Privacy Policy.
Last updated: April 2026
This Privacy Policy explains how The Gallop collects, uses, discloses, and processes your personal data in accordance with the UK GDPR and UK Data Protection Act 2018. We are committed to protecting your privacy and ensuring you have a positive experience on our website and services.
1. What Data We Collect
We collect personal data in the following circumstances:
- When you subscribe: Email address, name, payment method (via Stripe — we never see your card details), subscription tier (Free, Paddock Pass, or Pro)
- When you log in: Session cookies for authentication; no password is stored by us
- When you contact us: Your email address and message content
- Automatically from your browser: IP address, browser type, device type, pages visited, and referral source
- If you opt into alerts: Phone number for WhatsApp notifications (Pro/Paddock Pass members only)
2. How We Use Your Data
We use your personal data only for the following purposes:
- Service delivery: Processing your subscription, sending racing selections via email, providing WhatsApp alerts if enabled, managing your account
- Communication: Responding to support requests, sending billing notifications, and service updates
- Website analytics: Understanding visitor behaviour via Cloudflare Web Analytics (see section 5)
- Legal compliance: Meeting UK GDPR, UK Data Protection Act, and payment regulations
We do not sell, rent, or share your data with third parties for marketing purposes.
3. Legal Basis for Processing
Under UK GDPR, we process your data on the following bases:
- Contractual necessity: Your email and subscription tier to deliver your racing tips
- Legitimate interest: Website analytics and fraud prevention to maintain a secure service
- Legal obligation: Payment processing records required by payment providers and tax authorities
- Consent: WhatsApp alerts and additional marketing communications (you can withdraw this at any time)
4. Third-Party Services
The following third parties have access to your data:
- Stripe (payment processor): We use Stripe to handle payments. Stripe processes your payment information but never shares your card details with us. Stripe Privacy Policy
- Cloudflare (hosting & analytics): Our website is hosted on Cloudflare Workers. Cloudflare Web Analytics is privacy-first and does not use cookies or track individual users. Cloudflare Privacy Policy
- Email delivery: We use a UK-based email service to send racing tips; email addresses are processed solely for delivery
- WhatsApp (alerts only): If you opt into WhatsApp alerts, your phone number is used only for message delivery
All processors are bound by data protection agreements and are only permitted to process data as instructed by us.
5. Cookies Policy
We use minimal cookies. Our website does not require cookie consent banners because:
- Session authentication: A single session cookie (essential, not tracked for analytics)
- Cloudflare Web Analytics: Privacy-first analytics that does not set cookies or identify individuals
- No third-party tracking: We do not use Google Analytics, Facebook Pixel, or similar trackers
You can disable cookies in your browser settings at any time without affecting core functionality of our service.
6. Data Retention
We retain personal data only for as long as necessary:
- Active subscribers: Email and account data retained while subscription is active
- Payment records: Retained for 7 years (required for tax compliance)
- Billing history: Available in your Stripe account; you can delete your account and associated data upon request
- Support communications: Retained for 12 months after final contact
- Inactive accounts: If your subscription lapses, we may delete your data after 24 months unless you re-subscribe
You can request data deletion at any time by emailing hello@thegallop.uk.
7. Your Rights Under UK GDPR
You have the following data protection rights:
- Right to access: Request a copy of your personal data we hold
- Right to rectification: Correct inaccurate or incomplete data
- Right to erasure: Request deletion of your data (right to be forgotten)
- Right to restrict processing: Prevent us from using your data for certain purposes
- Right to data portability: Request your data in a portable, machine-readable format
- Right to object: Object to processing for marketing or analytics purposes
- Right to withdraw consent: Opt out of WhatsApp alerts or marketing communications at any time
To exercise any of these rights, email hello@thegallop.uk with your request. We will respond within 30 days.
8. Children & Age Restrictions
The Gallop is for adults 18+ only. We do not knowingly collect data from anyone under 18. If we become aware that a user is under 18, we will immediately suspend their account and delete their data. Gambling is not permitted for minors in the UK, and we enforce this restriction.
9. International Data Transfers
Our servers and payment processors are based in the UK and EU. If any data is transferred outside the UK/EEA, it will only be to countries with adequate data protection laws or under appropriate safeguards (e.g., Standard Contractual Clauses via Stripe).
10. Security
We implement industry-standard security measures:
- HTTPS/TLS encryption for all data in transit
- Secure authentication via Stripe and OAuth providers
- No storage of sensitive payment data (Stripe handles this)
- Regular security reviews and updates
However, no online service is 100% secure. If you suspect a security breach, contact us immediately at hello@thegallop.uk.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email or by prominently displaying the new policy on our website. Your continued use of our service constitutes acceptance of the updated policy. The "Last updated" date at the top of this page shows when the policy was last revised.
12. Contact & Data Protection Officer
Data Protection & Privacy Inquiries
Email: hello@thegallop.uk
Website: thegallop.uk
For data subject access requests, deletion requests, or other privacy concerns, email us with your full name and account details. Requests will be processed within 30 days in accordance with UK GDPR.
13. Your Right to Complain
If you believe we have violated your data protection rights, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by phone: 0303 123 1113. However, we encourage you to contact us first so we can resolve any issues.
14. Gambling Responsibility
The Gallop is a horse racing tips service intended for adults 18+. Gambling can be addictive and should never be your primary income. If you need support, please contact:
- GambleAware.org — free, confidential support
- GAMSTOP — self-exclude from UK bookmakers
- National Gambling Helpline: 0808 8020 133