Back

Privacy Policy

Summary of Privacy Policy

What is the purpose of this Privacy Policy?
Who controls your personal data?
What personal data does the Club hold about you and how do we use it?
Who do we share your personal data with?
Will we change the purpose for which we process your personal data?
Do we operate automated decision making?
Do we carry out profiling?
What security measures do we put in place?
How long will we keep your information for?
What about children under 16?
Does the Club have a Data Protection Officer?
What about changes to this Privacy Policy?


What is the purpose of this Privacy Policy?

Aston Villa Football Club Limited, Aston Villa Women’s Football Club Limited and Aston Villa Foundation (together “the Club”) are committed to protecting the privacy and security of your personal data.

This Privacy Policy aims to give you information on how the Club collects and processes your personal data through your use of the Club’s websites and / or other services.

The Club’s websites and services include:

  • the Club’s Official Website at avfc.co.uk;
  • the Club’s VillaTV channel
  • the Club’s Event Website at www.villaparkstadium.com
  • the Club’s Ticket Office (online at tickets.avfc.co.uk, via phone or in store at the Ticket Office, Villa Park);
  • the Club’s Official Mobile Application;
  • the Club’s official social media channels (including, for example, Facebook, Twitter, Instagram, YouTube, LinkedIn, Sina Weibo, YouKu, AudioBoo, Google+).

It is important that you read this Privacy Policy together with any other privacy policy, statement or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your personal data. This Privacy Policy supplements any other notices we provide and is not intended to override them.

Back to top



Who controls your personal data

There are three different legal entities within the Club’s group of companies that process personal data:

  • Aston Villa Football Club Limited (Company Number 03375789)
  • Aston Villa Foundation (Company Number 08589263; Charity Number 1152848)
  • Aston Villa Women’s Football Club Limited (Company number 08414046)

This Privacy Policy is issued on behalf of these companies so when we mention "the Club", "we", "us" or "our" in this Privacy Policy, we are referring to the relevant company in the Club’s group that is responsible for processing your personal data.

Which company controls your personal data will depend on the way you interact with the Club or the services you are using. In most cases, Aston Villa Football Club Limited will be the data controller.

Aston Villa Women’s Football Club Limited runs the Aston Villa Women first team and women’s development teams. In most cases, Aston Villa Football Club Limited or Aston Villa Women’s Football Club Limited (depending on the context) is the data controller in respect of any personal data processed in connection with the Aston Villa Women’s teams.

Aston Villa Foundation runs the Club’s soccer schools, community benefit programmes matchday raffles. When you use these services, or any other services offered by Aston Villa Foundation, then Aston Villa Foundation will be the data controller.

Our contact details are:

Email address: dpo@avfc.co.uk

Postal address: Legal Department, Aston Villa Football Club, Villa Park, Birmingham, B6 6HE

Back to top





The personal data the Club holds about you and how we use your personal data

Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

Information collected by the Club

The Club may collect some or all of the following personal data about you and may use it as follows:

Activity and the personal data we collect

Why we collect that personal data

The lawful basis for processing your personal data

When you create an account with us, use our services or sign up to receive communications from the Club, we will collect the identity and contact details that you provide us. This may include your name, title, date of birth, postal address, email address and telephone number(s). We will also collect your login information such as username and password. We may assign a unique identification number (known as a FanID) to your account.

To provide you with a personalised account when making use of the Club’s services.

To provide you with information, products and services you have requested, to tell you about the status of requests or to resolve any issues that have arisen).

To personalise communications with you (including marketing communications, where you are opted in to receive them).

 

Performance of a contract / potential contract with you.

 

 

Where you purchase a Matchday or season ticket (including half season tickets), ticketing memberships services or buy other products and services from us from us, we collect details of your identity (which may include your image / photograph), contact details, account information, purchase history and marketing preferences.

To provide you with tickets, products and services you have purchased and to maintain a record of your purchase history.

To conduct analysis of how supporters use our products / services so that we may to develop and improve our products and services, and develop our business (we may use third party suppliers to help us to this, and may share your personal data with those third party suppliers for that purpose).

We may share your data with the police or other law enforcement or governmental agencies, football Governing Bodies (for example The FA, the Premier League and The English Football League) and other football clubs in the event that we ban you from attending our matches or other events (for further information, see Section 5 below).

In addition, we may share your data with Fourth Wall FEP1 Limited in order to assist the Club to fulfil any ticketing membership products or services that you have purchased from the Club.

Performance of a contract / potential contract with you.

 

Necessary for our legitimate interests (for sale of a ticket or other products and services, to provide a dedicated seat and to control the number of individuals in the stadium; to ensure tickets for high demand fixtures are limited to active / loyal supporters and to support authorities (the police and other law enforcement agencies, the Health and Safety Executive and other government agencies) football Governing Bodies and other football clubs in delivering a safe and secure event; to study how supporters use our products/services; to develop them and to develop our business).

