Data Protection & Privacy
Last updated 11th July 2026 | Link to live document
Who we are
Dragon Gaming is a tabletop gaming club based in South Wales, United Kingdom. Our website address is https://dragongaming.co.uk.
You can contact us at:
Email: [email protected]
What personal data we collect and why
We collect the following information from members and visitors:
- Name and email address when you register an account, sign up for events or contact us
- Event registration details to manage bookings and send updates
- Billing address and order details when you make a purchase through our store
- Membership status and expiry date, for access control and renewal reminders
- DGM (virtual currency) balance and transaction history, for the in-club economy
- Event check-in records (date, guild branch, Game Master), for session management and financial reporting
- Voting eligibility snapshots and, depending on vote type, your voting choices
Why we collect it:
- To create and manage your account (legal basis: contract performance)
- To organise and administer events and send confirmations or reminders (legal basis: legitimate interests)
- To process orders and payments (legal basis: contract performance)
- To communicate news and announcements you have opted into (legal basis: consent)
We do not collect sensitive personal data. Payment card details are handled entirely by Stripe and are never transmitted to or stored on our servers.
Media
Any media you upload (such as photos from game nights) may be publicly accessible. Please do not upload sensitive or personal information in media files.
Contact forms
We use a contact form plugin to allow you to reach out to the club. When you submit a form, we collect:
- Your name
- Your email address
- The content of your message
We keep contact-form submissions for 12 months to ensure we can follow up on enquiries, after which they are permanently deleted. We use this information only to respond to your messages and do not use it for marketing purposes without your explicit consent.
Store and orders
Our online store is powered by WooCommerce. When you place an order we collect and store:
- Your name and email address
- Your billing address
- Your order history (products purchased, amounts, dates)
This information is stored in our WordPress database hosted in the United Kingdom and is used to fulfil your order, issue receipts and maintain an accurate transaction record. We do not store payment card details. These are handled entirely by Stripe (see below). Order data is retained for 3 years after the order date, in line with our financial record-keeping obligations.
Membership and Dragon Guild Marks (DGMs)
When you purchase a Guild Membership we record your membership expiry date and whether your membership is currently active. This controls access to member-only content and purchases, and is used to send you renewal reminders close to your expiry date.
If you purchase Dragon Guild Marks (DGMs), our in-club virtual currency, we record your balance and a full transaction history covering purchases, check-in deductions and peer-to-peer transfers with other members. DGM transaction records are retained for the lifetime of your account and for 3 years after deletion, in line with our financial record-keeping obligations.
Legal basis: contract performance.
Event attendance records
When you check in to a gaming session using our QR-code system or via the Check-In button, we record:
- Your user account and the date and time of check-in
- The Game Master running the session
- The guild branch the session took place at
- The DGM exchange rate in effect at the time (used for financial reporting)
This data is used to deduct DGMs for the session, to produce attendance reports for guild committee members and to inform our financial reporting. Check-in records are retained indefinitely as part of our financial and operational records.
Legal basis: contract performance (DGM deduction); legitimate interests (attendance reporting and financial record-keeping).
Voting and elections
Dragon Gaming runs member votes and guild elections through the website. When a vote or election is created, we take a snapshot of who is eligible to participate, based on your membership status, attendance history and guild role. Your eligibility for a specific vote is fixed at the moment it is created.
When you cast a vote, we always record that you voted (to prevent duplicate votes). What we record about how you voted depends on the vote type, which is visible to you before you submit your vote:
- Anonymous votes: Your specific choice is never recorded against your name. Nobody, including Dragon Gaming administrators, can see how you voted.
- HQ-only votes: Your choice is recorded but visible only to senior Dragon Gaming administrators. It is never shown to other members.
- Public votes: Your choice is recorded and shown to all members once the vote closes.
Guild elections are always conducted as HQ-only votes.
Voting and election records are retained indefinitely as part of our club governance records. Records from anonymous votes cannot be linked back to any individual.
Legal basis: legitimate interests (democratic governance of the club).
Payments and Stripe
All payments are processed by Stripe, a third-party payment processor. When you make a purchase, the following information is transmitted to Stripe to complete your transaction:
- Your name and email address
- Your billing address
- Your payment card details (card number, expiry date, CVV)
Your card details are transmitted directly and securely to Stripe and are never stored on our servers. Dragon Gaming only retains a record of the transaction (order total, date, and a reference token), not your card number or CVV.
