1. Introduction
At Valentine Lens, we are committed to protecting your privacy and handling your data in an open and transparent manner. This Privacy Policy outlines how we collect, use, and store your personal information and details your rights under the UK General Data Protection Regulation (UK GDPR).2. Who We Are (Data Controller)
Valentine Lens is the data controller responsible for your personal information. Our contact details are:
3. The Information We Collect
We collect, process, and retain the following types of personal data when you use our site and purchase products:
- Identity Data: Your first name, last name, and title.
- Contact Data: Your email address, billing address, and shipping address.
- Financial Data: Payment card details are processed by our trusted payment processor (e.g., Stripe, PayPal). We do not store your full payment card details on our servers.
- Transaction Data: Details about the products you have purchased, including the price, order number, and delivery status.
- Technical Data: Your IP address, browser type, device information, and operating system.
- Usage Data: Information about how you use our website, such as page views, clicks, and browsing behaviour collected through cookies and analytics.
4. How We Use Your Information (Legal Basis)
We process your personal information for the following purposes, based on specific legal grounds under the UK GDPR:
- To Process and Fulfil Your Order (Contract): We use your identity, contact, and financial data to process your payment and deliver your order. This processing is necessary for the performance of our contract with you.
- For Marketing Communications (Consent):With your explicit consent, we may use your contact details to send you promotional emails about our prints or special offers. You have the right to withdraw this consent at any time.
- To Improve Our Services and Website (Legitimate Interest): We use usage and technical data to understand how our customers use our site. This helps us to improve our website design, products, and overall customer experience. We have balanced this against your rights and freedoms and determined that it is a legitimate interest.
- To Prevent Fraud and Ensure Security (Legitimate Interest): We use your data to monitor for fraudulent transactions and to ensure the security of our website. This is necessary to protect our business and customers from harm.
- To Comply with Legal Obligations (Legal Obligation): We may process your data to comply with legal requirements, such as VAT record-keeping.
5. How We Share Your Information
Your personal data is shared with the following trusted third parties to operate our business effectively:
- Fulfillment Partner: We share your identity, contact, and transaction data with our fulfillment partner to print, frame, and ship your orders.
- Payment Processor: We share your financial and transaction data with our payment processor to securely handle your payments.
- Shipping Partners: We share your contact and transaction data with our shipping partners to deliver your order.
- Website Analytics Providers (e.g., Google Analytics): We share non-identifiable usage and technical data to help us analyse website traffic and improve our services.
6. International Data Transfers
If your data is transferred outside the UK or the European Economic Area (EEA), we ensure it is protected by appropriate safeguards, such as Standard Contractual Clauses, to maintain an equivalent level of protection.7. Cookies and Tracking Technologies
We use cookies to improve your browsing experience, analyse traffic, and personalise content. Our site will obtain your consent before placing any non-essential cookies. You can manage your cookie preferences at any time.8. Your Rights
Under the UK GDPR, you have the following rights regarding your personal data:
- The Right to Access: You can request a copy of the personal information we hold about you.
- The Right to Rectification: You can ask us to correct any inaccurate or incomplete data we hold.
- The Right to Erasure (Right to be Forgotten): You can ask us to delete your personal data, provided there are no legal grounds for us to continue processing it.
- The Right to Restrict Processing: You can ask us to suspend the processing of your personal data in certain circumstances.
- The Right to Object: You have the right to object to us processing your personal data for marketing purposes or based on our legitimate interests.
- The Right to Data Portability: You can request a copy of your personal data in a structured, machine-readable format.
- The Right to Lodge a Complaint: You have the right to complain to the Information Commissioner's Office (ICO) if you believe we have misused your data.
9. Data Security
We implement reasonable security measures to protect your personal information from unauthorised access, loss, or misuse. These measures include encrypting sensitive data, regular security audits, and restricting internal access to your data.10. Data Retention
We will retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, including for satisfying any legal or accounting requirements.11. Children's Privacy
Our website is not intended for children under 13, and we do not knowingly collect personal data from anyone under this age.12. Changes to This Privacy Policy
We may update this policy from time to time. The latest version will be posted on our website, and we will take reasonable steps to inform you of any material changes.13. How to Contact Us
If you have any questions or wish to exercise your rights, please contact us at: