Privacy Policy
Last updated: 27 April 2026
Note: This policy is a working draft. The current draft below is technically accurate to how the platform actually operates, and is intended as a basis for legal review before public launch.
Overview
Stable Neighbours is a platform that connects horse owners, riders, and service providers in the UK. This Privacy Policy explains what personal information we collect, how we use it, and the rights you have over it.
Who we are
Stable Neighbours Ltd is a private limited company registered in England & Wales.
- Company number: 17124229
- Registered office: 8 Andover Road, Southsea, England, PO4 9QG
- Contact: stableneighbours@gmail.com
For the purposes of UK GDPR, Stable Neighbours Ltd is the data controller for the personal information we hold about you.
Information we collect
We collect the following categories of information:
- Account information. Name, email address, password (hashed), date of birth, and phone number where you provide one.
- Profile information. Photo, bio, riding or horse-care experience, the horses you own or are associated with, services you offer, and any free-text you add to your profile.
- Location information. When you create or join a neighbourhood we record the geographic point you specify (typically your stable or home base). We do not track your real-time location.
- Bookings and payments. When you book or accept a booking, we record the parties, the type of arrangement, dates, and any agreed price. Payment card details are handled by Stripe — we do not see or store your card number.
- Messages. Direct messages between users are sent through Stream Chat and stored on their infrastructure. We have access to message history for safety and moderation purposes.
- Reviews. When you leave a review, we store the rating, free-text, and the identity of both reviewer and subject.
- Technical information. IP address, browser type, device type, and pages visited, used to operate the service and detect abuse.
- Cookies and similar storage. See "Cookies" below.
How we use your information
We use your information to:
- Operate the platform: authenticate you, show you relevant horses, neighbourhoods, and people, route messages, and process bookings.
- Process payments through Stripe.
- Communicate with you about bookings, account changes, and service updates.
- Enforce our Terms & Conditions and respond to abuse, fraud, and safety concerns.
- Improve the platform, including aggregated analysis of how the service is used. Where this involves non-essential analytics, we ask for your consent via the cookie banner.
We do not sell your personal information.
Lawful bases (UK GDPR)
We rely on the following lawful bases:
- Contract. To provide the service you've signed up for (your account, bookings, messaging, payments).
- Legitimate interests. To keep the platform safe, prevent fraud, debug problems, and improve features. Where we rely on legitimate interests, we balance them against your rights.
- Consent. For non-essential cookies and any future analytics or marketing use of your data. You can withdraw consent at any time via the "Cookie preferences" link in the footer.
- Legal obligation. Where we are required to retain or disclose information by law (e.g. in response to a valid court order).
Who we share information with
We share information only with:
- Service providers that help us run the platform. The main ones are:
- Supabase — database and authentication (data hosted in the EU).
- Stripe — payment processing (PCI-DSS compliant, UK/EU data centres).
- Stream Chat — direct messaging.
- Vercel — application hosting.
- Google Maps Platform — location lookup and map tiles.
- Other users, but only to the extent necessary for the service: profile information you've published, your reviews, and message content with people you've messaged.
- Authorities or third parties where we are legally required to do so, or where it is necessary to protect the safety of users or the public.
International transfers
Some of our service providers (notably Stream Chat and Google) may process data outside the UK and EU. Where this happens we rely on UK Adequacy Regulations or Standard Contractual Clauses with the relevant provider.
Cookies and local storage
We use cookies and similar browser storage in three categories:
- Strictly necessary. Required to keep you signed in, process payments, and route between sections of the site. These cannot be turned off.
- Functional. Remember preferences (e.g. dismissed banners, recent emoji reactions, skin-tone preferences) so you can pick up where you left off.
- Analytics. Reserved for future use. When we add analytics, we will only set these with your consent.
You can change your choices at any time via "Cookie preferences" in the footer.
Data retention
We retain your information only as long as we need it:
- Account information for as long as your account is active, and for up to 6 years after closure for accounting and dispute-resolution purposes.
- Bookings and payments for at least 6 years after the booking, to meet HMRC record-keeping obligations.
- Messages for as long as your account is active, then deleted on a rolling schedule unless required for an active safety investigation.
- Reviews remain visible after account closure (de-identified where appropriate) so the platform's review history isn't misleading.
Security
We take reasonable technical and organisational steps to protect your information:
- All connections are encrypted in transit (HTTPS).
- Passwords are stored hashed; we never see them in plain text.
- Database access is restricted by row-level security policies.
- Payment card data is never stored on our infrastructure.
No system is perfectly secure. If we ever experience a personal-data breach that materially affects you, we will notify you and the ICO as required.
Your rights
Under UK GDPR you have the right to:
- Access your personal information.
- Correct information that's inaccurate.
- Delete your information ("right to be forgotten"), subject to limits where we're legally required to retain it (e.g. payment records).
- Restrict or object to certain processing.
- Portability — receive a copy of your data in a machine-readable format.
- Withdraw consent for any processing based on consent.
- Complain to the Information Commissioner's Office (ico.org.uk) if you believe we've handled your information incorrectly.
To exercise any of these rights, email stableneighbours@gmail.com. We aim to respond within one calendar month.
Account and data deletion
To delete your account and personal data, email stableneighbours@gmail.com from the address registered to your account. We'll confirm receipt within a few working days and complete the deletion within 30 days, retaining only the minimum required by law (e.g. booking records for HMRC).
Age requirement
Stable Neighbours is intended for users aged 18 and over. If you become aware that someone under 18 has registered, please email us so we can remove the account.
Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect the most recent change. Material changes (i.e. ones affecting your rights or how we use your data) will be flagged in-app or emailed to you.
Contact
Privacy questions, requests, or complaints: stableneighbours@gmail.com
Stable Neighbours Ltd, 8 Andover Road, Southsea, England, PO4 9QG. Registered in England & Wales, company number 17124229.