Privacy Policy
Privacy Policy
Last updated: 01.09.2026
1. Introduction
This Privacy Policy explains how RAREPEEL LIMITED ("RAREPEEL", "we", "us" or "our") processes personal data when individuals use peelplee.com and the related digital entertainment services.
PeelPlee provides digital content, Digital Entertainment Experiences, Account functionality, Access Packages and related features. Certain features use P-Coins, which are internal digital interaction units. P-Coins allocated through the Service may be used only within the Service and have no monetary, transferable or redeemable value.
This Policy applies to browsing, Account registration and use, favourites, Access Packages, P-Coins, Digital Entertainment Experiences, support, payment-related inquiries, age and eligibility checks, security and fraud prevention, and other interactions with the Service. The Service is intended only for persons aged eighteen or over.
This Policy should be read together with the Terms of Service, Fair Play Policy and P-Coins Policy. Capitalised terms not defined here have the meanings given in the Terms of Service. "Website" means peelplee.com; and "Service" means the service made available through the Website.
2. Who We Are
RAREPEEL LIMITED operates peelplee.com and is the controller of personal data processed through the Service, except where another organisation independently determines the purposes and means of processing.
RAREPEEL LIMITED is incorporated in England and Wales under company number 16895462, with registered office at International House, 14 King Street, Leeds, England, LS1 2HL. We process personal data in accordance with the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR.
Third parties such as Payment Providers, banks and card issuers may act as independent controllers for their own processing. Service providers acting only on our instructions act as processors or sub-processors subject to appropriate contractual and data protection requirements.
Privacy requests concerning PeelPlee may be sent to support@peelplee.com. We may request reasonable information to verify the identity or authority of a requester before acting.
3. Scope of This Privacy Policy
This Policy applies to personal data collected or otherwise processed by RAREPEEL LIMITED through the Website and related Service. It covers data provided by Users, generated through use of the Service, or received from authorised third parties that support payment processing, hosting, communications, security, fraud prevention, Service administration and, where used, analytics or similar functionality.
It applies to browsing, Account registration and authentication, password resets, favourites, Access Packages, P-Coins, Digital Entertainment Experiences, support communications, complaints, refunds, payment inquiries and reasonable age, eligibility, security or fraud-prevention checks. Limited technical and usage data may also be processed where an experience is available without Account registration.
Records relating to P-Coins may constitute personal data where associated with an identifiable User, even though P-Coins are not money or stored value.
This Policy does not govern third-party websites, applications or services accessed through external links. Where a third party acts as an independent controller, it is responsible for its own processing and privacy notices. Mandatory data protection law prevails over any inconsistent provision of this Policy.
4. Information We Collect
We collect only personal data reasonably relevant to operating, supporting, securing and improving the Service. The specific information depends on how a User interacts with the Service.
4.1. Account and Registration Information
When you create or manage an Account, we may collect your first name, last name, email address, age confirmation, protected password credentials, acceptance of the Terms of Service and Privacy Policy, Account settings and communication preferences. A telephone number may be processed where requested through the relevant Account functionality.
We may also process registration date, Account status, sign-in activity, password reset requests, verification status, restrictions and changes to Account details. Registration information is not required merely to access an experience that is expressly available without sign-up.
4.2. Payment and Transaction Information
Payments for Access Packages are processed by independent Payment Providers. Full payment card details and card security codes are submitted directly to the relevant provider and are not required by RAREPEEL LIMITED for ordinary Service administration.
We may receive limited information such as transaction references, amount, currency, date, status, selected Access Package, associated P-Coins allocation, Payment Provider, refund or chargeback status and masked payment method details. We use such information to confirm purchases, allocate P-Coins, provide support, process or review refunds, investigate disputes and reconcile reversed transactions.
RAREPEEL LIMITED does not use payment information to provide banking, payment account, electronic money, stored-value, wallet or similar financial services.
4.3. Technical and Device Information
When you use the Website, we may automatically collect IP address, approximate location derived from IP, browser and operating system information, device or session identifiers, language and time-zone settings, referral source, access date and time, technical logs, error records and information from cookies or similar technologies.
This data may be used to operate and secure the Website, diagnose technical issues, maintain compatibility, apply geographic or security controls and detect unauthorised, fraudulent, automated or abusive activity. Precise device geolocation is not required for the core Service unless a specific feature clearly requires it and an appropriate legal basis applies.
