
Privacy Policy
Privacy Policy – Harper’s Lush Locks
Effective Date:17/09/2025
Harper’s Lush Locks (“we,” “our,” or “us”) is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
Harper’s Lush Locks is the data controller of the personal data you provide. If you have any questions, please contact us:
📧 Harperslushlocks@gmail.com
2. Personal Data We Collect
We may collect and process the following personal data:
-
Identity Data: name, date of birth (if provided).
-
Contact Data: email address, phone number, billing/shipping address.
-
Payment Data: payment details (processed securely by third-party providers – we do not store full card details).
-
Transaction Data: details of purchases and orders.
-
Technical Data: IP address, device type, browser information, cookies, and site usage analytics.
-
Marketing Data: preferences for receiving promotions and communications.
3. How We Use Your Personal Data
We will only use your personal data where lawful to do so, including:
-
Contractual necessity – to process and deliver your orders.
-
Legal obligation – to comply with UK law and tax regulations.
-
Legitimate interests – to improve services, prevent fraud, and ensure site security.
-
Consent – to send you marketing emails, offers, or newsletters (you may withdraw consent at any time).
4. Sharing Your Data
We will never sell your data. Your data may be shared with:
-
Payment processors (e.g., Stripe, PayPal).
-
Delivery partners (e.g., Royal Mail, courier services).
-
IT and website service providers who support our business operations.
-
Regulatory or legal authorities, if required by law.
All third parties are required to respect your privacy and keep your data secure.
5. International Data Transfers
Where data is transferred outside the UK/EEA (e.g., through cloud services), we ensure appropriate safeguards such as Standard Contractual Clauses (SCCs) are in place to protect your information.
6. Data Retention
We retain your personal data only as long as necessary for the purposes collected, including legal, accounting, or reporting requirements. Typically:
-
Customer/order data: up to 6 years (for tax purposes).
-
Marketing data: until you withdraw consent.
7. Your Legal Rights
Under the UK GDPR, you have the right to:
-
Access – request a copy of the personal data we hold about you.
-
Rectification – correct inaccurate or incomplete data.
-
Erasure – request deletion of your data (where legally possible).
-
Restriction – limit how we process your data.
-
Data portability – request your data in a structured, machine-readable format.
-
Object – stop processing for direct marketing purposes.
-
Withdraw consent – at any time for activities based on consent.
To exercise these rights, contact us at [Insert email].
8. Cookies
Our website uses cookies to enhance your browsing experience, analyze site traffic, and personalize content. You may disable cookies in your browser settings, though some features may not function properly.
9. Security
We use secure servers, encryption, and restricted access protocols to safeguard your personal data against unauthorized use, loss, or disclosure.
10. Complaints
If you believe your data has been mishandled, you may lodge a complaint with the Information Commissioner’s Office (ICO):
📍 ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF