Last updated: January 2025
1. Who We Are
Velvet & Valor Ltd (“we”, “us”, “our”) is a company registered in England and Wales. We operate the website velvetandvalor.com and are the data controller of your personal information. We take your privacy seriously and are committed to protecting it in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
If you have any questions about this policy or how we handle your data, please contact us at privacy@velvetandvalor.com.
2. Information We Collect
We collect the following types of personal information:
- Identity data: your name and, if you request engraving, the text you provide.
- Contact data: your email address, delivery address, and telephone number.
- Transaction data: details of purchases you make and payment confirmations. We do not store card details — payments are processed by Stripe, who are independently certified to PCI DSS Level 1.
- Technical data: IP address, browser type and version, time zone, browser plug-in types, operating system, and platform.
- Usage data: information about how you use our website, including pages visited and time spent.
- Marketing and communications data: your preferences for receiving marketing from us, and your communication preferences.
3. How We Use Your Information
We use your personal data for the following purposes:
- To process and fulfil your order, including arranging delivery and sending order confirmations.
- To manage your relationship with us, including responding to enquiries and complaints.
- To send you marketing communications where you have opted in, or where we have a legitimate interest to do so as an existing customer.
- To administer and improve our website, including troubleshooting and data analysis.
- To comply with legal obligations, including tax and fraud prevention requirements.
4. Legal Basis for Processing
We rely on the following legal bases to process your personal data:
- Performance of a contract: processing necessary to fulfil your order.
- Legitimate interests: where our interests (or those of a third party) override your interests and fundamental rights — for example, fraud prevention and direct marketing to existing customers.
- Consent: where you have opted in to receive marketing emails from us. You may withdraw consent at any time.
- Legal obligation: where processing is required by law.
5. Sharing Your Information
We do not sell your personal data. We share your information only with trusted third parties who assist in delivering our products and services, including:
- Stripe: payment processing. Stripe's privacy policy is available at stripe.com/privacy.
- DHL / courier partners: to arrange delivery of your order.
- Email service providers: to send transactional and marketing emails.
- Website analytics providers: to help us understand how visitors use our site.
All third-party processors are required to process your data in accordance with applicable data protection law and our written instructions.
6. International Transfers
Some of our third-party providers are based outside the UK. Where we transfer your data internationally, we ensure adequate protections are in place, including Standard Contractual Clauses or adequacy decisions as recognised under UK GDPR.
7. Data Retention
We retain your personal data only for as long as necessary. Order records are kept for 7 years to comply with HMRC requirements. Marketing preferences are retained until you opt out. Technical and analytics data is typically retained for no longer than 26 months.
8. Your Rights
Under UK GDPR, you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: ask us to correct inaccurate or incomplete data.
- Erasure: ask us to delete your personal data in certain circumstances.
- Restriction: ask us to restrict how we process your data.
- Portability: request your data in a structured, machine-readable format.
- Object: object to processing based on legitimate interests or for direct marketing.
- Withdraw consent: where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at privacy@velvetandvalor.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Cookies
We use cookies and similar tracking technologies on our website. For full details of the cookies we use and how to manage them, please see our Cookie Policy.
10. Changes to This Policy
We may update this policy from time to time. The date at the top of this page reflects when it was last revised. We will notify you of any significant changes by email if you are a customer.