 

 

Where you purchase tickets for away matches from us, we collect details of your identity (which may include an image of you), contact details, account information, ticket purchase history and marketing preferences.

To provide you with tickets you have purchased and to maintain a record of your purchase history.

To provide other clubs with details of any away tickets you have purchased to attend their stadium.

We may share your data with the police or other law enforcement or governmental agencies, football Governing Bodies (for example The FA, the Premier League and The English Football League) and other football clubs in the event that we ban you from attending our matches or other events (for further information, see Section 5 below).

Necessary for both our and the other club’s legitimate interests (ensuring supporters who have purchased valid tickets are permitted entry to the other club’s stadium, ensuring safety and security for all staff and visitors to the other club’s premises; to identify, protect against and report actual, potential or suspected fraud or criminal activity; to respond to claims).

 

When purchasing a product or service from us we will also collect your payment card details and, if that purchase is not made in person (for example you purchase online or over the phone), we will also collect your billing address. We will also collect details of your historic payment method and purchase history. We do not retain payment card details once the payment has been processed.

To collect payment from you for products and services you have purchased.

 

Performance of a contract / potential contract with you.

Necessary for our legitimate interests (to recover debts due to us).

 

When purchasing a non-football related product or service via the website www.villaparkstadium.com, we will collect your name, email address, phone number and the event type that you are interested in.

To respond to your enquiry, to contact you to assist you with your enquiry, and to send you marketing information (if you have opted in to receive it). In addition, if relevant, to share your personal data with Compass Contract Services (UK) Limited (trading as “Levy Restaurants”) to allow them to contact you to assist you with your enquiry, and to send you marketing information (if you have opted in to receive it). To understand how Levy Restaurants will use your personal data please refer to their privacy policy at https://www.compass-group.co.uk/privacy-notice 

Performance of a contract / potential contract with you.

Consent.

Where you sign up for auto renewal of your season ticket or automatic purchase of cup tickets and provide your payment card details and billing address, those details will be stored (by our third party payment gateway provider) for as long as you are a member of the relevant scheme (or until you update those payment details with new details). Once the details have been entered and provided to our third party payment gateway provider, the Club cannot access these details (they are masked).

To collect payment from you for products and services you have purchased.

 

Performance of a contract / potential contract with you.

Necessary for our legitimate interests (to recover debts due to us).

 

If you enter a competition, prize draw or other promotion that we may run, we will collect information that you may give us when you enter (or in any follow up communications we have with you), such as your name, Fan ID, contact details or social media handle(s), date of birth and proof of age (if relevant to entry), proof of address (if relevant to entry) and details of the prize won.

 

To administer the competition, prize draw or promotion and (if you are successful) to provide you with your prize.

 

 

Performance of a contract / potential contract with you.

 

As you interact with our websites and mobile applications, or use our WIFI services, we automatically collect data about your equipment, network connection details, browsing actions and patterns. We collect this personal data by using cookies, and other similar technologies. We may also receive such information about you if you visit other websites employing our cookies. Please click HERE to see our cookie policy for further details.

 

To use data analytics to improve our websites, products/services, marketing, information services, supporter relationships and experience.

To study how supporters use our products/services, to develop them and to develop our business.

To monitor the use of our WIFI network by guests visiting our premises.

Necessary for our legitimate interests (to define types of supporters for our products and services; to study how supporters use our products/services; to keep our websites and products / services updated and relevant; to develop our business and inform our marketing strategy and information services strategy; for security).

Where we communicate with you by email, we collect details of whether you opened that email and / or interacted with any of the content within that email.

 

To analyse, personalise and improve our communications, marketing, information services and supporter relationships.

 

Necessary for our legitimate interests (to understand relevance of our email communications; to develop our supporter experience; to develop our business; and inform our marketing strategy and information services strategy).

We may collect your age, contact details and marketing preferences to tell us how you prefer to be contacted when we communicate with you, or when you unsubscribe from receiving marketing communications. If you do not consent to any marketing, we also keep a record of this.

To send age appropriate marketing communications to supporters and to provide supporters with information services about the Club and products / services they have purchased.

Consent

Necessary for our legitimate interests (to provide age appropriate information, information services and marketing to supporters, to grow our supporter database; to develop our business; and inform our marketing strategy and information services).

If you have consented to receive Digital Advertisements, we will pass your personal data, in encrypted form, to social media platforms and other third party organisations in order for them to show advertisements regarding Club news, products and services to you on our behalf. If you do not consent to Digital Advertisements we will also keep a record of this. This consent does not cover campaigns where a social media platform or other third party organisation may use the personal data that they may hold about you to show you advertisements regarding Club news, products and services. Whilst your personal data will not be passed onto any such organisations by the Club for those purposes, you may still receive digital advertisements, including about the Club, if you have consented to receive the same from such organisation.

