Privacy Policy.
Last updated: 21 August 2026
Real Bedford FC Limited (“Real Bedford”, “we”, “us” or “our”) is committed to protecting your personal information. This policy explains what we collect, how and why we use it, who receives it, how long we keep it, and the rights available to you. It covers realbedford.com, the Real Bedford mobile app, ticketing, merchandise, membership and supporter communications.
1. Who we are
The data controller is Real Bedford FC Limited, company number 13774571, registered at Argent House, 5 Goldington Road, Bedford, United Kingdom, MK40 3JY.
Our ICO registration reference is 00011834182.
For privacy questions or to exercise your rights, email privacy@realbedford.com. General enquiries may be sent to hello@realbedford.com.
2. Personal information we collect
Depending on how you interact with us, we may collect:
- account and membership information, including your name, email address, authentication details, preferences and optional profile information;
- ticket, season-ticket and attendance information, including ticket holders, fixtures, scans and guest invitations;
- order and payment information, including products, amounts, payment method, billing and delivery addresses and fulfilment details;
- contact and communication information submitted through forms, email, hospitality, sponsorship or customer-support conversations;
- marketing preferences and consent history;
- loyalty, membership and purchase history used to operate club benefits;
- technical information such as IP address, browser/device information, security events and error logs;
- analytics and session-replay information where you have consented through cookie preferences; and
- information relating to children where required for junior or family services, with additional care and parental involvement where appropriate.
We do not store full card numbers. Card information is handled by our payment provider.
Player, staff, volunteer, medical and safeguarding information is subject to additional internal notices and controls because different legal bases and retention requirements may apply.
3. How and why we use information
We use personal information to:
- create and administer accounts and memberships;
- sell, issue and validate tickets and season tickets;
- process merchandise orders, payments, refunds and deliveries;
- operate loyalty and supporter benefits;
- respond to enquiries and provide customer support;
- send transactional messages such as sign-in codes, tickets, receipts and order updates;
- send marketing only where we have the required consent;
- maintain financial, tax and audit records;
- prevent fraud, secure our services, diagnose faults and investigate incidents;
- understand and improve our services where analytics consent has been given; and
- comply with legal, regulatory, safeguarding and football-governance obligations.
4. Our lawful bases
We rely on:
- Contract, where processing is needed to provide tickets, products, accounts, membership or other requested services;
- Consent, for optional marketing, push notifications, analytics, session replay and optional profile information where applicable;
- Legitimate interests, for running and improving the club, customer service, security, fraud prevention, limited operational analysis and maintaining appropriate business records, balanced against your rights; and
- Legal obligation, including accounting, tax, employment, safeguarding and regulatory duties.
Where special-category information is processed, an additional condition under data-protection law is identified and documented.
5. Who receives information
We do not sell personal information. We use service providers where necessary, including:
- Supabase — databases, authentication and file storage;
- Vercel — website and application hosting;
- Stripe — card, Apple Pay and Google Pay processing;
- OpenNode — Bitcoin payment processing;
- Mailchimp — consented newsletters and supporter communications;
- Resend — transactional and notification email;
- Xero — accounting and invoicing;
- Sentry — error monitoring and, only with consent, masked session replay;
- Google Analytics — website analytics, only with consent;
- Bunny Stream, YouTube and Vimeo — video hosting or embedded media, with consent where non-essential cookies or connections are involved;
- Apple and Google — mobile-app distribution and push-notification delivery; and
- GoDaddy and other infrastructure providers — domain and supporting services.
Historic transaction records may also originate from systems previously used by the club, including Zaprite, Ticket Tailor and Shopify. Such records are retained only where still needed for customer service, accounting, legal obligations or audit, and are included in our access and erasure processes.
We may disclose information to professional advisers, payment providers, delivery companies, governing bodies, regulators or law-enforcement authorities when reasonably necessary or legally required.
6. Cookies and similar technologies
Strictly necessary technologies support authentication, baskets, checkout, security and saved cookie choices.
Google Analytics, Sentry Session Replay and optional embedded media do not load unless you consent through Cookie preferences. You may change those choices at any time. Sentry’s essential error monitoring may process limited technical fault information under our legitimate interests, without recording session replay unless consent is given. See our Cookie Policy for more detail.
7. International transfers
Sentry error information is stored in its Germany/EU region. Some other providers may process information outside the United Kingdom. Where this happens, we use an applicable UK adequacy regulation or appropriate contractual safeguards, such as the UK International Data Transfer Agreement or UK Addendum. You may contact us for further information about the safeguards relevant to your data.
8. How long we keep information
We keep personal information only for as long as it is needed for the stated purpose, including:
- active account information — while the account remains active. A customer can request deletion from inside the mobile app; the account is then deleted or anonymised unless another retention obligation applies;
- public contact and enquiry submissions — normally up to 2 years after the last relevant contact;
- ticket, order, payment, refund and accounting records — normally 7 years where required for tax, accounting, dispute or audit purposes, with unnecessary contact information removed or anonymised when appropriate;
- marketing consent and suppression history — while marketing continues and afterwards as necessary to prove and honour the person’s choice;
- operational activity logs — normally 12 months, unless needed longer for an active security investigation;
- Sentry error or replay information — for up to 90 days under the club’s Team plan;
- Google Analytics information — detailed user and event data is retained for 14 months; and
- children’s, medical, safeguarding, staff and player records — according to the applicable legal, professional, safeguarding or employment retention requirement rather than a general customer-data period.
At the end of a period we review, delete or anonymise the information unless a documented reason requires it to be kept longer.
9. Children’s information
We recognise that children merit particular protection. We collect the minimum information necessary, involve a parent or guardian where appropriate, avoid behavioural advertising and do not knowingly send marketing to a child without the required consent. Safeguarding information is handled separately by authorised personnel under the club’s safeguarding procedures.
10. Your rights
Depending on the circumstances, you may have the right to:
- access your personal information;
- correct inaccurate or incomplete information;
- request erasure;
- restrict processing;
- object to processing based on legitimate interests or to direct marketing;
- receive information you provided in a portable format; and
- withdraw consent at any time without affecting processing already carried out lawfully.
The right to erasure is not absolute; for example, we may need to retain limited transaction information to meet a legal obligation.
To exercise a right, email privacy@realbedford.com. We may need to verify your identity and will normally respond within one month.
You may complain to the Information Commissioner’s Office at ico.org.uk or by calling 0303 123 1113.
11. Security
We use measures including encrypted connections, access controls, multi-factor authentication for privileged systems, database security rules, audit trails, backups and security testing. No online service can be guaranteed completely secure, but we work to prevent, detect and respond to unauthorised access.
12. Changes
We may update this policy as our services, providers or legal obligations change. The date at the top identifies the latest revision. Material changes will be highlighted where appropriate.




