We understand the importance of our customers' personal data and respect their privacy. We comply with the General Data Protection Regulations and do everything we can to uphold its key principles. This means that
- We will be clear and open about the way we collect, store and use personal data and how we use it.
- We will only collect the data for each individual that is adequate and relevant for us to run the business effectively
- We will do everything we can to keep the data accurate and up to date and will not keep it for longer than is necessary.
- The processes we have in place for collecting, storing and using data will, as far as is possible and reasonable, ensure that it is kept safely and only accessed by those who need to see it.
Data Collection - we collect personal data
In the shop
- When people ask to receive our newsletter - name & email address
- When customers book on our workshops - name & email address and / or telephone number in case we need to contact them about the workshop
- When people ask us to contact them with information - name & email address and / or phone number
On our website
- When people opt-in to receive our newsletter - name & email address
- When customers book on our workshops - name & email address and / or telephone number so we can confirm the booking and contact them about the workshop if needed
- When customers place an order for delivery - name, address & email address and / or telephone number - so we can deliver the order, confirm we have dispatched it and contact the customer about it if necessary
- When people message us - name & email address - so we can reply to their request
- To measure the effectiveness of the website
Data Storage - we store this data
In the shop
- Newsletter sign up - Names & email address are collected on slips of paper which are kept for a maximum of a year and then destroyed securely
- Workshop attendance - names and email addresses or phone numbers are written in our shop diary and only accessed by shop team members. After year end, diaries are kept in the back office area.
Electronically - data is kept on our management systems for up to 7 years and password protected so they can only be accessed by those who need to use them within the business
We do not share our customers, suppliers or employees personal data with any individuals or organisations other than the following:
- Our hosted content management system
- Our email marketing system
- Our online finance system
- Our accountant
- Our digital and IT consultant where appropriate
- Google Analytics in the case of website visitors
If you want any of your personal data removed from our systems, please email hello@coastalcraftcollective. You can also ask to check and amend the data we hold about you at any time and we will respond to your request within one month.May 2018