To send age appropriate marketing communications to supporters and to provide supporters with information services about the Club and products / services.

Consent

Necessary for our legitimate interests (to provide age appropriate information, information services and marketing to supporters, to grow our supporter database; to develop our business; and inform our marketing strategy and information services).

We may collect your child’s name and age, photographs of them, film or video recordings of them, their medication details and your name, relationship to child and contact details in connection with your child’s mascot experience and for use in marketing communications. If you do not consent to any marketing, we will also keep a record of this.

To administer the mascot experience, in particular if we need to contact you in the case of an emergency. For the child’s first name and image to be used in connection with publicity and marketing purposes for the Club to provide supporters with information services about the Club and its products and services.

Performance of a contract / potential contract with you

Consent

Necessary for our legitimate interests (to provide age appropriate information, information services and marketing to supporters, to grow our supporter database; to develop our business, ensuring safety and security for all staff and visitors to our premises; to respond to any claims and to claim from our insurers).

To comply with our legal obligations.

If you contact us, for example with an enquiry, comment or complaint, we collect any personal information you may give in such correspondence with us.

 

To investigate, review and respond to your enquiry, comment or complaint.

Necessary for our legitimate interests (supporter relations; to improve our information services, products, services and supporter experience; and to develop our business).

If you call us, for example to buy a match ticket, season ticket, membership, hospitality, or event, or in relation to a ticketing, hospitality or event enquiry, we may record the phone call

 

For training or monitoring purposes and to respond to any enquiry, comment, or complaint.

Necessary for our legitimate interests (supporter relations; to improve our information services, products, services and supporter experience; and to respond to enquiries and complaints).

For security and safety of the Club and those visiting Club premises, the Club uses CCTV in and around Villa Park and the Club’s other premises (this includes the Club’s training ground and car parks) and certain streets surrounding the Club’s premises and so if you attend either of those premises your image may be captured on CCTV recordings. The Club’s security staff and matchday stewards may also use body worn cameras which may also capture your image when attending our premises.

 

To monitor and review any accidents or incidents and for the safety and security of visitors to our premises.

We may share CCTV with the police or other law enforcement or governmental agencies, football Governing Bodies (for example The FA, the Premier League and The English Football League), insurance companies and / or the Club’s service providers (including the Club’s Catering and Events Partner and Retail Partner) where such sharing necessary and in accordance with data protection (for example, where sharing CCTV is necessary for the purposes of the prevention or detection or crime, the apprehension or prosecution of offenders or in relation to prospective or ongoing legal proceedings).

Necessary for our legitimate interests (ensuring safety and security for all staff and visitors to our premises; to improve our safety / security operations; to identify, protect against and report actual, potential or suspected fraud or criminal activity; to respond to claims).

To comply with our legal obligations.

If you have an accident whilst at our premises, we may record details of your identity and contact details, as well as details of the accident, any injury sustained, treatment received and any other relevant factors or medical conditions.

 

To maintain a record of any accidents or incidents in line with legislation and good industry practice, for our insurance purposes and to protect the Club in the event of any future claims or legal action.

Necessary for our legitimate interests (ensuring safety and security for all staff and visitors to our premises; to respond to any claims and to claim from our insurers).

To comply with our legal obligations.

 

If you are involved in any security related incident during a Matchday (whether at the Club’s stadium or at any other stadium or event which the Club participates in), we will keep details related to that incident, for example the identity and contact information of people involved or potential witnesses, details of the incident and copies of any relevant video footage.

 

To maintain a record of any accidents or incidents in line with legislation and good industry practice, for our insurance purposes and to protect the Club in the event of any future claims or legal action.

We may share your data with the police or other law enforcement or governmental agencies, football Governing Bodies (for example The FA, the Premier League and The English Football League) and other football clubs in the event that we ban you from attending our matches or other events (for further information, see Section 5 below).

Necessary for our legitimate interests (ensuring safety and security for all staff and visitors to our premises; to improve our safety / security operations; to identify, protect against and report actual, potential or suspected fraud or criminal activity; to respond to claims and to claim from our insurers).

To comply with our legal obligations.

 

We may collect details of your identity (including image from CCTV or other camera footage) together with any relevant details of any convictions, orders, arrests or suspected involvement in incidents which may impact on the safety or security of any Matchdays or other events the Club takes part in.

To ensure safety and security for all staff and visitors to our premises.

We may share your data with the police or other law enforcement or governmental agencies, football Governing Bodies (for example The FA, the Premier League and The English Football League) and other football clubs in the event that we ban you from attending our matches or other events (for further information, see Section 5 below).

Necessary for our legitimate interests (ensuring safety and security for all staff and visitors to our premises; to identify, protect against and report actual, potential or suspected fraud or criminal activity; to respond to claims).

To comply with our legal obligations.

If you attend an event hosted or arranged by the Club, we may take photographs and / or film or video recordings of the event, which may include your image.

