1. Introduction
Stoke Park Limited is registered in England & Wales with company number 02732069. We are committed to protecting the privacy and security of your personal information. We take care to protect the privacy of our customers and users of our products and services that communicate with us.
We have developed this privacy policy to inform you of the data we collect, what we do with your information, what we do to keep it secure, and the rights and choices you have over your personal information.
This policy applies to personal data collected through our green fee booking campaign landing pages, newsletter sign-up forms, and associated digital marketing activity, as well as our main website.
2. The Information We Collect on Our Website
We only collect, process and store personally identifiable information in accordance with the General Data Protection Regulation (GDPR) and Data Protection Act 2018, used expressly for the purposes of responding to enquiries or providing marketing communications you have consented to receive.
If you contact us other than via our website and you give us permission to do so, we may keep a record of that correspondence, adding your information and enquiry details to our CRM system. From time to time, we may also use third-party services to collect your information, for example for events bookings.
The data we collect includes details of your journey through our website, as well as device-specific information such as IP address, mobile device, browser version, operating system, mobile network, device settings and geographical data. The type of information we will collect on you, and you voluntarily provide to us, includes:
- Your full name
- Your email address
- Your address
- The name of your company
- Your telephone number(s)
- Your IP address at the time of submission
- The time and date when you submitted information
- The corresponding consent statement that you agreed to
- Your GDPR consent timestamp (where you have opted in to marketing communications)
We may, in further dealings with you, extend this information to include your purchases, services used and subscriptions, records of conversations and agreements, and payment transactions, as relevant.
You are under no statutory or contractual obligation to provide us with your personal information. However, we require at least the information above in order to deal with you as a user in an efficient and effective manner. The legal basis for processing your data is based on your specific consent, which we will have requested at the point the information was initially provided.
3. How We Use Your Information
- To contact you following your enquiry, and reply to any questions, suggestions, issues or complaints;
- Make available our products and services to you;
- Process your orders;
- Take payment from you or give you a refund;
- Personalise your experience — for example, providing you with details of products or services that may be relevant based on previous enquiries;
- For statistical analysis and to gather feedback about our products, websites and services;
- To power our security measures so you can safely access our website;
- Help us understand more about you as a customer so we can serve you better;
- Contact you about products and services from us, where you have consented to receive such communications;
- Provide you with relevant online advertising and promotions; and
- Help answer your questions and resolve any issues you have.
4. Who We Might Share Your Information With
We may share your personal data with other organisations in the following circumstances:
- If the law or a public authority says we must share the personal data;
- If we need to share personal data in order to establish, exercise or defend our legal rights (this includes providing personal data to others for the purposes of preventing fraud and reducing credit risk); or
- From time to time, we employ the services of other parties for dealing with certain processes necessary for the operation of our website and digital marketing activities.
Third-Party Data Processors
We use the following third-party services to operate our website and marketing communications. Each acts as a data processor on our behalf and is bound by appropriate data processing agreements:
- GoHighLevel / LeadConnectorHQ — our CRM and email marketing platform. Personal data submitted via our website forms and newsletter sign-up popup is securely transmitted to GoHighLevel servers. GoHighLevel is certified under the EU-US Data Privacy Framework. See their privacy policy for details.
- GolfManager — our online tee time booking platform. When you book a round online, your booking details and payment information are handled by GolfManager. See their privacy policy for details.
- Google Tag Manager, Google Analytics & Google Ads — we use Google Tag Manager to deploy tracking tags on our website, including Google Analytics (anonymised website analytics to help us understand how visitors use our site) and Google Ads conversion tracking (to measure the effectiveness of our advertising campaigns). These services are provided by Google LLC. Data collected may be transferred to Google servers in the United States. Google is certified under the UK-US Data Bridge and participates in the EU-US Data Privacy Framework. See Google’s privacy policy for details. Tracking tags only activate where you have given your consent via our cookie consent banner.
- Meta Pixel (Facebook Pixel) — we use the Meta Pixel on our website to measure the effectiveness of our advertising on Facebook and Instagram, and to build audiences for retargeting campaigns. The pixel may collect information about your visit, including pages viewed and actions taken. This data is shared with Meta Platforms, Inc., which operates servers in the United States. Meta is certified under the UK-US Data Bridge and the EU-US Data Privacy Framework. See Meta’s privacy policy for details. The Meta Pixel only activates where you have given your consent via our cookie consent banner.
- Cloudflare — DNS management, content delivery and DDoS mitigation.
All personal information shared with third-party processors is subject to appropriate contractual protections and is only used for the purposes stated in this policy.
5. How We Keep You Updated on Our Business, Products and Services
Email Marketing
From time to time we may send you relevant offers and news about our business, products and services by email — but only if you have consented to receive these marketing communications.
When interacting with our website or landing pages, you may be asked if you would like to sign up to receive our email marketing communications. You will be asked explicitly to opt in to receiving these by ticking an unchecked consent box. We record the time and date of your consent, the exact wording you agreed to, and the page on which you opted in.
