This Privacy Statement explains in detail the types of personal data we may collect about you when you interact with us. It also explains how we’ll store and handle that data, and keep it safe.
We want you to be fully informed about your rights and how we use your data.
We hope the following sections will answer any questions you may have but if not, please contact us.
It’s likely that we’ll need to update this Privacy Statement from time to time, but you’re welcome to come back and check it whenever you wish.
When you are using our website, ABC Ironmongery is the data controller.
SECTION 1 - LEGAL BASES WE RELY ON
The law on data protection sets out a number of different reasons for which a company may collect and process your personal data, including:
Consent : In specific situations, we can collect and process your data with your consent. eg. when you tick a box to receive email newsletters.
Contractual obligations : In certain circumstances, we will need your personal data to comply with our contractual obligations. eg. when you order an item or items via our website or over the phone we'll collect details of your address, email address and a contact number to enable us to delivery your purchase and we'll pass them to our courier or contracted delivery partner.
Legal compliance : If the law requires us to, we may need to collect and process your data. eg. we can pass on details of people involved in fraud or other criminal activity affecting us to relevant law enforcement agencies.
Legitimate interest : In specific situations, we require your data to pursue our legitimate interests in a way which might reasonably be expected as part of running our business and which does not materially impact your rights, freedom or interests. eg. we may use your purchase history or knowledge of your business to send or make personalised offers to you, if you have requested information about a product or service we offer or if you have requested us contacting you to inform you that a product that was previously out of stock is now available again.
SECTION 2 - WHEN DO WE COLLECT YOUR INFORMATION?
When you visit our website to buy products and services.
When you make an online purchase and check out as a guest (in which case we just collect transaction-based data).
When you create an account with us.
When you purchase a product or service in person or by phone either by using or without using your account.
When you engage with us on social media.
When you contact us by any means regarding stock availability, product specification or size, complaints, general queries etc.
SECTION 3 - WHAT DO WE DO WITH YOUR INFORMATION?
This is how we’ll use your personal information and why:
To process any orders that you make by using our website, via the phone or in person. If we don’t collect your personal data during checkout, we won’t be able to process your order and comply with our legal obligations.
Eg. Your details may need to be passed to a third party to supply or deliver the product or service that you ordered and we may keep your details for a reasonable period afterwards in order to fulfil any contractual obligations such as refunds, guarantees etc.
To respond to your queries, refund requests and complaints. Handling the information you send enables us to respond. We may also keep a record of these to inform you of any future communication with us and to demonstrate how we communicated with you throughout. We do this on the basis of our contractual obligations to you, our legal obligations and our legitimate interests in providing you with the best service and understanding how we can improve our service based on your experience.
SECTION 4 - HOW WE PROTECT YOUR INFORMATION
We understand how much data security matters to all our customers. To this end, we will treat your data with the utmost care and take all appropriate steps to protect it and ensure that it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
We secure access to all transactional areas of our websites and apps using ‘https’ technology.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
SECTION 5 - YOUR RIGHTS OVER YOUR INFORMATION
You have the right to request the following:
Access to the personal data we hold about you, free of charge in most cases.
The correction of your personal data when incorrect, out of date or incomplete.
Your right to withdraw consent
Whenever you have given us your consent to use your personal data, you have the right to change your mind at any time and withdraw that consent for us to contact you, for the continued collection, use or disclosure of your information, at anytime, by contacting us at firstname.lastname@example.org or writing to us us at: ABC Ironmongery, Darley Abbey Mills, Derby GB DE22 1DZ
SECTION 6 - CONSENT
How do you get my consent?
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.
If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent, or provide you with an opportunity to say no.
How do I withdraw my consent?
See Section 5 Your rights over your information.
SECTION 7 - DISCLOSURE
It has always been our policy to NEVER share, pass on or sell our customers personal information to any third party unless for legitimate purposes to fulfil an order via a courier or contracted delivery partner. This will remain the case in perpetuity.
We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.
SECTION 8 - SHOPIFY
Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
For more insight, you may also want to read Shopify’s Terms of Service (https://www.shopify.com/legal/terms) or Privacy Statement (https://www.shopify.com/legal/privacy).
SECTION 9 - THIRD-PARTY SERVICES
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.
For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
In particular, remember that certain providers may be located in or have facilities that are located a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
SECTION 10 - COOKIES
Here is a list of cookies that we use. We’ve listed them here so you that you can choose if you want to opt-out of cookies or not.
_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
_shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer.
cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
_secure_session_id, unique token, sessional
storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
SECTION 11 - AGE OF CONSENT
By using this site, you represent that you are over the age of 16. For age-restricted Goods, you confirm that you are over the age of 18 and that delivery will be accepted by a person over the age of 18. We reserve the right to cancel the Order if we reasonably believe you are not legally entitled to order certain Goods.
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
QUESTIONS AND CONTACT INFORMATION
If you would like to access, correct, amend or delete any personal information we have about you, register a complaint or simply want more information contact our Privacy Compliance Officer at email@example.com or write to us at ABC Ironmongery, The Coppice Barn, Darley Abbey Mills, Derby DE22 1DZ.