We are committed to protecting your privacy.
• Our Facebook Page - darkechoesodditiesboutique
• Our Website – https://www.darkechoesoddities.co.uk
• Our Instagram Account – dark_echoes_oddities
WHAT WE DO WITH IT AND WITH WHOM WE SHARE IT
HOW DO WE COLLECT YOUR PERSONAL INFORMATION?
There are a number of ways in which we collect your personal information. The two main ways are from things you tell us yourself, and from things other people or organisations share with us.
Things you tell us could include:
- Messages sent through the ‘Contact us’ page on our website
- Messages and emails sent as conversations
- Orders placed through the website
- Payments made through PayPal
THINGS OTHER PEOPLE OR ORGANISATIONS MAY SHARE WITH US COULD INCLUDE:
- Name and address
- Order details
- Payment / Order received notifications (such as from PayPal)
Other ways personal information can be collected:
- Via cookies – information on this can be found at: http://www.whatarecookies.com/
- When you provide details to us either online or offline (such as in conversation)
- From a third person (such as when sending an order to the recipient directly)
WHAT PERSONAL INFORMATION DO WE COLLECT?
- Contact details such as name, postal address, email address and telephone number
- Copies of messages relating to an order.
- Information relating to a third person (such as specifications for a Custom order)
- Addresses relating to a third person (such as a gift being delivered to someone else and not the purchaser)
NO Information relating to financial details are collected by us. All payments are handled by either Paypal or Create Payment gateways.
HOW DO WE USE YOUR INFORMATION?
We only collect, use and store your information where we have lawful grounds and legitimate business reasons to do so. We mainly use your information in the process of fulfilling orders, to make enquiries (such as finding postage costs prior to ordering) to confirm an order and/or payment and for any other customer requests/changes.
We will only share your personal information to other parties where it is a necessary part of the activities that we undertake, where you give us consent or where we are required to do so by law or regulation.
This may include:
- Sharing of name and address when it is required for online purchase of postage
- Sharing of name, address and telephone number when it is required for online purchase of Courier Services.
(Parcel Force, DHL or similar reputable companies)
- Sharing of name, address and telephone numbers when it is required for third party Courier services to arrange a delivery (Parcelforce and similar reputable companies. The Individual Privacy policies for the Postal/Courier services we use can be found at the end of this policy)
We only share your information if we are satisfied that services providers have sufficient measures in place to protect your information in the same way that we do.
We never share your information outside for marketing purposes, We do not provide a mailing list service or anything similar.
Transfer of personal data outside the UK
Certain personal information held on our Information Technology systems may be transferred across geographical borders in accordance with applicable law.
By providing us with your information, you consent to the collection, international transfer, storage, and processing of your information. These transfers are governed by European Union (EU) standard contractual clauses or equivalent data transfer agreements to protect the security and confidentiality of personal information.
How long we keep information about you
We will only keep your information for as long as it is required to fulfil the relevant purposes, order fulfillment, query, Customer service or as required by HMRC. Non identifiable information may be kept for up to 7 years.
General Enquiries through Facebook Page /Messenger services/ Email etc.:
Messages and emails are deleted after replying or within 24 hours.
Specific Queries / Custom order enquiries, etc.
These are kept on the platforms used (ie: Facebook Messenger) until the customer query is dealt with sufficiently. Once this has happened or a week has passed without reply, the messages are deleted.
We print a copy of each order placed through the website, or through PayPal. This is done to keep orders together, prioritise orders, for order fulfilment and to provide an invoice which is sent with each order to the customer/recipient. Along with the order is a proof of posting receipt, which is kept with the order in case of problems arising with the postal / Courier service, such as non-delivery.
Once the order is received by the customer / recipient, and no problems have arisen, we confidentially and securely destroy all orders and anything identifiable relating to the customer.
Emails – Order notifications
These are deleted from the email server when the order is printed off.
Emails – Paypal Payment notifications
These are deleted from the email server once they have been printed off.
Emails – Notifications / Messages from Social Media
These are deleted from the email server daily.
How information is stored
All orders placed through the website is kept by the website provider Create.
All payment transactions are handled by Create Payment gateways and Paypal and stored by them.
Order and Payment notifications are sent to a Password protected email address,and forwarded to my PC using a secure mailhost service.
The computer I use is for my own use only. It is password protected and has Norton Security.
MOBILE DEVICES: PHONE/TABLET
I only use mobile devices for responding to messages, I do not use them for checking or fulfilling orders. Both devices are password protected and have Norton Security.
Any information in paper form (orders, proof of posting, etc.) are securely locked in a box. Once your information is no longer needed it will be securely and confidentially destroyed
- Any individual whose personal information we hold has the right to:
object to us processing it. We will either agree to stop processing or explain why we are unable to (the right to object)
- Ask for a copy of their personal information we hold, subject to certain exemptions (a data subject access request)
- Ask us to update or correct their personal information to ensure its accuracy (the right of rectification)
- Ask us to delete their personal information from our records if it is no longer needed for the original purpose (the right to be forgotten)
- ask us to restrict the processing of their personal information in certain circumstances (the right of restriction)
- ask for a copy of their personal information, so it can be used for their own purposes (the right to data portability)
- complain if they feel their personal information has been mishandled. Iencourage individuals to come to me first, but they are entitled to complain directly to the Information Commissioner's Office (ICO) www.ico.org.uk
- ask us, at any time, to stop processing their personal information, if the processing is based only on individual consent (the right to withdraw consent).
If you wish to exercise any of these rights please contact us at: [email protected]
Links to Processors/Hosts/Services as used by Dark Echoes.
- PayPal: www.paypal.com
- Instagram: www.instagram.com
- Facebook: www.facebook.com
- Royal Mail: www.royalmail.com
- Parcelforce Worldwide: www.parcelforce.com
- Gmail (email): www.google.com/gmail