Ealing Florist Privacy Policy for Customers
Introduction
At Ealing Florist, we are committed to protecting your privacy and ensuring your personal data is handled with care. This Privacy Policy sets out how we collect, use, store, and protect your information in accordance with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018. This policy applies to all customers placing Ealing Florist orders in Ealing and surrounding districts.
What Personal Data We Collect
To provide you with our products and services, we collect and process the following categories of personal data:
- Identity Data: Name, surname, and title.
- Contact Data: Address, delivery address, postcode, phone number (optional), and any special instructions.
- Order Data: Details of floral arrangements, messages to recipients, payment history, and order preferences.
- Payment Data: Payment method (such as card type), card details provided at checkout (processed securely via payment gateway processors and never stored by Ealing Florist), and transaction details.
- Technical and Usage Data: IP address, device type, browser type, operating system, and information about how you use our website (collected via cookies and analytics where permitted).
Lawful Basis for Data Processing
We process your personal data only where we have a valid legal basis as required by the GDPR. These include:
- Contractual Necessity: To process and deliver your order, provide customer service, and manage payments and refunds.
- Legitimate Interests: To improve our services and website, send order or delivery updates, manage customer relationships, address complaints, and prevent fraud.
- Legal Obligation: To comply with UK law, for example, keeping certain transaction records for tax and accounting purposes.
- Consent: Where we seek your explicit consent for direct marketing or use of non-essential cookies. You can withdraw your consent at any time.
How We Use Your Personal Data
Your information is used strictly for the following purposes:
- Processing and delivering your flower orders.
- Communicating with you regarding your orders, delivery updates, and responding to enquiries.
- Personalising your shopping experience and providing customer support.
- Managing payment processing securely through trusted payment processors.
- Meeting legal, taxation, and regulatory obligations.
- Where you have opted in, sending special offers and marketing communications that may interest you.
Retention: How Long We Keep Your Data
Personal data is retained only as long as necessary to fulfil the purposes for which it was collected and to comply with legal or regulatory obligations. In general:
- Order and contact data are retained for up to six years from the date of your last transaction, for accounting and legal compliance.
- Payment details are handled securely by our payment processor and are not stored by us.
- Marketing consent records are kept for as long as you remain subscribed to receive communications from us.
- Technical and usage data collected for analytics may be held for up to two years, after which it is anonymised or deleted.
Data Security and Processors
We take the security of your information seriously and implement appropriate technical and organisational measures to protect your data against loss, misuse, and unauthorised access. Where we use third-party service providers (processors) to deliver our services or process payments, we ensure they meet robust privacy and security standards. Current categories of data processors include:
- Payment processing providers (for secure card payments).
- Delivery couriers (for delivering orders to your chosen address).
- IT hosting and website support providers (for maintaining our website and online order system).
- Analytics tools (to help us understand how our website is used and improve user experience).
All third-party processors are contractually bound to protect your data and to use it only for the specified services on our behalf.
Sharing of Personal Data
We do not sell your personal data. Your information is shared only as necessary with trusted partners and third-party processors as described above, and always in accordance with data protection laws. In some instances, we may be required to share data with regulatory authorities or law enforcement, where legally required.
Your Rights Under the GDPR
GDPR provides you with various rights concerning your personal data. You have the right to:
- Access: Request access to your personal data and obtain a copy.
- Rectification: Request corrections to incomplete or inaccurate information.
- Erasure: Request deletion of your personal data, where it is no longer required for the original purpose or you have withdrawn consent.
- Restriction: Request restriction of processing, under certain circumstances.
- Object: Object to processing based on legitimate interests, or to direct marketing at any time.
- Data Portability: Request transfer of your personal data to you or another service provider in a structured, commonly used format.
- Withdraw Consent: Where processing is based on consent, you can withdraw it at any time without affecting prior lawful processing.
If you wish to exercise any of these rights, please contact us using the details provided on our website or at our store.
Cookies and Analytics
Our website uses cookies to enhance your browsing experience, for core site functionality, and for analytics (where permitted). Non-essential cookies are placed only where you have provided consent. You can manage your cookie preferences in your browser settings or through website prompts.
Policy Changes
We may update this Privacy Policy from time to time. Any significant changes will be highlighted on our website. We encourage you to review this policy regularly to stay informed about our practices.
Contact and Questions
If you have any questions or concerns regarding your privacy or how we handle your personal data, please visit our store or contact us using details available on our official website. We are committed to addressing your requests and concerns promptly and in accordance with applicable data protection laws.