Privacy Policy – Grace Amber


1. Introduction


This Privacy Policy explains how Grace Golf trading as Grace Amber (“we”, “us” or “our”) collects, uses and protects your personal information when you visit our websites and landing pages, join our email list, enquire about or purchase The Phoenix Journey or any of our other coaching services, programmes or digital products.


We are the data controller for the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.​

2. Who we are and contact details

  • Legal entity: Grace Golf trading as Grace Golf
  • Postal address: Clevedon, UK
  • Email: grace@phoenixseason.co.uk

If you have questions about this policy or how we handle your data, please contact us using these details.​

3. What personal data we collect

We may collect and process the following information:​

    • Identity data: name, title.
    • Contact data: email address, phone number, billing address.
    • Programme and coaching data: information about which programme or service you have enquired about or joined (for example, The Phoenix Journey), your enrolment details, discovery‑call or application answers, session or group‑call attendance, high‑level coaching notes, homework or reflective exercises you choose to share, and feedback you give.
    • Account and access data: log‑in or access details for any course or membership platform, user settings and preferences, time zone and language settings.
    • Transaction data: purchase details, payment status and Stripe payment reference (we do not see your full card details; Stripe processes payments securely on our behalf).​
    • Technical and usage data: IP address, device and browser information, time zone settings, pages visited, referral sources and other analytics data (if we use analytics tools).​
    • Communication and marketing data: your preferences about receiving news, updates and offers from us, and your communication preferences, plus records of emails or messages we exchange with you.
    • Call and meeting data: details relating to online meetings or group calls (for example via Zoom), including your name, email address and whether you attend. If we record a call or session, we will explain this in advance and give you the option to keep your camera and microphone off if you prefer.


Our coaching work may touch on personal experiences (for example around motherhood, perimenopause and life transitions), we ask you not to share detailed medical or other highly sensitive information in emails, standard forms or chat messages. If, in specific circumstances, we need to process special‑category data (for example, limited health‑related information relevant to your coaching), we will explain this clearly and rely on an appropriate lawful basis such as your explicit consent.

We do not carry out automated decision‑making or profiling that has legal or similarly significant effects on you.​

Our services and website are not intended for children under 18, and we do not knowingly collect personal data relating to children


4. How we collect your data

We collect data in the following ways:​

    • When you complete an enquiry form, application, intake form or contact form on our website or landing pages.
    • When you book a discovery call, consultation or coaching session (for example via a scheduling tool).
    • When you enrol in The Phoenix Journey or any other coaching programmes or digital products.
    • When you email, message or call us about our services.
    • When we email you a Stripe payment link and you complete a purchase, or when you pay via an online checkout.​
    • When you sign up to our mailing list or request free resources (for example a free guide, webinar or challenge).
    • Automatically, when you browse our website, landing pages or course areas, through cookies and similar technologies (see section 7).​

5. How and why we use your data (lawful bases)

We use your personal data only where we have a lawful basis under UK GDPR:​

We use your personal data only where we have a lawful basis under UK GDPR.

Enquiries and discovery calls

  • To respond to your enquiries about The Phoenix Journey or other coaching offers, and to arrange discovery calls or consultations.
  • Lawful basis: our legitimate interests in responding to potential clients and running our business.

Programme enrolments, purchases and bookings

  • To process bookings and enrolments for The Phoenix Journey and any other coaching or digital products, including taking payment, sending confirmation emails and providing access to online platforms and materials.
  • Lawful bases: performance of a contract with you, and legal obligations for tax and accounting. Our legitimate interests may also apply where we need to follow up to clarify a booking, prevent fraud or manage our business effectively.

Coaching and programme delivery

  • To provide The Phoenix Journey and other coaching services to you, including scheduling sessions, managing group calls, sharing course materials, responding to your reflections or questions and tailoring our support to your needs at a high level.
  • Lawful bases: performance of a contract (to deliver the coaching or programme you have purchased) and our legitimate interests in delivering and improving our services. Where we process any special‑category data, we will rely on an additional lawful basis such as your explicit consent, which we will obtain separately where required.

Records, accounts and complaints

  • To maintain our records, manage accounts, handle queries or complaints and keep evidence of our relationship with you.
  • Lawful bases: our legitimate interests in responsible business operations and in establishing or defending legal claims, and legal obligations for record‑keeping.

Marketing communications

  • To send you emails about The Phoenix Journey and other courses, new coaching offers, free resources or events where you have opted in, or where the law otherwise permits us to contact you (for example, the “soft opt‑in” for existing customers, as long as you can easily opt out at any time).
  • Lawful bases: your consent and/or our legitimate interests in promoting and growing our business, provided we respect your rights under e‑privacy rules and your right to object to marketing. You can withdraw consent or object to marketing at any time (see sections 11 and 12).​

Website and service operation and improvement

  • To operate, maintain and improve our website, landing pages, course platforms and user experience, and to monitor performance and security.​
  • Lawful basis: our legitimate interests in running an effective, secure online presence and improving our client experience.

Legal and regulatory obligations

  • To meet legal, tax and regulatory obligations, such as accounting rules and responding to lawful requests from authorities.
  • Lawful basis: compliance with a legal obligation.​

Where we rely on consent (for example, for certain marketing emails or non‑essential cookies), you can withdraw it at any time by clicking “unsubscribe” or contacting us using the details in section 2.

