Privacy Policy
Effective Date: 16th October 2025
1. Introduction
The Beau Nash Ltd (“we”, “us”, or “our”) is committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This Privacy Policy explains how we collect, use, store, and protect your information when you interact with us, including when you visit our website and make purchases via our ecommerce store (WordPress + SureCart).
2. Who We Are
Data Controller: The Beau Nash Ltd
Company Number: [Insert Company Number]
Registered Address: 28 & 31 Brock Street, Bath, BA1 2LN, UK
Email: [email protected]
Data Protection Officer: Not appointed.
EU/EEA Representative (if applicable): Not applicable unless we begin targeting the EEA.
3. Data We Collect
We may collect and process the following categories of personal data:
- Identity and contact data: name, email address, phone number, postal/billing/shipping address.
- Account data: login, password (hashed), order history, saved preferences.
- Order and transaction data: products purchased, order dates, amounts, currency, tax, shipping method, refund/chargeback information.
- Payment data: processed by our payment providers (e.g., Stripe, PayPal). We do not store full card details; we may receive tokens and status information.
- Communications: enquiries, support requests, marketing preferences.
- Technical and usage data: IP address, device identifiers, browser type, pages viewed, referring/exit pages, timestamps, approximate location, collected via cookies and similar technologies.
We use the following services which may collect technical/usage data:
- Google Analytics (website usage statistics)
- Google Invisible reCAPTCHA (spam/abuse prevention)
- WordPress core and plugins (site functionality and security)
- SureCart (ecommerce/checkout and customer accounts)
- Stripe and/or PayPal (payment processing)
4. How We Use Your Data
- To operate our website and ecommerce store, including processing and fulfilling orders, deliveries, and returns.
- To create and manage customer accounts in SureCart.
- To process payments and prevent fraud (via payment processors and security tools).
- To respond to enquiries and provide customer support.
- To send service communications (order confirmations, delivery updates, account notices).
- To send marketing communications where permitted (you can opt out at any time).
- To improve our website, products, and user experience through analytics.
- To maintain site security and protect against spam and abuse.
- To comply with legal and tax obligations.
5. Legal Bases for Processing
- Contract: to process and deliver your orders, manage your account, provide customer service.
- Consent: for marketing emails and non-essential cookies/analytics (where required).
- Legitimate interests: to improve our services, ensure website security, prevent fraud, and understand site usage (balanced against your rights).
- Legal obligation: to keep records for tax/accounting and to respond to lawful requests.
6. Sharing Your Data
We do not sell your personal data. We may share data with trusted service providers who act as our processors and are contractually required to protect your data and only use it for specified purposes, including:
- SureCart: ecommerce, checkout, customer accounts.
- Payment processors: Stripe and/or PayPal for payment processing and fraud prevention.
- Hosting/CDN and security: our website host and security services (e.g., firewall, spam protection, reCAPTCHA).
- Analytics: Google Analytics.
- Email/communications: order confirmations and service emails (and marketing providers if used).
- Professional advisers and authorities: accountants, auditors, legal advisors, law enforcement where required.
7. International Data Transfers
Some providers (e.g., Google, Stripe, PayPal) may process data outside the UK. Where data is transferred internationally, we rely on lawful transfer mechanisms under the UK GDPR (such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses with the UK Addendum, and where applicable, adequacy decisions). Further details are available on request.
8. Data Retention
We keep personal data only as long as necessary for the purposes set out above or as required by law. Typical periods include:
- Orders and transaction records: generally 6 years for tax/accounting.
- Customer accounts: active while you have an account; deleted or anonymised after inactivity, subject to legal retention needs.
- Marketing data: until you opt out or your consent is withdrawn, then added to a suppression list to respect your choice.
- Technical logs/security data: retained for a limited period necessary for security and troubleshooting.
9. Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data (subject to legal obligations).
- Object to or restrict processing in certain circumstances.
- Data portability for information you provided to us.
- Withdraw consent at any time where processing is based on consent.
- Not be subject to decisions based solely on automated processing where it has legal or similarly significant effects.
To exercise your rights, contact us at [email protected]. We may request information to verify your identity. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
10. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. Measures include encryption in transit (HTTPS), access controls, and regular updates/patching. No system is completely secure; we encourage you to use strong, unique passwords and keep them confidential.
11. Cookies and Similar Technologies
We use cookies and similar technologies for site functionality, performance, analytics, and security. Non-essential cookies (e.g., analytics) are used with your consent where required. You can manage your preferences via our cookie banner (if presented) and your browser settings. Disabling some cookies may affect site functionality.
Third-party services that set cookies or collect data may include Google Analytics and Google reCAPTCHA. For more information, see Google’s privacy policy and your Google ad settings.
12. Children
Our website and services are not intended for children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us to request deletion.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. We encourage you to review this page periodically to stay informed.
14. How to Contact Us
If you have questions about this policy or how we handle your data, contact:
The Beau Nash Ltd, 28 & 31 Brock Street, Bath, BA1 2LN, UK
Email: [email protected]