Legal
Privacy policy
Last updated: 18 July 2026
This Privacy Policy explains how Booster Box ("Booster Box", "we", "us", "our") collects, uses, shares, and protects personal data when you use our website and services (the "Service"). It is written for the UK GDPR and the Data Protection Act 2018.
Related documents: our Terms of Use and the cookie notice shown when you first visit.
1. Who is the controller?
Booster Box Ltd is the data controller for personal data processed through the Service. Company number 15448183. Registered office: Booster Box, Unit 3, Western Avenue, London, England.
For privacy requests, contact support@boosterbox.uk.
If you are unhappy with how we handle your data, you may complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to resolve your concern first.
2. Personal data we collect
Depending on how you use the Service, we may process:
- Account data — email address, password (hashed by our auth provider), display name, date of birth, country, avatar, email verification status, and role.
- Profile and preferences — referral code, whether you appear in community-style feeds, notification or cookie choices.
- Transaction data — pack purchases, payment status, amounts, offer types, order IDs, store-credit balance and ledger entries, sell-backs, and shipping orders.
- Vault and gameplay data — sealed packs, opened packs, vault cards, locked values, Rip Til You Hit runs, XP, levels, ranks, achievements, and referral attributions/earnings.
- Shipping data — recipient name, address, contact details needed for postage, and tracking events.
- Technical data — IP address, device/browser type, approximate location derived from IP, logs, security signals, and cookie identifiers needed to keep you signed in.
- Support data — messages you send us and internal staff notes related to your account (where applicable).
- Marketing / analytics — only if we enable optional tools and you consent where required (see Cookies).
We do not intentionally collect special-category data. Please do not submit sensitive information unless we specifically ask and explain why.
3. How we obtain data
- Directly from you (registration, checkout, vault, shipping).
- Automatically from your device when you use the Service (logs, cookies, security checks such as bot protection where enabled).
- From payment and infrastructure providers (for example Stripe payment status, Neon Auth session events).
- From catalog/pricing partners (VendorTools / CardTrader) for card metadata and market prices — typically not personal data about you, except where linked to your vault pulls.
4. Why we use personal data (purposes and lawful bases)
- Provide the Service (accounts, purchases, pack opens, vault, shipping, rewards) — contract (UK GDPR Art. 6(1)(b)).
- Take payment and prevent fraud — contract and legitimate interests / legal obligations for financial crime controls (Art. 6(1)(b), (c), (f)).
- Age gating (18+) — legitimate interests and compliance with our Terms (Art. 6(1)(f)); we may also rely on legal obligations where applicable.
- Customer support and service messages (receipts, shipping updates, security alerts) — contract and legitimate interests.
- Improve security, reliability, and features —legitimate interests (Art. 6(1)(f)).
- Referrals and promotions you choose to use — contract / legitimate interests; marketing emails only with consent where required (Art. 6(1)(a)).
- Legal claims, accounting, and regulatory requests —legal obligation and legitimate interests (Art. 6(1)(c), (f)).
Where we rely on legitimate interests, we balance those interests against your rights. You may object — see Your rights below.
5. Payments
Card payments are processed by Stripe. We do not store full card numbers on our servers. Stripe receives payment details you submit and provides us with payment status, identifiers, and limited billing metadata needed for orders and receipts. Stripe acts as an independent controller or processor according to its own terms and privacy notice.
6. Cookies and similar technologies
We use:
- Essential cookies — authentication/session, security, and load balancing so the Service works. These do not require consent under UK PECR exemptions for strictly necessary cookies.
- Preference cookies — for example remembering your cookie choice in local storage.
- Analytics or marketing cookies — only if enabled and, where required, after you accept non-essential cookies.
You can accept all cookies or essential-only via our banner, and you can clear cookies in your browser. Blocking essential cookies may prevent sign-in.
7. Who we share data with
We share personal data only as needed with:
- Neon — database hosting and authentication.
- Stripe — payments and related fraud tools.
- Hosting / CDN / email providers that host the Service or send transactional email (receipts, verification).
- Shipping carriers — name and address needed to deliver parcels.
- Catalog/pricing partners (for example VendorTools) — typically product identifiers, not your identity, except indirectly through your vault activity on our systems.
- Professional advisers and authorities when required by law or to protect rights, safety, and security.
- A buyer of our business, under appropriate confidentiality, if we undergo a merger or sale.
Staff and admin users may access account data to operate support, fulfilment, and abuse prevention, under access controls.
8. International transfers
Some providers may process data outside the UK. Where that happens, we use appropriate safeguards such as the UK International Data Transfer Agreement / Addendum, adequacy regulations, or equivalent measures offered by the provider.
9. Retention
We keep personal data only as long as needed for the purposes above:
- Account and vault history — for the life of the account and a reasonable period afterward for disputes, accounting, and fraud prevention.
- Payment and order records — typically up to 6 years (or longer if law requires) for tax and bookkeeping.
- Security logs — for shorter operational periods unless needed for an investigation.
- Marketing consents — until you withdraw consent or we delete inactive data.
When data is no longer required, we delete or irreversibly anonymise it where feasible.
10. Security
We use technical and organisational measures appropriate to the risk, including encrypted transport (HTTPS), access-controlled admin tools, hashed credentials via our auth provider, and least-privilege database access. No method of transmission or storage is completely secure; please use a strong unique password.
11. Your rights
Under UK GDPR you may have the right to:
- Access your personal data;
- Rectify inaccurate data;
- Erase data in certain circumstances;
- Restrict or object to certain processing;
- Data portability for data you provided to us;
- Withdraw consent where processing is consent-based;
- Complain to the ICO.
To exercise these rights, email support@boosterbox.uk from your account email where possible. We may need to verify your identity. Some rights are limited where we must keep data for legal claims, security, or contract performance.
12. Children
The Service is for users aged 18+. We do not knowingly collect personal data from children under 18. If you believe a minor has registered, contact us and we will delete the account where appropriate.
13. Automated decisions
Pack openings use configured odds and inventory rules. Fraud and payment checks by us or Stripe may be partly automated. These decisions are necessary to provide the Service and protect against abuse; they are not used to produce legal effects beyond accepting or declining a transaction or suspending a risky account. Contact us if you want human review of an automated suspension where feasible.
14. Changes to this policy
We may update this Privacy Policy to reflect product, legal, or provider changes. We will revise the "Last updated" date and, for material changes, provide additional notice where appropriate.
15. Contact
Privacy and support: support@boosterbox.uk
Account tools: Account