 

For use in marketing materials and / or media coverage of the event.

Depending on the event, we may share these details with a third party (for example, Aston Villa Foundation may share copies of images with its grant funders, when the event was related to a grant funded project). We will tell you if we plan to do this and you will have the ability to opt out.

Where consent is sought prior to or at the relevant event: consent.

Where the Club deems it inappropriate to seek consent prior to or at the relevant event: necessary for our legitimate interests (to develop our business).

Regardless of the basis upon which this personal data is processed, the Club will respect a request not to use your image in any future marketing materials.

If you attend the Club’s premises (for example the  Villa Park stadium or Bodymoor Heath training ground) for a match or other event (or attend as part of any preparation for such match or event), the Club may need to collect your identity and contact information (such as name, company you are from, purpose of your visit and contact details). We may also need to collect any other information relevant to ensuring the safety and security of our premises and the people who use it.

We collect this information to comply with our obligation to provide a safe working environment and to fulfil our duty of care to those visiting and working at the Club’s premises. We may need to share your data with our football Governing Bodies (for example The FA, the Premier League and The English Football League) and Regulatory Bodies (for example the Health and Safety Executive), where necessary for the purposes of competition integrity.

We may also share your data with the police or other law enforcement or governmental agencies, football Governing Bodies (for example The FA, the Premier League and The English Football League) and other football clubs in the event that we ban you from attending our matches or other events (for further information, see Section 5 below).

Necessary for our legitimate interests (operating the stadium in a safe and lawful manner and ensuring safety for all staff and visitors to our premises).

To comply with our legal obligations.

As a result of the Covid-19 pandemic and the Club’s related obligations and protocols when permitting people to access the Club’s premises, if you attend the stadium for a match or other event (or attend as part of any preparation for such match or event) or attend the Club’s training ground, the Club may need to collect information about your health.

We collect this information to with our obligation to provide a safe working environment and to fulfil our duty of care to those visiting and working at the Club’s stadium and to make an assessment of whether you are fit and well enough to be permitted access to the stadium. We may need to share your data with our football Governing Bodies (for example The FA, the Premier League and the English Football League), but only where necessary for the purposes of competition integrity. 

Necessary for our legitimate interests (operating the stadium in a safe and lawful manner and ensuring safety for all staff and visitors to our premises).

To comply with our legal obligations.

 

Information received from third parties or publicly available sources

We may also receive personal data about you from various third parties and public sources as set out below. Click HERE to see a list of the names of our current third-party service providers.

 

Activity and the personal data we collect

Why we collect that personal data

The lawful basis for processing your personal data

The Club’s official retail channels (which includes over the phone, and online at shop.avfc.co.uk) are operated by Fanatics (International) Limited (“Fanatics”). When you buy products or services via those channels, we may receive information from Fanatics about your identity, contact details, purchase history and marketing preferences (only where you have given Fanatics consent to do so). You can view Fanatics’ privacy policy in relation to the operation of the Club’s official retail channels at:

https://shop.avfc.co.uk/en/astonvilla-privacy-policy/ch-1422

 

To market to you in line with your marketing preferences.

 

To study how supporters use our products/services, to develop them and to develop our business.

Consent

Necessary for our legitimate interests (to study how supporters use our products and services; to develop our products and services; and to develop our business).

 

 

We may receive details of your identity, contact details, account information, ticket purchase history and marketing preferences from the provider of our Online Ticket Office and back office ticketing software. They will tell us if you have purchased a ticket to any match or event at the Club’s stadium or for an away match in which one of the Club’s teams takes part.

 

To provide you with tickets you have purchased and to maintain a record of your ticket purchase history.

Performance of a contract / potential contract with you.

 

Necessary for our legitimate interests (to study how supporters use our products/services; to develop them and to develop our business).

 

If you access the Club’s WIFI service, we collect details of your identity (name, email address, post code, confirmation of being over 18) and marketing preferences as part of your registration for our WIFI service from the provider of our WIFI registration services.

Our third party provider also collects details of your browsing session, including the device and browser you are using and sites you visit whilst using our WIFI services.

To provide you with WIFI access at the Club’s premises.

To market to you in line with your marketing preferences.

 

To analyse and understand who uses the Club’s WIFI services.

For security and monitoring to ensure compliance with the law and terms and conditions of use of the services provided.

 

Performance of a contract / potential contract with you.

Consent

 

 

Necessary for our legitimate interests (supporter relations; to improve products / services / supporter experience and to develop our business; and to identify, protect against and report actual, potential or suspected fraud or breaches of our terms and conditions of service or criminal activity).

In periods where we expect high demand for tickets (e.g. key matches or periods where season tickets go on sale), we may use the services of a call centre to assist us with ticket purchases over the telephone. Where this occurs, you may be directed to a call centre when you call the Club’s Ticket Office. They will collect your identity, contact and payment details and provide them to us / our Ticket Office software provider to process the purchase.

