WRDRB™
The Mother Goose Group Ltd
Legal · Data Protection

Privacy Policy

This explains what personal data WRDRB collects, why, and what rights you have — whether you're a WRDRB customer, a staff or team member whose kit records live on the platform, or a visitor to our website.

Last updated: 27 August 2026 Version: 1.0 Applies to: wrdrb.org.uk, my.wrdrb.org.uk, grassrootswrdrb.lovable.app

01Who we are

WRDRB™ is a trading name of The Mother Goose Group Ltd, a company registered in England and Wales (Company No. 17250953), registered office 5 St. Nicholas Place, East Challow, Wantage, Oxfordshire, OX12 9SP, United Kingdom.

WRDRB is a kit and uniform management platform used by sports clubs, facilities teams and workwear-issuing organisations ("Customers") to track what's issued, to whom, and what's returned. We provide this through a paid platform (my.wrdrb.org.uk) and a free grassroots tier (grassrootswrdrb.lovable.app).

Throughout this policy, "we", "us" and "WRDRB" mean The Mother Goose Group Ltd.

02Two roles: controller & processor

Because WRDRB is a B2B platform, we sit in two different positions depending on whose data it is. This distinction matters for your rights, so it's worth being upfront about it.

We are the data controller for:

  • Your account details if you sign up as a Customer (name, work email, organisation, billing contact)
  • Billing and subscription records (via Stripe)
  • Website visitor and enquiry data (contact forms, demo bookings, live chat)
  • Marketing communications you've opted into

We are the data processor for:

  • The staff, player or member records your organisation enters into WRDRB — names, contact details, sizing, kit issued, department/group, requests

Here, your organisation is the data controller. They decide what's collected and why; we process it strictly on their instructions, under a Data Processing Agreement. If you're a staff or team member with a question about your own kit record, your first port of call is your club or organisation's admin — not WRDRB directly, though we'll always help route the request.

03What data we collect

WhoWhat we holdWhere it comes from
Customer account holders / adminsName, work email, password (hashed), organisation name, role, phone (optional)You, at signup
Billing contactsBilling name, email, address, payment method (held by Stripe — we never see full card numbers)You, via Stripe Checkout
Staff / team members on a Customer's rosterName, email, role, department/group, clothing sizes, kit issued/returned, requests, policy acknowledgementsEntered by the Customer's admin, or by the individual via the staff portal
Website visitorsPages viewed, general location (country/region), device/browser type, referrerCookies/analytics — see §11
Support & enquiriesName, email, message content, live chat transcriptsYou, via email or Tawk.to live chat
Platform activityLogin times, audit log of actions taken (who issued/returned what, when)Generated automatically by the platform

We don't collect special category data (health, religion, ethnicity etc.) by design. Clothing sizes and department/role are not special category data under UK GDPR.

04Children's data

Grassroots clubs may include players or dependants under 18. Where a Customer enters records for a minor, we process that data too — always as a processor, on the Customer's instructions, never as the controller.

We apply extra safeguards to this data specifically:

  • We never use children's data for marketing, profiling, or any purpose beyond kit/uniform administration
  • We collect the minimum needed — typically name, size, and department/squad; we do not ask Customers to enter a minor's date of birth, home address, or emergency contact details unless they choose to for their own administrative purposes
  • Minors' records carry the same access controls as any other record: only their club's authorised admins can see them, enforced at the database level
  • It is the Customer's responsibility, as controller, to establish the lawful basis for entering a minor's data (typically legitimate interests in running the club, or a parent/guardian's consent under the club's own membership terms) and to ensure a parent or guardian is aware their child's kit record is held digitally
  • Customers should not enter data about a child that isn't necessary for kit administration

If you're a parent or guardian and want to know what's held about your child, contact your club or organisation directly — they hold the record. If you believe WRDRB itself is processing a child's data unlawfully, contact us at hello@wrdrb.org.uk and we'll investigate directly with the Customer.