6. Stripe and other third‑party services


Payments are processed by Stripe (or any other secure payment provider we may use), which will collect and process your payment information directly. These providers act as independent controllers of your payment data, and their processing is governed by their own privacy policies. We receive only limited information such as confirmation of payment, the last four digits of your card, and your contact details for fulfilment and records.

We also use other third‑party service providers to help us deliver our services, such as email marketing platforms (for example, a mailing‑list provider), website and landing‑page hosting services, course or membership platforms, scheduling tools, video‑conferencing tools (for example, Zoom) and file‑storage providers. They only process your data on our instructions and are required to keep it secure (see also section 8).


7. Cookies and website analytics

Our sites and landing pages may use cookies and similar technologies. These can include:

  • Essential cookies: necessary for the site to function properly, for example to load pages securely, remember basic preferences or enable log‑in to secure areas.
  • Analytics cookies (if enabled): to help us understand how visitors use our website, improve content and troubleshoot problems.
  • Marketing or social‑media cookies (if enabled): to support marketing features such as social‑media sharing, or to measure the effectiveness of our marketing.

If we use non‑essential cookies (such as analytics or marketing cookies), where required we will ask for your consent via a cookie banner or settings tool, and you can change your choices at any time. You can also control cookies through your browser settings, although disabling some cookies may affect how the site functions.​

Specific details about the cookies we use and their purposes may be set out in a separate cookie notice or in the settings tool

8. Sharing your data

We do not sell your personal data.​

We may share it with:

  • Service providers who help operate our business and deliver our services, such as website hosting, landing‑page providers, email service providers, analytics tools (if enabled), payment processors like Stripe, scheduling tools, course or membership platforms, video‑conferencing providers and secure file‑storage providers.
  • Professional advisers such as accountants or legal advisers where necessary.
  • Government bodies, regulators or law‑enforcement agencies where the law requires us to share information.​

These third parties are only permitted to use your data to provide services to us (or to comply with their own legal obligations) and must keep it secure and act in accordance with data‑protection law.​

9. International data transfers

Some of our service providers may transfer or store personal data outside the UK, for example in the European Economic Area (EEA) or the United States. When we transfer data in this way, we rely on appropriate safeguards such as:

  • UK adequacy regulations (where the destination country is recognised as providing an adequate level of protection);
  • the UK‑US Data Bridge where applicable; or
  • standard contractual clauses, international data transfer agreements (IDTAs) or similar safeguards approved under UK GDPR.

You can contact us if you would like more information about international transfers relating to your data.

10. How long we keep your data

We keep your personal data only as long as necessary for the purposes set out in this policy, including legal and accounting requirements.

In general, this means:

  • Enquiries and discovery‑call information: up to 24 months after our last contact if no booking or purchase is made, so we can respond to follow‑ups and keep track of past conversations.
  • Booking and transaction records (coaching and digital products): up to 6 years from the end of the financial year in which the transaction took place, to comply with tax and accounting rules and to address any potential legal claims.​
  • Coaching and programme records (including The Phoenix Journey): typically up to 6 years after the end of our coaching relationship or programme, to support our legitimate interests in maintaining records, responding to queries or complaints and establishing or defending legal claims (your advisor can confirm a suitable period for your practice).
  • Recordings of sessions or group calls (if created): usually kept for a shorter, defined period (for example 6–12 months) for providing replays to participants and then deleted, unless we are required to keep them longer by law or for legal purposes.
  • Marketing contact details: until you unsubscribe or we determine that your details are no longer up to date or engaged (for example, if emails repeatedly bounce or remain unopened for an extended period).​

When data is no longer needed, we will securely delete or anonymise it.

11. Your rights

Under UK data‑protection law, you have rights including:​

  • Right to be informed about how we use your data (this policy and any related notices).
  • Right of access to your personal data.
  • Right to rectification of inaccurate or incomplete data.
  • Right to erasure in certain circumstances.
  • Right to restrict processing in certain circumstances.
  • Right to object to certain processing, including direct marketing.
  • Right to data portability in some circumstances.

You can exercise these rights by contacting us using the details in section 2. We may need to request proof of identity and additional information to confirm your request and keep your data secure.​

We aim to respond within one month, but complex or multiple requests may take longer; if so, we will let you know. We do not usually charge a fee, but we may charge a reasonable fee or refuse a request that is clearly unfounded, repetitive or excessive.​

12. Marketing emails


If you choose to join our mailing list or consent to receive updates, we will send you information about The Phoenix Journey, other coaching services, free resources, promotions and events.

You can opt out at any time by clicking the “unsubscribe” link in our emails or by contacting us directly, and we will update your preferences promptly. Opting out of marketing does not affect service emails about existing bookings, programmes or products that you are already part of.​


13. How we protect your data


We use appropriate technical and organisational measures to protect your personal information, including secure devices and accounts, strong passwords, limited access to client data, and using reputable third‑party providers with strong security practices.

Access to your personal data is restricted to people who need it for legitimate business purposes and who are subject to duties of confidentiality. We have procedures in place to deal with any suspected personal‑data breach and will notify you and any applicable regulator where we are legally required to do so


14. Complaints


If you have concerns about how we use your personal data, please contact us first so we can try to resolve the issue.​ Contact: grace@graceamber.com

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection: www.ico.org.uk, telephone 0303 123 1113.​


15. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services or legal requirements. When we do, we will update the “last updated” date below and may notify you via our website or email where appropriate.​

Last updated: July 2026