Privacy notice
Last updated 25 August 2026. This notice covers the TradeChamp directory and competition website.
TradeChamp is an independent UK public directory of local trades with a voting/competition layer. This notice explains what personal data we hold, why, how long we keep it, and your rights. We keep data to a minimum and we do not sell it or use third-party advertising or tracking pixels.
On this page
Who we are
The data controller for this website is [TradeChamp operator details to be confirmed before launch]. Once confirmed this will show the operator’s legal name, postal address and, if registered, ICO registration number.
What data we hold and why
Business listing information
Listings are built from publicly available information about UK trade businesses — trading name, town/area, website, published phone and email, and a service-area description. All listings start unclaimed; a listing appearing on TradeChamp does not mean the business joined, endorsed or asked to take part. We record internal notes on where each detail was verified (provenance), which are not shown publicly.
Business claims
If someone claims a listing, we store the contact name, email, optional phone, stated role and any message, plus the verification state. Verification codes and session tokens are stored only as salted hashes, never in plain text. A verification code is sent to the business’s already-published contact address to confirm control of the listing.
Corrections, removals and contact requests
If you use the “report incorrect information / request removal” route on a listing, or the contact form, we store your name, email, optional phone and your message so we can handle the request. Contact requests also store a one-way hash of your IP address (see cookies/analytics below) for abuse prevention — never the plain IP.
Votes and anti-abuse
When you vote in a competition we do not store your name, email or IP address. We store: a one-way HMAC of a random browser identifier (from the tc_vid cookie), a one-way HMAC of your IP address (a “network signal”, never the plain IP), a truncated browser user-agent string, and the vote status. This lets us enforce one vote per person per campaign and limit duplicate/automated voting.
To resist people clearing or forging the cookie to vote again, we keep a small ledger of anti-abuse events (the same one-way hashes plus an event type and time). Votes may be automatically flagged or rejected by deterministic rules; any such decision isreversible by a human operator and has no effect on you beyond whether a vote counts. We do not build advertising or behavioural profiles.
First-party analytics
We record basic, first-party usage events (for example a profile or campaign view, a vote started/completed, a share action) with a one-way hash of the browser identifier for coarse de-duplication. There are no third-party analytics or advertising trackers (no Google Analytics, Meta or TikTok pixels).
Operator and audit records
We keep an internal audit log of meaningful actions (e.g. a claim verified, a listing hidden, a vote invalidated) to keep the service accountable. It records the action, a short non-secret detail and who did it — never passwords, codes or tokens.
If you run a listed business
You can ask us to correct or remove your listing at any time using the report link on the listing, or by contacting us. We review every request; nothing is changed or deleted automatically. You can also claim your listing to manage the public details yourself.
Our legal bases (UK GDPR)
- Legitimate interests — running an accurate public trade directory and competition, and protecting it from duplicate/automated voting and abuse. We balance this against your interests and keep data minimal.
- Consent — where you submit a claim, correction or contact message, you provide your details so we can act on your request.
- Legal obligation — where we must keep or disclose information to comply with the law.
Cookies and analytics
We use a small number of first-party cookies that are essential to security and core function (voting integrity, owner and operator sign-in) — see the dedicated cookies page for the full list, purposes and lifetimes. We do not use advertising cookies or third-party tracking pixels.
Who we share data with
We do not sell personal data. We share it only with service providers that help us run the site, under contract and only as needed:
- Email delivery — a transactional email provider (intended provider: SMTP2GO) sends verification codes, sign-in links and operator notifications.
- Hosting / infrastructure — the server host that runs the application and database, and Cloudflare for DNS and, later, inbound email routing. [Hosting provider and region to be confirmed before launch.]
We may disclose information if required by law or to protect the service against abuse.
How long we keep data
- Business listings — for as long as the listing is published; correction and provenance history is retained while the listing exists.
- Claims — kept while a claim/ownership is active; verification codes are cleared on use or expiry (20 minutes).
- Owner sessions / sign-in links — sessions expire after 7 days; magic-link tokens after 30 minutes (single use).
- Votes — kept for the life of the competition and its published results.
- Anti-abuse event ledger — pruned after 90 days.
- Analytics events — kept as aggregate operational data; reviewed periodically and pruned when no longer needed (target retention 12 months).
- Correction and contact requests — kept while needed to handle the request and for a reasonable period afterwards for accountability (target 12 months).
- Audit log — retained for accountability; contains no secrets.
Your rights
Under UK data protection law you have the right to access your personal data, to have it corrected or erased, to object to or restrict certain processing, and to data portability where it applies. To exercise any of these, contact us (below). We may need to verify your identity before acting. Note that much listing information is drawn from public sources; we will always consider a removal or correction request.
Security
Secrets (verification codes, session and sign-in tokens) are stored only as hashes. IP addresses and browser identifiers used for anti-abuse and analytics are stored only as one-way HMACs, never in plain text. Sign-in cookies are HTTP-only and, in production, sent only over HTTPS. Access to the operator area is restricted and audited.
Contact and complaints
For any privacy request or question, use our contact form(choose “Privacy / data request”) or email [email protected]. If you are not satisfied you can complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.