Privacy policy
How Murphy’s Billiards collects, uses and protects your information.
This policy explains what Murphy’s Billiards collects when you use this website, why, and what we do with it. It covers this site only.
What we collect
- If you create an account: your name, email address, phone number and password. The password is stored only as a one-way hash — we cannot read it, and neither can anyone who obtains our database.
- If you buy something: your order, the delivery and billing address you give us, and a reference number from our payment processor.
- If you book a table: the booking, and the times you arrived and left.
- If you join a league or take lessons: your team, results and bookings.
- If you register a child for the youth programme: see “Children” below, which is stricter.
- Automatically: your IP address and the time of security-relevant actions such as signing in, changing a password, or an administrator viewing a record. This is a security log, not analytics.
We never store your card details
Card numbers are entered directly into a payment form hosted by our processor and never reach our servers. We keep only a token and a reference number — enough to issue a refund, and not enough to take a payment anywhere else.
We use Clover for one-off purchases and in-person payments, and Stripe for memberships and subscriptions. Each has its own privacy policy covering the details you give them.
Children
A child cannot be registered for the youth programme without a parent or guardian giving consent first. That is enforced by the system, not by procedure: a registration record cannot exist without a consent record attached to it.
For a registered child we hold their first name, last initial, date of birth, the guardian’s name and contact details, and any allergy or medical information the guardian chooses to give us. The last name and date of birth are encrypted.
Venue staff see far less than that. On the day of a session, staff see only the child’s name, the guardian’s name and phone number, and whether there is an allergy — so they can supervise the session and reach a parent. They cannot see medical notes, home addresses or email addresses. Anyone who does view a child’s full record leaves an entry in an access log.
A guardian can withdraw consent or ask us to delete their child’s record at any time, from their own account or by asking us. Records are automatically deleted after the retention period ends.
We send two kinds of email. Transactional messages — receipts, booking confirmations, password resets — are part of the service and you cannot unsubscribe from them while you have an account. Newsletters are optional, only go to people who opted in, and every one carries an unsubscribe link that works without signing in.
Cookies
We use cookies to keep you signed in and to protect forms against cross-site request forgery. That is all. There is no advertising network, no tracking pixel and no third-party analytics on this site.
Who else sees your information
Our payment processors, our email provider and our web host, each only as far as they need to in order to do their part. We do not sell your information, and we do not share it for anyone else’s marketing.
Your choices
You can see and correct most of your information from your account. You can ask us for a copy of what we hold, ask us to correct it, or ask us to delete it. Some records — a paid order, a refund — we have to keep for tax and accounting reasons even after an account is closed.
Contact
Ask us about anything on this page by phone or through the contact form, and say what you would like us to do.