 

To ensure your call is answered as quickly as possible; and to provide you with tickets you have purchased.

Performance of a contract / potential contract with you.

Necessary for our legitimate interests (to study how supporters use our products/services; to develop them and to develop our business).

We may receive details of your identity, contact details and account information received from the provider of our Pride Rewards scheme and e-cash scheme to tell us about your membership and use of the scheme (including products / services you have purchased from third party affiliates using your Pride Rewards e-cash card).

To administer the Pride Rewards and E-cash scheme.

To analyse and understand how supporters use the Pride Rewards and E-cash scheme.

Performance of a contract / potential contract with you.

Necessary for our legitimate interests (supporter relations; and to improve products / services / supporter experience and to develop our business).

We may receive details of your identity, contact details and transaction information from our secondary ticketing partner to tell us about any tickets you have purchased or sold on our official secondary ticketing platform.

 

To process any ticket sale / purchase made through our secondary ticketing partner.

Performance of a contract / potential contract with you.

 

When you use your Matchday ticket, season card or membership card to gain access to the Club’s facilities services at Villa Park (the Club’s stadium), we receive details of usage of your tickets from the providers of our stadium access control system.

 

To provide you with access to the Club’s stadium (Villa Park) and the Club’s facilities / services.

 

To analyse and understand how and when our supporters use our facilities / services.

Performance of a contract / potential contract with you.

Necessary for our legitimate interests (supporter relations; and to improve products / services / supporter experience and to develop our business).

When you purchase a product or service, we receive your contact details, payment details and details of the transaction from our payment gateway provider.

 

To collect payment from you for products and services you have purchased.

Performance of a contract / potential contract with you.

Necessary for our legitimate interests (to recover debts due to us).

If you have an accident whilst at our premises and are treated by a third party (for example, St John’s Ambulance), we may receive details of your identity and contact details, as well as details of the accident, any injury sustained, treatment administered and any other relevant factors or medical conditions.

 

To maintain a record of any accidents or incidents in line with legislation and good industry practice, for our insurance purposes and to protect the Club in the event of any future claims or legal action.

 

Necessary for our legitimate interests (ensuring safety and security for all staff and visitors to our premises; to respond to any claims; and to claim from our insurers).

To comply with our legal obligations.

We may receive details of your identity (which may include your image) from government and law enforcement authorities, football Governing Bodies (such as The FA, the Premier League and the English Football League) and / or other football clubs together with any relevant details of any convictions, orders, arrests, bans from other football or sporting events or suspected involvement in incidents which may impact on the safety or security of any Matchdays or other events the Club takes part in. 

 

To ensure safety and security for all staff and visitors to our premises.

Necessary for our legitimate interests (ensuring safety and security for all staff and visitors to our premises; to identify, protect against and report actual, potential or suspected fraud or criminal activity; to respond to claims).

To comply with our legal obligations.

We may receive details relating to any conduct, act or statement that is abusive, insulting, intimidating, offensive or discriminatory which has been directed to the Club or any member if its staff, player, match official or other individuals attending a Club football match, whether such conduct, act or statement takes place within the Club’s stadium, otherwise in person or online. Such information may be received from government and law enforcement authorities, football Governing Bodies (such as The FA, the Premier League and the English Football League) and / or other football clubs)

To meet the commitment made by the Premier League and its member football clubs (including Aston Villa Football Club) to ensure that any individual found to have engaged in discriminatory or abusive conduct is not only prevented from attending football matches at the stadium of the club that they support, but all Premier League football matches.

Necessary for our legitimate interests and the legitimate interests of the Premier League, its member football clubs and the wider public (preventing abusive and discriminatory behaviour).

If you are an away fan attending the Club’s stadium (Villa Park) and have purchased your tickets via the away club, we may receive details of your name and ticket details from that away club.

To ensure safety and security for all staff and visitors to our premises.

Necessary for both our and the away club’s legitimate interests (ensuring supporters who have purchased valid tickets are permitted entry to the Club’s stadium, ensuring safety and security for all staff and visitors to our premises; to identify, protect against and report actual, potential or suspected fraud or criminal activity; to respond to claims.

When you agree to receive notifications from our websites and / or mobile applications, our third party notification services providers will collect information about your device, the pages on our websites and / or mobile applications that you visited, the start and end time of your session(s) and the location of your device when visiting our websites and / or using our mobile applications. This information is collected on an anonymised basis (whilst this information is linked to the device you used, we do not link that information to an individual or an IP address).

To provide tailored notifications to you based on your websites and mobile applications usage, device type and location (subject to you providing your consent to receive notifications). 

Consent

If you agree to take part in an online Club survey or other data capture exercise hosted by a third party (for example, Survey Monkey), the Club will receive the information that you provide as part of that survey

To review and analyse the results of the survey or other data capture exercise. To administer any prize draws or competitions that are related to the survey or other data capture exercise. There may also be other purposes for collecting the personal data, which will be specified within the form used to collect the personal data.

