1. ABOUT US AND HOW TO CONTACT US
This website at www.nevergoalone.com (our “Website”) is operated by Never Go Alone Limited, a company incorporated and registered in England and Wales under company number 12588777, whose registered office is at 1 Paternoster Square, London EC4M 7DX, United Kingdom (“we”, “our”, or “us”).
This Website is not intended for children and we do not knowingly collect data relating to children.
- INFORMATION WE COLLECT ABOUT YOU
- HOW WE COLLECT AND USE YOUR INFORMATION
- HOW WE STORE YOUR INFORMATION
- INTERNATIONAL TRANSFERS OF YOUR INFORMATION
- YOUR LEGAL RIGHTS
Our Website may include links to third-party websites and applications. We do not control these third-party websites and are not responsible for their privacy statements, notices, or policies. When you leave our Website, we encourage you to read the privacy notice of every third-party website you visit. We do not accept any responsibility or liability for the privacy policies or notices on third-party websites. Please check these policies before you submit any personal data to such third-party websites.
2. INFORMATION WE COLLECT ABOUT YOU
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data, which includes first name, last name, and title.
- Contact Data, which includes email address, billing address, delivery address, and telephone number (including any phone number used to contact us by telephone).
- Financial Data, which includes payment card details and other financial and billing information.
- Transaction Data, which includes information such as details of your purchases and the fulfilment of your orders (such as basket number, order number, subtotal, title, currency, discounts, shipping, number of items, product number), payments to and from you and details of other products you have obtained from us, correspondence or communications with you in respect of your orders, and details of any rewards and bonuses awarded.
- Technical Data, which includes your internet protocol (IP) address, cookie identifiers, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our Website.
- Usage Data, which includes information about how you use our Website and products, such as clickstream to, through, and from our Website (including date and time), products you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
- Profile Data, which includes information about purchases or orders made by you, product and style interests, preferences, feedback, and survey responses.
- Marketing and Communications Data, which includes your preferences in receiving marketing from us, and your communication preferences.
3. HOW WE COLLECT AND USE YOUR INFORMATION
We will only collect and process your personal data where we have a lawful basis to do so, i.e. where:
- we need your personal data to perform a contract with you (for example, to process a payment from you, fulfil your order or provide customer support connected with an order);
- the processing is in our legitimate interests (as described below) and not overridden by your rights;
- we have a legal obligation to collect or disclose personal data from you; or
- we have your consent to process your personal data.
The following table sets out what personal data we collect about you, what we use that personal data for, and our lawful basis for doing so. Please be aware that we may process your personal data using more than one lawful basis, depending on the specific purpose or activity.
|Purpose/Activity||Type of data||Lawful basis for processing|
|To register you as a customer||(a) Identity
|Performance of a contract with you|
|To process and deliver your order, including recording your order details; keeping you informed about the order status; processing payments and refunds; and collecting money owed to us||(a) Identity
|(a) Performance of a contract with you
(b) Necessary for our legitimate interests (for collecting money owed to us)
|To inform or remind you by email of any task carried out via our Website which remains uncompleted, such as incomplete orders or abandoned baskets||(a) Identity
|Necessary for our legitimate interests (to improve your shopping experience)|
|(a) Performance of a contract with you
(b) Necessary to comply with a legal obligation
|To administer and protect our business and our Website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)||(a) Identity
|(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud, and in the context of a business reorganisation or group restructuring exercise)
(b) Necessary to comply with a legal obligation
|To use data analytics to improve our website, products/services, marketing, customer relationships and experiences||(a) Technical
|Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant and ensure that its content is presented in the most effective manner for you and for your device, to develop our business and to inform our marketing strategy)|
|To make suggestions and recommendations to you about goods or services that may be of interest to you, including by way of email and text message||(a) Identity
(f) Marketing and Communications
|Your consent (you can withdraw this at any time by clicking the link to unsubscribe in our marketing emails and/or the relevant ‘STOP’ number in text messages, or by contacting us using the details above)|
|To protect us, our customers, and our Website from fraud and theft||(a) Identity
|Necessary for our legitimate interests (for detecting and preventing fraud)|
Where the lawful basis stated above is your consent, you have the right to withdraw this consent at any time. You may also object to our processing in certain circumstances where our lawful basis for processing is our legitimate interests. Please see section 7 below for further information on how to exercise these rights. Please note that, where we rely on your consent or our legitimate interests to process your personal data and you withdraw that consent or object to our processing, we may no longer be able to provide certain services to you that are dependent on this processing.
If any of your personal data (such as your Contact Data) changes, please ensure that you let us know by editing this in your account settings, so that the information we have about you is kept up to date.
4. HOW WE STORE YOUR INFORMATION
We have appropriate security measures in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.
We will retain your information for as long as you have an account on our Website. If you delete your account or request us to do so, we will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data, and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting, or other requirements. In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
6. INTERNATIONAL TRANSFERS OF YOUR INFORMATION
This Website’s online store is powered through Shopify, an e-commerce platform operated by Shopify’s Irish entity, Shopify International Ltd (“Shopify Ireland”), which is based in the Republic of Ireland. We are permitted to transfer your personal data that we collect about you from the United Kingdom to Shopify Ireland under the United Kingdom’s own General Data Protection Regulation (UK GDPR).
Shopify Ireland processes your Identity Data, Contact Data, Transaction Data, Technical Data, and Usage Data. Some of this personal information is transferred by Shopify Ireland to its Canadian parent entity, Shopify Inc (“Shopify Canada”).
Because Shopify Canada is subject to Canada’s own Personal Information Protection and Electronic Documents Act (PIPEDA), this transfer of personal data from Shopify Ireland to Shopify Canada is compliant with Shopify Ireland’s obligations under the European Union’s General Data Protection Regulation (EU GDPR). This means that any transfer of your personal data outside of the UK and the European Economic Area will be subject to measures that are designed to help safeguard your privacy rights and give you remedies in the unlikely event of a misuse of your personal data.
Shopify Canada uses a combination of data centres and cloud server providers to store this personal data, some of which are located in the United States. Where personal data is transferred from Shopify Canada to third-party service providers in the United States, this is done in accordance with the export requirements of Canadian privacy law via contractual arrangements substantially similar to those between us and Shopify Ireland.
For further information as to how Shopify complies with applicable data protection legislation, please download its GDPR WHITEPAPER DOCUMENT.
Save as set out above, we will not otherwise transfer your personal data outside of the United Kingdom or the European Economic Area.
7. YOUR RIGHTS
Under applicable data protection laws, you have a number of important rights free of charge. In summary, those include rights to:
- require us to correct any mistakes in your information which we hold;
- require the erasure of personal information concerning you in certain situations;
- receive the personal information concerning you which you have provided to us, in a structured, commonly used, and machine-readable format and have the right to transmit those data to a third party in certain situations;
- withdraw your consent (if you have given this to us previously) for us to contact you for direct marketing purposes;
- object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you;
- object in certain other situations to our continued processing of your personal information; and
- otherwise restrict our processing of your personal information in certain circumstances.