Operated by Sabrina Ashworth • Sole Trader (UK)

Privacy Policy

How we collect, use, and protect your personal information in compliance with UK GDPR and the Data Protection Act 2018.

Last Updated: September 2026

1. Data Controller & Overview

This Privacy Policy explains how Sabrina Ashworth trading as Grails Collectors ("Grails Collectors", "we", "us", or "our") collects, uses, discloses, and protects your personal data when you visit our website, use our member portal, or subscribe to our VIP alert services.

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Sabrina Ashworth is the Data Controller responsible for your personal information.

2. Information We Collect

We strictly limit the data we collect to what is necessary to authenticate you, provision your VIP subscription, and grant you access to community channels:

  • Account & Contact Details: Your email address, collected during checkout or when requesting a magic login link.
  • Community Platform Identifiers: Your unique username and account identifier (ID) when you connect your account or join our private community channels, used solely to assign and verify your VIP membership role.
  • Subscription & Transaction Metadata: Payment status, subscription plan ID, billing period, and customer ID assigned by our payment processor. Note: We never process, see, or store your credit or debit card numbers on our servers; all payment transactions are handled directly by PCI-DSS Level 1 certified payment processors.
  • Technical & Log Data: Internet Protocol (IP) address, browser type, device information, and timestamps recorded for security auditing and fraud prevention.

3. How We Use Data & Lawful Bases

Under UK GDPR, we must have a valid lawful basis to process your personal information:

Performance of Contract (Article 6(1)(b))

Processing your email and community IDs to provide your paid VIP membership, generate one-time channel invite links, assign VIP roles, process subscription renewals, and deliver real-time alert notifications.

Legitimate Interests (Article 6(1)(f))

Protecting our systems against malicious activity, detecting unauthorized scraping or re-broadcasting of alert feeds, diagnosing technical issues, and ensuring community integrity.

Legal Obligation (Article 6(1)(c))

Retaining required transaction history, billing invoices, and accounting records to comply with statutory UK tax and financial reporting regulations (HMRC).

4. Third-Party Processors & International Transfers

We do not sell, rent, or trade your personal data. We only share data with essential third-party service providers ("subprocessors") required to operate our service:

  • Authorized Payment Processing: Stripe Inc. handles all subscription payments, card verification, invoice generation, and customer billing portal access under rigorous PCI-DSS compliance standards.
  • Community & Messaging Platforms: Authorized messaging APIs to verify memberships, validate join requests, and assign VIP server roles.
  • Encrypted Cloud Infrastructure: Secure MongoDB cloud database clusters and modern cloud hosting environments with end-to-end SSL/TLS encryption.
  • Transactional Email Delivery: Secure email service providers used solely for sending one-time magic access links and essential billing receipts.

Where service providers process data outside the UK or European Economic Area, transfers are protected by recognized safeguards, including the UK International Data Transfer Addendum and Standard Contractual Clauses (SCCs).

5. Cookies & Session Authentication

We practice data minimization. Our website utilizes strictly necessary first-party cookies and temporary session storage tokens required to:

  • Authenticate your magic login link session and verify active VIP status.
  • Provide Cross-Site Request Forgery (CSRF) protection during login.
  • Persist your visual preferences and store selection while browsing the portal.

We do not deploy intrusive third-party cross-site advertising trackers or sell advertising profiles.

6. Data Retention & Security Measures

We retain your personal data only as long as necessary to fulfill the purposes outlined in this policy:

  • Active Subscriptions: Maintained for the duration of your active membership to provide continuous alerts and role syncing.
  • Canceled Memberships: Inactive account records are retained for up to 12 months to facilitate easy reactivation, after which they can be purged upon request.
  • Statutory Accounting: Financial transaction logs are retained for six (6) years in compliance with UK tax law (HMRC).

All data in transit is protected using modern HTTPS/TLS 1.3 encryption, and internal databases are secured behind strict firewall rules with restricted administrative access.

7. Your UK GDPR & Privacy Rights

Under UK data protection legislation, you have key rights regarding your personal data:

Right of Access: Request a copy of the personal information we hold about you.
Right to Rectification: Request correction of inaccurate or incomplete data.
Right to Erasure: Request deletion of your personal data ("right to be forgotten"), subject to statutory legal record obligations.
Right to Restrict / Object: Object to processing based on legitimate interests or request temporary restriction of processing.

To exercise any of these rights, please email us at support@grailscollectors.com. We respond to all verified requests within one (1) calendar month.

8. Contact & Regulatory Authority

If you have questions, concerns, or requests regarding this Privacy Policy or our handling of your data, please contact:

Data Controller Contact:

Sabrina Ashworth trading as Grails Collectors

England & Wales, United Kingdom

Email: support@grailscollectors.com

Support Telephone: +44 7468 581729

You also have the statutory right to lodge a complaint with the UK data protection supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk or by phone at 0303 123 1113.