This policy specifies the personal data we collect, why we collect it, what use it for and the choices you have, including how to access and update information.
Information We Collect
We collect and store information that you submit when using our website or that you provide us in any other way (for example by email, telephone or social media). This information may be provided when ordering from us, registering or accessing an account on our website or querying an order.
When you purchase something from our store, as part of the buying and selling process, we may ask you for certain information and you may submit personal details such as your full name, address, email address and phone number, plus transaction information, such as the product you purchased, its price, your method of payment and your payment details.
How We Use Your Personal Information
When we’re required to enter into a contract with you
We use your personal information to process and deliver your order; by providing your details you are allowing us to pass any necessary details on to our nominated delivery partners to ensure delivery of your order (such as address and contact details). We will provide you with a relevant, reliable and efficient service. Information provided can be used to establish a customer account on our website using information previously provided to us with your consent.
Where you have provided consent
If you opted in to receive our emails, we will communicate with you about our products, promotions, competitions or events via email, to the address specified when placing your order.
Where there is a Legitimate Interest
As a Company we are required to process your personal data in order to carry out certain tasks in our business. In such cases, processing of personal data can be justified on grounds of legitimate interest.
When we’re required to comply with our Legal Obligation
We’ll use your personal information to comply with our legal obligations including:
- To identify you when you contact us
- To verify the accuracy of data that we hold about you
- To assist HMRC and/or the Police and/or other regulatory bodies in relation to an investigation by a public authority.
By placing an order and submitting your data you agree to the use of your data as detailed above.
Who We Share Information With
Within our business
Our service providers
We work with partners so they can process your personal information on our behalf and only where they meet our standards on the processing of data and security. We only share information that helps them provide their services to us or to help them provide their services to you.
Our store is hosted by Unlimited Web Hosting UK Ltd. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
Your data is stored through Web Hosting UK Ltd data storage, databases and the general Web Hosting UK Ltd application. They store your data on a secure server behind a firewall.
Other organisations and individuals
We may transfer your personal information to other organisations in certain scenarios. For example:
- If required to by law, under any code of practice by which we are bound or we’re asked to do so by a public or regulatory authority such as the Police or the Department for Work and Pensions
- Information may also be shared with fraud prevention agencies to prevent fraudulent claims
- If we need to do so in order to exercise or protect our legal rights, users, systems and services
- In response to requests from individuals (or their representatives) seeking to protect their legal rights or the rights of others.
How Long We Keep Your Personal Information
We can only keep your personal data for as long as necessary for the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
The precise length of time we hold your personal data for varies depending on the individual circumstances, but in determining the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
We regularly review our retention periods to ensure that we are not keeping your data for longer than necessary. Details of retention periods for different aspects of your personal data are available by contacting us.
We do not retain personal information in an identifiable format for longer than is necessary.
Access to Information held about you
You have the right to request what personal information we hold about you. If any of the personal information we hold about you is inaccurate or out of date, you may ask us to correct it.
Right to stop or limit our processing of your data
You have the right to object to us processing your personal information if we’re not entitled to use it any more, to have your information deleted if we are keeping it too long or have its processing restricted in certain circumstances.
Where we rely on our legitimate interests, as set out under ‘How we use your personal information’, you may object to us using it for these purposes. If we agree that your objection is justified in accordance with your rights under data protection laws, we’ll permanently stop using your data for those purposes. Otherwise we’ll provide you with our justification as to why we need to continue using your data.
You can ask us to restrict the use of your personal information if:
- It isn’t accurate.
- It has been used unlawfully but you don’t want us to delete it.
- It’s not relevant any more, but you want us to keep it for use in legal claims.
- You’ve already asked us to stop using your data but you’re waiting for us to tell you if we’re allowed to keep on using it.
Please note that we may be required by law to retain certain information. Before we are able to provide you with any information or correct any inaccuracies, we may ask you provide other details and proof of identity and/or address to help us respond to your request.
Opting Out of Direct Marketing
If you have previously opted in, we won’t send you further marketing messages if you tell us not to. You can click onto the “unsubscribe” link in any communication that we send to you by email which will automatically unsubscribe you from that type of communication. You can also contact us directly.
Please note that it may take up to 30 days to process your request.
If you choose a direct payment gateway to complete your purchase, then Stripe stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
For more insight, you may also want to read Shopify’s Terms of Service (https://stripe.com/payment-terms/legal) or Privacy Statement (https://stripe.com/gb/privacy).
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed. If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
Third Party Services
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us. However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.
For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
The main purposes for which cookies are used are:
- For technical purposes essential to effective operation of our websites, particularly in relation to on-line transactions and site navigation.
- For us to market to you, particularly web banner advertisements and targeted updates.
- To let us collect information about your browsing and shopping patterns, including to monitor the success of campaigns, competitions etc. This depends on which cookies you disable, but in general the website may not operate properly if cookies are switched off. If you only disable third party cookies, you will not be prevented from making purchases on our sites. If you disable all cookies, you won’t be able to complete a purchase on our sites.
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer by one of the following means:
Telephone: 01749 841 293
Post: Greens of Mendip, Unit 1 Rookery Farm, Binegar, Somerset, BA3 4UL
Complaining To The Data Protection Regulator
You have the right to complain to the Information Commissioners Office (ICO) if you are concerned about the way we have processed your personal information. Please visit the ICO’s website for further details at: https://ico.org.uk
Changes To This Policy
Last updated: 07/05/20