Stripe stores and processes payment data on their own secure infrastructure. They are certified to PCI DSS Level 1, the highest level of payment security certification. Stripe acts as a data processor on our behalf under a Data Processing Agreement. For full details of how Stripe handles your data, please see https://stripe.com/gb/privacy.
Saving payment details for future purchases
During checkout you may be offered the option to save your payment information for future purchases via Stripe Link. If you choose to do so, your card details are saved securely within Stripe’s own systems — not on the Dragon Gaming website. You can request removal of saved
payment details at any time by contacting us at [email protected].
Stripe, Inc. is based in the United States. Data transfers are carried out under Standard Contractual Clauses in accordance with UK GDPR.
Cookies
Cookies are small text files stored on your device by your browser. We use the below categories of cookies.
Strictly necessary cookies
These are required for the site to function and cannot be disabled:
| Cookie | Purpose |
|---|---|
| wordpress_[hash] | Keeps you logged in to your account |
| wordpress_logged_in_[hash] | Remembers your login state across pages |
| wp-settings-[UID] | Stores your site interface preferences |
| wp-settings-{time}-[UID] | Records when your preferences were last saved |
| woocommerce_cart_hash | Tracks whether your basket has changed |
| woocommerce_items_in_cart | Remembers that you have items in your basket |
| wp_woocommerce_session_[hash] | Maintains your active shopping session |
Payment cookies
These are set by Stripe during checkout to protect against fraud and process your payment securely. These are governed by https://stripe.com/gb/privacy.
We do not use advertising, tracking, or analytics cookies. You can manage or block cookies via your browser settings, though disabling strictly necessary cookies will affect your ability to log in and use the store.
Analytics
We do not use any analytics tools beyond anonymised server logs collected by our hosting provider. If we implement an analytics plugin, we will update this section.
Who we share your data with
We share your personal data with the following third-party services:
- Stripe: Processes all card payments. Your card details are transmitted directly to Stripe and never stored on our servers. Stripe is PCI DSS Level 1 certified. Data transfers take place under Standard Contractual Clauses as required by UK GDPR.
- AWS (Amazon Web Services): Our hosting provider. Your data is stored on AWS servers in the United Kingdom.
- Brevo: Our email service provider. We share your name, email address, home guild, and current game with Brevo in order to send membership-related communications. You can opt out of marketing emails at any time from the Email Preferences section of your My Account page. Service emails, such as vote and election notifications, are sent regardless of your marketing preference, as they relate directly to your participation in club activities.
We do not sell or rent your personal data to any third parties.
How long we retain your data
We retain your data only as long as necessary for the purposes for which it was collected:
- User accounts: Retained until you request deletion, or 3 years after your last activity
- Order and payment records: Retained for 3 years after the order date, in line with our financial record-keeping obligations
- Contact form submissions: Retained for 12 months, then permanently deleted
- Membership records: Retained for 3 years after your membership expires
- DGM transaction history: Retained for the lifetime of your account and for 3 years after account deletion
- Event attendance records: Retained indefinitely as part of our financial and operational records
- Voting and election records: Retained indefinitely for club governance records; anonymous votes cannot be linked back to individuals
What rights you have over your data
Under UK GDPR and the Data Protection Act 2018, you have the right to:
- Access the personal data we hold about you
- Request correction of any inaccurate data
- Request deletion of your data (“right to be forgotten”)
- Restrict or object to our processing of your data
- Request portability of your data
To exercise these rights, email us at [email protected].
Where your data is sent
Your data is stored in the United Kingdom. Stripe may transfer data to servers located outside the UK/EU but safeguards your privacy through Standard Contractual Clauses. See https://stripe.com/privacy for details.
Contact information
For privacy-specific concerns, you can reach our team on the following email: [email protected]
Additional information
How we protect your data
We use HTTPS encryption, enforce strong passwords and multi-factor authentication for admin accounts, and keep WordPress core, themes and plugins up to date.
Data breach procedures
In the event of a data breach, we will promptly investigate, notify affected individuals and the Information Commissioner’s Office within 72 hours if required and take steps to mitigate any impact.
Third-party data sources
We do not receive personal data about users from any third parties.
Automated decision-making and profiling
We do not use automated decision-making or profiling.
Regulatory disclosures
We are subject to UK GDPR and the Data Protection Act 2018. We are not bound by additional industry-specific privacy regulations
