Privacy Policy
Last updated: December 2024
Summary
We collect your name, contact details, and payment information to process orders and provide customer support. We never sell your data. We share it only with essential service providers (payment processors, shipping carriers). You can access, correct, or delete your data at any time by emailing us.
1. Who We Are
The data controller responsible for your personal information is:
[Your Store Name] [Your Business Address] Email: privacy@yourstore.com
We determine how and why your personal data is processed.
2. Data Protection Officer
We do not currently have a designated Data Protection Officer. For all privacy-related inquiries, please contact privacy@yourstore.com.
3. Information We Collect
Information you provide directly:
When you create an account, place an order, or contact us, we collect your name, email address, phone number, billing and shipping addresses, and payment details. Payment card information is processed securely by our payment provider and we do not store full card numbers.
Information collected automatically:
When you browse our website, we automatically collect your IP address, browser type, device information, operating system, pages visited, time spent on pages, referring URLs, and data from cookies and similar technologies.
4. How We Use Your Information and Our Legal Basis
We process your personal data for the following purposes:
Contract fulfillment: Processing and delivering your orders, sending order confirmations and shipping updates, managing returns and refunds.
Legitimate interests: Improving website performance and user experience, preventing fraud and detecting suspicious activity, providing customer support, analyzing website traffic and usage patterns.
Legal obligation: Maintaining records for tax and accounting purposes, responding to lawful requests from authorities.
Consent: Sending marketing emails and promotional offers. You can withdraw consent at any time by clicking "unsubscribe" or contacting us.
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
5. Who We Share Your Data With
We never sell your personal information.
We share your data only with trusted third parties who help us operate our business:
Payment processing: [e.g., Stripe, PayPal] β to securely process transactions
Shipping and fulfillment: [e.g., Royal Mail, DHL, FedEx] β to deliver your orders
Email communications: [e.g., Klaviyo, Mailchimp] β to send transactional and marketing emails
Analytics: [e.g., Google Analytics] β to understand website usage
Hosting: [e.g., Shopify, WooCommerce] β to host and operate our store
All third parties are contractually required to protect your data and use it only for the purposes we specify.
We may also disclose your data when required by law, to protect our legal rights, or in connection with a business merger or acquisition.
6. International Data Transfers
Some of our service providers are based outside the UK/EEA, including in the United States. When we transfer your data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, adequacy decisions, or other legally recognized mechanisms.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to keep you logged in, remember items in your shopping cart, analyze traffic and improve our website, personalize your experience, and deliver relevant advertising.
When you first visit our website, you will see a cookie consent banner allowing you to accept or reject non-essential cookies. You can change your preferences at any time through our cookie settings or your browser settings. Disabling certain cookies may affect website functionality.
For more details, see our Cookie Policy [link].
8. Data Retention
We keep your data only as long as necessary:
Account information: Until you request deletion or close your account
Order and transaction records: 7 years for tax and legal compliance
Marketing preferences: Until you unsubscribe
Website analytics data: 26 months
Customer support communications: 3 years after resolution
After these periods, data is securely deleted or anonymized.
9. Your Privacy Rights
Depending on your location, you have the right to access your personal data and receive a copy, correct inaccurate or incomplete information, request deletion of your data ("right to be forgotten"), restrict or object to certain processing, withdraw consent at any time where processing is based on consent, receive your data in a portable format, and lodge a complaint with a supervisory authority.
To exercise any of these rights, email us at privacy@yourstore.com. We will respond within 30 days.
Supervisory Authority:
If you are not satisfied with our response, you may file a complaint with your local data protection authority:
UK: Information Commissioner's Office (ico.org.uk) EU: Your national data protection authority
10. Sensitive Personal Information
We do not intentionally collect sensitive personal information such as health data, biometric data, racial or ethnic origin, religious beliefs, or political opinions.
If such information is inadvertently provided (for example, in a customer service message), we will delete it promptly.
11. Children's Privacy
Our website is not directed at children under 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it immediately. If you believe a child has provided us with personal data, please contact us.
12. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including SSL/TLS encryption for data in transit, PCI-DSS compliant payment processing, restricted access controls, regular security monitoring and assessments, and security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy).
No method of transmission or storage is completely secure. If you believe your data has been compromised, please contact us immediately.
13. Do Not Track Signals
Our website does not currently respond to "Do Not Track" browser signals due to the lack of a uniform standard. You can manage tracking preferences through your browser settings or our cookie consent tool.
14. Changes to This Policy
We may update this Privacy Policy periodically. When we make significant changes, we will notify you by posting the updated policy on our website and, where appropriate, by email.
We encourage you to review this page regularly. The "Last updated" date at the top indicates the most recent revision.
15. Contact Us
For questions, concerns, or requests regarding your personal data:
Email: privacy@yourstore.com Address: [Your Business Address]
We aim to respond to all inquiries within 30 days.