Generally, the lawful basis for processing personal data captured via a survey or other data capture exercise will be consent.

There may a separate lawful basis – if so, details will be set out in the form used to collect the personal data.

Specialist data providers provide us with profile information about our supporters. We use this to segment and understand our supporters and the way we communicate with them (including any marketing we may send).

Currently, we use two companies to do this: Experian Limited and X Channel Marketing Limited– you can visit their websites and view their privacy policies at www.experian.co.uk and https://www.xcm-uk.com/).

To understand supporter preferences. To provide supporters with relevant information and improve our products and services.

Necessary for our legitimate interests (supporter relations; and to improve products / services / supporter experience and to develop our business).

Data analytics providers provide us with: (a) data on supporters’ behaviour on our websites and mobile applications (e.g. how much time supporters spend on which pages / sections, which links they choose to click, what supporters do and don’t like, etc.); and (b) devices used to access our websites and mobile applications (in particular device's IP address (in an anonymised form), screen size, type (unique device identifiers), browser data, geographic location (country only), preferred language).

Currently we use Hotjar Limited to do this for website data and Shift6 Limited (trading as “AppSee”) for mobile application data.

 

Hotjar, AppSee and the Club will never use this information to identify individual supporters or to match it with further data on an individual supporter.

 

For further details, please see Hotjar’s website and privacy policy at www.hotjar.com and AppSee’s website and privacy policy at www.appsee.com

To understand the needs of supporters and to optimise service and experience.

Necessary for our legitimate interests (supporter relations; and to improve products / services / supporter experience and to develop our business).

The Club’s Catering and Hospitality Services partner (currently Compass Contract Services (UK) Limited, trading as Levy Restaurants) operates “frictionless retail units at the Club’s Villa Park Stadium. Where you use one of these frictionless retail units, your personal data will be collected and processed by Levy Restaurants.

Data collected by Levy Restaurants and processed pursuant to Levy’s privacy notice (www.compass-group.co.uk/about/privacy-notice/).

Data collected by Levy Restaurants and processed pursuant to Levy’s privacy notice (www.compass-group.co.uk/about/privacy-notice/).

Back to top



Sharing personal data with third parties

The Club may share your personal data with third parties, including other entities in the wider Club Group, where required by law, where it is necessary to administer the working relationship with you, where the Club has another legitimate interest in doing so.

 

Transfers to Third Party Service Providers

The Club uses third parties to help us provide you with products and services. We will share your personal details with those third parties where it is relevant to the service we are providing to you.

We may also share your personal data with third party suppliers to assist us in analysing how supporters use our products / services, so that we may to develop and improve our products and services, and develop our business.

Details of the Club’s third party service providers can be found HERE.

Transfers pursuant to the events website www.villaparkstadium.com

Where you have provided data to the Club on the events website, www.villaparkstadium.com, the Club will share your data with Compass Contract Services (UK) Limited (trading as “Levy Restaurants”).

Transfers within the Club’s group of companies

 The Club may share your personal data with other entities in its group as part of its regular reporting activities on Club performance, in the context of a Club reorganisation or restructuring exercise, for system maintenance support and hosting of data.

Transfers to law enforcement,other agencies and other third parties in connection with security, crime, law enforcement and / or legal claims

 We may share information with the police or other law enforcement or governmental agencies where necessary:

  • for maintaining safety and security at the Club’s premises and matches and other events that the Club takes part in; or
  • for the prevention or detection of crime or the apprehension or prosecution of offenders.

This includes sharing personal data with the police or other law enforcement or governmental agencies in connection with the commitment made by the Premier League and each of its member football clubs (including Aston Villa Football Club) to ensure that any individual found to have engaged in discriminatory or abusive conduct is not only prevented from attending football matches at the stadium of the club that they support, but all Premier League football matches.

The Club may also share information with other relevant third parties, including:

  • third parties who use the Club’s premises (such as the Club’s Catering and Hospitality Services Partner (currently Compass Contract Services (UK) Limited), the Club’s Official Retailer (currently Fanatics International Limited) and the Club’s In Stadium where such information is relevant to their operations or use of the Club’s premises; and
  • insurance companies in connection with insurance claims about which the Club may hold CCTV footage or other relevant information

where such sharing is necessary:

  • for maintaining safety and security at the Club’s premises and matches and other events that the Club takes part in; or
  • for the prevention or detection of crime or the apprehension or prosecution of offenders.

Transfers to other football clubs

We may share ticketing information with other football clubs where the Club is taking part in a match at their stadium, to ensure that any issues with the Club’s travelling fans who have purchased tickets can be resolved quickly and easily or do address any safety or security issues which may arise.

