Stroud Green Florist Privacy Policy
Introduction
Stroud Green Florist is committed to safeguarding the privacy and personal data of our customers. This Privacy Policy describes how we collect, use, store, and protect your personal information in accordance with the UK General Data Protection Regulation (UK GDPR). The policy applies to all customers placing orders with Stroud Green Florist for delivery or collection in Stroud Green and surrounding districts.
What Data We Collect
When you place an order or interact with Stroud Green Florist, we collect various types of personal data to process your order and provide our services. The types of data we may collect include:
- Identity information: such as your full name and, if applicable, the recipient’s name.
- Contact information: including your address, delivery address, and any additional delivery instructions, as well as telephone numbers (where provided).
- Order details: the content of your order, payment amount, preferred delivery date, and any messages for greeting cards accompanying the flowers.
- Payment information: including payment method and transaction reference. We do not directly store full card details; these are handled securely by our payment processor (see section on Processors).
- Communications: information you provide when you contact us for enquiries, feedback, complaints, or aftercare, including all correspondence.
- Technical data: limited information from your interaction with our website (such as IP address, browser type, and device information) for security and analytics purposes.
Lawful Basis for Processing
We process your personal information using the following legal bases as set out in Article 6 of the UK GDPR:
- Contractual necessity: Most of the personal information we collect is required to fulfil your order and meet our contractual obligations to you.
- Legitimate interest: We process information such as communications and certain analytics data to ensure the effective delivery of our services, maintain our business operations, and improve customer experience, provided these interests are not overridden by your rights and freedoms.
- Legal obligation: We may retain and process certain records as required to comply with accounting, tax, and other statutory duties.
- Consent: In instances where consent is the lawful basis, for example, for direct marketing, you will be explicitly informed and given the choice to opt in.
How We Use Your Data
Your personal data is used for the following purposes:
- To process orders and deliver products and services to your nominated address.
- To update you on the status of your order or respond to your customer service enquiries.
- To manage and improve our website, products, and services.
- To comply with legal and regulatory requirements.
- For accounting and tax purposes.
- To protect our business, website, and customers from fraud and abuse.
- Where permitted, to send information about our own services or promotions, subject to your communication preferences.
How Long We Keep Your Data
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. The main retention periods are as follows:
- Order information: Held for up to six years from the date of transaction for tax, accounting, and possible warranty or dispute purposes.
- Marketing preferences: Retained only as long as you remain subscribed or express an ongoing interest.
- General correspondence: Retained for up to three years from the date of your last contact with us, unless a longer period is legally required or necessary for dispute resolution.
- Technical and analytics data: Kept for a maximum of two years for security and business analysis purposes.
When your data is no longer required, we securely delete or anonymise it.
Processors and Data Sharing
We engage third-party service providers (“processors”) to support our business operations, and we ensure that each meets the requirements of the GDPR. The main categories of processors we use include:
- Payment processors: Securely manage payments and refund transactions on our behalf. These processors do not have our permission to use your payment information for any purpose other than processing transactions.
- IT and website support services: Provide technical infrastructure and help maintain the functionality and security of our website and digital systems.
- Delivery partners: When required for fulfilling an order, relevant delivery information may be shared with a trusted courier or delivery service operating on our behalf.
- Accountants and legal advisers: Only where required, to comply with our legal obligations.
We never sell your personal data or share it for unrelated third-party marketing. Where processors are located outside the UK or EEA, we ensure appropriate safeguards are in place to protect your information.
Your Rights Under UK GDPR
You have a range of rights over your personal information under the UK GDPR, including:
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You have the right to have incomplete or inaccurate data corrected.
- Right to erasure (‘right to be forgotten’): You can request deletion of your data when it is no longer needed or where processing is based on your consent.
- Right to restriction: You can ask us to restrict the use of your personal data in certain circumstances.
- Right to data portability: In some cases, you may be entitled to receive your data in a commonly used format and transmit it to another provider.
- Right to object: You can object to the processing of your personal information for direct marketing at any time or on grounds relating to your particular situation.
- Right to withdraw consent: If your data is being used on the basis of your consent, you may withdraw this at any time.
If you wish to exercise any of these rights or have concerns about how your data is being used by Stroud Green Florist, you can contact us using the details provided on our website or in your order confirmation. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), which is the UK supervisory authority for data protection issues.
Policy Updates and Further Information
We may update this Privacy Policy to reflect changes in our practices, legal obligations, or regulatory guidance. When changes occur, we will update the date and provide information about significant changes on our website. We encourage you to review this policy regularly. For further questions about our privacy practices, please refer to our website for details on how to contact us.