Flower Delivery Cowley Privacy Policy
Introduction
This Privacy Policy describes how Flower Delivery Cowley collects, uses, and protects personal data of individuals placing orders with us from Cowley and its surrounding districts. We are dedicated to ensuring your privacy is protected and that your rights under the General Data Protection Regulation (GDPR) are upheld. This policy lays out the types of information we gather, our reasons for doing so, how long we keep it, who processes the data on our behalf, and the rights you have as a data subject.
Scope of this Policy
This Privacy Policy applies to all Flower Delivery Cowley customers ordering flowers and related services in Cowley and nearby areas. By using our services or placing an order, you acknowledge and accept the practices outlined here.
Information We Collect
We collect data to efficiently process your flower delivery order, maintain records, and ensure customer satisfaction. The types of personal data we typically collect include:
- Contact Information: Your name, address (including delivery and billing address), and phone number.
- Order Details: Items ordered, preferences, messages included with deliveries, and any delivery instructions you provide.
- Payment Information: Transaction details such as payment card type, partial card number, payment amount, and confirmation status. We do not retain full card numbers or CVV codes.
- Account Information: Login credentials if you register an account with us.
- Communications: Records of correspondence with you, including enquiries, complaints, and reviews.
- Technical Data: Internet Protocol (IP) address, browser type, and usage information when you visit our website for analytics and security.
Lawful Basis for Processing
Under the GDPR, we must have a valid lawful basis for processing your personal data. Flower Delivery Cowley relies on several:
- Contractual Necessity: Most data processing occurs to fulfil your order, provide customer service, and handle payment transactions.
- Legal Obligation: We may retain personal data to comply with legal requirements, such as accounting and tax regulations.
- Legitimate Interests: For activities such as improving our service, safeguarding our website, or marketing similar services, when these interests are not overridden by your rights.
- Consent: For direct marketing beyond our usual services or other purposes where legally required, we obtain your explicit consent. You may withdraw your consent at any time.
How We Use Your Data
We use the information we collect for the following purposes:
- To process and deliver your orders, including handling payment and keeping you updated on delivery status.
- To provide customer support, respond to inquiries, and resolve issues.
- To personalise your experience, such as remembering your preferences and previous orders.
- To meet accounting, legal, or regulatory requirements.
- To improve our website, services, and offerings through analysis of usage patterns.
- To communicate with you about promotions, updates, or similar services, when permitted.
How Long We Keep Your Data (Retention)
We do not keep your personal data longer than necessary. The period varies depending on the type of information:
- Order Records, Contact and Delivery Details: Retained for up to 7 years to comply with legal and accounting obligations.
- Customer Account Information: Stored as long as your account remains active or for 2 years after inactivity unless you request deletion.
- Marketing Communications: Retained until you unsubscribe or withdraw consent.
- Correspondence and Complaints: Maintained for up to 3 years to manage customer service history and resolve disputes.
- Technical and Analytical Data: Aggregated and anonymised after one year for statistical analysis.
After the applicable retention period, your data is securely deleted or anonymised.
Processors and Third Parties
To provide our services, it is necessary to share certain data with trusted third parties acting as data processors under our instruction:
- Payment Providers: We use external payment processors to handle payment securely. Only transaction-related information is shared, and we never store your complete card details.
- IT Service Providers: Our website, database, and communications may be hosted by third-party service providers offering secure managed services, maintenance, and support.
- Delivery Partners: In the event of partnering with local couriers, only necessary information (e.g., recipient’s name and address) is provided to fulfil delivery.
- Legal and Regulatory Authorities: Data may be disclosed if required by law or legal proceedings.
All processors are required to comply with GDPR and are prohibited from using your data for unrelated purposes. We do not sell or share your personal data with other third parties for marketing.
Your Rights Under GDPR
You have a number of important rights over your personal data:
- Right of Access: Request access to your personal data we hold.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Ask us to delete your personal data, subject to legal or contractual retention requirements.
- Right to Restrict Processing: Request to limit how we use your data in certain circumstances.
- Right to Data Portability: Obtain your information in a structured, commonly used, machine-readable format and request its transfer to another provider where feasible.
- Right to Object: Object to processing in specific situations, particularly direct marketing.
- Right to Withdraw Consent: Withdraw any consent you have given us at any time, where applicable.
To exercise your rights, please contact us through our published contact details on our website. We may require identification to ensure your data is only transferred or deleted at your request.
Data Security
Your security is important to us. We implement suitable technical and organisational measures to safeguard your personal data from loss, theft, unauthorised access, and disclosure. This includes encrypted communications, secure servers, and ensuring our partners follow high data protection standards.
Children’s Privacy
Flower Delivery Cowley services are not intended for use by individuals under the age of 16. We do not knowingly collect data from children. If you believe a child’s information has been provided, please contact us so we can remove it promptly.
Changes to This Policy
We may amend this policy from time to time to reflect changes in the law or our data practices. Updates will be published on our website, and we encourage you to review this page periodically.
Contact Us
If you have any questions about this Privacy Policy, your rights, or how we handle your data, please reach out through the contact details listed on our website.