Privacy Policy
Last updated: 24 April 2026
1. Who we are and how to contact us
This Privacy Policy explains how bikerhillshop.com (the “Site”) collects, uses, stores, and shares personal data when you browse our pages, interact with our age gate or cookie banner, send us email, or follow outbound links to third-party operators. The data controller responsible for decisions about personal data processed through the Site is the publishing entity identified in the site footer and reachable at info@bikerhillshop.com. For general correspondence you may use the same address; for formal data subject requests please include “Data Request” in the subject line and enough information for us to verify identity proportionately without excessive intrusion.
We are a UK-focused editorial and comparison publisher. We do not operate gambling accounts on your behalf. However, because we finance the Site partly through commercial relationships with operators, certain technical identifiers may be shared with analytics or affiliate networks strictly as described below. This Policy should be read together with our Cookie Policy, which lists storage technologies used in your browser.
2. Scope and children
This Policy applies to processing connected with the Site and our related infrastructure (for example CDN logs, security appliances, and email inboxes). It does not govern operators you visit after you leave the Site; each operator publishes its own privacy notice and is independently responsible for account data, KYC documents, and transactional records. The Site is not intended for anyone under 18. We do not knowingly collect children’s data. If you believe a minor has submitted personal data, contact us immediately so we can delete it where retention is not legally required for security investigations.
3. Categories of personal data we may process
Depending on how you use the Site, we may process: (a) technical and usage data such as IP address, approximate location derived at regional level, user agent string, device type, operating system, referring URL, pages viewed, timestamps, and click paths; (b) communications data including your email address, message body, attachments you choose to send, and metadata needed to deliver and archive correspondence; (c) preference flags stored locally in your browser after you interact with our cookie banner or age gate; (d) aggregated or de-identified statistics derived from the above; (e) limited security telemetry such as failed login attempts to administrative interfaces not exposed to the public; and (f) where applicable, records of consents and withdrawals of consent with timestamps.
4. Sources of data
Most data is collected directly from your device when you request pages or assets. We may also receive forwarded abuse reports from hosting providers, legal demands from competent authorities, or duplicate suppression signals from email infrastructure vendors. We do not buy marketing lists that profile named individuals for cold outreach.
5. Purposes and legal bases under UK GDPR
We process personal data for the following purposes, relying on the legal bases indicated: operating and securing the Site (legitimate interests in publishing a sustainable service and protecting users, balanced against your rights); remembering essential session choices such as age confirmation for the current browser session (strictly necessary for compliance with age-gating expectations in the UK gambling advertising context); recording cookie banner decisions in local storage where that is the only practical mechanism (consent for non-essential storage where required, otherwise legitimate interests in evidencing preferences); measuring aggregated traffic to improve navigation and detect fraud spikes (legitimate interests); responding to your emails (performance of a request you initiate or legitimate interests in customer support); complying with legal obligations including court orders and regulatory information requests; and establishing, exercising, or defending legal claims.
6. Automated decision-making and profiling
We do not make solely automated decisions that produce legal or similarly significant effects on individuals in the sense of Article 22 UK GDPR. Basic bot filtering or IP reputation checks may run at the edge for security; those measures classify traffic, not individuals, and do not determine creditworthiness or employment.
7. Cookies and similar technologies
We use cookies and local storage only to the extent described in the Cookie Policy. Essential technologies are needed to remember age confirmation during a session and to keep security tokens where administrative tools exist. Optional analytics or advertising tags, if ever introduced, will be gated behind renewed consent and documented in the Cookie Policy before activation.
8. Recipients and international transfers
Personal data may be disclosed to infrastructure providers (hosting, DNS, email delivery, DDoS mitigation) under written contracts containing UK GDPR-compliant terms, including Standard Contractual Clauses or the UK International Data Transfer Agreement where processors are located outside the United Kingdom. We do not sell personal data in the colloquial sense of exchanging lists for cash. Where affiliate networks pay us for tracked referrals, they may receive pseudonymous click identifiers rather than your full name unless you later become their customer under their own policies.
9. Retention
Server logs are retained for a rolling period sufficient to investigate abuse and satisfy tax or accounting needs, typically not longer than twelve months unless a shorter period is technically enforced sooner. Email correspondence may be retained longer where ongoing disputes, legal holds, or regulatory enquiries require preservation. Local storage entries you control through your browser persist until you clear site data.
10. Security
We implement administrative, technical, and organisational measures appropriate to the risk, including access controls on production systems, encrypted transport (HTTPS), patching cadences, and least-privilege credentials. No online transmission is perfectly secure; you should keep devices patched and avoid reusing passwords across operators.
11. Your rights
Subject to conditions in UK data protection law, you may have the right to access, rectify, erase, restrict, object to certain processing, and request portability of data you supplied in a structured machine-readable format. You may withdraw consent where processing was consent-based without affecting the lawfulness of prior processing. You may lodge a complaint with the Information Commissioner’s Office (ICO). We will respond to rights requests within one month unless complexity warrants an extension as permitted by law.
12. Marketing
We do not send bulk promotional email unless you have explicitly opted in to a distinct mailing list with clear unsubscribe mechanics. Browsing the Site alone will not add you to such a list.
13. Changes
We may revise this Policy to reflect new features, partners, or legal guidance. The updated version will be posted with a new “Last updated” date. Where material changes affect consent-based processing, we will seek fresh consent through the cookie banner or another prominent mechanism.