Your Privacy Choices

Privacy Policy for Up'N'Down Golf

Effective Date: October 31, 2025

At Up'N'Down Golf ("we," "us," or "our"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website (www.upndowngolf.co.uk), use our services (including club rentals, bookings, and deliveries in the Algarve), or interact with us. We operate as a data controller under applicable laws.

This policy complies with:

  • EU/EEA: General Data Protection Regulation (GDPR).
  • UK: UK GDPR (retained EU law post-Brexit).
  • USA: Key state laws including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and similar requirements in states like Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA). (Federal laws like COPPA apply if we process data of children under 13, but we do not target minors.)

By using our services, you consent to the practices described here. If you do not agree, please do not use our site or services. We may update this policy; changes will be posted here with the updated effective date.

1. Information We Collect

We collect personal information to provide our rental services, process bookings, and improve your experience. This includes:

  • Personal Identifiers: Name, email address, phone number, postal address (e.g., for delivery in the Algarve).
  • Payment and Financial Information: Credit/debit card details, billing address (processed securely via third-party providers; we do not store full card numbers).
  • Booking and Usage Data: Rental preferences (e.g., club selections, bundle choices), passport/driving license details (for verification at delivery/collection to prevent fraud).
  • Technical Data: IP address, browser type, device information, cookies, and usage analytics (e.g., pages visited).
  • Communication Data: Emails, inquiries, or feedback you provide.

We do not collect sensitive personal information (e.g., health data) unless voluntarily provided (e.g., in accessibility requests).

Sources: Directly from you (e.g., booking forms), automatically via cookies/tools, or from third parties (e.g., payment processors).

2. How We Use Your Information

We use your information for legitimate business purposes, including:

  • Processing rentals, deliveries, and collections.
  • Verifying identity and preventing fraud (e.g., checking payment card, passport, and driving license at handover).
  • Communicating about your booking, updates, or promotions (with opt-out options).
  • Improving our services (e.g., analyzing usage for better club recommendations).
  • Legal compliance (e.g., tax records, dispute resolution).

Legal Bases (for EU/UK GDPR):

  • Consent (e.g., for marketing emails; you can withdraw anytime).
  • Contract necessity (e.g., fulfilling bookings).
  • Legitimate interests (e.g., fraud prevention, site analytics; balanced against your rights via Legitimate Interests Assessment).
  • Legal obligation (e.g., record-keeping).

Under US laws like CCPA/CPRA, uses align with consumer expectations and do not involve "sales" of personal information (we do not sell data).

3. Sharing Your Information

We share information only as necessary and with your implied consent through service use:

  • Service Providers: Payment processors (e.g., Stripe), delivery partners in the Algarve, email tools (e.g., Mailchimp), and analytics (e.g., Google Analytics). They are bound by data processing agreements.
  • Legal Requirements: To comply with laws, respond to authorities, or protect rights (e.g., fraud claims).
  • Business Transfers: In case of merger/acquisition.

We do not sell or rent your data to third parties for marketing. For EU/UK, international transfers (e.g., to non-adequate countries like the US) use Standard Contractual Clauses (SCCs) or adequacy decisions.

4. Data Retention

We retain information only as long as needed:

  • Booking data: Duration of rental + 6 years (for legal/tax purposes).
  • Verification docs: Deleted immediately after handover unless fraud suspected (up to 1 year).
  • Marketing data: Until you unsubscribe or 2 years of inactivity.

Secure deletion follows when no longer required.

5. Your Rights and Choices

Your rights vary by jurisdiction but include:

EU/UK (GDPR/UK GDPR):

  • Access, rectification, erasure ("right to be forgotten"), restriction, portability.
  • Object to processing (e.g., legitimate interests, marketing).
  • Withdraw consent.
  • Lodge complaints with supervisory authorities (EU: local DPA; UK: ICO at ico.org.uk).

USA (State Laws like CCPA/CPRA):

  • Right to Know (access categories/sources of data collected in last 12 months).
  • Right to Delete (including from service providers).
  • Right to Correct inaccuracies.
  • Right to Opt-Out of Sale/Sharing (we do not sell/share for targeted ads; use Do Not Sell My Personal Information link if added).
  • Right to Limit Sensitive Data Use (we do not process sensitive data routinely).
  • Non-discrimination for exercising rights.
  • For other states (VA, CO, CT, UT): Similar access/deletion/opt-out rights via authorized agents.

How to Exercise Rights: Email hello@upndowngolf.co.uk with your request. We verify identity (e.g., via booking details) and respond within 1 month (EU/UK) or 45 days (US). No fee unless requests are excessive.

Cookies and Tracking: We use cookies for functionality and analytics. You can manage via browser settings. For opt-out of targeted ads, use tools like YourAdChoices (US) or Your Online Choices (EU/UK).

6. Children's Privacy

Our services are not directed at children under 13 (US COPPA) or 16 (EU/UK GDPR). We do not knowingly collect data from minors. If we discover such data, we delete it promptly. Parents/guardians: Contact us to review/delete.

7. Security

We use reasonable technical/organizational measures (e.g., encryption, access controls, secure servers) to protect data. However, no system is 100% secure; we cannot guarantee absolute protection.

8. International Transfers

As a UK-based business serving EU/EEA and US customers, data may transfer to the UK/EU/US. We ensure adequacy (e.g., EU-UK adequacy) or safeguards like SCCs.

9. Contact Us

For questions, rights requests, or complaints:

  • Email: hello@upndowngolf.co.uk
  • Address: Up'N'Down Golf, [Your UK Address, e.g., Algarve Delivery Hub, Portugal/UK Office]
  • EU Representative: [If applicable; otherwise, use contact above]
  • DPO: Not appointed (small business); direct to us.
  • Supervisory Authorities: ICO (UK), local DPA (EU), CA AG (US).

10. Additional US State Disclosures

  • California (CCPA/CPRA): Categories collected (last 12 months): Identifiers, financial info, commercial info, internet activity. Disclosed to service providers for operational purposes. No sales/sharing.
  • Virginia/Colorado/Connecticut/Utah: Opt-out of targeted ads/profiling via email request; data processed for service provision.
  • Shine the Light (CA): Affiliates may share data; request disclosure via email.