Skip to content
BBOG Bespoke Board & Oak Guild
  1. Home
  2. Privacy Policy
Privacy Policy

Privacy Policy

What personal data this website involves, why, for how long, and the rights you can exercise over it at any time.

Last updated: 12 August 2026

This Privacy Policy explains how Sport Casual Limited, trading as BBOG — Bespoke Board & Oak Guild, handles personal data in connection with the website published at bringbackourgirls.org (the "Site").

The short version. The Site has no database and no backend. The two forms on it validate what you type in your own browser and send nothing anywhere. If you decide to contact us, you do so by email, and from that point we hold only what you chose to write to us. We do not sell personal data, we do not run advertising trackers, and we set no cookies of our own.

1. Controller identity

The controller responsible for personal data processed in connection with the Site is:

Sport Casual Limited
7 Grove Park Road
Wrexham, Clwyd
LL12 7AA, United Kingdom

For all data protection matters, write to [email protected]. We have not appointed a statutory data protection officer, as we are not required to; privacy correspondence is handled directly by the operator of the business.

2. Scope of this policy

This policy covers the Site, the inquiry forms published on it, and email correspondence that arises from it. It does not cover any third-party website you may reach through a link from the Site; those sites have their own policies and we are not responsible for them.

"Personal data" means information relating to an identified or identifiable natural person. Where this policy refers to the GDPR it means the UK GDPR and the Data Protection Act 2018 and, where applicable, Regulation (EU) 2016/679; where it refers to the CCPA it means the California Consumer Privacy Act as amended by the California Privacy Rights Act.

3. Data collected through our forms

The Site publishes two inquiry forms:

  • a callback request form in the hero section of the home page, which asks for your name, your email address, a preferred contact time, a short message and your consent;
  • a question form in the contact section and on the contact page, which asks for your name, your email address, a subject, a message and your consent.

It is important to understand what these forms do. They are front-end forms only. When you submit one, a script running in your own browser checks that the required fields are filled in, that the email address has a valid form and that the consent box is ticked. It then shows you a confirmation panel. No data is transmitted to us, to any server, or to any third party at that point. The confirmation panel says so plainly and offers you a link that opens your own email application with what you typed, ready for you to review and send yourself.

In other words: unless you take the separate step of sending an email, we never receive what you typed into a form, and nothing is stored beyond the page in front of you. Refreshing or closing the page discards it.

Data we receive when you email us

Once you do email us — whether through the link the form generates, through an address published on the Site, or from your own mail client — we receive and process the content of that email. Typically this is:

  • your name, as you give it;
  • your email address and any signature block it contains;
  • the subject line and body of your message, including anything you choose to tell us about your project, your room, your measurements or your timing;
  • any attachment you choose to send, such as photographs or plans of a room;
  • the correspondence history of the thread and the technical headers of the message.

Please send us only what is relevant to your enquiry. We do not ask for and do not want special category data (such as health, religious or political information), government identifiers, or financial account details, and you should not include them.

4. Technical data

The Site is a set of static files. It runs no analytics product, no advertising pixel, no session recording, no heat mapping and no social media tracker, and it embeds no third-party iframes.

As with any website, the hosting infrastructure that serves the files may automatically record technical information in server logs for security and reliability purposes. Where that occurs it typically includes the requesting IP address, the date and time of the request, the file requested, the HTTP status code, the referring URL where one is sent, and the browser user agent string. We use such logs, when we consult them at all, only to keep the Site available and to investigate abuse; we do not attempt to identify individual visitors from them and we do not combine them with any other data set.

The Site also loads the Manrope typeface from Google Fonts. That request necessarily discloses your IP address and user agent to Google, which acts as an independent controller for that request. See section 8 and section 9.

5. Purposes and legal bases

Where the GDPR applies to our processing, we rely on the following purposes and legal bases.

PurposeData involvedLegal basis
Answering an enquiry you send us by email Name, email address, message content, attachments Consent (Art. 6(1)(a)) — given by ticking the consent box or by choosing to write to us — and, where an enquiry concerns a possible commission, steps taken at your request prior to entering a contract (Art. 6(1)(b))
Discussing, specifying and delivering an agreed commission Name, email address, room details, measurements, delivery access information Performance of a contract (Art. 6(1)(b))
Aftercare, warranty and re-felt correspondence Correspondence history, commission record Performance of a contract (Art. 6(1)(b)) and our legitimate interest in supporting our own work (Art. 6(1)(f))
Keeping the Site available and secure Server log data Legitimate interest in the security and integrity of our systems (Art. 6(1)(f))
Keeping records of enquiries and agreements Correspondence, commission records Legitimate interest in defending legal claims (Art. 6(1)(f)) and compliance with legal obligations (Art. 6(1)(c))

Where we rely on legitimate interests, we have considered the effect of the processing on you and are satisfied that it does not override your interests or fundamental rights. You may object to that processing at any time — see section 11.

