Introduction
Your privacy matters to me. This policy explains clearly and honestly what personal information I collect when you shop with Denalis Jewellery, why I collect it, how I use it, and what your rights are.
I, Denise de Gromoboy, am the Data Controller for all personal data relating to Denalis Jewellery. I am registered with the Information Commissioner's Office (ICO) under reference ZB826420.
If you have any questions at all about how your data is handled, please do get in touch using the contact details at the end of this policy.
What Personal Data I Collect
The data I collect depends on how you interact with me:
When you place an order:
When you purchase through my shop, Big Cartel provides me with your name, delivery address, email address, and telephone number (if given). This is the minimum needed to fulfil your order and communicate with you about it.
When you request a commission or repair:
For bespoke commissions and repair work, I may collect additional details you share with me, such as design ideas, preferences, or information about the piece being repaired. This is used solely to create or restore your jewellery to your brief.
When you contact me:
If you get in touch by email or through the website contact form, I collect your name, email address, and the contents of your message.
When you subscribe to my newsletter:
If you sign up for my newsletter, I collect your email address and, where you choose to provide it, your name. This is managed through MailerLite. I will only ever send you my newsletter if you have actively signed up for it, and you can unsubscribe at any time using the link in any email I send.
When you visit my website:
My website is hosted on Big Cartel. Big Cartel may collect standard technical data such as your IP address and browser type as part of running the platform. Please see the Cookies section and Big Cartel's own privacy policy for more detail.
Lawful Basis for Processing
Under UK GDPR, I must have a lawful reason for processing your data. Here is the basis I rely on for each type of processing:
- Contract: Processing your order, commission, or repair, including delivering your purchase and responding to order-related queries
- Legal obligation: Retaining financial and transaction records for six years, as required by HMRC
- Legitimate interests: Responding to general enquiries and improving how I serve customers, where this does not override your rights
- Consent: Sending you my newsletter and marketing emails. You may withdraw consent at any time by clicking the unsubscribe link in any email, or by contacting me directly
Security of Your Information
My shop uses SSL encryption, which protects the information you enter at checkout. Big Cartel addresses and custom domains connected to Big Cartel shops are fully encrypted.
Payments are processed by Stripe, PayPal, or Google Pay. I do not store or process your payment card details myself. All payment providers used are PCI DSS compliant.
Who I Share Your Data With
I share your data only where it is strictly necessary:
- Big Cartel: As my shop platform, Big Cartel processes order data on my behalf
- Postal and courier services: Your name and delivery address, to fulfil your order
- Stripe, PayPal, and Google Pay: Payment processing only. I do not see or store your card details
- MailerLite: Your email address, where you have subscribed to my newsletter
- Legal and tax authorities: Where required by law
Your personal data will never be sold, rented, or shared with third parties for marketing purposes.
How Long I Keep Your Data
- Order and transaction records: Six years, in line with UK tax and accounting requirements (HMRC)
- Commission and repair records: Deleted once the work is complete and any related queries are resolved
- General enquiries: Deleted once the matter has been dealt with
- Newsletter subscribers: Until you unsubscribe or ask me to remove you
When data is no longer required, I delete it securely.
Cookies
My website is hosted on Big Cartel. Big Cartel states that its platform uses only strictly necessary cookies to make the shop function, and does not use advertising or tracking cookies on your behalf.
However, Big Cartel may set its own platform-level cookies as part of running the service. Full details can be found in their privacy policy: www.bigcartel.com/resources/policies/privacy-policy
You can manage or block cookies at any time through your browser settings. Please be aware that blocking strictly necessary cookies may affect how the shop functions.
Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access: You can request a copy of the data I hold about you
- Right to rectification: You can ask me to correct inaccurate or incomplete data
- Right to erasure: You can ask me to delete your data, subject to any legal obligations to retain it
- Right to restriction: You can ask me to limit how I use your data in certain circumstances
- Right to data portability: You can ask me to provide the data I hold about you in a format that is easy to read or transfer
- Right to object: You can object to processing based on legitimate interests
- Right to withdraw consent: Where I rely on your consent, such as for newsletter emails, you can withdraw it at any time
To exercise any of these rights, please contact me using the details below. I will respond within one month. There is no charge for making a request.
If you are unhappy with how I have handled your data, you have the right to complain to the Information Commissioner's Office (ICO):
- Website: www.ico.org.uk
- Telephone: 0303 123 1113
External Links
My website may contain links to external websites, including YouTube and social media platforms. Once you leave my site, this Privacy Policy no longer applies. I am not responsible for the privacy practices of those sites and encourage you to read their policies before sharing any personal information.
The third-party providers I use operate under their own privacy policies:
- Big Cartel: www.bigcartel.com/resources/policies/privacy-policy
- Stripe: https://stripe.com/gb/privacy
- PayPal: www.paypal.com/uk/legalhub/paypal/privacy-full
- Google: https://support.google.com/googlepay/answer/9039712?hl=en
- MailerLite: www.mailerlite.com/legal/privacy-policy
- YouTube: www.youtube.com/howyoutubeworks/privacy/
Children's Privacy
My website and services are not directed at children under the age of 16. I do not knowingly collect personal data from children. If you believe I have inadvertently done so, please contact me and I will delete it promptly.
Changes to This Policy
I may update this Privacy Policy from time to time to reflect changes in my practices or legal obligations. When I do, I will update the date at the top of this page. Where changes are significant, I will let you know via my website or newsletter.
Contact
If you have any questions about this Privacy Policy or how your data is handled, please get in touch. I am always happy to help.
Contact Denalis