PRIVACY AND COOKIES POLICY
WHO WE ARE
We are Rose and Rock, a partnership, and we are the data controller responsible for your personal information. Our office is located at 26 Water Lane, Histon, Cambridge, CB24 9LR.
WHAT IS A PRIVACY NOTICE?
At Rose and Rock we take your privacy very seriously. We believe in transparency and we are committed to being upfront about our privacy practices. This document contains our obligations and promises to you about the different types of personal data we might collect about you when you shop, make contact or browse with us. It explains how we will store, handle and protect that data.
WHAT INFORMATION DO WE COLLECT AND WHEN?
Types of data we may collect:
- Identity data is your first and last names.Contact data is the data we use to contact you including an email address, company name, billing and delivery addresses, and telephone number including mobile number.
- Financial Data means the data we use to process your payments for your orders including your payment card details. We do not store or process your card details ourselves, they are processed and stored via one of our contracted third party service providers. Transaction data means the details of your purchase and order history with Rose and Rock.
- Usage data includes information about your online browsing activities on the Rose and Rock website.
- Profile data includes your password and username, login data, purchases and orders made by you, feedback and survey responses.
- Marketing and Communications data includes your communication and marketing preferences.
- Technical data means details about the device(s) you use to access our website including your IP address, browser type and version, location, browser plugin types and versions, operating system and platform and other technology on the devices you use to access this website.
- Information from cookies, including information on the devices you may use to make a purchase.
- Your correspondence and communications with Rose and Rock.
We collect the information in the following circumstances:
- When you register to or use our website, including when you use our guest checkout.
- When you contact us by telephone, email or post.
- When you enter any event, prize draws or competitions.
- When completing any of our surveys or leaving us a review.
- When you allow social media sites to provide your data to us.
- When you buy products or gift cards/vouchers.
- When you have given a third party permission to share with us the information they hold about you.
HOW DO WE USE YOUR PERSONAL DATA?
We use your data to:
- provide you with goods and services ie handle your orders, personalise and tailor your products, deliver products and process your payments and refunds (including to ensure secure payment and prevent fraud).
- respond to your queries, refund requests and complaints.
- maintain records of when and why you contact us and to keep your contact details up-to-date.
- manage any registered accounts that you hold with us.
- for statistical, analytical or survey purposes on an anonymised basis to improve our website and services available to you.
- with your agreement, contact you about promotional offers, events, products and services, which we think may interest you using the email address which you have provided.
- send communications required by law or which are necessary to inform you about changes to the services we provide you. For example updates to this Privacy Notice, product recall notices, and legally required information relating to your orders. These service messages will not include any promotional content and do not require prior consent when sent by email. If we do not use your personal data for these purposes, we would be unable to comply with our legal obligations.
- where we have a legal right or duty to use or disclose your information (for example in relation to an investigation by a public authority or in a legal dispute).
- process your application when you enter a competition, promotion or prize draw. (If there are other purposes specific to that competition promotion or prize draw, these will be explained in the applicable Competition Terms & Conditions).
In order to help us manage our customer relationships, we use third party platforms. These platforms assist us to do lots of things, including: conduct email marketing campaigns, advertise online, undertake customer analytics, fulfil orders, make deliveries, returns and refunds etc. We therefore pass on your personal data to these third parties, on the condition that they agree to handle your information in line with this notice.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis, which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Why are we allowed to handle and store your personal data?
The law on data protection sets out a number of different reasons for which a company can collect and use your personal data. The following sets out more detailed explanations of the basis we rely on to collect and process your personal data:
If you visit our site and are not an existing customer, we will ask for your consent to process your data, so that we can send you our special offers and news.
b) Contractual obligations
Our primary use of this basis is when you purchase our products. In this situation it is necessary for us to process your personal data in order to fulfil your order and send your goods to you.
c) Legal compliance
In some circumstances, we may be legally required to collect and process your data e.g. to pass it on to the police if criminal activity is suspected.
d) Legitimate Interest
It may be necessary to use your data in a way which might reasonably be expected as part of running our business. For example, to action any changes to your account that you request or to personalise the services we provide – with the aim of improving your customer experience.
We will also use your email address to send you direct marketing information from us by email, telling you about products and offers that we think might be of interest to you. You are free to opt out of hearing from us by email at any time.
We will only use your data in these instances, where doing so does not materially impact your rights, freedom or interests.
How do we protect your personal data?
We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.
How long do we keep your personal data for?
We only keep your personal data for as long as is necessary for the purpose for which it was collected (subject to any legal requirements). Once it is no longer necessary, we will either delete the data, or anonymise it. The use of anonymised data helps us to optimise our customer service.
Who else sees your personal data?
From time to time, we will collect from and share your personal data with trusted third parties. We will do this in the following circumstances:
- to process your order e.g. delivery companies, with third party web platform and payment service providers;
- to detect any fraudulent activity, or assist law enforcement authorities;
- to understand the behaviour of our customers online;
- to manage risks and claims.
When we share information with third parties, we will ensure that:
- we only provide the data they need to perform their specific function.
- they only use the data provided as intended.
- they have the requisite measures in place to protect your data and delete it once the function has been performed, or delete it when we cease working with them.
Where is your data stored?
Some of our partners and third parties who may receive your personal data are based outside of the European Economic Area. In such cases, we ensure that our partners are contractually-bound to protect your data to the same degree that is required in the European Union.
What rights do you have over the data we store and how can you ask us to stop storing it?
- You have the right to correct any information we store, which might be incomplete, out of date or incorrect. You can do this yourself by logging into your account, or by contacting us so we can do this for you. You can contact us by emailing: firstname.lastname@example.org.
- If we are processing your personal data on the basis of our legitimate interest, you have the right to ask us to stop. We must then do so unless we believe we have a legitimate overriding reason to continue processing your personal data.
- You have the right at any time to stop us sending you marketing material. You can do this by:
- Clicking on ‘unsubscribe’ in any email communication that we send you. We will then stop any further emails.
- Contacting us by email: email@example.com and ask us to stop sending you marketing material.
- Writing to us at Rose and Rock, 26 Water Lane, Histon, Cambridge, CB24 9LR, notifying us that you want us to stop sending you marketing material.
- You have the right to ask us to transfer your personal data to you or to a third party. We will provide your personal data in a structured, commonly used format.
- You have the right to request erasure of your personal data.
Please note that you may continue to receive communications for a short period after changing your preferences whilst our systems are fully updated.
- You have the right to ask us what data we hold relating to you. Such requests are usually free, but we will ask you to submit your query in writing and include the following:
- Full name (we will ask you to verify your identity)
- Full address
- Email address
- Contact number
- Specific details of your request
We will process your request and will either respond within 30 days, or contact you to gather more information before we fulfil your request. In the event that we might refuse to fulfil your request (for example if it is unreasonable), we will give a full explanation as to why.
Submit your request by writing to us:
Rose and Rock
26 Water Lane
Or send us an email to: firstname.lastname@example.org.
What can you do if you are unhappy with how we handle your data?
You should contact us as outlined below:
Rose and Rock
26 Water Lane
Or send us an email to: email@example.com.
A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.
Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.
Google Analytics (Google Inc.)
We use Google Analytics, to collect and analyse our traffic log cookies to identify which pages are being used. This helps us analyse data about web page traffic and improve our website in order to tailor it to customer needs. The information is only processed in a way which does not identify an individual. We only use this information for statistical analysis purposes and then the data is removed from the system.
These cookies are set by the social networks (Facebook, Twitter, Instagram and allow you to share content from Rose and Rock with your friends on social networks. We don’t control the setting of these cookies, so we suggest you check the third-party websites for more information about their cookies and how to manage them. In addition, we enable you to share content from our website. Listed below are some of the social media platforms which may place cookies on your device. By disabling social cookies, you will not be able to share content from our website:
If cookies aren’t enabled on your computer, it will mean that your shopping experience on our website will be limited to browsing and researching; you won’t be able to add products to your basket and buy them.
You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies, if you prefer. Check the ‘Help’ menu of your particular browser to change your cookie preferences. This may prevent you from taking full advantage of our site.
Further information about controlling or deleting cookies can be found at www.aboutcookies.org.uk (opens in a new window – please note the we cannot be responsible for the content of external websites).
We may update this notice and our policies from time to time. This may be necessary, for example, if the law changes, of if we change our business in a way that affects personal data protection.
This policy was last updated on 6 October 2018.