Privacy
Last updated: April 2026
1. Who we are
Airsoft.Bio (https://airsoft.bio) is a community platform for airsoft players, operated by M Smith, based in the United Kingdom.
When we say "we", "us", or "our" in this policy, we mean the operators of Airsoft.Bio. We are the data controller for the personal data we process through the platform.
For data protection queries, contact us at: hello@airsoft.bio
2. What data we collect and why
Account information
What: Email address, chosen callsign/handle, and profile details you provide (bio, location, playstyle, social links).
Why: To create and maintain your account, authenticate you, and display your profile to other users.
Legal basis: Contractual necessity (we need this to provide the service you signed up for).
Profile content
What: Loadout items, game day logs, team memberships, images you upload, and team information.
Why: To provide the core platform features and display your content to other community members based on your visibility settings.
Legal basis: Contractual necessity.
Messages
What: Direct message content sent between users.
Why: To provide the messaging feature. We do not proactively read or monitor DM content. However, if a message is reported, we will access the reported content to review it and take appropriate action.
Legal basis: Contractual necessity for providing the messaging feature. Legitimate interests for reviewing reported content (our interest in keeping the platform safe and complying with our legal obligations).
Moderation and safety data
What: Reports submitted by users, reported content, moderation decisions, enforcement actions, and associated metadata (timestamps, user IDs, reason for report, action taken).
Why: To review reports, enforce our Terms of Service and Community Guidelines, maintain records of moderation activity, and comply with our obligations under the Online Safety Act 2023.
Legal basis: Legal obligation (the Online Safety Act 2023 requires us to maintain records of safety measures and moderation activity). Legitimate interests (keeping the platform safe).
Analytics data
What: Anonymous, aggregated usage statistics such as page views, scroll depth, and button interactions, collected via DataFast.
Why: To understand how the platform is used so we can improve it. No personally identifiable information is attached to these events.
Legal basis: Legitimate interests (improving the platform).
Authentication cookies
What: Session cookies managed by Supabase to keep you signed in.
Why: Essential for the platform to function.
Legal basis: Contractual necessity.
3. How we use your data
- To provide and maintain your player profile and account
- To display your profile to other community members based on your visibility settings
- To send transactional emails (magic links, team invites, follower notifications)
- To review and act on reported content and user reports
- To enforce our Terms of Service and Community Guidelines
- To maintain moderation records as required by law
- To understand how the platform is used so we can improve it
- To comply with our legal obligations, including under the Online Safety Act 2023
4. Who we share data with
We do not sell your personal data.
We use the following third-party services to operate the platform:
- Supabase - database, storage, and authentication
- Vercel - hosting and deployment
- DataFast - privacy-friendly analytics
- Resend - transactional email delivery
These providers process data on our behalf and are bound by data processing agreements.
Law enforcement and regulators. We may share personal data with law enforcement agencies (including the National Crime Agency) or regulators (including Ofcom) where:
- We are legally required to do so (for example, in response to a court order or legally binding information request)
- We have reasonable grounds to believe that content on the platform constitutes a criminal offence, particularly in relation to child sexual exploitation and abuse, terrorism, or threats to life
- We are responding to an information request from Ofcom under the Online Safety Act 2023
We will share the minimum data necessary to fulfil the request.
5. Cookies
We use a small number of cookies:
- Authentication cookies - essential for keeping you logged in. Set by Supabase. Cannot be disabled while using an account.
- Analytics cookies - set by DataFast to track anonymous usage. These do not contain personal information.
- Consent cookie - stores your cookie banner preference in local storage.
6. Your rights
Under UK GDPR, you have the right to:
- Access your personal data (request a copy of what we hold)
- Rectify inaccurate data (you can update most information directly from your dashboard)
- Erase your data (you can delete your account by requesting deletion by contacting us)
- Restrict processing in certain circumstances
- Object to processing based on legitimate interests
- Data portability (receive your data in a structured, machine-readable format)
To exercise any of these rights, contact us at: hello@airsoft.bio
We will respond to your request within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk.
7. Data retention
Account data: Retained for as long as you have an active account. If you delete your account, we remove your personal data within 30 days.
Moderation records: Reports, moderation decisions, and enforcement actions are retained for 3 years after the action was taken, to comply with our record-keeping obligations under the Online Safety Act 2023 and to support any potential regulatory or law enforcement enquiries. Content that has been removed for breaching our terms may be retained in our moderation records for this purpose.
Analytics data: Anonymised analytics data may be retained indefinitely as it contains no personal information.
Legal holds: Where data is subject to a legal hold (for example, in connection with a law enforcement investigation or regulatory enquiry), we will retain it for as long as necessary to comply with that obligation, even if it would otherwise be deleted.
8. Data security
We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), secure authentication via Supabase, and access controls limiting who can access moderation data. However, no system is completely secure, and we cannot guarantee absolute security.
9. International transfers
Some of our third-party providers may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions, to protect your data in accordance with UK GDPR.
10. Children's data
Airsoft.Bio requires users to be at least 13 years old. We do not knowingly collect data from children under 13. If we become aware that a user is under 13, we will take steps to delete their account and associated data.
For users aged 13-17, we process data on the same basis as adult users, with the additional safeguards described in our Terms of Service (including messaging restrictions and content safety measures).
11. Changes to this policy
We may update this privacy policy from time to time. If we make significant changes, we will notify registered users by email or through the platform. Any changes will be reflected on this page with an updated date.
12. Contact
If you have questions about this privacy policy, want to exercise your data rights, or have a data protection concern, contact us at:
Email: hello@airsoft.bio
If you are not satisfied with our response, you can contact the ICO: https://ico.org.uk