Privacy & Cookies Policy
Last updated: 27 October 2025
This Privacy & Cookies Policy explains how The Big Baller Challenge LTD LTD (“we”, “us”, “our”) collects, uses and protects your personal data when you use our website, create an account, purchase or submit entries to skill-based prize competitions, or interact with us in other ways. We are a controller under the UK GDPR and the Data Protection Act 2018.
1) Who We Are (Controller)
- Company: The Big Baller Challenge LTD (16808185)
- Data protection contact / DPO: thebigballerchallenge@gmail.com
2) Data We Collect
- Identity & contact — name, email, phone, postal address, age/ID verification outcomes.
- Account & usage — login data, preferences, support messages, IP address, device/browser info, log files, approximate location (from IP), referral data.
- Competition data — orders, entries, answers to skill questions, ticket numbers, draw outcomes, wins and fulfilment records.
- Payment data — last 4 digits, card brand and transaction metadata from our payment processor (we do not store full card numbers).
- Marketing data — consent preferences, campaign interactions.
- Cookies & similar tech — see the Cookies section below.
3) Sources
We collect data directly from you; automatically via cookies and analytics; from payment processors (transaction status); from age/ID verification providers; and from service providers who support our website/app.
4) Lawful Bases for Processing
- Contract — to register your account, process entries, take payment, conduct draws, contact winners, deliver prizes and provide support.
- Legitimate interests — to run and improve our services, prevent fraud, keep the Site secure, publish minimal winner information for transparency, and measure campaign performance (balanced against your rights).
- Consent — for email/SMS marketing (opt-in) and for non-essential cookies. You can withdraw consent at any time.
- Legal obligation — to meet record-keeping, tax, consumer and AML requirements.
5) How We Use Your Data
- Operating prize competitions and your account.
- Taking payments and managing orders/entries.
- Conducting fair draws and notifying winners.
- Age/identity checks before prize release.
- Delivering/arranging prizes and winner verification.
- Fraud prevention, security monitoring and diagnostics.
- Customer support and service communications.
- Sending marketing with your consent (you can opt out any time).
- Publishing minimal winner details for transparency (see below).
6) Sharing Your Data
We share personal data with trusted processors who help us run the business, such as:
- Payments — Stripe (card processing); chargeback and anti-fraud tools.
- Email & comms — Resend (transactional email), email hosting.
- Hosting/CDN — our cloud infrastructure and content delivery providers.
- Analytics — privacy-respecting analytics (e.g., Plausible) or Google Analytics if configured (consent-based where required).
- Age/ID verification — to ensure 18+ and eligibility.
- Fulfilment — prize suppliers, couriers, insurers (for vehicle prizes), etc.
We require processors to protect your data and process it only on our instructions. We may also disclose data if required by law or to protect our legal rights.
7) Winner Publicity
For transparency, we may publish winners’ first name, initial of surname, town/region and winning entry number(s). We may ask winners for photos/testimonials. You may object to non-essential publicity at any time — contact us and we will honour your objection unless minimal publication is necessary for integrity and compliance.
8) Data Retention
- Account & order records: generally 6 years for tax/audit.
- Verification and support logs: typically up to 24 months.
- Marketing data: until you withdraw consent or the campaign ends.
- We may anonymise data for statistics and service improvement.
9) Security
We implement appropriate technical and organisational measures, including TLS encryption in transit, restricted access, and reputable hosting. No system is 100% secure; please keep your account credentials confidential and notify us of any suspected compromise.
10) International Transfers
Where a processor stores data outside the UK/EEA, we ensure appropriate safeguards (e.g., UK/EEA Standard Contractual Clauses, adequacy decisions) are in place.
11) Your Rights
- Access, rectification, erasure (where applicable).
- Restriction or objection to processing in certain circumstances.
- Data portability for information you provided to us.
- Withdraw consent for marketing or cookies at any time.
- Complain to the UK Information Commissioner’s Office (ICO): ico.org.uk. We would appreciate the chance to address your concerns first.
To exercise rights, contact thebigballerchallenge@gmail.com. We may request ID to verify your identity.
12) Children
Our services are for adults. We do not knowingly collect data from anyone under 18.
13) Cookies & Similar Technologies
We use cookies and similar tech to operate the Site, keep you logged in, measure performance and (with consent) personalise marketing. On your first visit we present a banner allowing you to accept or manage cookies. You can also control cookies via your browser settings.
- Strictly necessary — required for core functions (e.g., login, checkout).
- Performance/analytics — aggregated usage (consent where required).
- Marketing — only if you opt in.
14) Marketing Communications
We send marketing only with your consent (or as otherwise permitted by PECR). You can opt out from links in our emails/SMS or by contacting us. Transactional/important service notices may still be sent.
15) Changes to This Policy
We may update this Policy from time to time. Material changes will be highlighted on the Site. Continued use of the Site after changes indicates acceptance.
16) Contact
For privacy queries or to exercise your rights, email thebigballerchallenge@gmail.com or write to The Big Baller Challenge LTD.