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects, and we do not send marketing email to people who have simply made an enquiry.

6. We do not sell personal data

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We have never done so, including in the twelve months preceding the date at the top of this page. We do not trade, rent, licence or otherwise make personal data available to data brokers, advertisers, list builders or analytics networks.

Personal data is disclosed only in the narrow circumstances described in section 8, and only to the extent needed to run the Site or to answer you.

7. Retention periods

We keep personal data only for as long as there is a reason to keep it.

  • Form input: not retained at all. It exists only in your browser's memory until the page is closed or reset.
  • General enquiries that do not become a commission: kept for up to 24 months from the last message in the thread, so that we can recognise a returning enquirer, then deleted.
  • Correspondence relating to an agreed commission: kept for the duration of the work and then for up to 7 years from completion, which reflects the lifetime nature of our structural warranty and the applicable limitation periods for contractual claims.
  • Commission records used for the re-felt and aftercare programme (client name, contact address, the specification of the table built): kept while the programme relationship subsists, and deleted on request.
  • Server logs: retained by the hosting provider under its own retention schedule, typically for a short period measured in weeks.

At the end of a retention period, data is deleted or irreversibly anonymised. Where deletion is not immediately possible — for example because a copy sits in a backup — the data is isolated from further processing until deletion is possible.

8. Processors and hosting

We keep the number of third parties involved deliberately small. The following categories may process personal data on our behalf or receive it in the course of ordinary operation:

  • Hosting provider. The static files that make up the Site are served by a hosting provider, which necessarily processes the connection data described in section 4.
  • Email provider. Our mailboxes at the bringbackourgirls.org domain are operated through an email service provider, which processes the content of correspondence in order to deliver and store it.
  • Google Fonts. The Manrope typeface is requested from Google's font service when a page loads. Google receives the request data described in section 4 and acts as an independent controller in respect of it, under its own privacy policy. No cookie is set by that request.
  • Professional advisers. Lawyers, accountants or insurers may see relevant correspondence where necessary to advise us or defend a claim.

We may also disclose personal data where we are required to do so by law, by a court order or by a competent authority, or where disclosure is necessary to establish, exercise or defend legal claims. We do not disclose personal data to any authority voluntarily where a lawful basis for the request has not been shown.

Where a third party acts as a processor for us, it is engaged under a written agreement that restricts it to processing on our documented instructions and requires appropriate security measures.

9. International transfers

We are established in the United Kingdom, and our correspondence is handled from the United Kingdom. If you write to us from the European Economic Area, your personal data is therefore transferred to and processed in the United Kingdom, which the European Commission has recognised as providing an adequate level of protection, so no additional safeguard is required for that transfer.

Some of the infrastructure that serves this Site and carries our mail may process data outside the United Kingdom and the EEA. Where such a transfer involves data protected by the UK GDPR or the GDPR, it is made on the basis of an appropriate safeguard under Chapter V — in practice the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses concluded with the relevant provider, together with any supplementary technical and organisational measures required in the light of the transfer. Where a provider is covered by an applicable adequacy decision, we may rely on that instead.

You may request further information about the safeguards applied to a specific transfer, and a copy of the relevant clauses, by writing to [email protected].

10. Security measures

We apply technical and organisational measures appropriate to the modest amount of personal data we hold:

  • the Site is served over HTTPS, so traffic between your browser and the host is encrypted in transit;
  • the Site holds no database, no user accounts and no login, which removes the most common categories of web attack surface altogether;
  • mailboxes are protected by strong, unique credentials and multi-factor authentication;
  • access to correspondence is limited to the people who need it to answer you;
  • devices used to access correspondence are encrypted at rest and kept up to date;
  • data is deleted on the schedule in section 7 rather than kept indefinitely.

No method of transmission or storage is completely secure, and email in particular is not an inherently confidential medium. Please do not send us information you would consider sensitive. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where the risk is high, you directly, within the timescales required by applicable law.