If the Club has banned you from attending football matches or events which are held at the Club’s premises or the Club participates in, we may also transfer your personal data to other football clubs. This includes sharing personal data with other football clubs in connection with the commitment made by the Premier League and each of its member football clubs (including Aston Villa Football Club) to ensure that any individual found to have engaged in discriminatory or abusive conduct is not only prevented from attending football matches at the stadium of the club that they support, but all Premier League football matches.  The personal data that we may share may include your name, date of birth, contact details and image (where we have such personal data).

 

Transfers to Governing Bodies

We may need to share information with our football governing bodies (for example, The Football Association, the Premier League and / or the English Football League) where required pursuant to any regulations we may be subject to by those Governing Bodies.

We may also transfer your personal data to our football Governing Bodies where the Club has banned you from attending football matches or events which are held at the Club’s premises or the Club participates in. This includes sharing personal data with Governing Bodies in connection with the commitment made by the Premier League and each of its member football clubs (including Aston Villa Football Club) to ensure that any individual found to have engaged in discriminatory or abusive conduct is not only prevented from attending football matches at the stadium of the club that they support, but all Premier League football matches.  The personal data that we may share may include your name, date of birth, contact details and image (where we have such personal data).

 

Transfers to Lions Clubs / chairman

If you create an account on the Club’s official website to register to join an Official Lions Club, we will pass your information (name and email address) to that Lions Club as part of your application. The Lions Club will be the data controller of that information in respect of anything that Lions Club does with it. The Lions Club will tell us whether or not your application is successful and we will contact you to tell you. If successful, we will keep a record of this so that we can give you access to any Club benefits you may be entitled to receive as an Official Lions Club member.

 

Transfers to your friends and family (when connected)

If you (or another person on your behalf) links your ticketing account with another person’s ticketing account, we will share your personal data (name, FanID, ticket purchase history and ticket use) with that person (via their Club Ticketing Account).

We advise that you keep your FanID secure and only link or permit links with close friends and family that you trust to have access to this information. You can find out who is linked to your account or has linked your account to theirs and add / edit / remove links through your account profile by logging in at tickets.avfc.co.uk.

 

Transfers to other third parties

The Club may share your personal data with other third parties, for example in the context of the possible sale or restructuring of the Club’s business. In this situation the Club will, so far as possible, share anonymised data with the other parties before the transaction completes. Once the transaction is completed, the Club will share your personal data with the other parties if and to the extent required under the terms of the transaction.

 

The Club may also need to share your personal data with a regulator or to otherwise comply with the law.

 

Transfers outside of the United Kingdom

This may occur when the third party that we share your data with is situated outside the United Kingdom, or they use servers or other cloud services based outside the UK. If the Club does so, the Club will do its best to ensure a similar degree of protection in respect of your personal data as if the transfer was made within the UK.

 

Ensuring security when transferring personal data to third parties

All of the Club’s third-party service providers and other entities in the Club’s group are required to take appropriate security measures to protect your personal data in line with the Club’s policies and the law and to treat the information confidentially. The Club does not allow the Club’s third-party service providers to use your personal data for their own purposes. The Club only permits them to process your personal data for specified purposes and in accordance with the Club’s instructions.

Back to top



Change of Purpose

The Club will only use your personal data for the purposes for which we collected it, unless the Club reasonably considers that it needs to use it for another reason and that reason is compatible with the original purpose. If the Club needs to use your personal data for an unrelated purpose, the Club will notify (by updating this Privacy Policy) and explain the legal basis for doing so.

Please note that the Club may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

Back to top



Automated Decision-Making and profiling

Automated decision-making

The Club does not currently operate any automated decision-making. However, we do carry out profiling (see below).

Please note that V12 Retail Finance, the company which offers a finance solution for the Club’s season ticket purchasers may use automated decision-making when deciding whether or not to offer you credit. The Club has no influence or involvement in this. Please refer to V12 Retail Finance’s website for further information. V12 Retail Finance’s Privacy Notice can be found at https://www.v12retailfinance.com/privacy-policy (please note this will take you to a third party website – the Club is not responsible for V12 Retail Finance’s website).

Profiling

We do use specialist data providers to provide us with profile information about our supporters, by grouping people who are likely to share similar demographics, lifestyles or behaviours (sometimes referred to as “segmentation”). The data used by our providers for this purpose comes from a combination of both individual and household data and aggregated data (such as postcodes, towns or regions). We use segmentation data to better understand our supporters and their likely preferences. This information may influence the way we communicate with our supporters (including any marketing we may send).

Currently, we work with two companies to do this: Experian Limited and X Channel Marketing Limited. You can visit their website and view their privacy policy at www.experian.co.uk and https://www.xcm-uk.com/.

You are entitled to object to us carrying out this profiling using your personal data. If you wish to object, please email dpo@avfc.co.uk or write to the Club at the postal address given in Section 2. 