4.4. Service Usage Information
We may process information about sign-ins, Website navigation, Digital Entertainment Experiences accessed, interactions with features, saved favourites, selected Access Packages, P-Coins allocations and use, Account preferences, session duration and technical outcomes.
Where an experience is available without sign-up, limited session and usage information may still be processed. P-Coins records may include allocations, deductions, corrections, cancellations and other adjustments and remain associated with the Service.
4.5. Communications and Support Information
When you contact us, we may process your name, email address, Account information, transaction reference, message content, complaints, refund or payment inquiries, attachments and correspondence history. A telephone number may be processed where you voluntarily provide it for the relevant request.
Support interactions may be retained where reasonably necessary for customer support, dispute resolution, security, compliance or record-keeping. Users should not send passwords, PINs, CVV codes or full payment card numbers through support channels.
4.6. Verification and Security Information
Where reasonably necessary, we may request or receive information to confirm age, eligibility, identity, Account ownership, location or authority to use a payment method, or to investigate suspected misuse or unauthorised activity.
This may include verification status, limited payment-holder information, network or location information and records relating to suspicious, disputed or technically abnormal activity. We may also process security indicators involving multiple Accounts, unusual access patterns, automated activity, P-Coins misuse or attempts to circumvent Service restrictions. Such information will be limited to what is reasonably necessary for the relevant purpose.
4.7. Information Received from Third Parties
We may receive limited personal data from Payment Providers, banks, card issuers, hosting and infrastructure providers, technical providers, analytics and communications providers, security or fraud-prevention providers and professional advisers.
This may include payment status, transaction identifiers, masked payment information, refund or chargeback data, authentication or security results, technical signals, device or network information and suspected unauthorised activity. Independent controllers are responsible for their own processing; processors acting on our instructions are subject to appropriate contractual requirements.
4.8. Special Categories of Personal Data
RAREPEEL LIMITED does not require special category personal data to use the ordinary functionality of the Service. Users should not submit such information unless genuinely necessary for a legal, accessibility or support request.
If special category data is incidentally provided, we will process it only where an applicable Article 6 lawful basis and Article 9 condition are available and, where required, the additional requirements of the Data Protection Act 2018 are satisfied.
4.9. Information Relating to Minors
The Service is available only to persons aged eighteen or over. We do not knowingly permit persons under eighteen to create an Account, select an Access Package or use restricted functionality.
If we reasonably believe that personal data relates to a person under eighteen, we may request age verification, restrict or suspend access and delete or restrict the data where appropriate, subject to legal, security, payment, dispute-resolution and retention requirements.
4.10. Information Required to Use the Service
Certain information is required to create and secure an Account, confirm eligibility, administer a Purchase or respond to a request. Mandatory fields will be identified at or before collection.
Failure to provide required registration, verification or payment information may prevent the relevant Account, payment or Service functionality from being provided. Optional cookies, communication preferences and optional telephone information are not required for core functionality unless clearly explained otherwise.
5. How We Use Personal Data
RAREPEEL LIMITED uses personal data only for specified and legitimate purposes supported by an appropriate lawful basis.
5.1. Providing and Administering the Service
We use personal data to create and maintain Accounts, authenticate Users, provide access to PeelPlee, save favourites, maintain preferences, provide Digital Entertainment Experiences and administer Access Packages and P-Coins.
Where an experience is available without registration, we may process limited technical and usage data necessary to deliver and secure that functionality. P-Coins remain administered within the Service through which they were allocated.
5.2. Processing Access Packages and Payments
We use limited transaction information to present Access Packages, confirm payment status, make the selected package available, allocate P-Coins, maintain transaction records and provide payment-related support.
We may also use transaction data to investigate duplicate or disputed payments, process or review refunds, respond to chargebacks and reconcile reversed transactions. Full payment card details are processed by the relevant Payment Provider.
5.3. Account and Customer Support
We use personal data to answer questions, assist with Account access, resolve technical issues, investigate complaints, review refund or payment inquiries and process privacy requests. Relevant correspondence may be retained to maintain an accurate support history and demonstrate how a request was handled.
Where necessary, we may request reasonable verification before disclosing Account or transaction information.
