Privacy Policy
Last updated: 9 April 2026
Introduction and scope
This Privacy Policy explains how step1minimalist.com (“we”, “us”, “our”) collects, uses, stores, and shares personal data when you visit or interact with our website (the “Site”). We respect your privacy and process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and related regulations, where they apply. This policy should be read together with our Cookie Policy and Terms of Service. If you do not agree with this policy, please discontinue use of the Site.
Data controller
For the purposes of applicable data protection law, step1minimalist.com acts as the controller of personal data processed through the Site, meaning we determine the purposes and means of processing for the activities described here. Where we appoint processors (such as hosting or analytics vendors), they process data only on our documented instructions and under contractual safeguards required by law.
Categories of personal data we may process
We may process the following categories of data, depending on how you use the Site: (1) Technical and usage data, including IP address, browser type and version, operating system, device type, screen resolution, referring URL, pages viewed, approximate geographic region derived from IP at a coarse level, timestamps, and diagnostic logs needed to maintain security and performance. (2) Communication data, including your email address and the contents of messages you send to us, if you contact support or make enquiries. (3) Preference data where you choose settings that we store, such as cookie consent choices recorded through our banner. We do not intentionally collect special categories of personal data (such as health data) through this Site.
Sources of data
We obtain personal data directly from you when you email us or submit information through available contact channels, and indirectly through automated technologies when you load pages, interact with menus, or click outbound links. Third-party operators you visit after leaving the Site may collect their own data under separate notices; we do not control those relationships.
Purposes and legal bases for processing
We process personal data for the following purposes and on the following legal bases under UK GDPR: (a) To deliver, secure, and maintain the Site, including troubleshooting, abuse prevention, and network security—based on our legitimate interests in operating a safe online service, and where necessary to perform steps at your request prior to entering a contract where applicable. (b) To remember essential preferences and cookie choices—based on consent for non-essential cookies, and legitimate interests or legal obligation for strictly necessary cookies as described in our Cookie Policy. (c) To measure aggregate traffic and improve content layout using analytics where enabled—based on consent where required, or legitimate interests where we use privacy-enhancing settings and provide opt-out mechanisms. (d) To respond to correspondence and manage user enquiries—based on legitimate interests and, where relevant, pre-contractual steps. (e) To comply with legal obligations, respond to lawful requests from public authorities, and establish, exercise, or defend legal claims—based on legal obligation or legitimate interests as applicable.
Cookies and similar technologies
We use cookies, local storage, and similar technologies as described in our Cookie Policy. You can manage non-essential cookies through our cookie banner and through your browser settings. Strictly necessary cookies may be required for core Site functions such as load balancing, security, and storing your cookie choice itself.
Sharing and recipients
We may share personal data with trusted service providers who assist us with hosting, content delivery, security monitoring, analytics, email delivery, and IT support. These providers may only process data under our instructions and must implement appropriate technical and organisational measures. We may disclose data if required by law, court order, or regulatory authority, or to protect the rights, property, or safety of our users, the public, or our business. We do not sell your personal data in the conventional sense of exchanging data for money. If we undertake a business transfer such as a merger or asset sale, personal data may transfer to the successor under safeguards required by law. When you click outbound links to gambling operators or affiliate networks, those parties may process your data as independent controllers; you should read their privacy notices carefully.
International transfers
Our infrastructure or subprocessors may be located in the United Kingdom, the European Economic Area, or other countries. Where personal data is transferred outside the UK and EEA, we ensure appropriate safeguards such as adequacy decisions, standard contractual clauses approved by regulators, or other lawful transfer mechanisms, together with supplementary measures where required by guidance.
Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law. Server logs and security records may be retained for limited periods consistent with incident response and legal obligations. Email correspondence may be retained for a reasonable period to manage ongoing or follow-up queries. Cookie retention periods are described in the Cookie Policy.
Security
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. No method of transmission over the Internet is completely secure; we encourage you to use updated browsers and devices and to avoid sharing sensitive credentials in unencrypted channels.
Automated decision-making and profiling
We do not use automated decision-making that produces legal or similarly significant effects solely based on automated processing. We may use basic analytics to understand aggregate trends; this does not involve individual profiling for automated decisions about you in the sense described in Article 22 UK GDPR.
Children
The Site is not directed at individuals under 18, and we do not knowingly collect personal data from children. If you believe we have collected data from a minor, please contact us so we can delete it promptly where required by law.
Your rights
Subject to applicable law, you may have the following rights: the right of access; the right to rectification; the right to erasure; the right to restrict processing; the right to object to processing based on legitimate interests; the right to data portability for data you provided where processing is based on consent or contract and carried out by automated means; and the right to withdraw consent at any time where processing is consent-based, without affecting the lawfulness of processing before withdrawal. You may also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) or another supervisory authority in your country of residence. To exercise your rights, contact us using the details below. We may need to verify your identity before responding.
Changes to this policy
We may update this Privacy Policy to reflect changes in law, technology, or our practices. Material changes will be indicated by updating the “Last updated” date. Where required, we will provide additional notice. Continued use of the Site after changes constitutes acceptance of the updated policy where permitted by law.
Contact
Privacy requests: info@step1minimalist.com