Privacy Policy
1. Data Controller
2. Personal Data We Collect
When you use our website or place an order, we may collect:
Identity & Contact Data
-
Full name
-
Billing and shipping address
-
Email address
-
Telephone number
Transaction Data
-
Order details
-
Purchase history
-
Payment confirmations
Technical Data
-
IP address
-
Browser type and version
-
Device information
-
Website usage data
We do not store full debit or credit card details.
3. How We Use Your Data
We use personal data to:
Process and fulfil orders
Manage shipping and delivery
Communicate regarding orders or enquiries
Maintain customer accounts
Prevent fraud and misuse
Comply with legal and tax obligations
Improve website performance and security
We do not sell or rent personal data.
4. Lawful Basis for Processing
Under UK GDPR, we rely on the following lawful bases:
Contract
To process orders and deliver products.
Legal Obligation
To comply with UK tax, accounting, and regulatory requirements.
Legitimate Interests
To operate our business, ensure website security, and prevent fraud.
Consent
For optional cookies, analytics, and marketing communications (if applicable).
Consent may be withdrawn at any time.
5. Payment Processing
Orders are processed through WooCommerce and payments are handled by Fenna (payment provider).
Payment information is processed securely by the payment provider in accordance with their privacy policy. We do not store full payment card details on our servers.
6. Third-Party Processors
We may share data with trusted service providers necessary for operating our business, including:
Payment providers
Shipping and courier services
Website hosting providers
Technical support services
Analytics providers (if enabled)
All third parties are required to process data securely and in compliance with UK GDPR.
7. Data Retention
We retain personal data only as long as necessary:
Order and financial records: Up to 6 years (for UK tax compliance)
Customer account data: Until account deletion
Customer service communications: Up to 3 years
Marketing consent records: Until withdrawn
Analytics data: Up to 14 months
Data is securely deleted or anonymised once no longer required.
8. International Data Transfers
If any service providers process data outside the United Kingdom, we ensure appropriate safeguards are in place, such as adequacy regulations or standard contractual clauses.
9. Your Rights Under UK GDPR
You have the right to:
Access your personal data
Request correction of inaccurate data
Request erasure
Restrict processing
Object to processing
Request data portability
Withdraw consent at any time
10. Security Measures
We implement appropriate technical and organisational measures to protect personal data from unauthorised access, misuse, loss, or disclosure.
However, no online system can be guaranteed to be completely secure.