5.4. Security and Fraud Prevention
We may process Account, device, network, transaction and usage information to protect login credentials, detect unauthorised access, prevent payment misuse, investigate suspected fraud, identify duplicate or unauthorised Accounts and detect prohibited conduct or technical manipulation.
We may also detect unauthorised automation, refund or chargeback abuse, P-Coins misuse and attempts to circumvent geographic, eligibility or security restrictions. Relevant functionality may be temporarily restricted while an issue is reviewed. Such processing will be proportionate to the identified risk.
5.5. Eligibility and Verification
We may use personal data to confirm age, eligibility and geographic requirements under the Terms of Service and, where reasonably necessary, verify identity, Account ownership, location or authority to use a payment method.
Verification may also be carried out for Account recovery, suspected misuse, disputed transactions, Payment Provider requirements or Service restrictions. We will not request information disproportionate to the purpose of the check.
5.6. Legal and Compliance Purposes
We may process personal data to comply with applicable law, court orders and lawful requests, maintain legally required records, enforce the Terms of Service, Fair Play Policy and P-Coins Policy, investigate suspected violations, protect rights and security, and establish, exercise or defend legal claims.
Personal data may also be processed in connection with sanctions restrictions, payment disputes, fraud prevention, consumer complaints or regulatory inquiries. Disclosures will be limited to information reasonably necessary or legally required.
5.7. Service Operation, Maintenance and Improvement
We may use technical and usage data to monitor performance, diagnose errors, maintain compatibility, conduct testing, improve security and refine Service functionality. We may analyse general navigation and feature usage to understand how the Service operates and where improvements are needed.
Where reasonably practicable, internal reporting and analytics will use aggregated, anonymised or de-identified information.
5.8. Service Communications
We may use contact details to send registration confirmations, password reset instructions, security alerts, payment or Access Package confirmations, support responses, verification requests, policy updates and other administrative notices.
Marketing or promotional communications will be sent only where permitted by law and, where required, with consent. Users may opt out of marketing without affecting necessary Service communications.
5.9. Corporate and Business Transactions
Personal data may be processed or disclosed where reasonably necessary for a proposed or completed merger, acquisition, financing, restructuring, sale of assets, investment or transfer of all or part of RAREPEEL LIMITED's business or the Service.
Appropriate confidentiality and data protection safeguards will apply, and Users will be informed where required if the identity of the controller or the manner of processing materially changes.
5.10. Automated Processing
We may use automated tools to support technical monitoring, security, fraud detection and identification of unusual activity. These tools may flag activity for further review.
RAREPEEL LIMITED does not currently make decisions based solely on automated processing that produce legal or similarly significant effects for Users. If qualifying automated decision-making is introduced, we will provide the information and safeguards required by applicable law.
6. Legal Bases for Processing Personal Data
RAREPEEL LIMITED processes personal data only where a lawful basis applies under the UK GDPR, the Data Protection Act 2018 and, where relevant, the EU GDPR. The basis depends on the purpose and circumstances of processing.
6.1. Performance of a Contract
We may process personal data where necessary to perform the Terms of Service or take steps requested by a User before entering into them. This includes Account administration, authentication, provision of the Service, favourites, Access Packages, payment confirmation, P-Coins administration, Digital Entertainment Experiences, password recovery and contractual support.
We rely on contractual necessity only where processing is objectively necessary to provide the relevant service or fulfil a contractual obligation.
6.2. Compliance with Legal Obligations
We may process personal data where necessary to comply with applicable legal obligations, including tax, accounting, corporate record-keeping, consumer and data protection requirements, binding court orders and lawful requests from competent authorities.
We will assess the legal basis of any authority request and disclose only information we are legally required or permitted to provide.
6.3. Legitimate Interests
We may process personal data where necessary for legitimate interests pursued by RAREPEEL LIMITED or a third party and those interests are not overridden by the User's rights and freedoms.
Relevant interests may include operating and securing the Service, preventing fraud and unauthorised activity, investigating misuse, protecting Users and Payment Providers, enforcing platform rules, maintaining records, resolving disputes, improving technical performance and establishing or defending legal claims.
Before relying on this basis, we consider the purpose, necessity and impact of the processing and apply additional safeguards where appropriate.
6.4. Consent
We may rely on consent for optional cookies and similar technologies, optional marketing communications or other processing that is not necessary to provide the core Service.
