Privacy Policy

Effective 30 June 2026

This Privacy Policy explains how Barneys Box Ltd (trading as SameAcres) (“SameAcres”, “the Company”, “we”, “us”, or “our”) collects, uses, shares, and safeguards personal data in connection with the SameAcres platform (“the Platform”). This document is structured to satisfy the disclosure mandates of the UK General Data Protection Regulation (“UK GDPR”), the EU General Data Protection Regulation (“EU GDPR”), the Data Protection Act 2018, the United States Children’s Online Privacy Protection Act (“COPPA”), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA / CPRA”).

This policy does not create any contractual rights or warranties beyond those strictly compelled by applicable statutory law. Your interaction with the Platform is governed comprehensively by our separate Terms of Service.

1. Data Controller & Contact Framework

The sole data controller for personal data processed via the Platform is Barneys Box Ltd, a private limited company registered in England and Wales.

All formal privacy inquiries, statutory rights requests, or data protection communications must be directed exclusively via email to help@barneysbox.co.uk. Communications sent via other channels or social media platforms shall not constitute formal legal notice.

2. Children’s Privacy, Parental Warranties, and Indemnity

The Platform is intended exclusively for adult users aged 18 or over who are parents, legal guardians, or authorised care advocates. We do not knowingly collect personal data directly from any child under the age of 18. Children are strictly prohibited from holding accounts, logging in, or interacting directly with the Platform.

2.1 User Warranties and Mandatory Upload Controls

When a user inputs limited information regarding a minor (specifically a nickname, age band, or voluntary interest and support tags), the user explicitly warrants and represents that:

  • They are the biological parent, legal guardian, or possess full, unrevoked legal authority under applicable law to input such data.
  • The data provided does not infringe upon the privacy rights, custody agreements, or court orders of any third party.
  • They agree to fully indemnify, defend, and hold harmless the Company against any claims, regulatory fines, or legal disputes arising from unauthorised or contested uploads of minor information, in absolute accordance with the indemnification provisions set forth in our Terms of Service.

2.2 Discovery and Deletion Protocol

If we become aware that personal data has been inadvertently received directly from a child or via an unauthorised adult in breach of this policy, we reserve the right to purge that data immediately without liability. Registered parents may request the review or deletion of their child’s profile data by emailing help@barneysbox.co.uk, subject to standard identity verification procedures to prevent fraudulent deletion requests by non-custodial entities.

3. Data Capture, Verification, and Marketing Communications

3.1 Verification Data Processing and Absolute Status Disclaimer

To assign the optional “Verified Email” designation, we collect and process the user’s email address by dispatching a localized verification code. The lawful basis for this processing is the performance of a contract under UK/EU GDPR Article 6(1)(b) to deliver the baseline digital account verification features requested by the user.

CRITICAL LEGAL DISCLAIMER REGARDING ACCOUNT BADGES:

The “Verified Email” designation signifies exclusively that the Company has successfully verified the technical ownership and functionality of the specific email address provided during registration. The deployment of this badge does not constitute, imply, or provide any warranty, representation, background check, identity confirmation, vetting, or endorsement by the Company regarding the user’s true identity, parental status, legal standing, safety, or character. The Company explicitly disclaims all liability for misrepresentation, fraud, or bad-actor manipulation of this technical feature. Users interact with all other verified or unverified members entirely at their own risk.

3.2 Legitimate Interests & Marketing Opt-Out Protocol

We process your contact information to distribute updates regarding related SameAcres products, services, events, community initiatives, and resources. The lawful basis for this processing is our legitimate interest under UK/EU GDPR Article 6(1)(f) in maintaining an engaged and informed user ecosystem.

Absolute Right to Object. Users maintain an absolute right to opt out of commercial marketing communications at any time. To ensure processing accuracy and systemic validation, this right must be exercised exclusively through one of the following two channels:

  • Automated Link. Utilising the one-click unsubscribe mechanism embedded at the footer of any commercial marketing email received.
  • Manual Request. Transmitting a formal opt-out demand via email to help@barneysbox.co.uk.

Please note that opting out of commercial marketing communications does not restrict, suppress, or modify essential system, security, safety, verification, or transaction-related notifications required for the ongoing performance of our service.

4. AI Engines, Algorithmic Processing, and Absolute Liability Disclaimers

4.1 Scope of Automated Operations

The Platform utilises automated algorithms, third-party Large Language Model (LLM) interfaces, and proprietary processing tools to generate dynamic user interface copy, surface venue suggestions based on user-inputted keywords, score peer matches via proximity bands, and assist in triaging community forum reports.