11. Your rights under the GDPR

If the GDPR applies to our processing of your personal data, you have the following rights:

  • Access. To be told whether we process your personal data and, if so, to receive a copy of it together with information about the processing.
  • Rectification. To have inaccurate personal data corrected and incomplete data completed.
  • Erasure. To have your personal data deleted where one of the grounds in Article 17 applies — for example where it is no longer necessary for the purpose it was collected for, or where you withdraw the consent it was based on.
  • Restriction. To have processing restricted while a dispute about accuracy or legitimate interests is resolved.
  • Portability. To receive personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Objection. To object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests. If you object we will stop unless we can demonstrate compelling legitimate grounds that override your interests.
  • Withdrawal of consent. To withdraw consent at any time where processing is based on it. Withdrawal does not affect the lawfulness of processing carried out before it.
  • Complaint. To lodge a complaint with a supervisory authority. As we are established in the United Kingdom, that is the Information Commissioner's Office (ICO), ico.org.uk; if you are in the EEA you may instead complain to the authority of the Member State of your habitual residence, place of work or the place of the alleged infringement.

To exercise any of these rights, write to [email protected]. We respond within one month; that period may be extended by two further months for complex requests, in which case we will tell you within the first month. We ask nothing in return for handling a request, unless it is manifestly unfounded or excessive. We may ask you for information to confirm your identity before acting, in order to avoid disclosing your data to somebody else.

12. Your rights under the CCPA/CPRA

If you are a California resident, you have the following rights in relation to personal information we have collected about you:

  • Right to know the categories and specific pieces of personal information collected, the categories of sources, the business purposes for collection, and the categories of third parties to whom it is disclosed.
  • Right to delete personal information we have collected from you, subject to the statutory exceptions, such as completing a transaction you requested or complying with a legal obligation.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of personal information. As set out in section 6, we do not sell or share personal information, so there is nothing to opt out of; we publish no "Do Not Sell or Share My Personal Information" link because no such activity takes place.
  • Right to limit the use and disclosure of sensitive personal information. We do not collect sensitive personal information as defined by the CPRA.
  • Right to non-discrimination for exercising any of these rights. We do not treat anyone differently for making a request.

The categories of personal information we collect are limited to identifiers (name, email address) and electronic network activity information (server log data), together with whatever you volunteer in the body of an email. We do not collect biometric, geolocation, employment, education or financial account information through the Site.

To make a request, write to [email protected] with "California privacy request" in the subject line. You may use an authorised agent, in which case we will ask for written proof of authorisation. We confirm receipt within 10 business days and respond substantively within 45 days, extendable once by a further 45 days where reasonably necessary.

13. Children under 16

The Site is intended for adults. It is not directed at children, it does not offer content designed to appeal to children, and we do not knowingly collect personal data from anyone under 16 years of age.

Our services are offered to people aged 18 or over, as set out in the Terms and Conditions. If you are a parent or guardian and you believe that a child has sent us personal data, write to [email protected] and we will delete it promptly.

14. Do Not Track

Some browsers can send a "Do Not Track" (DNT) or Global Privacy Control signal. There is still no single accepted standard for how a website should respond to DNT.

Because the Site performs no tracking of any kind — no analytics, no advertising identifiers, no cross-site profiling and no third-party cookies — there is nothing for such a signal to switch off. Your browsing of this Site is not tracked whether or not you send one. We honour the Global Privacy Control by default, in the sense that the behaviour it asks us to stop is behaviour we never perform.

15. Cookies and local storage

The Site sets no cookies of its own, and it displays no cookie consent banner because there is nothing to consent to. It does write a single key to your browser's local storage — remembering which product filter you last selected — which is a functional preference set by your own action and not a tracking technology.

That key, what it holds, how long it lasts and how to remove it are described in full in our Cookie Policy.

16. Changes to this policy

We may update this policy to reflect changes in our practices, our infrastructure or the law. The current version is always the one published on this page, and the "Last updated" date at the top of the page shows when it was last revised.

Where a change is material — for example if we were ever to introduce analytics, or to begin transmitting form data to a server — we will make that clear on the Site before the change takes effect, and where the change requires your consent we will ask for it rather than assume it. We recommend reviewing this page when you return to the Site after a long gap.

17. How to contact us

For any question about this policy, about the data we hold, or to exercise any right described above:

By post: Sport Casual Limited, 7 Grove Park Road, Wrexham, Clwyd, LL12 7AA, United Kingdom. Email reaches us considerably faster and is the channel we ask you to use wherever possible.