Consent will be requested through a clear affirmative action and may be withdrawn at any time through the relevant preference mechanism or by contacting support@peelplee.com. Withdrawal does not affect processing carried out before consent was withdrawn or processing supported by another lawful basis.
6.5. Legal Claims and Dispute Resolution
We may process personal data where reasonably necessary to investigate complaints, refunds, duplicate or unauthorised payments, payment disputes or chargebacks, enforce agreements or establish, exercise or defend legal claims.
Depending on the circumstances, the lawful basis may be contractual necessity, legitimate interests, legal obligation or another basis permitted by law. Where special category data is relevant to a legal claim, an applicable Article 6 basis and Article 9 condition will be identified.
6.6. Security and Fraud Prevention
We may process Account, technical, device, network, usage and limited transaction data to prevent unauthorised access, payment misuse, duplicate Accounts, technical manipulation, fraudulent refund requests, chargeback abuse and other prohibited conduct.
Depending on the circumstances, this may rely on contract, legal obligation or legitimate interests. Processing will be limited to what is reasonably necessary and proportionate to the identified risk.
Criminal Offence Data
Where security or fraud-prevention activity involves personal data relating to criminal convictions, offences or suspected unlawful conduct, we will process such information only in accordance with Article 10 of the UK GDPR, the Data Protection Act 2018 and any other applicable requirements, and where an appropriate Article 6 lawful basis applies. Review of suspicious activity does not by itself amount to a determination that a criminal offence has occurred.
6.7. Data Protection Principles
Regardless of the lawful basis, we process personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.
Personal data will not be used for a materially incompatible purpose unless permitted by law and, where required, appropriate information or choice is provided to the User.
7. Sharing and Disclosure of Personal Data
RAREPEEL LIMITED does not sell personal data. We share it only where an appropriate lawful basis applies and disclosure is reasonably necessary to operate or protect the Service, perform our obligations, administer payments, resolve disputes or comply with law.
7.1. Service Providers Acting on Our Behalf
We may use processors supporting hosting, cloud infrastructure, data storage, technical maintenance, cybersecurity, authentication, communications, email delivery, customer support, analytics, error monitoring and fraud prevention.
Processors may use personal data only for agreed purposes, on documented instructions and subject to appropriate confidentiality, security and data protection requirements. Where required, we enter into written processing agreements and assess whether processors provide sufficient guarantees.
7.2. Payment Providers and Financial Institutions
Limited personal and transaction data may be shared with or received from Payment Providers, banks, card issuers and other organisations involved in authorising, authenticating, refunding, reversing or investigating a payment.
This may be necessary to confirm payments, allocate Access Packages and P-Coins, investigate unauthorised transactions, process refunds, manage chargebacks and prevent fraud. Full card details and security codes are processed by the relevant Payment Provider. Independent financial institutions process personal data under their own privacy notices where they act as separate controllers.
7.3. Professional Advisers and Business Support
We may disclose personal data where reasonably necessary to legal advisers, accountants, auditors, insurers, consultants, tax advisers, information security specialists and other professional advisers.
Recipients are expected to maintain appropriate confidentiality and use the information only for the relevant professional or support purpose unless another lawful basis applies.
7.4. Legal and Regulatory Disclosures
We may disclose personal data where required by law, binding court order or a valid request from a competent authority, or where reasonably necessary to investigate fraud or unlawful activity, protect rights and security, enforce platform rules or establish, exercise or defend legal claims.
We will assess the scope and legal basis of requests and, where permitted, limit disclosure to information reasonably necessary for the relevant purpose.
7.5. Corporate Transactions
Personal data may be disclosed to prospective or actual purchasers, investors, lenders, advisers or other participants in a merger, acquisition, financing, restructuring, sale of assets or transfer of all or part of the business or Service.
Before completion, disclosures will be limited to what is reasonably necessary and subject to appropriate confidentiality and data protection safeguards. Users will be informed where required if the controller changes.
7.6. Aggregated and Anonymised Information
We may use or disclose information that has been irreversibly anonymised so that it no longer identifies an individual. Information that remains capable of being linked to a person, including pseudonymised data, continues to be treated as personal data.