05Why we process it (lawful basis)

PurposeLawful basis
Providing the platform to Customer accountsContract (performing our contract with the Customer)
Processing staff/member kit records on a Customer's instructionWe act on the Customer's lawful basis, as their processor
Billing and subscription managementContract, and legal obligation (accounting/tax records)
Platform security, fraud prevention, audit loggingLegitimate interests (keeping the platform and Customer data secure)
Responding to support enquiriesLegitimate interests / contract
Marketing emails to prospects or account holdersConsent (opt-in), or legitimate interests for existing Customers with an opt-out on every email
Website analyticsConsent, via cookie banner — see §11

06Who we share it with

We use a small number of trusted sub-processors to run the platform. We don't sell personal data, and we don't share it with anyone for their own marketing purposes.

ProviderPurposeData involved
SupabaseDatabase, authentication, file storageAll platform data (EU/UK hosted)
StripePayment processingBilling contact, payment method (Stripe never shares full card numbers with us)
ResendTransactional email (welcome, billing, policy notifications)Name, email, notification content
NetlifyWebsite & application hostingSite delivery — no database access
Tawk.toLive chat supportName, email, chat transcript, if you use live chat
LovableHosting for the free grassroots tierGrassroots tier data only — never paid-platform data

Each provider is contractually bound to process data only for the purpose we specify and to appropriate security standards. We may also disclose data where required by law, to enforce our terms, or to protect the rights and safety of WRDRB, our Customers, or others.

A supplier connected to a Customer's account (e.g. a kit supplier) only ever sees order and catalogue data — never staff or member personal data.

07International transfers

Our core database (Supabase) is hosted in the EU/UK, and Resend's email infrastructure runs on EU/Ireland servers, so this data does not routinely leave the UK/EEA. Some sub-processors (for example, elements of Stripe's or Netlify's infrastructure) may process data outside the UK/EEA. Where that happens, we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent adequacy mechanism, as required under UK GDPR.

08How long we keep it

DataRetention
Customer account & billing recordsDuration of the contract, then 6 years (statutory limitation/accounting requirements)
Staff/member records (roster data)Duration of the Customer's subscription; deleted or exported within 30 days of account closure, per the Customer's instruction
Audit logs12 months
Support & chat transcripts24 months
Marketing/enquiry data24 months, or until you unsubscribe/object
Website analyticsAs set by the analytics tool in use — see §11

Where a Customer closes their account, we delete or irreversibly anonymise the staff/member data associated with it, except where we're required to retain it for legal or accounting purposes.

09Keeping it safe

  • Every organisation's data is isolated at the database level using row-level security — one Customer cannot access another's data, even in the event of an application-layer bug
  • Access to production data is limited to what's needed to operate the platform
  • Card payment data is handled entirely by Stripe; we never store full card numbers
  • Passwords are hashed, never stored in plain text
  • Data is encrypted in transit (HTTPS/TLS) and at rest

No system is 100% secure, and we maintain a breach response process to investigate and, where required, notify the ICO and affected parties without undue delay, and within 72 hours of becoming aware of a qualifying breach.

10Your rights

Under UK GDPR you have the right to:

  • Access the personal data we (or, for staff/member records, your organisation) hold about you
  • Rectify inaccurate data
  • Erase your data, subject to legal retention requirements
  • Restrict or object to certain processing
  • Port your data to another provider in a common format
  • Withdraw consent at any time, where processing is based on consent
  • Complain to the ICO (see §14)

If your data was entered by your club or employer as part of a roster (staff/member records), please contact them first — they control that data and can action most requests directly within the platform. If they're unable to help, or you're not sure who to contact, email us at hello@wrdrb.org.uk and we'll assist.

11Cookies & tracking

We use only the cookies necessary to keep you logged in and the platform functioning, plus (where you consent via our cookie banner) basic analytics to understand site usage. We do not use third-party advertising trackers. A full cookie list is available on request at hello@wrdrb.org.uk.

12Automated decisions

WRDRB does not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. Low-stock alerts, reorder thresholds and request routing are operational automations, not decisions about people.

13Changes to this policy

We'll update this page when our processing changes, and update the "Last updated" date at the top. For material changes, we'll notify Customer admins by email.

14Contact & complaints

Data protection contact: hello@wrdrb.org.uk

Postal address: The Mother Goose Group Ltd, 5 St. Nicholas Place, East Challow, Wantage, Oxfordshire, OX12 9SP, United Kingdom

If you're unhappy with how we've handled your data, you have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
ico.org.uk · 0303 123 1113