This policy explains how BallVault Golf ("we", "our", "us") collects and uses your personal information when you use this website or buy from us. It is written to meet our obligations under the UK GDPR and Data Protection Act 2018.
Data controller
The data controller for this site is BallVault Golf, 29 Lord Street, BL4 8BE, United Kingdom. You can reach us at any time at ballvaultgolf@gmail.com.
What we collect
- Account information — name, email, referral code, birthday (if you add one).
- Order information — delivery address, items ordered, order history.
- Payment information — handled directly by Stripe. We do not see or store full card details; we retain the last-four digits and transaction reference for reconciliation.
- Contact information — anything you send us by email, WhatsApp, or through the contact / supplier / request-a-ball forms.
- Marketing consent — your email if you sign up to the newsletter, plus a record of when and how you consented.
- Loyalty & referral data — points earned, redeemed and held, referral codes used, and the outcome of automated fraud checks (see below).
- Site usage — session ID, pages viewed, referring URL, device type, and (server-side) your IP address and user agent. Details in our Cookie Policy.
- Order IP — the IP address a checkout was completed from, kept for fraud prevention and chargeback defence.
How we use it and our legal basis
- To fulfil your order (Contract) — process payment, pack, ship, handle cancellations and refunds.
- To run your account & loyalty programme (Contract) — points, referrals, order history.
- To respond to enquiries (Legitimate interests) — replying to contact, supplier and ball-request forms.
- To prevent fraud & abuse (Legitimate interests / Legal obligation) — including automated scoring of referrals against signals such as shared signup IP, matching addresses, or bursts of referrals from the same account. Flagged referrals may be held for review and can be rejected. You can ask for a human to review any automated decision that affects you.
- To send marketing emails (Consent) — only if you ticked the newsletter box; you can unsubscribe at any time using the link in every marketing email.
- To improve the site (Consent, via the cookie banner) — first-party analytics of page views, referrers and cart activity.
- To meet legal obligations — keeping order and tax records.
Who we share it with
We only share data with the providers we need to run the business. We do not sell your data.
- Stripe Payments Europe, Ltd. — payment processing (Ireland; may transfer to the US under UK IDTA/SCCs).
- Supabase / Lovable Cloud — database, authentication and hosting of app data (EU/UK region where available).
- Mailgun / our transactional email provider — sending order, auth and newsletter emails from our verified domain notify.ballvaultgolf.com.
- Royal Mail — delivery of your parcel.
- Cloudflare / our hosting network — content delivery and DDoS protection.
Where a provider is based outside the UK/EEA we rely on the UK International Data Transfer Addendum, EU Standard Contractual Clauses or an equivalent safeguard.
How long we keep it
- Order and tax records — up to 7 years, to meet HMRC rules.
- Account & loyalty ledger — while your account is active; deleted on request unless we need it for the record above.
- Marketing emails — until you unsubscribe, then a small suppression record to prevent us re-adding you.
- Analytics events — up to 24 months.
- Contact enquiries — deleted once resolved and no longer needed.
Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or export your data, to object to processing based on legitimate interests or direct marketing, and to withdraw consent at any time (without affecting processing done before you withdrew). Email ballvaultgolf@gmail.com and we will respond within one month.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk.
Cookies
The exact cookies and browser storage we set — and how to switch analytics off — are listed in our Cookie Policy.
Security
We use HTTPS across the site, store passwords hashed by our authentication provider, and rely on Stripe for payment security. Access to admin data is restricted by role. No system is 100% secure, but we act quickly on anything that puts your data at risk and will notify you and the ICO where required.
Changes
We may update this policy from time to time. The "last updated" date at the top will always tell you when.
