1. Introduction
Gridsoft Solutions Ltd, trading as Trail Quest ("we", "us", or "our"), is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the Trail Quest website and digital trail platform (the "Service"), and sets out your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller
Gridsoft Solutions Ltd
Company Registration Number: 16453645
Registered in England and Wales
Trading as: Trail Quest
Email: [email protected]
3. What Personal Data We Collect
We collect and process the following categories of personal data:
| Category | Examples |
|---|---|
| Identity data | Full name, username |
| Contact data | Email address, phone number |
| Location data | Town or city provided at registration; approximate GPS location during trail play (used only for navigation, not stored persistently) |
| Account data | Password (stored as a one-way cryptographic hash), account creation date, role |
| Purchase data | Trail purchases, payment reference identifiers (Stripe customer ID, payment intent ID), purchase date and amount |
| Usage data | Trails played, clues answered, hints used, completion times, leaderboard entries |
| Communication data | Support messages submitted through the Service |
| Marketing preferences | Whether you have opted in to receive marketing communications |
| Technical data | IP address, browser type and version, device type, session identifiers, cookies |
We do not collect or store full payment card numbers, CVV codes, or card expiry dates. Payment card data is handled exclusively by Stripe, Inc.
4. How We Collect Your Personal Data
Directly from you when you register an account, make a purchase, complete a trail, submit a support request, or sign up to receive notifications about new trails.
Automatically when you use the Service, through cookies and similar tracking technologies (see Section 10).
From third parties, including Stripe (payment confirmation and customer identifiers) and Google Maps Platform (location and mapping data used to deliver trail content).
5. How We Use Your Personal Data
We use your personal data for the following purposes and on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Creating and managing your account | Performance of a contract (Article 6(1)(b) UK GDPR) |
| Processing trail purchases and delivering digital content | Performance of a contract (Article 6(1)(b) UK GDPR) |
| Verifying identity and preventing fraud | Legitimate interests (Article 6(1)(f) UK GDPR) |
| Providing customer support | Performance of a contract / Legitimate interests |
| Sending transactional emails (purchase confirmations, password resets) | Performance of a contract (Article 6(1)(b) UK GDPR) |
| Sending marketing emails about new trails, offers, and updates | Consent (Article 6(1)(a) UK GDPR) — only where you have opted in |
| Improving the Service and analysing usage patterns | Legitimate interests (Article 6(1)(f) UK GDPR) |
| Complying with legal obligations | Legal obligation (Article 6(1)(c) UK GDPR) |
6. Marketing Communications
We will only send you marketing communications where you have given your explicit consent at the time of registration or subsequently through your account settings. Each marketing email we send will include a clear and easy mechanism to unsubscribe. You may withdraw your marketing consent at any time by updating your preferences in your account settings or by contacting us at [email protected]. Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal.
8. Data Retention
We retain your personal data for as long as is necessary to fulfil the purposes for which it was collected.
| Data type | Retention period |
|---|---|
| Account data | Duration of account, plus 2 years after deletion |
| Purchase records | 7 years (financial record-keeping obligations) |
| Support communications | 3 years from date of communication |
| Leaderboard and completion data | Duration of account |
| Marketing consent records | Duration of consent, plus 3 years |
| Technical/log data | Up to 12 months |
10. Your Rights Under UK GDPR
You have the following rights in relation to your personal data:
| Right | Description |
|---|---|
| Right of access | Request a copy of the personal data we hold about you. |
| Right to rectification | Ask us to correct inaccurate or incomplete personal data. |
| Right to erasure | Ask us to delete your personal data in certain circumstances. |
| Right to restriction | Ask us to restrict processing of your personal data in certain circumstances. |
| Right to data portability | Ask us to provide your personal data in a structured, machine-readable format. |
| Right to object | Object to processing based on legitimate interests or for direct marketing purposes. |
| Right to withdraw consent | Where processing is based on consent, withdraw consent at any time. |
To exercise any of these rights, please contact us at [email protected]. We will respond within one month. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by telephone on 0303 123 1113.