Terror Toad – Privacy Policy
​Last updated: 04/12/2025
​
Terror Toad (“we”, “us”, “our”) is a tabletop game publisher based in Lanark, Scotland. We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains what information we collect, why we collect it, how we use it, and the rights you have under UK data protection law.
If you have any questions, you can contact us at:
toadterror@gmail.com
1. Who we are
Terror Toad is the controller of your personal information.
Website: https://www.terrortoad.co.uk
2. The information we collect
2.1 Information you give us directly
When you place an order, contact us, or join our mailing list, we may collect:
-
Name
-
Postal/billing address
-
Email address
-
Phone number (optional)
-
Order details and purchase history
-
Payment information (processed securely by our payment provider – we never see full card details)
If you are a retailer buying wholesale, we may also collect:
-
Shop name and address
-
Business contact details
-
VAT or company registration information
2.2 Information we collect automatically
When you browse our website, we may collect:
-
IP address
-
Device and browser type
-
Pages visited and time spent on the site
-
Clicks and interactions
-
Cookies and similar tracking technologies
This helps us operate the website securely and improve performance.
2.3 Information from other sources
We may receive information from:
-
Retailers who stock our games (e.g., Zatu)
-
Payment processors (e.g., Stripe, PayPal)
-
Delivery companies
-
Advertising and analytics tools (e.g., Meta Pixel, Google Analytics)
-
Marketplaces (e.g., Google Shopping, Amazon sales)
We only receive the information required for orders, analytics, or support.
3. How we use your information
3.1 To fulfil orders
-
Processing payments
-
Shipping products
-
Providing order updates
-
Handling returns or support requests
3.2 To improve and operate our website
-
Fixing errors
-
Enhancing performance
-
Preventing fraud and maintaining security
3.3 To communicate with you
-
Responding to messages
-
Sending service emails (order confirmations, dispatch notices, etc.)
3.4 Marketing (only with your consent or where legally allowed)
-
News, announcements, and new product launches
-
Special offers or events
You can unsubscribe at any time.
3.5 Advertising and analytics (Meta Pixel & cookies)
We may use Meta Pixel to:
-
Measure the effectiveness of our ads
-
Understand how visitors use our site
-
Show relevant ads on Facebook, Instagram, and other Meta services
Meta may use this data in line with their own privacy policies. You can manage Meta ad preferences via your account settings or consent tools on our website.
4. Our legal bases for using your information
We use your information only where permitted under UK GDPR, including:
-
Contract – to process and deliver your order
-
Legitimate interests – running our business, website analytics, preventing fraud, improving our products
-
Legal obligation – keeping tax and accounting records
-
Consent – marketing emails, analytics/advertising cookies (including Meta Pixel)
You can withdraw consent at any time.
5. Who we share your information with
We only share your data when necessary to run our business, such as with:
-
Payment processors (Stripe, PayPal)
-
Delivery companies (Royal Mail, couriers)
-
Website hosting and technical providers
-
Email newsletter platforms
-
Advertising/analytics tools (e.g., Meta Pixel, Google Analytics)
-
Wholesale partners or marketplaces (if required to resolve order issues)
We do not sell your personal data.
Everyone we share data with must comply with UK data protection law.
6. International transfers
Some providers (such as hosting, email, or analytics services) may process data outside the UK.
When this happens, we ensure lawful protection is in place, such as:
-
UK-approved Standard Contractual Clauses (SCCs)
-
Adequacy decisions
-
Additional safeguards where appropriate
We do not rely on the invalid EU–US Privacy Shield.
7. How long we keep your information
We keep your information only as long as necessary:
-
Orders and financial records: 6 years (legal requirement)
-
Customer enquiries: usually 12–18 months
-
Marketing data: until you unsubscribe
-
Analytics data: typically up to 26 months (depending on the tool)
If you ask us to delete your data, we will do so unless we must keep it for legal reasons.
8. Your rights
You have the right to:
-
Access your information
-
Correct inaccurate data
-
Request deletion (in certain cases)
-
Restrict or object to certain uses
-
Object to direct marketing
-
Receive your data in a portable format
To exercise any of these rights, email us at: toadterror@gmail.com.
We may ask for proof of identity.
9. Cookies and tracking technologies
Our website uses cookies to:
-
Keep the site functioning
-
Remember preferences
-
Improve performance
-
Analyse how visitors use our website
-
Provide personalised or targeted ads (e.g., Meta Pixel)
You can manage or block cookies via your browser settings. Some features may not work correctly if you disable essential cookies.
A full cookie list is available on request.
10. Children
Our website is not aimed at children under 16.
We do not knowingly collect data from children.
If a child has provided information, contact us and we will delete it.
11. How we keep your information safe
We use reasonable technical and organisational measures, including:
-
Secure website hosting
-
Encryption where appropriate
-
Strong access controls
-
Staff awareness and limited access
-
Regular security checks
No method is completely secure, but we take data protection seriously.
12. Links to other websites
Our site may contain links to other websites.
We are not responsible for their privacy practices, so please check their policies.
13. Changes to this policy
We may update this Privacy Policy from time to time.
The latest version will always be available on our website.
14. Contact us
If you have any questions or want to exercise your rights, contact us at: toadterror@gmail.com
If you are not satisfied with our response, you can contact the UK’s data protection authority:
Information Commissioner’s Office (ICO)
https://ico.org.uk
​​
​

