questions, fix issues such as code delivery, GPS permissions, or app troubleshooting).
  • To improve the Service (debugging, aggregated analytics, product improvement).
  • To ensure security (fraud prevention, abuse prevention, securing the website and systems).
  • To send service messages (important updates about purchases, access, or critical changes).

Marketing emails (newsletter / offers)

If we send promotional emails (for example, discounts for other quests), we will do so only when we have a lawful basis. In most cases this means:

  • your explicit consent (opt‑in) for marketing newsletters, or
  • where permitted, legitimate interests for limited marketing of similar services, with an easy opt‑out in every message.

You can unsubscribe at any time using the link in our emails or by contacting us.

GDPR lawful bases we rely on

We process personal data under one or more of the following legal bases (GDPR Art. 6):

  • Contract (Art. 6(1)(b)) – to deliver purchased quests and access codes and provide necessary support.
  • Legitimate interests (Art. 6(1)(f)) – to keep the Service secure, prevent fraud, and improve the Service. We balance these interests against your rights.
  • Consent (Art. 6(1)(a)) – for marketing emails and, where applicable, non‑essential cookies/analytics.
  • Legal obligation (Art. 6(1)(c)) – where we must keep records to comply with applicable laws (for example, accounting/tax).

Who we share data with (recipients)

We share personal data only as needed to operate the Service:

  • Payment processors: e.g., Stripe (for processing payments). We do not store full card details; they are handled by the payment provider.
  • Email delivery / mailbox providers: to send access codes and support replies.
  • Marketplace partners: e.g., Viator, if you purchase through them (they may share booking information with us; their processing is governed by their own policies).
  • Actionbound: used to deliver the quest experience inside the Actionbound app.
  • Hosting and infrastructure providers: e.g., Cloudflare (website delivery, security, and performance).
  • Automation providers: workflow automation for code delivery/support operations.

All service providers are required to process personal data only on our instructions and with appropriate safeguards.

International transfers

Some of our service providers may process personal data outside the EU/EEA. When this happens, we use appropriate safeguards, such as:

  • adequacy decisions (where applicable), and/or
  • Standard Contractual Clauses (SCCs) and other legally recognized transfer mechanisms.

How long we keep your data (retention)

We keep personal data only as long as necessary for the purposes described above, and in line with applicable legal requirements.

  • Accounting / transaction records (invoices, receipts, purchase records): kept for 7 years after the end of the calendar year of the transaction, in line with Swedish accounting rules (Bokföringslagen).
  • Access code delivery records (e.g., email + order reference + code issued): kept for up to 24 months after purchase to handle support cases and disputes, unless a longer legal retention period applies.
  • Support communications: kept for up to 24 months after the support case is closed, then deleted or anonymised unless we need to keep it longer for legal claims.
  • Technical security logs: kept for 30–90 days (depending on log type), then deleted or anonymised, unless we need to keep them longer to investigate abuse or security incidents.
  • Marketing list (if you opted in): kept until you unsubscribe or withdraw consent.

If you ask us to delete your data, we will do so unless we must keep certain data to comply with legal obligations or to establish, exercise, or defend legal claims.

Your rights under GDPR

If you are in the EU/EEA (or where GDPR applies), you have the right to:

  • access your personal data,
  • correct inaccurate data,
  • request deletion (“right to be forgotten”),
  • restrict processing,
  • object to processing based on legitimate interests,
  • data portability (for data you provided to us, where applicable),
  • withdraw consent at any time (where processing is based on consent).

To exercise your rights, contact us at support@unlocksweden.se.
We may need to verify your identity before fulfilling your request.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten – IMY) at https://www.imy.se/, or with your local supervisory authority.

Automated decision-making

We do not use automated decision‑making, including profiling, that produces legal effects concerning you or similarly significantly affects you (GDPR Art. 22).

Security

We use reasonable technical and organisational measures to protect personal data (for example, access controls and secure tooling). However, no method of transmission or storage is 100% secure.

Children’s privacy

Our Service is not intended for children. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us and we will take appropriate steps.

Our Service may contain links to third‑party websites. We are not responsible for their privacy practices. Please review their policies.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last updated” date.

Contact

If you have questions about this Privacy Policy or your personal data: