Privacy Policy

Controller {{legal_entity}}
Contact {{privacy_email}}
Analytics Only if you accept them
Sold to anyone Never
Complaints To us, or straight to the ICO
Last updated {{privacy_last_updated}}

Who's responsible for your data

{{legal_entity}} (company number {{company_number}}, registered office {{registered_address}}) is the data controller for personal information collected through {{site_url}}. We trade as {{brand_name}}.

We're a small company and we haven't appointed a Data Protection Officer. UK GDPR only requires one of public authorities and organisations whose core activity is large-scale monitoring or large-scale processing of special category data, and we're none of those. Privacy questions and rights requests go to {{privacy_email}}, which is read by a person, not a queue.

Buying through our TikTok Shop is a separate matter. TikTok is its own controller for what happens inside that platform and its privacy policy governs it. We receive the order and delivery details it passes to us, and this policy covers what we do with those from that point on.

What we collect

When you order

  • Your name, delivery address, email and phone number
  • What you ordered, when, and for how much
  • Any correspondence about that order, including returns

We do not see or store your card details. Payment is taken by the sales channel you order through and its payment providers.

When you email us

  • Your email address and whatever you put in the message
  • Our replies, kept with the thread

When you browse, and only if you accept analytics

  • Pages viewed and how long you spent on them
  • Device type, browser and approximate region
  • How you arrived at the site

We collect this only after you press Accept. Two products receive it. Google Analytics counts visits and shows us how people arrive. PostHog shows how a page gets used, so we can find the parts that get in the way. Choose Reject and neither one loads. The site works either way, and we don't ask again on every visit.

Why we're allowed to

Each thing we do with your data sits on one of these bases under UK GDPR Article 6.

Contract: processing your order, arranging delivery, handling a return or refund. We can't do any of it without your details.

Legal obligation: keeping sales records for HMRC, and responding to product safety obligations if a reaction is reported.

Consent: analytics cookies, and marketing emails if you sign up for them. Cookie consent is given through the banner and withdrawn through the same control. Email consent is given by ticking the box on the sign-up form and confirming the address, and withdrawn through the unsubscribe link in any email we send. Nothing rides on either one.

Soft opt-in: if you start a checkout and don't complete it, we may email you about that purchase, under the marketing rules that allow this to existing or prospective customers already in the process of buying from us. Every one of these emails carries an unsubscribe link, and using it stops them for good.

Legitimate interests: answering your emails, keeping records of complaints, and protecting the site from abuse. We've weighed these against your interests and consider them uncontroversial. If you disagree, you can object.

We don't do automated decision-making or profiling, and we've never sold or rented personal data to anyone.

Who else sees it

A short list, because we run a short operation. Each of these processes data on our instructions under a written agreement.

Shopify: runs the checkout and takes payment for orders placed on this site, and sends the order and shipping confirmation emails that go with a purchase. It handles your card details directly, so they never reach us, and holds the order, your name and delivery address. It also stores the product and page content this site is built from.

TikTok Shop: the other channel you can order through. It handles checkout and payment for orders placed there and passes us the order.

Couriers: Royal Mail or an equivalent carrier gets your name, address and phone number so the parcel arrives.

Vercel: hosts this website and processes standard server request logs.

Klaviyo: sends our marketing and order-related emails. If you sign up for marketing emails, it holds your address, the date you signed up and the wording you agreed to, and every marketing email carries an unsubscribe link that stops them for good. It also uses order and checkout data from Shopify to send emails tied to a specific order or an incomplete checkout, and holds the product and email address you give us if you ask to be told when something is back in stock.

Google Analytics 4: counts your visit, the pages you opened, your device and browser, and the region you were in. Google is the provider and holds this in the United States, covered by the transfer mechanism described below. Runs only after you accept analytics.

PostHog: records how you used a page, so we can see where the site gets in the way. Held in the European Union. Runs only after you accept analytics. It stores counts and page names. Session recording is switched off, so nothing replays your screen.

Our accountant and HMRC: sales records, as tax law requires.

We'll also disclose data where the law requires it, or to establish or defend a legal claim.

Cookies

We use one strictly necessary browser storage entry to remember your cookie choice, so the banner stops asking. PECR lets us set that without consent, because without it we couldn't honour your answer.

Everything else is analytics, and analytics only loads after you press Accept. Nothing is set before you choose, and rejecting leaves the site fully usable. You can withdraw consent at any time using the cookie preferences control below.

How long we keep it

  • Order and sales records: six years after the end of the financial year they fall in, which is what HMRC requires of company records.
  • Customer correspondence: two years after the thread goes quiet, unless it relates to a complaint or a claim.
  • Analytics data: 14 months from your last visit in Google Analytics, and 12 months in PostHog, then deleted.
  • Your cookie choice: stored in your own browser until you clear it or use the control above.
  • Marketing email sign-ups: your address and the record of when and to what you consented, until you unsubscribe, and for a year after that so we can show the sign-up was genuine.
  • Back-in-stock requests: your address and which product you asked about, until we've sent the notification or the product is discontinued, whichever comes first.

Keeping it safe

What we actually do, rather than what sounds reassuring. The site is served over HTTPS. Accounts that hold customer data use multi-factor authentication. Access is limited to the people who need it, which at our size is a very short list. We don't run our own payment infrastructure, so card data never reaches us.

We don't commission penetration tests or formal security audits, and we're not going to claim we do. If that changes, this paragraph changes with it.

If a breach happens that risks your rights and freedoms, we'll report it to the ICO within 72 hours and tell you where the risk to you is high.

Transfers outside the UK

Some of the services above process data outside the UK. Where they do, the transfer relies on UK adequacy regulations for that country, or on the UK's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment behind it.

Ask us at {{privacy_email}} and we'll tell you which mechanism covers a given service.

Your rights

  • Access: get a copy of what we hold about you
  • Rectification: have anything wrong corrected
  • Erasure: have it deleted, where we don't need to keep it by law
  • Restriction: have us pause processing while something is disputed
  • Portability: receive the data you gave us in a machine-readable form
  • Objection: object to anything we do on legitimate interests
  • Withdraw consent: for analytics, at any time, using the control above

Email {{privacy_email}} and we'll respond within one month. It's free. If a request is genuinely excessive or repetitive we can charge a reasonable fee or refuse, and we'll explain why if we ever do. We may ask you to confirm who you are before we hand anything over.

Complaining

Tell us first if you'd like to, but you don't have to. You have the right to complain directly to the Information Commissioner's Office, the UK's data protection regulator.

ico.org.uk/make-a-complaint

Helpline: 0303 123 1113
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Changes to this policy

We'll update this page when what we do changes, and move the date at the top when we do. For anything material we'll say so on the site, and email you if we hold your address and the change affects you.

Privacy contact

Email {{privacy_email}}
Controller {{legal_entity}} (company number {{company_number}})
Address {{registered_address}}
Last updated {{privacy_last_updated}}