Privacy policy
At Sports Direct, we take the protection of your personal data seriously. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our website , mobile app, in-store services, or interact with our brand (collectively, the “Services”). We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, ensuring your data is handled lawfully, fairly, and transparently.
Sports Direct is operated by Frasers Group Retail Limited (registered in England and Wales, company number: 03817513; registered address: Shirebrook Retail Park, Mansfield Road, Shirebrook, NG20 8RY) (“we”, “us”, “our”). We are the data controller for the personal data we collect about you.
1. What Personal Data We Collect
We only collect personal data that is necessary to provide and improve our Services, process your orders, and communicate with you. The types of data we may collect include:
1.1 Data You Provide Voluntarily
- Contact Details: Full name, email address, phone number, postal address (for delivery and marketing).
- Account Information: Username, password (encrypted for security), and account preferences (e.g., saved delivery addresses, communication opt-ins).
- Payment Data: Cardholder name, card number (processed securely by third-party payment providers—we do not store full card details), and billing address.
- Purchase and Order Data: Details of products you buy, order history, delivery preferences, and any special requests (e.g., gift wrapping notes).
- Marketing Consent Data: Records of whether you’ve opted in to receive marketing communications (e.g., newsletters, promotional offers).
- Customer Service Data: Information you provide when contacting us (e.g., queries, complaints, feedback) and records of our communications with you.
1.2 Data Collected Automatically
- Technical Data: IP address, browser type and version, operating system, device model, and unique device identifiers (e.g., IMEI for mobile devices).
- Usage Data: Pages you visit on our website/app, time spent on each page, search queries, click-through rates, and how you navigate our Services (e.g., from homepage to product page).
- Location Data: Approximate location (based on your IP address or, if you enable it, GPS data from your device) to show local stores, delivery options, or region-specific offers.
- Cookie Data: Information collected via cookies and similar technologies (e.g., web beacons) – see our Cookie Policy. for full details.
2. Why We Use Your Personal Data
We use your personal data only for specific, lawful purposes outlined below. We will never use your data for unrelated reasons without notifying you first:
2.1 To Process Your Orders and Deliver Products
- Fulfill your purchases (e.g., verify payment, arrange delivery, send order confirmations).
- Communicate with you about order updates (e.g., dispatch notifications, delivery delays).
- Resolve issues with your order (e.g., returns, refunds, replacements) – as required by our Return Policy.
2.2 To Manage Your Account
- Create and maintain your Sports Direct account (e.g., save preferences, track order history).
- Verify your identity to prevent unauthorised access to your account.
- Notify you of account updates (e.g., password changes, security alerts).
2.3 To Provide Customer Service
- Respond to your queries, complaints, or feedback (via email, phone, or live chat).
- Personalise our customer service (e.g., reference your past interactions to resolve issues faster).
2.4 To Send Marketing Communications
- Share promotional offers, new product launches, and event updates – but only if you have given us explicit consent (you can opt out at any time).
- Personalise marketing content to match your interests (e.g., sending running gear offers if you’ve bought running shoes before).
2.5 To Improve Our Services
- Analyse usage data to identify trends (e.g., popular products, user navigation patterns) and enhance our website/app functionality.
- Test new features or services (e.g., a revised checkout process) to improve user experience.
- Prevent fraud and ensure the security of our Services (e.g., detecting unusual payment activity).
2.6 To Comply With Legal Obligations
- Maintain accurate records for tax and accounting purposes (required by UK law).
- Respond to requests from regulatory authorities (e.g., police, data protection bodies) where legally obligated.
3. Who We Share Your Personal Data With
We will never sell your personal data to third parties. We may share your data with the following trusted partners, but only to fulfill the purposes outlined in Section 2:
3.1 Service Providers
- Payment Processors: BBVA, PayPal, and Adyen – to securely process your card payments (they only receive data needed to complete transactions).
- Logistics Partners: DPD, Yodel, and Royal Mail – to deliver your orders and provide tracking updates.
- IT and Security Providers: Companies that host our website/app, manage our data servers, or provide cybersecurity tools (e.g., to prevent data breaches).
- Marketing Agencies: Partners who help us create and send marketing communications (but they cannot use your data for their own purposes).
3.2 Group Companies
- Other businesses within the Frasers Group (e.g., Flannels, House of Fraser) – but only to provide consistent services (e.g., if you use a Frasers Group loyalty card across brands).
3.3 Legal and Regulatory Bodies
- Police, HM Revenue & Customs (HMRC), or data protection authorities – if required by law (e.g., to investigate fraud or comply with a court order).
4. How Long We Keep Your Personal Data
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:
- Order and Payment Data: Retained for 7 years after your last purchase (to comply with tax and accounting regulations).
- Account Data: Retained for 24 months after your account becomes inactive (we will notify you before deleting your account).
- Marketing Data: Retained until you opt out of marketing communications (after which we delete your data from our marketing lists).
- Customer Service Data: Retained for 3 years after your last interaction (to reference past queries if needed).
Once your data is no longer needed, we will securely delete it (e.g., by erasing electronic records) or anonymise it (so it can no longer identify you).
5. Your Data Protection Rights
Under UK GDPR and the Data Protection Act 2018, you have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you (we provide this free of charge).
- Right to Rectification: Ask us to correct inaccurate or incomplete data (e.g., update your postal address).
- Right to Erasure (“Right to be Forgotten”): Request that we delete your data, provided it is no longer needed for legal or service purposes.
- Right to Restrict Processing: Ask us to stop using your data temporarily (e.g., while we investigate a complaint).
- Right to Data Portability: Receive your data in a structured, machine-readable format (e.g., CSV file) to share with another service provider.
- Right to Object: Refuse to have your data used for direct marketing, or for processing based on our legitimate interests (we will comply unless we have a strong legal reason not to).
- Right to Withdraw Consent: If you gave consent for marketing or other processing, you can withdraw it at any time (this does not affect past processing).
To exercise any of these rights, contact us using the details in Section 7. We will respond to your request within 1 month (we may extend this by 2 months for complex requests, but we will notify you).
6. How We Keep Your Data Secure
We implement robust technical and organisational measures to protect your data from unauthorised access, loss, or theft:
- Encryption: Sensitive data (e.g., passwords, payment details) is encrypted using industry-standard TLS (Transport Layer Security) technology.
- Access Controls: Only authorised employees (e.g., customer service teams, IT staff) can access your data, and they are trained on data protection rules.
- Secure Servers: Our data is stored on secure servers in the UK and EU, protected by firewalls and regular security audits.
- Third-Party Checks: We only work with service providers who meet strict security standards (we include data protection clauses in our contracts with them).
While we take all reasonable steps to secure your data, no online service is completely risk-free. If a data breach occurs, we will notify you and the Information Commissioner’s Office (ICO) within 72 hours if it poses a risk to your rights.
7. Contact Us
If you have questions about this Privacy Policy, want to exercise your data rights, or report a data concern:
- Email: privacy@sportsdirect.com (we aim to reply within 24 working hours).
- Phone: 0344 245 9000 (Monday–Friday: 8 AM–8 PM; Saturday: 9 AM–6 PM; Sunday: 10 AM–4 PM).
- Post: Data Protection Team, Frasers Group Retail Limited, Shirebrook Retail Park, Mansfield Road, Shirebrook, NG20 8RY.
You can also lodge a complaint with the ICO (the UK’s data protection authority) if you are unhappy with how we handle your data:
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our Services. When we make significant changes, we will:
- Notify you via email (if you have an account).
- Display a notice on our website homepage for 30 days.
Your continued use of our Services after the changes take effect means you accept the updated Policy. We recommend reviewing this page periodically.