7.7. Protection of Shared Personal Data
We apply reasonable due diligence to processors and require appropriate contractual, technical and organisational safeguards depending on the recipient, purpose, data involved and applicable law.
Where a disclosure constitutes an international transfer, the safeguards described in Section 8 will apply.
8. International Data Transfers
RAREPEEL LIMITED is established in the United Kingdom, but some providers supporting the Service may process or access personal data from countries outside the United Kingdom or European Economic Area.
Where UK GDPR transfer restrictions apply, we will use an appropriate mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses or another lawful mechanism. Where the EU GDPR applies, safeguards may include an EU adequacy decision, Standard Contractual Clauses, binding corporate rules or another permitted mechanism.
Where required, we will assess whether destination-country laws and practices could affect the protection provided by the relevant safeguard and may implement supplementary technical, contractual or organisational measures.
International providers may include hosting, cloud, communications, analytics, technical support, cybersecurity, fraud-prevention and payment providers. Use of a global provider does not mean data is transferred to every country in which that provider operates.
Independent controllers are separately responsible for their own international transfers. Users may request further information about relevant categories of recipients and safeguards by contacting the support address for the Service.
9. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, to provide and secure the Service, comply with legal obligations, resolve disputes and protect legal rights. Retention periods depend on the type of data, purpose of processing and applicable legal, accounting, tax, security and dispute-resolution requirements.
9.1. Account Information
Account and registration information may be retained while an Account is active and for a reasonable period after closure, suspension or termination. Limited information may remain where necessary to confirm closure, respond to inquiries, prevent duplicate or unauthorised Accounts, investigate misuse, resolve disputes or comply with law.
Data no longer required for these purposes will be deleted, anonymised or securely disposed of.
9.2. Payment and Transaction Information
We may retain limited transaction information for as long as necessary to confirm Access Package payments, administer P-Coins, process refunds, answer payment inquiries, manage disputes or chargebacks and satisfy accounting, tax, consumer protection or legal requirements.
RAREPEEL LIMITED does not retain complete card numbers, CVV codes or PINs. Payment Providers, banks and card issuers determine their own retention periods where they act independently.
9.3. P-Coins and Service Usage Records
P-Coins allocation, use, deduction and adjustment records may be retained while an Account is active and for a reasonable period afterwards to maintain Account accuracy, investigate errors, reconcile refunds or reversals, respond to inquiries and detect misuse.
Service usage information and preferences may be deleted or anonymised when no longer required for administration, security, analytics, technical improvement or another lawful purpose.
9.4. Communications and Support Records
Support requests, complaints, privacy requests and related correspondence may be retained for as long as reasonably necessary to respond, maintain an appropriate support history and resolve the relevant issue.
Records concerning payment disputes, Account restrictions, fraud investigations, security incidents or legal claims may be retained longer where reasonably necessary for that matter.
9.5. Technical and Security Information
Technical logs, device and network data, login records, error logs and security records may be retained for periods reasonably necessary to operate and protect the Service, diagnose issues, investigate incidents and prevent fraud or unauthorised access.
Security records may remain after Account closure where necessary to prevent repeated misuse or preserve evidence of an incident.
9.6. Verification Information
Verification information will be retained only for as long as necessary for the relevant age, identity, Account ownership, payment, security, dispute-resolution or legal purpose.
Where a full verification document is not required, we may retain only the verification result, date, reference or status needed to demonstrate that the check was completed.
9.7. Account Closure, Suspension and Termination
Account closure does not necessarily result in immediate deletion of all personal data. We may retain information necessary to comply with law, resolve outstanding payments or complaints, investigate prohibited conduct, prevent fraud, enforce the Terms of Service or defend legal claims.
Information retained for those purposes will not be used for unrelated promotional activity.
9.8. Backups and Technical Archives
Personal data may remain temporarily in secure backups or technical archives after removal from active systems. Backup copies are protected against ordinary access and are deleted, overwritten or rendered inaccessible according to applicable backup cycles unless longer retention is required for security, disaster recovery or legal purposes.
9.9. Deletion and Anonymisation
When personal data is no longer required and no lawful basis exists for continued retention, it will be deleted, anonymised or securely disposed of. Irreversibly anonymised information may be retained for statistical, analytical, security, technical or operational purposes.
Pseudonymised information that can still be linked to an identifiable person remains personal data.
