Privacy Policy

Privacy Policy for SavviShop

SavviShop (“we” or “us”) is committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and related laws. This Privacy Policy explains what information we collect about you, why we collect it, how we use it, with whom we share it, and your rights regarding your personal data. Please read this policy carefully. By using savvishop.uk, you agree to the practices described below.

Information We Collect

We collect the following categories of personal information when you interact with our site, place orders, or create an account:

  • Personal & Contact Data: Your name, email address, telephone number, shipping and billing addresses savvishop.uk.

  • Account & Transaction Data: Details of your purchases and order history, and any profile information (e.g. username, password) if you create an account.

  • Payment Information: Payment details are processed securely by third-party payment gateways (such as Stripe or PayPal); we do not store your full credit/debit card details on our servers savvishop.uk.

  • Technical Data: Your IP address, device and browser type, and usage information (such as pages visited and links clicked) collected through cookies, web server logs, and Google Analytics savvishop.uk. This helps us maintain and improve our site.

We do not collect any special category (sensitive) data such as health, race, ethnicity, political or religious beliefs, or biometric information ico.org.uk. All data collected is voluntary and relevant to providing our services or improving your experience on the site. We will ask only for the information we need for our legitimate purposes.

How We Use Your Data & Our Legal Basis

We use your personal data for the following purposes, on the legal bases specified:

  • Order Fulfilment: Processing your purchases (including sending you order confirmations, receipts, and shipping notifications) is necessary for the performance of our contract with you (UK GDPR Article 6(1)(b)) gdpr-info.eu. For example, we need your name and address to deliver your goods.

  • Account Management: Creating and maintaining your account, customer support, and responding to your inquiries. This is also on a contractual basis or a legitimate interest (to manage our relationship with you).

  • Payment Processing: Verifying and processing payments to fulfil your order. We rely on contract (to process a sale) and compliance with legal obligations (e.g. tax laws) gdpr-info.eu. Payments are handled by secure third parties (Stripe, PayPal) who have their own privacy policies.

  • Communication: Sending you transactional messages (order updates, customer service emails). These are necessary under our contract with you. Sending marketing or promotional emails (newsletters, special offers) is based on your consent (UK GDPR Article 6(1)(a)) ico.org.uk. You may unsubscribe or withdraw consent at any time (see Your Rights below).

  • Site Improvement & Security: Using cookies and Google Analytics to improve site performance and security. We may process usage data on the basis of our legitimate interests (UK GDPR Article 6(1)(f)) – for example, to analyze traffic trends, detect fraud or abuse, and enhance the user experience, provided this does not override your rights ico.org.ukgdpr-info.eu.

  • Legal Compliance: Complying with statutory obligations (e.g. tax and accounting laws), which may require us to retain certain data (see Data Retention). This is necessary for compliance with a legal obligation (Article 6(1)(c)) gdpr-info.eu.

We will not use your personal data for any purpose other than those stated above without your explicit consent. If we ever need to process your data for a new purpose (e.g. a new service or feature), we will update this Privacy Policy and obtain your consent if required.

Third-Party Services and Data Sharing

To operate and improve our services, we share personal data with trusted third parties under strict terms:

  • Payment Gateways: We use Stripe and PayPal to process payments. These providers may receive your name, address, email, and partial payment details. They comply with GDPR and apply strong security (e.g. encryption). We do not store your full card details.

  • Shipping Partners: To deliver orders, we share your shipping address and contact details with couriers (e.g. Royal Mail, DHL). They also abide by data protection laws and use your data only to fulfill the delivery.

  • Analytics Providers: We use Google Analytics to understand site usage. Google collects anonymized analytics data (it may process IP addresses and usage data) to help us improve our site support.google.com. We disclose this clearly and you can opt out via cookie settings. Google’s privacy policies and safeguards (including the EU-US Data Privacy Framework) apply to analytics data.

  • Email Service Providers: If we send email newsletters or updates, we will use a professional emailing service. We will only send marketing emails to users who have opted in, in compliance with UK law ico.org.uk.

  • Other Providers: We may use services for fraud detection, customer support, or hosting (e.g. databases, servers). Each third party is bound by GDPR-compliant contracts and may only use your data for the purposes we specify.

We never sell or rent your personal data to unauthorised third parties. We only share data necessary for the services above, and ensure all processors implement appropriate security measures. If any service transfers your data outside the UK/EU (for example, Google or PayPal in the US), we rely on legally approved safeguards. For transfers to the United States, for instance, these services participate in the EU-US Data Privacy Framework, which the European Commission has recognized as providing adequate protection commission.europa.eu.

Cookies and Tracking

Like most websites, we use cookies and similar technologies to make our site work, to understand how you use it, and to improve your experience. Cookies are small data files stored on your device. We use:

  • Essential Cookies: Necessary for basic website functions (e.g. keeping you logged in, maintaining your shopping cart). These are strictly necessary for our contract with you, so no opt-in is needed.

  • Analytical/Performance Cookies: To track website usage via Google Analytics. This helps us improve page load times, layout, and content. Google Analytics uses first-party cookies and does not identify you personally. According to the ICO, we must provide clear information about such cookies and obtain consent before setting them ico.org.uk. We present a cookie banner or settings page where you can agree to non-essential cookies.

