Privacy Policy
Last updated: 18 May 2026This Privacy Policy describes how DropShot ("we", "us", "our") collects, uses, and shares information about you when you use our website and services (the "Service"). DropShot is operated from the United Kingdom and complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Information We Collect
We collect the following categories of personal data:
- Account information: name, email address, password (hashed), and optional profile photo when you register.
- Player and competition data: match results, scores, fixtures, club memberships, and team affiliations you create or are added to.
- Communications: messages you send via our contact form or in response to system emails.
- Payment information: if you take out a paid subscription, payment is processed by PayPal. We do not store full card details — only a transaction reference and subscription status.
- Technical data: IP address, browser type, device type, pages visited, and approximate location, collected via cookies and server logs.
2. How We Use Your Information
We use your personal data to:
- Provide, maintain, and improve the Service;
- Authenticate you and keep your account secure;
- Manage competitions, fixtures, and results you participate in;
- Send transactional emails (e.g. result verifications, fixture reminders, password resets);
- Process subscription payments and manage entitlements;
- Display advertising (see "Advertising and Cookies" below);
- Comply with our legal obligations.
3. Lawful Basis for Processing
We process your data on the following lawful bases under UK GDPR Article 6: (a) contract, where processing is necessary to deliver the Service you've signed up for; (b) legitimate interests, for fraud prevention, service improvement, and limited advertising; (c) consent, where you have opted in (e.g. to non-essential cookies); and (d) legal obligation, where required by law.
4. Advertising and Cookies
DropShot uses Google AdSense to display advertising on certain pages. Google and its partners may use cookies and similar technologies to serve ads based on your prior visits to this and other websites. You can opt out of personalised advertising by visiting Google Ads Settings or www.aboutads.info. For more detail on the cookies we set, see our Cookie Policy.
5. Sharing Your Information
We share personal data only with:
- Service providers who help us operate the Service, including Microsoft Azure (hosting), Azure Communication Services (transactional email), Google AdSense (advertising), and PayPal (payments);
- Other users of the Service, where you have chosen to participate in a public competition, club, or team — your display name, results, and profile photo may be visible to those users. Your mobile number may additionally be visible to other competitors within a competition you have entered, but only after you give explicit consent at the point of entry, and only to administrators and players in the same division;
- Legal authorities where we are required by law to do so.
We do not sell your personal data.
5a. Mobile Numbers and Competition Entry
Mobile numbers are collected so that competitors can coordinate matches between themselves. They are handled as follows:
- Explicit per-competition consent. When you enter a competition, you are shown a notice with your masked number and must actively tick a consent checkbox before entry is confirmed. The exact wording you saw is recorded for audit.
- Limited audience. Your number is shown only to other active participants in the same division of that competition, and to administrators of the competition or its host club (the latter under a legitimate-interest basis for running the event).
- Instant withdrawal. A single "Leave competition" action withdraws you from the competition and immediately removes your number from other competitors' views.
- Under-13 protection. Mobile numbers belonging to players under 13 are never shared with other competitors, regardless of consent.
Our lawful basis for sharing mobile numbers with other competitors is your consent under UK GDPR Article 6(1)(a), which you may withdraw at any time via the Leave competition action.
6. International Transfers
Some of our service providers (notably Google) are based outside the United Kingdom. Where personal data is transferred outside the UK, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an applicable adequacy decision.
7. Data Retention
We keep account information for as long as your account is active. If you close your account, we delete or anonymise your personal data within 90 days, except where we are required to keep records for tax, fraud-prevention, or legal reasons. Anonymised match and competition results may be retained indefinitely.
8. Your Rights
Under UK GDPR you have the right to:
- Request access to the personal data we hold about you;
- Request correction of inaccurate data;
- Request erasure of your data;
- Restrict or object to processing;
- Data portability;
- Withdraw consent where we rely on it;
- Lodge a complaint with the Information Commissioner's Office (ico.org.uk).
To exercise any of these rights, please use the Contact form.
9. Children
DropShot is not directed at children under 13. If you become aware that a child under 13 has provided us with personal data without parental consent, please contact us and we will remove that data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect the most recent revision. Material changes will be notified via the Service or by email.
11. Contact
Questions about this Privacy Policy or your personal data should be sent via our Contact page.
DropShot