Privacy Policy

Last updated: 26 July 2026

1. Who We Are

Legends Series ("we", "us", "our") is a premium sports hospitality company registered in England and Wales. Our registered address is available on request by emailing info@legends-series.com.

We are the data controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. What Data We Collect

We may collect and process the following personal data:

  • Identity data: first name, last name
  • Contact data: email address, telephone number, postal address
  • Booking data: event selections, guest numbers, dietary requirements, special requests
  • Payment data: processed securely by Stripe — we never see or store your full card number, CVV or expiry date
  • Technical data: IP address, browser type, device information, pages visited, referring URL
  • Communication data: records of correspondence if you contact us by email, phone or social media

3. How We Collect Your Data

  • Directly from you: when you fill in a booking or enquiry form, email us, call us, or message us on social media
  • Automatically: when you browse our website, via cookies and similar technologies (see our Cookie Policy)
  • From third parties: payment confirmation from Stripe; analytics data from Vercel

4. Why We Use Your Data (Legal Basis)

PurposeLegal basis
Process your booking and take paymentPerformance of a contract
Send booking confirmations and event updatesPerformance of a contract
Respond to your enquiriesLegitimate interest
Send marketing emails about future eventsConsent (you can opt out at any time)
Improve our website and servicesLegitimate interest
Comply with legal or regulatory obligationsLegal obligation

5. Who We Share Your Data With

We may share your personal data with:

  • Stripe: to process payments securely
  • Supabase: our database provider, which stores booking records
  • Vercel: our website hosting provider
  • Email service providers: to send booking confirmations and, where you have consented, marketing communications
  • Event venues and partners: where necessary to fulfil your booking (e.g. dietary requirements shared with catering)
  • Legal or regulatory authorities: where required by law

We do not sell your personal data to any third party. We do not share your data with any third party for their own marketing purposes.

6. International Transfers

Some of our service providers (Stripe, Supabase, Vercel) may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the ICO, or reliance on adequacy decisions.

7. How Long We Keep Your Data

  • Booking records: 6 years from the date of the event (in line with HMRC requirements)
  • Enquiry data: 2 years from last contact
  • Marketing consent records: until you withdraw consent
  • Website analytics: 26 months (aggregated and anonymised)

8. Your Rights

Under UK GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate or incomplete data
  • Erasure — ask us to delete your data (where we have no ongoing legal reason to retain it)
  • Restrict processing — ask us to limit how we use your data
  • Data portability — request your data in a structured, machine-readable format
  • Object — object to processing based on legitimate interests or for direct marketing
  • Withdraw consent — where processing is based on consent, withdraw it at any time

To exercise any of these rights, email us at info@legends-series.com. We will respond within one month.

9. Data Security

We take appropriate technical and organisational measures to protect your personal data, including:

  • All data transmitted via our website is encrypted using TLS/SSL
  • Payment processing is handled entirely by Stripe, a PCI DSS Level 1 certified provider — the highest level of payment security certification
  • Database access is protected by row-level security policies and restricted API keys
  • We use two-factor authentication on all administrative accounts

10. Cookies

Our website uses cookies and similar technologies. For full details, see our Cookie Policy.

11. Third-Party Links

Our website may contain links to third-party websites (e.g. Instagram, TikTok, Facebook). We are not responsible for the privacy practices of those sites. We encourage you to read their privacy policies before providing any personal data.

12. Children

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have collected data from a minor, please contact us immediately.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically.

14. Complaints

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

15. Contact Us

For any questions about this Privacy Policy or your personal data, contact us at: