Privacy Policy for Crystal Palace Florist Users
Introduction
This Privacy Policy outlines how Crystal Palace Florist ("we", "us", or "our") collects, uses, shares, and protects your personal information when you order flowers and related services from us. This Policy applies to all customers placing orders from Crystal Palace and surrounding districts.
What Data We Collect
When you place an order or interact with us, we may collect the following types of personal data:
- Identification data: Your full name and, where applicable, the name of the recipient.
- Contact information: Address, delivery address, phone number, and (where provided) email address.
- Order and transaction data: Details about your purchases, requested delivery dates, payment status, and order history.
- Payment information: Limited payment details, such as transaction reference numbers (note: we do not process or store full card details).
- Correspondence: Messages, instructions, or preferences you communicate to us.
We do not intentionally collect or process special category data (such as health information or data revealing racial or ethnic origin) unless you provide it incidentally during your communications with us (e.g., in a personalized card message). Such data is treated with extra care and only processed when strictly necessary for your order.
Lawful Basis for Processing
We process your personal data lawfully, fairly, and transparently in accordance with the General Data Protection Regulation (GDPR). The lawful bases under which we process your information are:
- Contractual necessity: To process and fulfill your orders, deliver products, manage payments, and provide customer service.
- Legal obligation: To comply with applicable laws and record-keeping requirements (e.g., for accounting or tax purposes).
- Legitimate interests: For business administration, managing our business, improving our quality of service, and responding to enquiries or complaints. We always consider your rights and interests before relying on this basis.
- Consent: Where required, particularly for sending you marketing communications, we will only do so with your explicit consent. You may withdraw this consent at any time.
How We Use Your Information
Your personal data is used for the following purposes:
- Managing and fulfilling your flower orders and deliveries
- Processing payments and issuing invoices or receipts
- Contacting you about your order and responding to your requests or comments
- Maintaining our business records in accordance with legal requirements
- Improving our website, products, and services based on feedback and order history
- Sending you carefully selected promotional offers if you have opted in
Retention of Your Data
We retain your personal information only for as long as is necessary to fulfill the purposes for which it was collected, to comply with legal and regulatory requirements, or as otherwise described in this Policy:
- Order and transaction records: Up to seven years to satisfy accounting, tax, and legal requirements.
- Contact and identification data: Retained as long as you remain a customer and for a reasonable period thereafter, subject to legal obligations.
- Marketing consent: Retained until you withdraw your consent or unsubscribe.
After the relevant retention periods have expired, your data will be securely deleted or anonymized.
Processors and Data Sharing
Your data is treated with strict confidentiality. We only share it with trusted third parties when necessary for the running of our business or to fulfill your order, including:
- Delivery partners: To deliver your order to you or your chosen recipient.
- Payment service providers: To securely process payments and refunds (we do not store or access your full card details).
- IT support providers: For hosting, security, and managing our order systems.
- Professional advisers: Such as accountants or legal advisers, only when necessary and under confidentiality obligations.
Data processing agreements are in place with all processors to ensure your personal information is handled lawfully and securely. We do not sell or rent your personal information to third parties. Data is only transferred outside the UK or EEA when adequate safeguards are in place, such as the use of Standard Contractual Clauses or adequacy decisions.
Your Rights Under GDPR
Under GDPR, you have important rights regarding your personal data:
- Right to access: You may request a copy of the personal data we hold about you at any time.
- Right to rectification: You may request that we update or correct inaccurate or incomplete personal data.
- Right to erasure: Also known as the 'right to be forgotten'—you can request the deletion of your data where there is no legal basis for retaining it.
- Right to restrict processing: You may ask us to restrict how we use your data in certain circumstances.
- Right to data portability: You have the right to receive your data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
- Right to object: You can object to us processing your personal data for marketing or legitimate interest purposes.
- Right to withdraw consent: Where we rely on your consent (e.g., for marketing), you are free to withdraw this at any time.
To exercise any of these rights, or for any concerns regarding your data, please contact us in writing. We will respond to your request within one month, unless the request is complex or numerous, in which case we will notify you if additional time is needed.
Security of Your Data
We implement appropriate technical and organisational safeguards to protect your personal data from loss, misuse, unauthorised access or disclosure. These measures include secure storage, limited access, and staff training. However, while we do our best to protect your data, no method of electronic transmission or storage is completely secure.
Updates to This Policy
This Privacy Policy may be updated periodically to reflect changes in our practices, operational needs, or legal and regulatory developments. We encourage you to review it regularly so that you are aware of how we protect your data.
How to Contact Us
If you have questions or concerns regarding this Policy, or how your personal data is processed by Crystal Palace Florist, you may contact us via our physical shop location or through our website’s contact form. Your privacy is important to us and we are committed to addressing your queries in a timely manner.