Privacy Policy – BrandLuxe
Last Updated: 8 March 2025 Jurisdiction: United Kingdom Framework: UK GDPR & Data Protection Act 2018
1. Who We Are
BrandLuxe is an online retail store based in the United Kingdom, specialising in premium footwear, sportswear, accessories, and luxury fashion items. We operate through our website at brandluxe.shop.
For the purposes of UK data protection law, BrandLuxe is the Data Controller of your personal information — meaning we determine how and why your data is processed.
2. Information We Collect
Information you provide directly:
- Full name and billing/shipping address
- Email address and phone number
- Payment details (processed securely — we never store card numbers)
- Account login credentials
- Messages sent via contact forms or customer support
- Newsletter subscription preferences
Information collected automatically:
- IP address and browser type
- Device type and operating system
- Pages visited, time on site, and clickstream data
- Referring website or traffic source
- Cookie and session data
Information from third parties:
- Payment processors (e.g. Stripe, PayPal) — transaction status only
- Analytics providers (e.g. Google Analytics) — aggregated behaviour data
3. How We Use Your Data
We use your personal data for the following purposes:
- Order fulfilment — to process, pack, and deliver your purchases and send tracking updates
- Account management — to create and maintain your customer account
- Customer support — to handle enquiries, returns, complaints, and refund requests
- Marketing communications — to send promotional emails and offers (only with your consent)
- Legal compliance — to meet obligations under UK tax, consumer, and financial laws
- Fraud prevention — to detect and prevent fraudulent transactions
- Site improvement — to analyse usage patterns and improve your shopping experience
We will never sell your personal data to third parties for their own marketing purposes.
4. Legal Basis for Processing
Under UK GDPR, we rely on the following legal bases:
- Contract Performance — processing is necessary to fulfil your order
- Legal Obligation — to comply with UK law (e.g. HMRC tax records, consumer rights)
- Legitimate Interests — fraud prevention, site security, and business analytics
- Consent — for marketing emails and non-essential cookies (you may withdraw consent at any time)
5. Sharing Your Data
We share your data only where necessary, with the following categories of recipients:
- Delivery & logistics partners (e.g. Royal Mail, DHL, DPD) — to ship and track your orders
- Payment processors (e.g. Stripe, PayPal) — to handle transactions securely
- Email service providers — to send transactional and marketing emails
- Analytics providers — to understand site traffic and improve performance
- Legal and regulatory bodies — where required by UK law, court order, or HMRC
All third-party providers are contractually required to handle your data in compliance with UK GDPR and to use it solely for the purposes we specify.
6. How Long We Keep Your Data
We retain your personal data only as long as necessary:
- Order records — 7 years (UK tax and accounting obligations)
- Customer accounts — for the duration your account is active; deleted upon request
- Marketing preferences — until you unsubscribe or withdraw consent
- Support communications — up to 3 years
- Website analytics — up to 26 months in anonymised form
When data is no longer needed, it is securely deleted or permanently anonymised.
7. Your Rights Under UK GDPR
As a UK resident, you have the following rights regarding your personal data. We will respond to all valid requests within 30 days.
- Right of Access — request a copy of the data we hold about you (Subject Access Request)
- Right to Rectification — ask us to correct inaccurate or incomplete data
- Right to Erasure — request deletion of your data where there is no lawful reason to retain it
- Right to Restriction — ask us to pause processing in certain circumstances
- Right to Data Portability — receive your data in a machine-readable format to transfer elsewhere
- Right to Object — object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent — withdraw consent at any time without affecting prior processing
- Right to Complain — raise a concern with the ICO at ico.org.uk or call 0303 123 1113
To exercise any of these rights, please contact us using the details in Section 13. We may ask you to verify your identity before processing your request.
8. Cookies
Our website uses cookies to enhance your experience and help us understand how our site is used.
Types of cookies we use:
- Essential cookies — required for shopping cart, login sessions, and site security
- Functional cookies — remember your preferences and settings
- Analytics cookies — Google Analytics, to understand traffic and behaviour (optional)
- Marketing cookies — retargeting and ad performance measurement (optional)
You can manage or withdraw cookie consent at any time via your browser settings. Disabling non-essential cookies will not affect your ability to shop with us. For more information, visit allaboutcookies.org.
9. How We Protect Your Data
We implement appropriate technical and organisational security measures, including:
- SSL/TLS encryption across the entire website
- Secure payment processing via PCI-DSS compliant providers (we never store card details)
- Strict access controls limiting who can view customer data internally
- Regular security reviews and software updates
- Secure hosting with regular data backups
In the event of a data breach posing a risk to your rights, we will notify the ICO within 72 hours and inform affected individuals without undue delay.
10. International Data Transfers
Some of our third-party service providers may be based outside the UK, including in the EEA or the United States. Where we transfer data internationally, we ensure appropriate safeguards are in place, such as UK adequacy decisions or Standard Contractual Clauses (SCCs) approved by the ICO.
11. Children’s Privacy
BrandLuxe’s website is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When significant changes are made, we will update the “Last Updated” date at the top of this page and notify registered customers by email where appropriate. We encourage you to review this policy periodically.
13. Contact Us
For any privacy-related questions, data requests, or concerns, please contact us:
BrandLuxe Website: brandluxe.shop