Privacy Policy for Grant’s Wee Workshop
Effective Date: August 17 2025
Grant’s Wee Workshop (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you visit our website https://grantsweeworkshop.co.uk, place an order, or interact with our services.
What Information We Collect
We may collect and process the following types of personal data:
- Contact Details: Name, email address, phone number, and shipping address
- Order Information: Product selections, custom engraving requests, and commission notes
- Payment Data: Billing details and transaction history (processed securely via Stripe)
- Technical Data: IP address, browser type, device information, and site usage via cookies and analytics tools
How We Use Your Information
We process your data for the following purposes:
| Purpose | Lawful Basis |
|---|---|
| Fulfilling orders and commissions | Contractual necessity |
| Responding to enquiries | Legitimate interests |
| Sending newsletters and promotions | Consent |
| Improving website performance | Legitimate interests |
| Processing payments via Stripe | Contractual necessity |
Payment Processing with Stripe
We use Stripe to securely process payments. When you make a purchase, your payment information is handled directly by Stripe and not stored on our servers.
Stripe may collect and process:
- Name and billing address
- Credit/debit card details
- IP address and device information
- Transaction history
Stripe complies with PCI-DSS standards and acts as a data controller and/or processor depending on context. For more details, see Stripe’s Privacy Policy.
Cookies and Analytics
Our website uses cookies to enhance your experience and gather usage data. You can manage cookie preferences through your browser settings. Some cookies may be set by third-party services like Stripe or Google Analytics.
Data Retention
We retain:
- Order and transaction data for up to 6 years (for tax and accounting purposes)
- Marketing data until you unsubscribe or request deletion
- Website analytics data for up to 26 months
Data Security
We take appropriate technical and organizational measures to protect your data from unauthorized access, alteration, or disclosure. All payment transactions are encrypted and handled securely.
Your Rights Under UK GDPR
You have the right to:
- Access your personal data
- Request correction or deletion
- Restrict or object to processing
- Receive a copy of your data (data portability)
- Withdraw consent at any time
- Lodge a complaint with the ICO
To exercise these rights, contact us
Children’s Privacy
Our website is not intended for children under 13. We do not knowingly collect personal data from children without parental consent.
Contact Us
If you have questions about this Privacy Policy or how your data is handled, please contact us
If you’re unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO): https://ico.org.uk
