This privacy policy explains how we collect, store and process your personal data. Personal data is any information that can be used to identify an individual, either directly or indirectly. It can refer to obvious things like your name and address, but also to online identifiers such as IP addresses.
This Privacy Policy describes how your personal information is collected, used, and shared when you visit or make a purchase from Love BTC - The Beauty Therapy Clinic website (the “Site”).
By making a purchase, creating a Love BTC - The Beauty Therapy Clinic account, using our website, signing up to online marketing, entering a Love BTC competition, or providing your details to us in store or over the phone, you are acknowledging that your personal data may be used according to the practices set out in this policy
Our Privacy Promise
We promise to be transparent with you about how we use your personal data. We are committed to maintaining the safety and security of all personal data from the point of collection to its deletion from our company.
We have to collect some personal data from you in order to provide you with our services. This means that we may also need to share this information with third parties who help us to provide these services, such as our couriers so they can deliver your items to you. We will make sure that all third parties we are engaged with treat your personal data with as much respect as we do.
Personal information we collect
You share your data with us when:
You register for an account
You sign up for our emails, newsletter and other online marketing
You sign up for our catalogue
You enter our competitions
You talk with us on the phone or in-store
You send emails or letters to us
We collect your data when you use these services
Transactional details when you order something from us
Cookies gathered from the devices you use to connect to our website or social media platforms
Data from 3rd parties we work with
Our social media platforms
When you visit the Site, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Site, we collect information about the individual web pages or products that you view, what websites or search terms referred you to the Site, and information about how you interact with the Site. We refer to this automatically-collected information as “Device Information”.
We collect Device Information using the following technologies:
- “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. For more information about cookies, and how to disable cookies, visit http://www.allaboutcookies.org.
- “Log files” track actions occurring on the Site, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
- “Web beacons”, “tags”, and “pixels” are electronic files used to record information about how you browse the Site.
Additionally when you make a purchase or attempt to make a purchase through the Site, we collect certain information from you, including your name, billing address, shipping address, payment information (including credit card numbers, email address, and phone number. We refer to this information as “Order Information”.
When we talk about “Personal Information” in this Privacy Policy, we are talking both about Device Information and Order Information.
What personal data do we collect from you?
We have to collect some information from you so we can provide you with our services, for example when you order items from us. We do our best to make sure that we do not collect excessive information from you and limit it to only what is necessary for us to provide the service you require.
We do not collect any special category personal data from any of our customers. This includes information about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data. Nor do we collect any information about criminal convictions and offences.
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
Identity data – name and title
Contact data – address, postcode, email address and telephone numbers
Transactional data – details of products you have purchased from us, including date and time of purchase and spend in relation to that purchase
Technical data – internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our website
Profile data – purchases or orders made by you, your interests, preferences, feedback and survey responses, preferences about the use of the services (including whether you are interested in certain services that we offer)
Usage data – information about how you use our website, products and services
Marketing and communications data – your preferences in receiving marketing from us and our third parties and your communication preferences.
How we use your personal data
We are only allowed to use personal information about you if we have a legal basis to do so, and we are required to tell you what that legal basis is. We have set out in the table below the personal information which we collect from you, how we use it, and the legal ground on which we rely when we use the personal information.
In some circumstances we can use your personal information if it is in our legitimate interest to do so, provided that we have told you what that legitimate interest is. A legitimate interest is when we have a business or commercial reason to use your information which, when balanced against your rights, is justifiable. If we are relying on our legitimate interests, we have set that out in the table below.
|
What we use your personal information for |
What personal information we collect |
Our legal grounds for processing |
Our legitimate interests (if applicable) |
|
To register you as a new customer and create your account |
Identify Contact |
Performance of a contract with you |
|
|
To process your transactions and deliver your items |
Identify Contact Transaction |
Performance of a contract with you Legitimate interests |
To provide you with delivery updates about your order |
|
To make suggestions and recommendations to you about items that may be of interest to you |
Identify Contact Marketing & Communications Technical Profile Useage |
Legitimate interests Consent |
To develop our services and grow our business |
|
To send automated email campaigns to you based on your purchase intent, purchase history, frequency and activity |
Identify Contact Marketing & Communications Technical Profile Useage |
Legitimate interests Consent |
To better understand our customers and their interests, and to assist customers |
|
To send you the Willow & Wild at Home catalogue |
Identify Contact |
Legitimate interests Consent |
To increase awareness of, and grow, our business |
|
To manage our relationship with you, including notifying you about changes to our terms or privacy notices |
Identify Contact Transaction |
Performance of a contract with you. Necessary to comply with a legal obligation Legitimate Interests |
To keep our records up to date |
|
To enable you to partake in a prize draw, competition or to complete a survey |
Identify Contact Transaction |
Performance of a contract with you. Legitimate Interests Consent |
To understand how customers use our services and to collaborate with third parties in order to increase awareness of our business |
|
To administer and protect our business and our website |
Transaction Technical Useage |
Legitimate Interests |
Running our business, provision of administration and IT services, network security |
|
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you |
Identity Contact Marketing and communications |
Legitimate Interests |
To study how customers use our services, to develop them, to grow our business and to inform our marketing strategy |
|
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences |
Technical Useage Profile |
Legitimate Interests |
To define types of customers for our services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy |
We use the Order Information that we collect generally to fulfil any orders placed through the Site (including processing your payment information, arranging for shipping, and providing you with invoices and/or order confirmations). Additionally, we use this Order Information to:
- Communicate with you;
- Screen our orders for potential risk or fraud; and
- When in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.
- We will use your order information to inform our buying team about products which are popular to help inform what they buy.
