Privacy Policy
Last updated: 3 May 2026
1. Who We Are
SayPlay\u00AE is a trading name of SayPlay Ltd, a company registered in the United Kingdom. Our registered address is in London, UK. UK Trademark number: UK00004311084. This Privacy Policy explains how we collect, use, and protect your personal information when you use our website and services.
2. Information We Collect
We collect the following types of information:
- Account information: name, email address, password (encrypted), and phone number when you create an account.
- Order information: shipping address, billing address, payment details (processed securely by Stripe), and order history.
- Voice/video messages: the recordings you create using SayPlay NFC stickers. These are stored securely in the cloud and linked to your sticker codes.
- Usage data: pages visited, device type, browser information, and IP address for analytics and security purposes.
3. How We Use Your Information
We use your information to:
- Process and deliver your orders.
- Provide customer support and respond to enquiries.
- Store and deliver your voice/video messages to recipients.
- Send order confirmations, shipping updates, and marketing emails (only if you opt in).
- Improve our website and services through analytics.
- Prevent fraud and ensure security.
4. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
- Contract: processing necessary to fulfil your order.
- Consent: marketing emails and optional features.
- Legitimate interests: fraud prevention, security, and service improvement.
- Legal obligation: tax and accounting requirements.
5. Data Sharing
We do not sell your personal data. We only share information with:
- Stripe: for secure payment processing. Stripe is PCI-DSS compliant.
- Shipping partners: Royal Mail and courier services to deliver your orders.
- Supabase: our cloud database provider for secure data storage.
- Legal authorities: only when required by law or to protect our rights.
6. Your Rights
Under GDPR, you have the right to:
- Access your personal data.
- Correct inaccurate data.
- Request deletion of your data (right to be forgotten).
- Restrict or object to processing.
- Data portability — receive your data in a structured format.
- Withdraw consent at any time.
To exercise any of these rights, contact us at info@sayplay.co.uk.
7. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes outlined in this policy. Order data is retained for 7 years for tax and accounting purposes. Voice and video messages are retained until you delete them or close your account.
8. Security
We implement industry-standard security measures including SSL/TLS encryption, secure database storage, and regular security audits. Your payment information is never stored on our servers — it is processed directly by Stripe.
9. Cookies
We use essential cookies for site functionality and analytics cookies to understand how visitors use our site. You can manage cookie preferences through your browser settings. See our Terms of Service for more details.
10. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
Email: info@sayplay.co.uk
Website: sayplay.co.uk