Newsletter Sign-Up Popup
Our golf landing pages include a newsletter sign-up popup. If you submit your email address via this popup, you will have been presented with a clear consent statement specifying what you are signing up to receive, and you will have actively ticked a checkbox to confirm your agreement. We store a record of this consent in our CRM system (GoHighLevel).
Unsubscribing
You can change your email marketing subscription at any time by unsubscribing via the link at the bottom of any of our marketing emails, or by contacting us via the details at the end of this policy.
6. Your Rights Over Your Information
Under GDPR and the Data Protection Act 2018, you have the following rights in relation to the personal data we hold about you:
- Right of Access — You may request a copy of the personal data we hold about you (a ‘Subject Access Request’). We will respond within 30 days of verifying your identity, free of charge.
- Right to Rectification — If any personal information we hold about you is inaccurate or out of date, you may ask us to correct it.
- Right to Erasure — You have the right to ask us to erase your personal information in certain circumstances (‘the right to be forgotten’).
- Right to Restrict Processing — Under Article 21 GDPR, you have the right to object to the processing of your personal data, and to stop or limit our use of it.
- Right to Object — You have the right to object to processing where we rely on legitimate interests.
- Right to Data Portability — Where processing is based on your consent and carried out by automated means, you have the right to ask us to transfer your information to you or to another organisation.
The Information Commissioner’s Office (ICO) regulates data protection and privacy matters in the UK. You can make a complaint to the ICO at any time at ico.org.uk. However, we hope you would consider raising any issue with us first.
7. How Long We Keep Your Information For
We retain a record of your personal information in order to provide you with a high quality and consistent service. We will always retain your personal information in accordance with GDPR and the Data Protection Act 2018 and never retain your information for longer than is necessary.
Unless otherwise required by law, your data will be stored for a period of 3 years after our last significant interaction or any identifiable action, at which point it will be permanently deleted or anonymised.
If you unsubscribe from our marketing communications, we will retain a record of your email address on our suppression list to ensure we do not contact you again. This record is kept for compliance purposes only.
8. Your Data and Social Networks
When using our website, you may be able to share information through social networks such as Facebook and Instagram. For example, when you ‘like’, ‘share’ or review our services. When doing this, your personal information may be visible to the providers of those social networks and/or their other users.
Please remember it is your responsibility to set appropriate privacy settings on your social network accounts. Stoke Park Limited is not responsible for the privacy practices of social media platforms.
9. Security
Data security is of great importance to Stoke Park Limited. To protect your data we have put in place suitable physical, electronic and managerial procedures to safeguard and secure your collected data. We conduct regular penetration testing and have an incident response plan to quickly handle potential breaches.
Physical & Managerial Procedures
- Limiting access to our buildings to those entitled to be there (by use of passes, key card access and related technologies)
- Implementing access controls to our information technology
- Using appropriate procedures and technical security measures (including strict encryption, anonymisation and archiving techniques) to safeguard your information across all our computer systems, networks and offices
- Never asking you to disclose your own passwords
- Advising you never to enter your account number or password into an email or after following a link from an email
Website Application & Hosting Security
- HTTPS — All communications between your browser and this website are securely encrypted.
- Secure Booking via GolfManager — Tee time bookings are handled by GolfManager, an independent platform. Payment and booking data is processed securely by GolfManager and is not stored on our web servers.
- Secure Update Process — This website’s code-base is administered and updated via a password and FTP-free process.
- Two-Factor Authentication — Where possible, the administration interface is secured behind two-factor authentication for all staff who have access to it.
- Web Application Maintenance — We regularly monitor the security of this website and consistently update the core platform and supporting extensions.
- PCI-DSS Compliant Server — Our website application is hosted on a PCI-DSS compliant server independently certified by Security Metrics.
- Cloudflare — Our website’s DNS is managed through Cloudflare, who provide our CDN, DDoS attack mitigation, and internet security services.
10. International Transfers
Your personal information may be transferred (sent to or accessed from) outside the UK. Specifically via our use of data processors, GoHighLevel (CRM and email marketing), Google (Analytics, Ads and Tag Manager) and Meta (Facebook Pixel). Any such transfer will be only:
- To a recipient located in a country which provides an adequate level of protection for your personal information (i.e. a country where the data protection standards are the same as or better than in the UK), for example a country in the European Union (EU), or European Economic Area (EEA); or
- To a recipient under a contractual agreement which satisfies UK legal requirements for the transfer of personal information, to ensure that appropriate safeguards are in place to protect your personal information in accordance with UK levels of data protection; or
- To a recipient under the UK-US Data Bridge to the EU-US Data Privacy Framework; or
- When your personal information has first been anonymised
The countries/areas to which we routinely transfer personal information are:
- USA: To recipients certified under the UK-US Data Bridge, which provides an adequate level of protection for your personal information
11. How to Contact Us
If you would like to exercise one of your rights as set out in this policy, or you have a question or a complaint about this policy or the way your personal information is processed, please contact us by one of the following means:
Thank you for taking the time to read our Privacy Policy.
Stoke Park Limited — This policy was last updated on 30th March 2026.