Privacy Policy for Viola’s Buys

Effective Date: 21/02/2025

At Viola’s Buys (“we”, “our”, or “us”), we take your privacy seriously and are committed to protecting and respecting your personal data. This Privacy Policy explains how we collect, use, and protect your personal information when you visit our website and make a purchase. It also outlines your rights under UK law, including the General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

By accessing or using our website and services, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect
We collect personal data that you provide when using our website, including:

– Account Information: Name, email address, postal address, phone number, and password (if you create an account).
– Order Information: Product details, billing and shipping address, payment details, and order history.
– Communication: Any messages or queries you submit to us via contact forms or emails.

We may also collect information automatically through cookies and other tracking technologies, such as:

– Usage Data: IP address, browser type, device information, and browsing activity on our website.
– Cookies: Small files placed on your device that help us improve your user experience.

2. How We Use Your Information
We use the information we collect for the following purposes:

– Order Processing: To process and fulfill your orders, including managing payments, shipping, and returns (since we operate a dropshipping model, third-party suppliers may be involved in fulfillment and delivery).
– Account Management: To create and manage your account, process your login, and offer customer support.
– Communication: To respond to your inquiries, send order updates, and provide promotional material (if you’ve opted in).
– Website Improvement: To improve and personalise your experience, enhance website functionality, and conduct analytics.

As we operate a dropshipping model, we share relevant order information with our third-party suppliers for the purpose of fulfilling your orders. These suppliers will process your personal information in accordance with their privacy policies, and we do not have control over their practices. We ensure that they comply with relevant data protection laws.

3. Legal Basis for Processing Your Data
Under the UK GDPR, we process your personal data based on the following legal grounds:

– Contractual Necessity: We process your data to fulfill our contractual obligations to you, such as completing your orders and providing customer support.
– Consent: If we use your information for marketing purposes (e.g., sending promotional emails), we will obtain your explicit consent.
– Legitimate Interests: We may process your information for legitimate business interests, such as improving our website and offering relevant product recommendations.

4. Data Sharing
We may share your personal data with third parties for the following reasons:

– Dropshipping Suppliers: Since we use third-party suppliers to fulfill your orders, we may share your order details (including your name, address, and product information) with them to ensure your items are shipped directly to you.
– Payment Providers: To process payments, we share your payment information with trusted third-party payment processors (e.g., PayPal, Stripe) in accordance with their privacy policies.
– Service Providers: We may engage third-party service providers for website hosting, analytics, marketing, and customer support services.

We do not sell your personal data to third parties.

5. International Data Transfers
Because our suppliers and service providers may be located outside the UK, your personal data may be transferred and stored in countries outside the UK. We ensure that any data transferred outside the UK is protected through appropriate safeguards, such as the use of Standard Contractual Clauses (SCCs) approved by the UK government.

6. Your Data Protection Rights
Under the UK GDPR, you have the following rights regarding your personal data:

– Right to Access: You can request access to the personal data we hold about you.
– Right to Rectification: You can request that we correct any inaccurate or incomplete data.
– Right to Erasure: You can request that we delete your personal data, subject to certain conditions.
– Right to Restriction of Processing: You can request that we restrict the processing of your personal data in certain situations.
– Right to Data Portability: You can request to receive your data in a structured, commonly used, and machine-readable format.
– Right to Object: You can object to the processing of your personal data for direct marketing purposes.
– Right to Withdraw Consent: If we rely on consent to process your data, you can withdraw it at any time.

To exercise any of these rights, please contact us at the details provided in the Contact Information section below.

7. Data Retention
We will retain your personal data for as long as necessary to fulfill the purposes for which it was collected, including fulfilling any legal, accounting, or reporting requirements. When your data is no longer needed, we will securely delete it or anonymise it.

8. Cookies
We use cookies and similar technologies to enhance your browsing experience and provide services on our website. Cookies help us analyse website traffic, remember your preferences, and improve your overall experience.

For detailed information on the cookies we use and how you can manage or disable them, please refer to our Cookie Policy.

9. Security
We take appropriate technical and organisational measures to protect your personal data from unauthorised access, alteration, disclosure, or destruction. However, no method of data transmission or storage is 100% secure, so we cannot guarantee absolute security.

10. Links to Other Websites
Our website may contain links to other websites. We are not responsible for the privacy practices of these third-party sites and recommend that you read their privacy policies before providing any personal data.

11. Children’s Privacy
Our website is not intended for children under the age of 18, and we do not knowingly collect personal data from children. If we become aware that a child has provided us with personal information, we will take steps to delete such data.

12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Effective Date.” We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal information.

13. Contact Us
If you have any questions or concerns about this Privacy Policy or how we handle your personal information, please contact us at:

Viola’s Buys 
Email: info@violas-buys.com
Phone: +44 734 925 3016