We use the Device Information that we collect to help us screen for potential risk and fraud (in particular, your IP address), and more generally to improve and optimize our Site (for example, by generating analytics about how our customers browse and interact with the Site, and to assess the success of our marketing and advertising campaigns).
We may use the information about what you view on your devise to suggest other products you may like to you.
Share your personal information
We share your Personal Information with third parties to help us use your Personal Information, as described above. For example, we use Shopify to power our online store--you can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy. We also use Google Analytics to help us understand how our customers use the Site -- you can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
Catalogues
Our catalogues and leaflets maybe delivered by a mailing house, so we need to share your name and address with them. We have ensured that our chosen mailing house will treat your personal data with as much respect as we do.
Deliveries
We will share your name, address, email address and phone number with our trusted couriers so that they can make the delivery to you and send delivery updates directly to you. We use different couriers depending on the size of the item(s) you have ordered, how quickly you have requested delivery and where you live, but we will always let you know who will be delivering your order.
Competitions
Sometimes we run competitions with other businesses. When entering a competition, you may choose whether to also receive marketing from them too. We will always be transparent with you about who the third party is, and we will not share your email with them for marketing unless you opt-in for this.
Finally, we may also share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
Website Behavioural advertising
As described above, we use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For more information about how targeted shopify site advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.
You can opt out of targeted advertising by using the links below:
- Facebook: https://www.facebook.com/settings/?tab=ads
- Google: https://www.google.com/settings/ads/anonymous
Do not track
Please note that we do not alter our Site’s data collection and use practices when we see a Do Not Track signal from your browser.
How long we keep your data
We work hard to ensure that we do not keep your personal data for longer than is necessary to fulfil the purpose for which it was collected. Generally, we will not retain your personal data for longer than six years, as this is the statutory period for retaining HMRC records.
When you place an order through the Site, we will maintain your Order Information for our records unless and until you ask us to delete this information.
How we look after your data
We will protect the data you entrust to us with appropriate measures and controls, as well as ensuring that the companies we work with are just as careful with your data.
We will always use appropriate technical and organisational measures to prevent the loss, misuse, destruction or alteration of your personal data.
We will continually test, audit and monitor our compliance with Information Security standards and relevant Data Protection regulations.
We are PCI DSS compliant – we do not store any of your card details when you make a payment to us.
We ensure that the third parties we work with who process your personal data operate under a Data Sharing Agreement.
Your data outside the EEA
We transfer your personal data outside of the EEA in limited circumstances. We have ensured that the organisations who process your personal data outside of the EEA on our behalf have the appropriate safeguards in place for doing so, as required by GDPR.
Additionally, please note that your information may be transferred outside of Europe, including to Canada and the United States.
Your rights
You have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted. If you would like to exercise this right, please contact us through the contact information below.
We will process your information in order to fulfil contracts we might have with you (for example if you make an order through the Site), or otherwise to pursue our legitimate business interests listed above.
The right to be informed – this privacy notice explains to you how your personal data is processed by us.
The right to access – you can request that we provide you with all of the personal data that we hold about you. We will provide this to you free of charge within one month of your request.
The right to rectification – we like to make sure that the information we have about you is correct. You can manage your personal details within your account to ensure that they are up to date, or you can contact us to let us know if we have any incorrect information about you by contacting thebeautytherapyclinic@gmail.com.
The right to erasure – you have the right to have your data ‘erased’ in the following situations:
Where the personal data is no longer necessary in relation to the purpose for which it was originally collected or processed
When you withdraw consent
When you object to the processing and there is no overriding legitimate interest for continuing the processing
When the personal data was unlawfully processed
When the personal data has to be erased in order to comply with a legal obligation
The right to restrict processing – You have the right to request that we stop processing your personal data in certain situations such as:
Where you contest the accuracy of your personal data, we will restrict the processing until you have verified the accuracy of your personal data
Where you have objected to processing and we are considering whether our legitimate grounds override your legitimate grounds
When processing is unlawful and you oppose erasure and request restriction instead
Where we no longer need the personal data but you require the data to establish, exercise or defend a legal claim
The right to object – You have the right to object to the processing of your personal data in the following circumstances:
Direct marketing – remember you can opt out at any time from our marketing communications at Any time by contacting us at thebeautytherapyclinic@gmail.com with the subject header ‘UNSUBSCRIBE’.
We use an automated platform to send ecommerce campaigns to customers, based on customer purchase history, frequency and activity. You can opt-out of these emails at any time.
When we share your details with data profiling companies, they analyse the pooled information from all participating retailers in order to understand consumer’s wider buying patterns. From this information, we can tailor our communications, so that we only send people suitable offers that should be of interest to them, based on what they like to buy. You can update your preferences and request us to stop sharing your information by emailing us.
Changes
We may update this privacy policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons.
Minors
The Site is not intended for individuals under the age of 18.
Contact us
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e‑mail at thebeautytherapyclinic@gmail.com marking it for the attention of our privacy officer.
About cookies
Cookies are small text files that are stored on your device when you visit a website that are used to track, save and store information. They enable websites to work properly and efficiently by allowing them to recognise the user’s device and remember things like preferences and items in a basket.
Our cookies
In addition to the cookies above, we also use cookies to:
Ensure you remain logged into the website throughout your browsing session
Maintain the functions that support your customer journey
Help us to improve your browsing experience by giving us insight into how our website is being used
How can I change my cookie settings?
You can disable cookies through your web browser’s settings at any time. Visit your browser developer’s website to find out how to do this.
Please bear in mind that disabling cookies may affect and limit the use of our website.
Further information
If you would like more information on cookies and privacy legislation, please visit the Information Commissioner’s Office at http://ico.org.uk/global/contact-us/ or call 0303 123 1113.