Last updated May 2018

Privacy/Cookies Notice

1. Scope

This website is operated by or on behalf of Tour Racing Limited a company registered in England and Wales with company number04078205 and registered address atGrant Way, Isleworth, Middlesex, TW7 5QD. Tour Racing Limited operates the professional cycling team known as "Team Sky". Any reference in this policy to "we", "us" or "our" is to Tour Racing Limited.

You are not required to give us any personal data in order to use our website. However, when you interact with us through our website (or otherwise) you may provide, or we may collect, certain information from which you are personally identifiable (which is referred to as personal data). For the purposes of the General Data Protection Regulation or "GDPR" (and all other laws relating to the use your personal data), we are the "data controller", meaning that we are responsible for deciding how your personal data is used and more importantly, for keeping your data safe and only using it for legitimate reasons.

We are committed to protecting your privacy and will take all steps necessary to comply with our legal obligations when using your personal data. This privacy/cookies notice explains how we fulfil this commitment, so please read this carefully.

2. Information we collect and how we use it

You may provide us with certain personal information when you interact with our website (including via our online store). This includes:

  • Identity - first name, surname, date of birth, gender, country of residence
  • Contact - email address, telephone numbers and address
  • Financial – payment card details, billing address, purchase information, payment history
  • Profile – your preferences for marketing, other website preferences and feedback

We may collect the following types of information from you when you use our website (using Cookies or other tracking technologies):

  • Usage – information about how you use our website, including time spent on page, click-throughs, download errors
  • Technical – IP address, browser type, hardware type, network and software identifiers, device information, operating system and system configuration.

Aggregated data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your usage data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy/cookies notice

The information below sets out how and why we use your personal data and our lawful basis for doing so. We may process your personal data for more than one lawful basis depending on the specific purpose for which we are using it. Importantly, we will only use your personal data when the law allows us to.

Reason why we use your data:

Provide you with news about Team Sky, special offers, and other products and services we offer.

What data we use: Identity, Contact, Profile

Legal ground for using the data: Performance of a contract with you.
Necessary for our legitimate interests (to develop our business, including our products and services and to increase the profile of Team Sky).
Consent

Register you as a customer of the Team Sky online store ("Online Store").

What data we use: Identity, Contact, Profile

Legal ground for using the data: Performance of a contract with you

Enable you to log-in to your Online Store account

What data we use: Identity, Contact

Legal ground for using the data: Performance of a contract with you

To process payments which you make through our Online Store

What data we use: Identity, Contact, Financial

Legal ground for using the data: Performance of a contract with you

Enable you to participate in Team Sky Competitions

What data we use: Identity, Contact, Financial

Legal ground for using the data: Performance of a contract with you

For internal administration and record keeping purposes

What data we use: All

Legal ground for using the data: Performance of a contract with you
Necessary to comply with a legal obligation
Necessary for our legitimate interests (for effective business administration and service provision)

Notify you of changes to our privacy/cookies notice, our Terms and Conditions or other changes to our services or products

What data we use: Identity, Contact

Legal ground for using the data: Performance of a contract with you.
Necessary to comply with a legal obligation

Answer your enquiries which may involve contacting you by post, e-mail or phone

What data we use: Identity, Contact

Legal ground for using the data: Performance of a contract with you.
Necessary for our legitimate interests (to ensure our customers are informed and satisfied with our services)

Contact you about third party products and services which we believe may be relevant to you or pass your details on to third parties to contact you directly about the same (in each case, only where you have indicated you would like to hear about these)

What data we use: Identity, Contact, Profile

Legal ground for using the data: Consent

Improve and personalise your experience of our website by delivering more relevant content and advertising whilst you browse

What data we use: Identity, Contact, Profile, Usage, Technical

Legal ground for using the data: Necessary for our legitimate interests (to develop our business, improve our website and overall user experience and inform our marketing strategy)

Administer our website, including website trouble shooting, testing and analysis and to enable you to participate in interactive features of our website

What data we use: All

Legal ground for using the data: Performance of a contract with you
Necessary for our legitimate interests (to ensure that our website is fully functional and operating in the most effective way for you)

Verify your identity and detect fraud and security issues

What data we use: All

Legal ground for using the data: Necessary for our legitimate interests (to prevent and detect fraudulent activity, security incidents and criminal activity)

Give you the opportunity to provide us with feedback through reviews and surveys

What data we use: Identity, Contact, Profile, Usage, Technical

Legal ground for using the data: Necessary for our legitimate interests (to develop our business, promote new products and services, obtain feedback from customers to improve our services)

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

3. Who we share your data with

You agree that we have the right to share your personal information with:

Any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries.

Selected third parties including:

  • Greensnow Online Fulfilment Limited who operate the Online Store on behalf of Tour Racing Limited and Shopify Inc. who host the Online Store and provide us with the online e-commerce platform that allows us to sell our products and services to you;
  • Mailchimp and Winners FDD Ltd as service providers who assist with the effective administration of any email communications outlined in this privacy/cookies notice;
  • Other business partners, suppliers and sub-contractors for the performance of any contract we enter into with you;
  • select companies outside our group for marketing purposes (where we have your express opt-in consent); and
  • analytics and search engine providers that assist us in the improvement and optimisation of our website.

We will disclose your personal information to third parties:

  • if we are required to do so by law or pursuant to a binding regulatory request (in such circumstances, such disclosure will at all times be solely to the extent required by law or the applicable regulatory request);
  • in the event that we sell or buy any business or assets, in which case we will disclose your personal data to the prospective seller or buyer of such business or assets;
  • in order to enforce or apply our Terms and Conditions and other agreements; or
  • to protect the rights, property or safety of our users or others which may include exchanging information with third party companies for the purpose of fraud prevention or credit risk reduction.

4. Profiling

We may use the information you provide to us to better understand your interests so we can try to predict what other products, services and information you might be most interested in. We call this profiling. This enables us to tailor our communications to make them more relevant and interesting for you.

5. Cookies

We use cookies to collect information about your online preferences. Cookies are small pieces of information sent by a web server to a web browser which allow the server to uniquely identify the browser on each page.Cookies and other similar technologies distinguish you from other users of our website and may: 1) be fundamental to the running of our website; 2) help the website to perform effectively; 3) allow us to deliver a more personalised browsing experience; 4) enable us to understand our customers' browsing behaviour; and/or 5) allow us to improve our website. We use the following categories of cookies on our website:

We use the following cookies/categories of cookies on our website:

  • Category 2: Performance Cookies -These cookies collect anonymous information on how people use our website. For example, we use Google Analytics cookies to help us to understand how users arrive at our site, browse or use our site and highlight areas where we can improve areas such as navigation. The data stored by these cookies never shows personal details from which your individual identity can be established.
  • _session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
  • _shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider's internal stats tracker to record the number of visits
  • _shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer.
  • cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
  • _secure_session_id, unique token, sessional
  • storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
  • PREF, persistent for a very short period, Set by Google and tracks who visits the store and from where

We may also use various third-party cookies to report usage statistics of the service, deliver advertisements on and through the service, and so on.

Importantly, we will not use any cookies or similar technologies (or permit any third parties to place these on our website) which are not strictly necessary for the operation of the website, without first getting your consent.

If you want to delete any cookies that are already on your computer, please refer to the help and support area on your internet browser for instructions on how to locate the file or directory that stores cookies.

Please note that by deleting our cookies or disabling future cookies you may not be able to access certain areas or features of our website.

To find out more about cookies please visit: www.allaboutcookies.org or see www.youronlinechoices.eu which contains further information about behavioural advertising and online privacy.

Further, some of our web pages may contain electronic images known as web beacons (sometimes known as clear gifs) that allow us to count users who have visited these pages. Web beacons collect only limited information which includes a cookie number, time and date of a page view, and a description of the page on which the web beacon resides. We may also carry web beacons placed by third party advertisers. These web beacons do not carry any personally identifiable information and are only used to track the effectiveness of a particular campaign.

6. Do we send any of your data outside the EEA?

The European Economic Area or "EEA" is deemed to have good standards when it comes to data privacy. As such, we consciously limit the occasions when we may need to transfer or handle your data outside of the EEA. Where we do, for example where our service providers (including Shopify inc.) are based outside of the EEA, we make sure that your data is still treated fairly and lawfully in all respects (including making sure we have a legal ground for sending your data outside the EEA and putting in place all necessary safeguards for such arrangement).

Where relevant, you will have the right to see a copy of any safeguards we put in place for international transfers of your data. Just get in touch with us if you would like to find out more.

7. How Long Do We Keep Your Data For?

We will retain your personal data only for as long as is strictly necessary for the purposes for which such data was originally collected (or for such longer period as may be required by law). In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

8. Links

Our website may contain links to other websites over which we have no control. We are not responsible for privacy policies or practices of other websites to which you choose to link from this site. Once you leave our website or are redirected to a third-party website or application, you are no longer governed by this privacy/cookies notice or our website's Terms and Conditions. We encourage users to review the privacy policies of those other websites so you can understand how they collect, use and share your information.

9. Security

We have implemented reasonable technical and organisational measures designed to secure your personal information from accidental loss and from unauthorised access, use, alteration or disclosure.We also make sure that third parties who need to handle your data when helping us to deliver our services are subject to suitable confidentiality and security standards.

Any data you provide to us via the Online Store is stored through Shopify's data storage, databases and the general Shopify application on a secure server behind a firewall.

If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.

Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards. However, the internet is an open system and we cannot guarantee that unauthorised third parties will never be able to defeat those measures or use your personal information for improper purposes and consequently such transmission is at your own risk.

10. Your rights

In certain situations, you are entitled to:

  • access a copy of your personal data;
  • correct or update your personal data, which you can do yourself in relation to the Online Store by logging into your account or by contacting us at the address in this privacy/cookies notice;
  • erase your personal data;
  • object to the processing of your personal data where we are relying on a legitimate interest (as set out in the above table);
  • restrict the processing of your personal data;
  • request the transfer of your personal data to a third party; or
  • where you have provided your consent to certain of our processing activities you may withdraw your consent at any time (but please note that we may continue to process such personal data if we have legitimate legal grounds for doing so).

If you want to exercise any of these rights, please contact Us. The good news is that you don't have to pay a fee to exercise your rights, unless your request is clearly unfounded, repetitive or excessive (in which case we can charge a reasonable fee). Alternatively, we may refuse to comply with your request in these circumstances. Where your request is legitimate, we will always respond within one month (unless there is a legal reason to take longer, such as where your request is particularly complex). We may also need you to confirm your identity before we proceed with your request if it is not clear to us who is making the request.

In addition to the above, you may get in touch with the ICO (Information Commissioner's Office) if you are concerned about the way in which we are handling your personal data. However, where possible, we would really appreciate you speaking with us first if you have any concerns.

11. Changes to our Privacy/Cookies notice

We will occasionally update this privacy policy and we encourage you to periodically review this privacy/cookies notice to be informed of how we use your information.

12. How to contact us

If you have any questions about this privacy/cookies notice, please contact us at website@teamsky.com or for questions in relation to our Online Store contact store@teamsky.com.