4.2 Complete Disclaimer of Clinical and Medical Liability

  • Non-Clinical Nature. All AI-generated outputs, micro-affirmations, and textual responses are generated algorithmically for general informational and peer-matching purposes only.
  • No Professional Advice. The Platform does not provide medical, clinical, psychological, diagnostic, or psychiatric advice.
  • Exclusion of Liability. The Company explicitly disclaims all liability for any emotional, psychological, physical, or financial harm resulting from, or attributed to, reliance upon AI-generated text, recommendations, or algorithmic matching. All AI outputs are provided strictly “as-is.”

4.3 Third-Party AI Data Integrity

We do not sell personal data to third parties, nor do we permit third-party AI providers to utilise data containing minor nicknames or direct identifiers to train external models. Prompts transmitted to AI processors are programmatically stripped of direct identifiers, and sub-processors are legally bound by data processing terms restricting data reuse. None of the automated processing carried out by the Platform produces legal or similarly significant effects on you within the meaning of UK GDPR Article 22.

5. Advanced Geolocation Resolution and User Assumption of Risk

5.1 Technical Obfuscation Protocols

To facilitate localised peer discovery without exposing precise physical addresses, the Platform processes UK alphanumeric postcodes or US ZIP codes via the following structural parameters:

  • Coordinates Privacy Mask. Postcodes and ZIP codes are resolved to latitude and longitude values via external geocoding services. Raw coordinates are restricted to secure, server-side database environments and are never exposed to the client-side application or other users.
  • Three-Mile Privacy Floor. The Platform enforces a strict minimum precision floor of approximately three miles for any proximity data displayed to other users. Users are displayed within localised bands such as “about 3 miles away,” and inside the three-mile perimeter directional bearings are automatically suppressed, so no combination of distance and direction can be used to narrow another family’s home to a street, block, or neighbourhood.

5.2 User Assumption of Geolocation Risks

Legal Acknowledgement of Risk. While the Company enforces rigorous server-side technical measures to mask user proximity, the user explicitly acknowledges that no obfuscation method is mathematically infallible. Sophisticated third parties utilising external data correlation techniques or iterative physical movement could attempt to triangulate approximate areas. The user assumes all risks associated with participating in a proximity-based matching platform.

5.3 Independent Third-Party Geolocation Controllers

When you use the venue search feature, your approximate coordinates are sent via our servers to Google’s Places API through a secure connector gateway so that nearby venue results can be returned. Google acts as an independent data controller for that request. The Company disclaims all liability for Google’s independent processing, retention, or potential monetisation of such requests; please review Google’s privacy notice for full details.

6. Complete Third-Party Payment Processor Liability Firewall

Voluntary community-support donations and any optional booking deposits made through the Platform are processed natively by Stripe, a PCI-DSS Level 1 certified payment processing entity.

  • Zero Server Storage. Payment card numbers, card verification codes (CVC), and banking credentials bypass SameAcres infrastructure entirely. They are tokenised directly by Stripe within the user’s browser environment.
  • Exclusion of Transactional Liability. Stripe operates as an independent data controller for payment processing operations. The Company retains only tokenised references and transaction status metadata for accounting purposes. The Company assumes zero liability for financial losses, unauthorised data access, or payment processing breaches originating within Stripe’s infrastructure.

7. Comprehensive Inventory of Processed Data Types

  • Account Metadata: name, email address, password hash, regional territory, profile photo (optional). Lawful basis: Contract Performance (Art. 6(1)(b)).
  • Family Profiles: minor’s nickname, age band, voluntary interest keywords, support tags. Lawful basis: Consent / Contract Performance (Art. 6(1)(b)).
  • Communications: direct messages, friend requests, community forum posts, interaction history. Lawful basis: Contract Performance / Legitimate Interests.
  • Security & Logs: IP address, browser type / user-agent, timestamps, error logs. Lawful basis: Legal Obligation / Legitimate Interests (Art. 6(1)(f)).
  • Cookies: strictly necessary operational cookies. No behavioural tracking cookies deployed. Lawful basis: Contract Performance (Art. 6(1)(b)).

