DRAFT — NOT YET IN EFFECT. Placeholder structure only. A UK business handling customer data needs a genuine privacy notice under UK GDPR regardless of what any payment processor asks for. Replace every [[TODO]] with a description of what this store actually does — a copied notice that does not match reality is a compliance problem in itself.
1. Who we are
[[TODO: The data controller — registered company name, number, registered office, and a contact address for privacy enquiries. Note whether you are registered with the ICO; most e-commerce controllers must be and must pay the data protection fee.]]
2. What personal data we collect
[[TODO: List what you genuinely collect: name, delivery and billing address, email, phone, order history, and any eligibility or verification information you ask for. Note that card details are handled by the payment processor on their own systems and never reach this store — that is true of this architecture and is worth stating plainly.]]
3. Why we use it, and our lawful basis
[[TODO: Take each purpose in turn — fulfilling the order (contract), fraud prevention and record keeping (legal obligation / legitimate interests), marketing (consent). Name the lawful basis for each rather than listing them all at the end.]]
4. Cookies and analytics
[[TODO: What this site sets and why. As built, the storefront keeps a WooCommerce cart session token in the browser’s local storage so a cart survives a reload, and WooCommerce sets its own cookies at checkout. List any analytics or marketing tools once they are added, and describe the consent mechanism if any non-essential ones are used.]]
5. Who we share it with
[[TODO: Categories of recipient — payment processor, couriers, hosting and email providers, accountants. Name them once they are chosen.]]
6. International transfers
[[TODO: Whether any processor stores data outside the UK, and the safeguard relied on. Check this against your hosting and email providers rather than assuming.]]
7. How long we keep it
[[TODO: Retention periods per category, and the reason for each — order records typically follow HMRC’s retention requirement.]]
8. Your rights
[[TODO: Access, rectification, erasure, restriction, portability, objection, and withdrawing consent; how to exercise them and how quickly you respond.]]
9. Complaints
[[TODO: Right to complain to the Information Commissioner’s Office, with its contact route, and an invitation to raise it with you first.]]
10. Changes to this notice
[[TODO: How changes are notified, and the date this version took effect.]]