Last updated: September 29, 2026. This policy covers GDPR / UK GDPR and CCPA / CPRA requirements.

1. Data controller

The data controller responsible for your personal data is:

2. What data we collect and why (purposes & legal basis)

DataPurposeLegal basis (GDPR)
Name, email, password (hashed)Account creation & authenticationContract
Shipping address, phoneOrder fulfilment & deliveryContract
Order & payment records (no card numbers)Processing orders, tax/accounting, fraud preventionContract / Legal obligation / Legitimate interest
Referral code, clicks, attributed ordersOperating the affiliate programmeContract / Legitimate interest
Support tickets & chatCustomer serviceContract / Legitimate interest
Device/browser, IP, analytics cookiesSecurity, analytics, site improvementConsent / Legitimate interest
Marketing email & preferencesPromotional communicationsConsent (or applicable soft opt-in)

This preview does not accept payments or collect card numbers. Payment processor details must be updated here before payments are enabled.

3. Your rights (GDPR / UK GDPR)

You have the right to: access, rectify, erase ("right to be forgotten"), restrict processing, data portability, object to processing, and withdraw consent at any time. EU/UK users may also lodge a complaint with a supervisory authority.

Exercise these from your account (Settings → Export/Delete), via the privacy request form, or through our contact form. Response periods depend on the applicable jurisdiction.

4. CCPA / CPRA (California)

We collect the categories described above for the listed business purposes. You have the right to know/access, delete, correct, and limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights.

Do Not Sell or Share My Personal Information: we do not sell personal information in the traditional sense and do not share it for cross-context behavioural advertising beyond what you consent to. You may submit an opt-out via the privacy request form. We honor the Global Privacy Control (GPC) signal automatically.

5. Cookies

We use essential, analytics and marketing cookies. You control optional cookies through our consent banner; see the Cookie Policy.

6. Data sharing & processors

The service uses hosting and database providers. Payment, email and storage providers must be listed here when those integrations are enabled. Ask for current processor details through our contact form.

7. International transfers

International transfer locations and applicable safeguards must be confirmed and documented before trading.

8. Retention

Account and order records are retained as needed to provide the service and meet applicable obligations, then deleted or anonymised. Specific retention periods must be confirmed before trading. Marketing consent records are retained to document consent and withdrawal.

9. Security & breach response

We apply technical and organisational measures (encryption in transit, hashed passwords, access controls, audit logging). No system is guaranteed perfectly secure. In the event of a personal-data breach likely to result in risk to individuals, we will notify the competent supervisory authority (and, where required, you) within the legal deadlines.

10. Children

The applicable age threshold for each market must be confirmed before accounts are opened to the public.

11. Contact & changes

Questions: use the contact form. We may update this policy; material changes will be notified where required.