UK GDPR & Data Protection

Last updated: 25 August 2026.
This notice supplements our Privacy Policy and explains in more detail how personal data is collected, processed, stored, protected, retained and transferred when you use Sweepline. It is intended to address the UK GDPR, the Data Protection Act 2018, applicable EU GDPR requirements and the Privacy and Electronic Communications Regulations (PECR).

1. Who is responsible for your data?

Sweepline is the data controller for the personal data it determines how and why to process. Our current controller and contact details are set out in our Privacy Policy. Privacy and data-protection requests can be sent to sweepline41@gmail.com.

Some providers, including ecommerce, payment, delivery, communications, security and marketing providers, process personal data on our behalf as processors. In some circumstances a provider may act as an independent controller for its own services, in which case its own privacy notice also applies.

2. What personal data do we process?

Depending on your interaction with Sweepline, we may process:

  • identity and contact data, including name, email address, telephone number, postal and delivery address;
  • account data, login details, preferences and account activity;
  • order and competition-entry data, including entry references, entry route, timestamps, products, quantities, payment status and draw-related records;
  • payment and transaction data received from payment providers, such as transaction references, billing information, payment method type, status and fraud or risk signals;
  • eligibility and verification data where reasonably required, including age or identity evidence for a potential winner;
  • communications, complaints, support requests and correspondence;
  • marketing preferences, consent records, unsubscribe records and suppression lists;
  • technical data such as IP address, browser, device, operating system, session identifiers, referral source, page activity and security logs;
  • cookie, analytics and advertising-event data where the relevant technology is enabled and any legally required consent has been obtained.

3. Why do we process it?

Contract and steps before contract

We process data where necessary to provide the service you request, administer an order or competition entry, issue confirmations, maintain entry records, contact a potential winner, verify eligibility, arrange delivery, respond to support requests and administer refunds, cancellations or complaints.

Legal obligations

We may process and retain information where required for tax, accounting, consumer-protection, regulatory, fraud-prevention, law-enforcement or other legal obligations.

Legitimate interests

Where our interests are not overridden by your rights, we may process data to secure the website, prevent fraud and abuse, manage chargebacks, preserve an auditable competition record, investigate complaints, improve the service, defend legal claims and maintain the integrity of a draw.

Consent

Where consent is required, we rely on it for activities such as non-essential cookies, certain analytics or advertising technologies and electronic marketing. You can withdraw consent at any time. Withdrawal does not affect processing that was lawful before it was withdrawn.

4. Where is the data stored?

Shopify infrastructure. Sweepline uses Shopify to operate its ecommerce website. Shopify states that for new European merchants, store data, order data and customer personal data are stored at rest in Europe by default. Shopify also operates globally, so personal data may still be processed or transferred internationally where necessary to provide its services.

We do not represent that every copy of every item of personal data remains physically inside the United Kingdom. Data may be stored or processed in the UK, the EEA, Canada and other countries used by Shopify or other approved service providers, subject to the transfer safeguards described below.

Where data is exported from Shopify into another business system, for example an email platform, customer-support tool, fraud-prevention service, payment platform, accounting system or delivery provider, it may also be stored in that provider's secured systems in accordance with the role and instructions applicable to that provider.

5. How Shopify processes Sweepline customer data

Under Shopify's Data Processing Addendum, the merchant generally acts as controller and Shopify acts as processor for customer personal data processed to provide the relevant Shopify services, except for services where Shopify identifies a different role. Shopify processes data under documented instructions and contractual data-protection obligations.

Shopify states that international transfers may occur to Shopify entities and approved subprocessors. For UK data, Shopify describes safeguards including the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses and, where relevant, adequacy mechanisms such as the applicable Canadian adequacy framework.

6. Payments and card information

Payment transactions are handled by payment service providers. Sweepline does not need to receive or store the full card number, card security code or equivalent full payment credentials handled by those providers. We may receive and retain limited transaction information needed for order administration, reconciliation, fraud prevention, chargebacks and legal or accounting records.

The payment provider may process data as a processor or independent controller depending on the service and legal context. Its own privacy and security terms may therefore also apply.

7. Competition and draw records

To maintain a transparent and auditable competition process, we may retain records such as entry identifiers, customer identifiers, timestamps, entry route, payment or eligibility status, refunds or invalidations, draw identifiers, draw method, draw result, winner contact attempts, eligibility checks and delivery evidence.

Paid and valid free-entry records are administered under the applicable competition terms. Data collected for entry administration is not used to disadvantage a participant because they used a lawful free-entry route.

Winner identity or age-verification documents are restricted to what is reasonably necessary for eligibility, fraud prevention, legal compliance and prize delivery. Such documents are not retained indefinitely and are deleted or minimised when they are no longer required, subject to any overriding legal or dispute-related need.

8. Cookies, Meta Pixel, Conversions API and analytics

Essential cookies may operate where necessary for security, sessions, checkout and core site functions. Non-essential cookies and similar technologies are managed in accordance with PECR and applicable data-protection law.

If Sweepline enables Meta Pixel, Meta Conversions API, analytics platforms or similar advertising technologies, the related processing is treated as marketing and analytics processing. Where consent is legally required, those non-essential technologies should not be activated for that user before valid consent is obtained. Server-side technology such as a Conversions API does not remove the need to consider consent and transparency requirements.

You can change or withdraw non-essential cookie choices using the privacy or cookie controls made available on the site, where available.

9. Email and direct marketing

Transactional messages, such as order confirmations, entry confirmations, security notices and service communications, are sent where necessary to provide the service. We keep promotional marketing separate from service communications where required.

Electronic direct marketing to individuals is sent only where we have an appropriate legal basis under UK GDPR and PECR, such as valid consent or a lawful soft opt-in where all applicable conditions are met. Every marketing message will provide an appropriate way to unsubscribe. We retain suppression information where necessary so that an opt-out is respected.

10. How long is data kept?

We apply data minimisation and storage-limitation principles. Data is retained only for as long as reasonably necessary for the purpose for which it was collected, plus any period required for legal, tax, accounting, fraud-prevention, dispute or record-keeping purposes.

  • Orders and accounting records: financial and accounting records may need to be retained for up to six years from the end of the relevant company financial year where UK record-keeping requirements apply.
  • Competition and draw records: retained for a period appropriate to demonstrate the integrity of the competition, resolve disputes, handle chargebacks and defend legal claims; where those records overlap with transaction or accounting records they may be retained for the corresponding legal period.
  • Winner verification data: retained only for as long as necessary to verify eligibility, complete prize delivery and address any resulting legal or fraud issue, then deleted or minimised unless continued retention is legally required.
  • Marketing data: retained while marketing permission remains valid and relevant, subject to periodic review. Opt-out and suppression records may be retained longer so we can honour your request not to receive marketing.
  • Support and complaint records: retained for as long as reasonably needed to resolve the matter and protect the parties' legal interests.
  • Security and fraud data: retained for a proportionate period based on the security or fraud risk and any related claim or investigation.

When information is no longer required, we take reasonable steps to delete, anonymise or securely dispose of it. Copies may remain temporarily in protected backups until those backups are overwritten in accordance with the relevant provider's retention processes.

11. International transfers

Where personal data is transferred outside the UK or EEA to a country that does not benefit from an applicable adequacy decision, we require an appropriate transfer mechanism where the law requires one. Depending on the provider and transfer, this may include the UK International Data Transfer Addendum, approved Standard Contractual Clauses, binding corporate rules or another legally recognised safeguard.

We also consider the nature of the data, the destination, the provider and the security measures used when assessing international transfers.

12. Who receives personal data?

We disclose only the data reasonably required for the relevant purpose. Recipients may include Shopify, payment providers, couriers and fulfilment providers, email and communications providers, IT and hosting suppliers, fraud and security providers, identity-verification providers, analytics or advertising providers where lawful, accountants, insurers, legal advisers, regulators, courts, law-enforcement agencies and a buyer or successor in a legitimate business transaction.

Processors acting for Sweepline are expected to process personal data only for the agreed service, under appropriate contractual and security obligations.

13. Security measures

We apply reasonable technical and organisational measures appropriate to the size and nature of the service. These include access controls, account authentication, restricted administrative access, use of established service providers, secure transmission technologies where supported, payment-provider segregation of card data, data minimisation, backups and procedures for investigating suspected security incidents.

No online service can guarantee absolute security. Customers should use strong passwords, keep account credentials confidential and contact us promptly if they suspect unauthorised account activity.

14. Personal-data breaches

If we become aware of a personal-data breach, we assess the nature, scope and likely risk of the incident, take reasonable containment and remediation steps, document the incident and notify the relevant supervisory authority and affected individuals where the law requires notification.

15. Automated processing and fraud signals

Shopify, payment providers, security tools and advertising platforms may use automated signals to detect fraud, assess risk, protect accounts, measure conversions or deliver services. Sweepline does not intend to make a solely automated decision that produces legal or similarly significant effects on you without providing the information and safeguards required by applicable law.

16. Your rights

Subject to the conditions and exemptions in applicable law, you may have the right to access your personal data, correct inaccurate data, request erasure, request restriction, object to certain processing, receive eligible data in a portable format, withdraw consent and object at any time to direct marketing.

Requests can be sent to sweepline41@gmail.com. We may ask for reasonable information to verify your identity and locate the relevant records. We aim to respond within the timeframe required by applicable data-protection law.

17. Children and age-restricted competitions

Sweepline competitions are intended for adults aged 18 or over. We do not knowingly seek competition-entry data from children. If we learn that a person under the required age has submitted data for an age-restricted competition, we may restrict the account or entry and delete or retain only the information required to document and resolve the issue.

18. Complaints and supervisory authorities

If you have a concern about how your personal data is handled, contact us first at sweepline41@gmail.com. You may also have the right to complain to the UK Information Commissioner's Office (ICO) or another competent data-protection authority.

19. Changes to this notice

We may update this notice when our systems, service providers, business model or legal requirements change. The current version and update date will be published on this page. Material changes may also be communicated by another appropriate method where required.