9.10. Extended Retention
Personal data may be retained longer where required by law, court order, lawful authority request, an ongoing security or fraud investigation, an unresolved payment dispute or chargeback, or an actual or reasonably anticipated complaint or legal claim.
Once the reason for extended retention ends and no other lawful basis remains, the information will be deleted, anonymised or securely disposed of.
10. Your Privacy Rights
Depending on applicable law and the circumstances of processing, you may have the rights described below. These rights are not absolute and may be subject to legal conditions, limitations or exemptions.
10.1. Right of Access
You may request confirmation of whether we process your personal data and, where applicable, a copy of that data together with information about the purposes of processing, categories of data, recipients, retention criteria and sources where the information was not collected directly from you.
10.2. Right to Rectification
You may request correction of inaccurate personal data or completion of incomplete data. Certain Account information may be updated directly through the Service; otherwise you may contact us.
We may take reasonable steps to verify a requested correction where it affects eligibility, payments, P-Coins or security.
10.3. Right to Erasure
You may request deletion where personal data is no longer necessary, consent has been withdrawn and no other basis applies, a valid objection has been made, processing is unlawful or deletion is otherwise required by law.
The right is not absolute. We may retain personal data where a lawful basis for continued processing remains, including where the information is still reasonably necessary for proportionate fraud-prevention or security purposes, or where retention is required to comply with a legal obligation, maintain necessary accounting or payment records, establish, exercise or defend legal claims, or satisfy another exception permitted by applicable law.
10.4. Right to Restriction of Processing
You may request restriction where you contest data accuracy, believe processing is unlawful but do not want deletion, require the data for a legal claim after we no longer need it, or have objected while that objection is being assessed.
Restricted data will generally be stored but not otherwise used except where permitted by law.
10.5. Right to Data Portability
Where processing is based on consent or contractual necessity and carried out by automated means, you may request certain personal data you provided in a structured, commonly used and machine-readable format and, where technically feasible, request transmission to another controller.
This right generally does not apply to derived, inferred or anonymised information and does not make P-Coins transferable to another person, platform or Service.
10.6. Right to Object
You may object to processing based on legitimate interests for reasons relating to your particular circumstances. We will stop the relevant processing unless compelling legitimate grounds override your interests, rights and freedoms or processing is required for legal claims.
You have an unconditional right to object to processing for direct marketing.
10.7. Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time through the relevant preference mechanism or by contacting support@peelplee.com.
Withdrawal does not affect processing carried out before consent was withdrawn or processing supported by another lawful basis.
10.8. Direct Marketing
Where marketing communications are used, you may unsubscribe or object at any time through the relevant message, preference controls or support contact. You may continue to receive non-promotional communications required for Account administration, security, payments, support or important policy updates.
10.9. Automated Decision-Making
Where applicable law provides such a right, you may request not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
RAREPEEL LIMITED does not currently make such decisions. If qualifying automated decision-making is introduced, the safeguards required by law may include human intervention, the opportunity to express your view and the ability to challenge the decision.
10.10. Exercising Your Rights
Requests concerning PeelPlee may be sent to support@peelplee.com. A request should identify the right being exercised and provide enough information to locate the relevant data.
We may request reasonable identity or authority verification before acting. We will not request passwords, PINs, CVV codes or full card numbers for this purpose. Where a request is submitted by an authorised representative, evidence of authority may be required.
10.11. Response Timeframes
We will respond to valid privacy rights requests without undue delay and normally within one month after receiving the request and any information reasonably required for verification. Where permitted by law, this may be extended by up to two additional months for complex or multiple requests, and we will inform the requester of the extension within the initial period.
Requests are ordinarily handled free of charge. Where a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act where permitted by law. If we refuse a request, we will explain the reason and available complaint or judicial remedies.
11. Complaints
Complaints concerning the Service, Accounts, Access Packages, P-Coins, payments, refunds, personal data or customer support may be sent to support@peelplee.com, or through the support form on the Website.
A complaint should contain enough information to identify the relevant User, Account, transaction or processing activity. For payment-related matters, this may include the Account email address, transaction reference, payment date and a clear description of the issue. Users should not send passwords, PINs, CVV codes or full card numbers.
