What is personal data?
Personal data is determined by any information that can be used to identify you as an individual, for example: your name, address, phone number or email address. It can also refer to Internet Protocol (IP) addresses.
How do we collect your personal data?
When you place an order or attempt to place an order through The Den & Now, we collect certain information from you, including your name, billing address, delivery address, email address and phone number. This is referred to as your personal data.
We also collect personal data in a number of other ways, including when:
- you select to opt-in to subscribing to our newsletter when placing an order via our online store, which confirms that you are happy to receive email marketing from us
- you sign up to our newsletter using your email address on the homepage of our online store
- you set up a customer account through our online store
- you contact us regarding an enquiry and information is exchanged with our customer service team
- you enter a competition and opt-in to receive email marketing when you enter
What personal data do we collect and what do we use this for?
- When you purchase something from our online store, as part of the buying and selling process, we collect the personal information you give us such as your name, billing address, delivery address, phone number and email address. This is so that we can process your order efficiently and send you updates, for example to confirm your order details and to notify you when your order has been dispatched, or to contact you to arrange a convenient delivery dates and time for larger orders such as furniture
- When you opt-in to receive email marketing, such as our newsletter, we collect your email address in order for us to send you this information
- When you browse our store, we also automatically receive your computer’s device information (in particular, your IP address) which we use to help us screen for potential risk and fraud, and more generally to improve and optimise our online store. For example, by generating analytics about how our customers browse and interact with The Den & Now, and to assess the success of our marketing and advertising campaigns.
Consent and how to opt-out?
When you provide us with personal information to complete a transaction, verify your debit/credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.
If we ask for your personal information for a secondary reason, such as email marketing, we will ask you directly for your expressed consent by requesting that you tick an opt-in box to sign up to our newsletter. You can opt-out of receiving these newsletters at any time by using the 'unsubscribe' link at the bottom of all emails sent to you.
You can request that you withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information at any time by contacting us by email at email@example.com or calling us on 01244 911 890.
How long do we keep your personal information for email marketing use?
We will continue to send you email marketing until you:
- opt-out of receiving newsletters by using the unsubscribe link at the bottom of an email
- inform us directly that you no longer wish to be contacted via email marketing
What other data do we retain?
When you place an order through The Den & Now we will maintain your information relating to a previous or existing order for our records, unless and until you ask us to delete this information.
What are your rights under the new General Data Protection Regulation (GDPR)?
You have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted. This includes:
- The right to access - at any time you can request that we provide you with all of the personal data that we hold about you. We will provide this to you within 30 days of the request, free of charge.
- The right to rectification - you can update your details at any time, either by logging in and updating your online customer account (if you have one set up) or contacting us directly either by emailing us at firstname.lastname@example.org or calling us on 01244 911 890.
- The right to erasure - also known as ‘the right to be forgotten’. You have the right to have any data we hold of you erased under specific situations, for example for marketing email purposes. This will be carried out within 30 days of the request, free of charge. To notify us to take action, please contact us directly either by emailing us at email@example.com or calling us on 01244 911 890.
- The right to restrict processing - you have the right to request the restriction or suppression of your personal data in certain circumstances. For example: if you contest the accuracy of your personal data, we will restrict the processing of the current data until you can verify the accuracy of the new data // we no longer need your personal data but you require us to keep it in order to establish, exercise or defend a legal claim.
- The right to object - you have the right to object to the processing of your personal data in certain circumstances. You also have the absolute right to opt-out of email marketing at any time by unsubscribing to our newsletters by using the unsubscribe link at the bottom of an email. Alternatively you can inform us by contacting us directly by email at firstname.lastname@example.org or calling us on 01244 911 890. We will ensure that your request is then processed within 30 days, free of charge.
Additionally, if you are a European resident please note that we are processing your information in order to fulfil contracts we might have with you (for example if you make an order through the The Den & Now), or otherwise to pursue our legitimate business interests listed above. Additionally, please note that your information will be transferred outside of Europe, including to Canada (where our store host, Shopify is based) and the United States.
Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you. Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
Payment: If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted. All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers. For more insight, you may also want to read Shopify’s Terms of Service or Privacy Statement.
We use your payment information to:
- Take payments and give refunds
- Prevent and detect fraud
We do this on the basis of our legitimate business interests
We use external payment systems such as Shopify Payment powered by Stripe, PayPal and Klarna to process all our online payments. All these systems have their own security. We do not store your credit card details and we do not store your card’s security/CVV code.
Klarna Payment Method
In order to be able to offer you Klarna’s payment options, we will pass to Klarna certain aspects of your personal information, such as contact and order details, in order for Klarna to assess whether you qualify for their payment options and to tailor the payment options for you.
We only share your personal information with third parties (where applicable or relevant) to allow them to perform the services they provide to us. For example, we use:
- Shopify Payments to process debit/credit card payments made through our online store. You can read Shopify Payment's Terms of Service here
- Apple Pay to process Apple Pay payments made through our online store. Read Apple Pay's Terms and Conditions here
- Google Pay to process Google Pay payments made through our online store. Read Google Pay's Terms of Service here
Finally, we may disclose your personal information if we are required by law to do so or if you violate our Terms & Conditions.
When you visit our online store, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse, we collect information about the individual web pages or products that you view, what websites or search terms that referred you to The Den & Now, and information about how you interact with the our online store. We refer to this automatically-collected information as “Device Information.”
We collect device information using the following technologies:
- “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. You can read more information about cookies, and how to disable them, here.
- “Log files” track actions occurring on our online store, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps
- “Web beacons,” “tags,” and “pixels” are electronic files used to record information about how you browse The Den & Now.
Please note that we do not alter our online store’s data collection and use practices when we see a Do Not Track signal from your browser.
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed. If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
How to contact us