  • Preference Cookies: To remember your settings (language, items added to cart) and improve convenience.

You can control cookies through your browser settings or by adjusting our Cookie Notice on the site. Disabling non-essential cookies may limit some features. We do not use cookies to collect sensitive information or to automatically share your browsing data for unrelated marketing.

Data Retention

We retain your personal data only for as long as needed to fulfill the purposes in this policy and comply with our legal obligations:

  • Order and Payment Data: We keep order, transaction and financial records for at least 6 years after the transaction, in line with UK tax and accounting laws gov.uk. This period covers the time you have ordered and the legally required retention period for company records.

  • Account Information: If you have an account, we retain your account data (contact details, password) as long as the account remains active.

  • Marketing Data: We keep records of your marketing consents until you unsubscribe. If you revoke consent, we delete your email from marketing lists.

  • Inactive/Redundant Data: Periodically, we review data we hold. If data is no longer needed (for example, you never created an account or you have not purchased in a long time), we will delete or anonymize it sooner if possible.

These retention practices help us comply with the UK GDPR’s storage limitation principle (only keep data as long as necessary ico.org.uk). After the retention period expires, data is securely deleted or anonymized.

Marketing and Advertising

We follow all relevant laws and industry standards for marketing communications:

  • Consent: We will only send you marketing emails (newsletters, promotions) if you have explicitly opted in. We will clearly identify the sender, content, and how to unsubscribe. You can withdraw consent at any time, and each marketing email will include an unsubscribe link. The ICO emphasizes that you must not send marketing emails to individuals without consent ico.org.uk.

  • Soft Opt-In: By law, we may send promotional messages about similar products to existing customers, provided we gave them a simple opt-out when collecting their contact details and in every message we send ico.org.uk. We will always honor any request to stop marketing.

  • Accuracy and Honesty: All product descriptions, advertisements, and promotions on our site are written clearly and truthfully. We do not use misleading claims, fake reviews, or exaggerated statements. Our content (product pages, blog posts, and ads) is regularly reviewed to ensure accuracy and compliance with UK advertising standards savvishop.uk. We prohibit plagiarism, hate speech, unlawful, or defamatory content in any published material savvishop.uk. In other words, marketing messages will always be fact-based and not deceptive.

We may post user-generated content (like reviews or testimonials) only with permission. Such content is labeled appropriately and is the responsibility of the user who submitted it. We moderate all user content: if we discover any illegal or inappropriate content (hate speech, defamation, pornography, etc.), we will remove it. Users grant us a license to use and display their reviews, but we do not share reviewers’ personal data publicly beyond what is voluntarily included in their review.

Your Rights (UK GDPR)

Under the UK GDPR, you have several rights with respect to your personal data, including:

  • Right of Access: You can request a copy of the personal data we hold about you, and information about how we use it.

  • Right to Rectification: You can ask us to correct any inaccuracies or complete any incomplete data we hold about you.

  • Right to Erasure (“Right to be Forgotten”): In certain circumstances, you can ask us to delete your personal data (for example, if it is no longer necessary for the purposes we collected it, or if you withdraw consent and no other legal basis exists) ico.org.uk.

  • Right to Restrict Processing: You can ask us to suspend processing your data while you contest its accuracy or if you object to our use of it (for example, if you have objected to processing and we are verifying whether we have legitimate grounds to continue).

  • Right to Data Portability: You can request your personal data in a common format (e.g. CSV) so you can transfer it to another service, when processing is based on your consent or a contract and the processing is carried out by automated means.

  • Right to Object: You have the right to object to our processing of your data for direct marketing or on grounds relating to your particular situation, unless we have compelling legitimate grounds to override. We will inform you if any processing is based on a legitimate interest and remind you that you can object ico.org.uk.

  • Right to Withdraw Consent: If we rely on your consent for any processing (such as email marketing or cookies), you can withdraw that consent at any time and we will stop the processing (provided there is no other legal basis). We make it as easy to withdraw consent as it is to give it ico.org.uk.

  • Right to Complain: You have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at any time if you believe our processing of your personal data violates the law ico.org.uk.

To exercise any of these rights, please contact us using the details below. We will respond to your request without undue delay and in any event within one month, as required by law. If we refuse your request (in whole or part), we will explain the reasons and inform you of your right to complain to the ICO.

How We Protect Your Data

We implement appropriate technical and organizational measures to protect your personal data. This includes using SSL/TLS encryption for data transmission (such as credit card details) and secure, access-controlled servers for storage. Encryption is an example of an effective measure to protect personal information and is recommended under the UK GDPR ico.org.uk. We regularly update our security practices and train our staff to safeguard data. Access to your personal data is limited to employees and contractors who need it to perform their job.

Updates to This Policy

We may update this Privacy Policy from time to time (for example, if we add new services or to reflect legal changes). When we make changes, we will revise the “Effective Date” at the top and post the new policy on our site. We encourage you to review this Privacy Policy periodically. Continued use of our site after any update means you accept the revised policy.

Contact Us

If you have any questions, requests, or concerns about this Privacy Policy or our data practices, please contact us at:

  • Email: info@savvishop.uk

For more information or to lodge a complaint, you can also contact the UK Information Commissioner’s Office at www.ico.org.uk.

Effective Date: 1 June 2025. All rights reserved by SavviShop.