We may request reasonable additional information to verify identity or investigate the matter. Complaints will be acknowledged and reviewed without undue delay. Privacy complaints and rights requests will be handled within applicable statutory timeframes; other complaints will be reviewed within a reasonable period having regard to complexity and any third-party involvement.
Users may contact the Information Commissioner's Office, another competent supervisory authority, a consumer protection body, Payment Provider, bank, card issuer, court or other competent organisation where applicable. Contacting RAREPEEL LIMITED first is encouraged but does not limit any mandatory right or remedy.
12. Cookies and Similar Technologies
PeelPlee may use cookies, local storage, pixels and similar technologies ("Cookies") to operate, secure, maintain and improve the Website. Cookies may be placed by RAREPEEL LIMITED or authorised third-party providers.
12.1. What Cookies Are
Cookies are small files or similar identifiers stored on or accessed from a User's device. They may process browser, device, session, Website activity and preference information. Some last only for a browser session, while others remain for a defined period or until deleted.
12.2. Strictly Necessary Cookies
Strictly necessary Cookies may maintain sessions, authenticate Accounts, remember essential privacy choices, support checkout, protect forms, prevent unauthorised access and maintain Website security.
They cannot normally be disabled through consent settings because essential Website or Account functionality may not operate correctly without them.
12.3. Functional Cookies
Functional Cookies may remember optional settings such as language, interface or accessibility preferences. Disabling them may cause non-essential features or preferences to be unavailable or require repeated selection.
Where consent is legally required for a functional Cookie, it will not be activated before that consent is obtained.
12.4. Analytics and Performance Cookies
Where used, analytics and performance Cookies may provide information about page visits, navigation, session duration, errors, compatibility and general usage patterns so that we can measure performance and improve the Service.
Where required by law, these Cookies will be activated only after consent. Where reasonably practicable, analytics reporting will use aggregated or de-identified information.
12.5. Security and Fraud-Prevention Technologies
Cookies and similar identifiers may support session security, authentication, detection of unusual or automated requests, prevention of unauthorised Account activity and investigation of security incidents or attempts to circumvent Service restrictions.
Where such technology is strictly necessary to provide or protect the Service, it may be used without consent to the extent permitted by law.
12.6. Marketing Cookies
Marketing or advertising Cookies will be used only if such functionality is introduced and permitted by applicable law. Where required, they will not be activated before consent and Users will be able to change or withdraw that consent.
This section does not mean that every described marketing technology is currently used.
12.7. Third-Party Cookies
Third-party providers supporting hosting, payments, analytics, security, communications or other functionality may place or access Cookies. Providers acting on our instructions are subject to appropriate processing terms; independent controllers process data under their own privacy notices.
Payment Providers may also use their own Cookies or security technologies during checkout or authentication.
12.8. Cookie Preferences
Where required, the Website will provide a cookie notice or preference tool allowing Users to accept, reject or manage non-essential Cookies. Rejecting non-essential Cookies will not prevent access to core functionality that does not depend on them.
Users may also manage Cookies through browser or device settings. Blocking strictly necessary Cookies may affect essential functionality.
12.9. Legal Basis
Strictly necessary Cookies may be used without consent where permitted by law because they are needed to provide a requested service, transmit communications or maintain essential security and functionality.
Non-essential Cookies will be used on the basis of consent where required. Consent will require a clear affirmative action and will not be inferred merely from continued browsing.
12.10. Updates and Further Information
Cookie technologies may change as the Website and providers are updated. Where a material change affects Cookies or User choices, the relevant notice or preference mechanism will be updated where required.
Further details about specific Cookies, providers, purposes and duration may be provided in a separate Cookies Policy, cookie notice or management tool on the Website.
13. Security of Personal Data
RAREPEEL LIMITED implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, access, misuse or other unlawful processing. Measures are selected having regard to the nature of the data, processing and relevant risks.
13.1. Security Measures
Measures may include access controls, authentication, password protection, encryption or pseudonymisation where appropriate, network safeguards, logging, monitoring, vulnerability management, secure backups and incident-response processes.
Authentication credentials are protected using technical and organisational safeguards appropriate to the nature and risks of the processing. Security controls are reviewed where reasonably necessary to address changes in technology, processing and identified risks.
13.2. Access Restrictions
Access to personal data is limited to authorised personnel, contractors and service providers who require it for a legitimate operational, technical, support, payment, security, legal or compliance purpose.