8. Permitted Data Sharing & Disclosure Categories

We share personal data exclusively with the following categories of recipients:

  • Bound Sub-processors. Cloud hosting infrastructure, email delivery services, geocoding engines, and payment processors operating under strict Data Processing Agreements (DPAs).
  • Legal & Regulatory Compulsion. Law enforcement, regulatory bodies, judicial courts, or government officials where mandatory under valid legal processes, or where necessary to defend the Company’s legal rights or prevent imminent physical harm.
  • Corporate Transition. A successor corporate entity in the event of a merger, acquisition, asset sale, or restructuring, provided the entity maintains equivalent or superior privacy standards.

The Company does not sell personal data, nor does it monetise user information via cross-context behavioural advertising under the CCPA / CPRA framework.

9. Cross-Border International Data Transfers

Where personal data originates within the UK or European Economic Area (EEA) and is transferred to jurisdictions lacking an adequacy decision (such as the United States), the Company secures such transfers through the execution of the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses (SCCs), supplemented by technical encryption measures where required.

10. Data Retention and Account Liquidation

We retain different categories of data for different periods, based on the purpose for which they were collected and the statutory obligations that apply:

  • Profile, family, message, and connection data. Retained for the active lifecycle of the user profile. Upon a user-initiated request to delete an account via profile settings, the Company will permanently delete or irreversibly anonymise associated personal data within 30 days, subject to standard identity verification.
  • Donation and payment transaction records. Tokenised payment references, transaction amount, currency, status, and timestamp are retained for up to five (5) years in order to satisfy UK tax, accounting, and financial audit statutes, and to preserve the statute of limitations for chargeback and fraud disputes. They are then deleted or irreversibly anonymised.
  • Security and access logs. Retained for a short rolling window for abuse prevention and incident investigation, then automatically purged.

Where a longer retention period is required by prevailing legal, regulatory, or financial statutes, that statutory period will prevail over the standard schedule set out above.

11. Statutory Rights, Identity Verification, and Vexatious Request Controls

Depending on your geographic jurisdiction (including the UK, EEA, or specific US states such as California), you may possess statutory rights regarding your data, including rights of access, correction, erasure, portability, objection, and processing restriction.

11.1 Proportionate Identity Verification

We apply proportionate identity verification before actioning statutory rights requests, in line with guidance from the UK Information Commissioner’s Office. Routine requests submitted from the registered account email address will not normally require additional documentation. For higher-risk requests — for example, bulk erasure, requests originating from a new or unverified email, requests concerning a minor’s profile made by someone other than the registered parent, or where account compromise is suspected — the Company may request supplementary evidence including government-issued identification before processing the request.

11.2 Statutory Exemptions & Request Denials

The Company reserves the right to deny erasure or restriction requests where the data is required for the defence of legal claims, compliance with statutory obligations, or where the request is determined to be manifestly unfounded, repetitive, or vexatious under UK/EU GDPR Article 12(5) or equivalent local laws. If permitted by law, an administrative fee may be levied to cover operational costs for excessive requests.

11.3 US State-Specific Disclosures (CCPA / CPRA)

For residents of California, the Company explicitly states that it has not sold personal information and has not shared personal information for cross-context behavioural advertising over the preceding twelve months. The Company does not utilise or disclose sensitive personal information for purposes other than those permitted under the CCPA / CPRA.

12. Security Architecture and Limitation of Liability

The Company deploys administrative, technical, and organisational safeguards including Transport Layer Security (TLS) encryption in transit, AES-256 encryption at rest on the managed database platform, row-level database security, and principle-of-least-privilege access matrices.

Security Disclaimer. No electronic transmission or storage architecture can achieve absolute infallibility. The user acknowledges that they transmit data at their own risk. The user remains entirely responsible for maintaining the strict confidentiality of their account credentials and password protocols.

13. Policy Modifications and Unilateral Updates

The Company reserves the right to unilaterally modify, amend, or rewrite this Privacy Policy at any time to reflect regulatory adjustments, platform updates, or enhanced defensive postures. Material updates will be highlighted via conspicuous in-app notifications or via the registered email address on file. Continued utilisation of the Platform following the posting of an updated policy constitutes formal acknowledgement of the updated terms.

14. Availability of Service and Data Preservation

The Platform is provided strictly as a complimentary, free-of-charge community service. The Company reserves the absolute, unilateral right to suspend, terminate, modify, or permanently discontinue the Platform, or any feature therein, at any time, for any reason, and without prior notice or liability to any user. In the event of service discontinuation, decommissioning, or closure of the Platform, the Company is under no obligation to preserve, maintain, or return any uploaded user data, profile content, peer connections, or message histories, and will securely delete or anonymise such data in accordance with our standard compliance retention protocols.