1.0 OUR CORE BELIEFS REGARDING USER PRIVACY AND DATA PROTECTION User privacy and data protection are human rights. We have a duty of care to the people within our data. Data is a liability, it should only be collected and processed when absolutely necessary. We loathe spam as much as you do! We will never sell, rent or otherwise distribute or make public your personal information.
2.0 RELEVANT LEGISLATION We comply with the following national and international legislation with regards to data protection and user privacy: UK Data Protection Act 1988 (DPA) EU Data Protection Directive 1995 (DPD) EU General Data Protection Regulation 2018 (GDPR)
3.0 PERSONAL INFORMATION I COLLECT AND WHY I COLLECT IT
3.1 Order Processing When you place an order via my shop on either consciouscrafties.com or kindpreneurs.com, I receive only the required information in order to process your order (your name, address, email and phone number). I do not receive any card or bank details. When you place an order via my shop on Redbubble I only recieve a notification of sale. Redbubble process all orders for me so they will receive the required information to process your order (your name, address, email address and phone number)
For your information you can find privacy policies for all the sites I sell through here:
Conscious Crafties - https://www.consciouscrafties.com/privacy-policy/
KIND Shop - https://www.kindshop.co.uk/privacy-policy/
RedBubble - https://www.redbubble.com/privacy
Sustainable Clothing Shop - https://gertlushdesigns.teemill.com/privacy-policy/
4.0 HOW I USE THE INFORMATION The information you provide is used to fulfil your order on a ‘contract’ basis and is only used for the purpose of communicating with you regarding your purchase and for delivery of your items. Your personal information will not be added to my mailing list and you will not be contacted for marketing or advertising purposes unless you request me to do so.
5.0 SHARING WITH THIRD PARTIES We will NEVER sell or rent your personal data. To process your order and to fulfil your contract with us, your information is shared with third parties for the purpose of delivery (Royal Mail). You can find information about this delivery service providers privacy policies and practices here https://www.royalmail.com/privacy-notice and here https://www.royalmail.com/business/system/files/royal-mail-the-gdpr-opportunity-with-mail.pdf It may be shared for compliance with legal, regulatory and law enforcement requests as appropriate and necessary. I will endeavour to notify you of any such requests. I am not responsible for how these third parties process your data, please visit their websites to read their privacy policies.
6.0 HOW I SECURE, STORE AND RETAIN DATA We use Conscious Crafties, Kindpreneurs and Redbubble websites to trade and complete your purchase. Your data is secured, stored and retained by Conscious Crafties and Kindpreneurs to complete your purchase. We do not hold hard copies of your data and any data collected is held only as long as is necessary to carry out your order and to maintain adequate and accurate business and financial records (7 years).
7.0 BUYING FROM ME VIA A CRAFT FAIR
7.1 If you visit the craft fair I am attending you may be recorded on CCTV if the location has this in operation.
7.2 If you purchase from me using cash and collect your item on the day, no personal information will be collected or stored. 7.3 If you purchase from me using a card all payments are dealt with using iZettle. We will share transaction data with our payment service providers only to the extent necessary for the purposes of processing your payments, refunding such payments and refunds. You can find information about the payment services providers' privacy policies and practices at https://www.izettle.com/gb/help/articles/1084830-smartphones-and-security
7.4 For made-to-order items that can’t be collected on the day, I will need to ask you for your name and address in order to deliver your order. If I’m unable to hand deliver your item, I would need to pass your name and address to a third party (eg Royal Mail) in order for them to deliver your parcel. You can find information about this delivery service providers privacy policies and practices here https://www.royalmail.com/privacy-notice and here https://www.royalmail.com/business/system/files/royal-mail-the-gdpr-opportunity-with-mail.pdf
8.0 HOW YOU CAN ACCESS, UPDATE OR DELETE INFORMATION HELD ABOUT YOU You have the right to access, update or ask us to delete your personal information. Please email our Data Controller found in section 9.0 below. We are obliged by law to provide this service within 30 calendar days of your request free of charge. However, we have the right to refuse or charge for requests that are manifestly unfounded or excessive and repetitive.
9.0 DATA BREACHES We will report any unlawful data breach to any and all relevant persons and authorities within 72 hours of the breach, if it is apparent that personal data stored in an identifiable manner has been stolen. If you feel your data has been compromised you have a right to contact the Information Commissioners Office (ICO).
10.0 DATA CONTROLLER Our data controller is Sharon Fielding of Gert Lush Designs Whose registered and operating office is: 7 Burchells Green Road, Kingswood, Bristol, BS15 1DT Email: firstname.lastname@example.org