Authorised persons are subject to appropriate confidentiality, access-management and information-security obligations, and access may be restricted or withdrawn when no longer required.
13.3. Security Monitoring
We may monitor Account activity, sign-ins, transaction information, device and network information, technical logs and security events to identify unauthorised access, payment misuse, duplicate Accounts, automated activity, technical exploitation or other prohibited conduct.
Monitoring will be limited to what is reasonably necessary and proportionate. Automated indicators may flag activity for review, but we do not currently make decisions based solely on automated processing that produce legal or similarly significant effects.
13.4. Third-Party Service Providers
We take reasonable steps to assess the security safeguards of service providers processing personal data on our behalf. Processors are required to follow documented instructions, contractual obligations and applicable data protection requirements.
Payment Providers, banks, card issuers and other independent controllers are responsible for the security of personal data within their own systems.
13.5. Personal Data Breaches and Security Incidents
We maintain procedures for identifying, assessing, containing and responding to suspected personal data breaches and security incidents.
Where required by applicable law, we will notify the competent supervisory authority without undue delay and, where feasible, within seventy-two hours after becoming aware of a breach likely to result in a risk to individuals. Where a breach is likely to result in a high risk, affected individuals will also be informed without undue delay unless a legal exception applies.
Breaches will be documented as required by law, including relevant facts, effects and remedial measures.
13.6. User Responsibilities
Users are responsible for taking reasonable steps to protect their Account credentials, should use strong and unique passwords, and must not share authentication information with others.
Suspected unauthorised access or credential compromise should be reported promptly to support@peelplee.com. Users should not include passwords, PINs, CVV codes or full card numbers in such reports. We may require password reset, verification or temporary restrictions where reasonably necessary to protect the Account or Service.
13.7. No Absolute Security Guarantee
No method of internet transmission, electronic storage or information processing can guarantee absolute security. Users should exercise appropriate care when submitting personal data online or using shared, public or unsecured devices and networks.
This does not reduce RAREPEEL LIMITED's obligation to maintain security measures appropriate to the risks of its processing activities.
14. Children's Privacy
PeelPlee is intended exclusively for persons aged eighteen or over. Persons under eighteen must not access or use the Service, create an Account, select an Access Package or use P-Coins.
We do not knowingly permit minors to use the Service and may use reasonable age-confirmation or verification measures where necessary. If we reasonably determine that personal data relates to a person under eighteen in circumstances inconsistent with the Terms of Service, we may restrict or terminate the relevant Account and delete or restrict the data where appropriate.
Limited information may be retained where necessary to document the issue, prevent repeated unauthorised registration, process a valid refund, resolve a dispute, comply with law or establish, exercise or defend legal claims.
A parent, guardian or other person who believes that a minor has provided personal data through PeelPlee may contact support@peelplee.com. We may request reasonable information to identify the relevant Account and verify the requester's identity or authority.
15. Changes to This Privacy Policy
RAREPEEL LIMITED may update this Policy to reflect changes in law, regulatory guidance, Service functionality, providers, security practices or processing activities. The revised Policy will be published on the Website and will identify the effective date.
Where a change materially affects how personal data is processed, we may provide additional notice through the Website, Account interface, email or another appropriate method. Where a new or changed activity requires consent, consent will be requested before that processing begins.
An update does not retrospectively authorise processing that lacked an appropriate lawful basis. Users are encouraged to review this Policy periodically. Nothing in this section limits rights available under applicable data protection law.
16. Contact Information
Questions concerning this Privacy Policy, personal data processing, privacy rights, security or privacy-related complaints may be submitted to RAREPEEL LIMITED.
For PeelPlee: RAREPEEL LIMITED, International House, 14 King Street, Leeds, England, LS1 2HL, company number 16895462, peelplee.com, support@peelplee.com.
Requests should contain sufficient information to identify the requester, relevant Account or Service and nature of the inquiry. We may request reasonable information to verify identity or authority before responding. Users should not provide passwords, PINs, CVV codes or full payment card numbers.
We will respond within the timeframes required by applicable data protection law. Users may also complain to the Information Commissioner's Office in the United Kingdom or, where applicable, another competent supervisory authority. Contacting RAREPEEL LIMITED first is encouraged but is not a condition for exercising that right.