The Club may also apply flags to supporter accounts based on its own internal analysis. For example:

  • the Club's current season ticket holders may have a 'flag' applied to their account which states that a current season ticket is registered with that account; or
  • recent customers of the AVFC Online Store may have a flag applied to their account which states that they have recently purchased a product from the AVFC Online Store.

The Club uses such flags:

  • to tailor any marketing communications that we send to our supporters who have opted in to receive marketing communications (for example, to send an early bird ticket price special offer to our existing season ticket holders);
  • to tailor any communications that we send in connection with a product or service that a supporter has purchased from the Club (for example, to notify a match ticket purchaser of a change in the arrangements for a match); and
  • on an aggregated and anonymised basis in internal analysis to understand our fans (e.g. to identify how records have both the ‘current season ticket holder flag’ and the ‘recent retail purchase’ flag).

The Club’s systems do not currently have the functionality to permit you to opt out of the placing of flags on a your account or the use of flags on an aggregated and anonymised basis in internal analysis. However, you can:

  • opt out from receiving marketing communications at any time (which would prevent the use of flags in connection with sending marketing communications);
  • request deletion of your personal data (which would include any flags associated with their personal data). Note that this would result in the deletion of any Digital Account, FanID and ticket purchase history which you may have with the Club and you may be required to register for a new Digital Account and / or FanID should you wish to access the Club’s products or services in the future (for example, tickets, memberships or VillaTV).

Back to top



Data Security

The Club has put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, the Club limits access to your personal data to those employees, agents, consultants and other third parties (referred to in section 5) who have a business need to know. They will only process your personal data on the Club’s instructions and they are subject to a duty of confidentiality.

The Club has put in place procedures to deal with any data security breach and will notify you and any applicable regulator of a breach where the Club is legally required to do so.

Back to top



How long will the Club keep your information for?

The Club will only retain your personal data for as long as necessary to fulfil the purposes it collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. The Club has in place a Data Retention Policy which includes recommended data retention periods for your personal data.

In some circumstances the Club may anonymise your personal data so that it can no longer be associated with you, in which case the Club may use such information without further notice to you.

  • We keep information related to your Official AVFC Website account for as long as your account remains active. To delete your Official AVFC Website Account, please contact the Club using the details provided in section 2.
  • We keep supporter personal data in our Club database for the longer of:
  • 2 years from the supporter’s last known interaction with the Club; or
  • in the case of Club ticket purchases, 5 seasons since the last purchase.

As we review our databases on a quarterly basis, personal data may be retained for slightly longer than the periods specified above, until the next quarterly review.

  • Where you have opted in to receive marketing, we retain details of your consent and shall continue to market to you in accordance with your preferences for a period of 2 years from your last interaction with the Club or until you opt out, whichever is earlier.
  • For the purposes of retaining personal data, we currently regard the following as interactions with the Club: attending a Club match; logging into your online account; purchasing a product from the Club’s Online Store; opening an email from the Club. We may update this from time to time, depending on the data available to the Club to capture interactions.
  • We keep information which may relate to accidents or injuries for a period of 3 years from the date of the last entry in the log in which it is recorded (or, where the accident involves a child/ young adult, until that person reaches the age of 21, if longer). We do this in case there are any queries and to respond to any claims in relation to that incident. If we are aware that claim or legal action is or ongoing in relation to an accident or injury, we will keep relevant information until that claim or legal action has concluded.
  • We keep other information which may relate to a claim or legal action for a period of 7 years (or longer, if a claim or legal action is in progress). We do this in case there are any queries and to respond to claims in relation to that incident.
  • We keep CCTV footage for a period of 28 days following the recording (or longer if required in connection with an ongoing issue or if required by law).

Back to top





Children under the age of 16

We expect parents and guardians to supervise their child when they access the Club’s websites, mobile applications and other services provided by the Club.

If you are under the age of 16, you must ask your parent / guardian for consent before you access the Club’s services or provide personal data or other information to the Club.

Back to top



Data Protection Officer

The Club’s designated Data Protection Officer (dpo@avfc.co.uk) will oversee compliance with this Privacy Policy. If you have any questions about this Privacy Policy or how the Club handles your personal data, please contact the Club using the details given in section 2.

Whilst we hope you would contact the Club (using the details provided in section 2) with any issues first, you have the right to make a complaint at any time to the Information Commissioner's Office (“ICO”), the UK supervisory authority for data protection issues. You can contact the ICO online HERE, or by post at:

Information Commissioner's Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

Back to top



Changes to this Privacy Policy

We will update this Privacy Policy from time to time, so please check this Privacy Policy periodically, so you are aware of any updates. The date below records when this Privacy Policy was last updated.

January 2025

Back to top



Service providers & Official Partners

3rd party service providers who process personal data
Official Partners / Pride Rewards Affiliates

The 3rd party service providers list is updated from time to time. Please check back periodically for any changes.

 Last updated: March 2023