Privacy Policy for Flowers Chase Cross Orders
Scope of This Privacy Policy
This Privacy Policy describes how Flowers Chase Cross collects, processes, stores, and protects the personal data of all customers who place orders with us from Chase Cross and the surrounding districts. We are committed to ensuring any personal data you provide is handled in compliance with the General Data Protection Regulation (EU Regulation 2016/679, "GDPR") and UK Data Protection Act 2018. By placing an order with Flowers Chase Cross, you consent to the terms described in this Privacy Policy.
What Personal Data We Collect
When you place an order for flowers, gifts, or related services, we may collect the following categories of data about you:
- Identification Data: Name, title, and if ordering on behalf of a company, company name
- Contact Data: Delivery and billing address, telephone number, and (if provided) any alternative contact details
- Order Data: Products ordered, requested delivery dates, personalised card messages
- Payment Data: Payment method details and transaction confirmation (please note: card payments are processed securely and we do not store full payment card information)
- Communications: Emails, order confirmations, and correspondence regarding enquiries, delivery, or complaints
- Technical Data: IP address, device information, browser type (collected when you browse our website or use online order services)
We only collect data which is necessary for fulfilling your order, communicating with you, and improving our services.
Lawful Basis for Processing Your Data
Under GDPR, we must have a lawful basis for processing your personal data. Flowers Chase Cross relies on the following grounds:
- Contractual Necessity: Most of the data we process is required to complete your order, fulfil delivery, take payment, provide customer support, and manage your account. Without this information, we cannot provide you with our services.
- Legitimate Interests: We may use your data to improve our services, safeguard against fraud, respond to your queries, or for limited marketing if you have previously purchased from us. Our interests do not override your privacy rights.
- Legal Obligations: In some cases, we are required by law to retain certain data for accounting, tax, or regulatory requirements.
- Consent: Where we send direct marketing material to new customers, or respond to subscription requests (for example, to newsletters), we will only do so with your explicit consent. You can withdraw this consent at any time.
How We Use Your Personal Data
Your personal information is used only for purposes necessary to provide you with our products and services or where we are legally obliged to do so. Specifically, we use your data to:
- Process and fulfil your flower orders
- Deliver your chosen products to specified addresses
- Send order confirmations, invoices, and delivery updates
- Respond to customer support queries or resolve complaints
- Improve and develop our products and customer experience
- Comply with legal duties and regulatory requirements
- Detect and help prevent fraud or abuse
Data Retention Policy
We retain your personal data only for as long as necessary for the purposes for which it was collected, or as otherwise required by applicable laws and regulations. In general:
- Order and delivery records are kept for up to 7 years to comply with tax and financial record-keeping laws.
- Account-related data (where applicable) is retained for the life of your customer relationship with us. If your account becomes inactive, we will usually delete your personal data after 24 months unless required for legal reasons.
- Marketing consent and preferences are retained until you withdraw consent or request deletion.
- Communications and complaints are held for up to 36 months from resolution for audit and training purposes.
Once retention periods expire, data will be securely deleted or anonymised.
Processors and Third Parties
To deliver our services, we may share your data with selected third parties who act as data processors on our behalf. These include:
- Payment processing providers: to handle secure card transactions
- Couriers and delivery partners: for delivery of your orders
- Website and IT services: for hosting and maintaining our e-commerce platform
- Accountancy firms: for legal tax and audit compliance
All processors are verified to ensure GDPR compliance and enter into appropriate data processing agreements. We do not sell or rent your personal information to third parties for marketing purposes. Data is not transferred outside the UK or European Economic Area except with safeguards, including standard contractual clauses as required by law.
Your Rights Under GDPR
As a customer of Flowers Chase Cross, you have the following rights with respect to your personal data, as provided by GDPR:
- Access: Request a copy of the personal data we hold about you
- Rectification: Ask us to correct any inaccurate or incomplete data
- Erasure: Request deletion of your data, subject to our legal retention obligations
- Restriction: Restrict processing of your data in certain circumstances
- Objection: Object to certain processing, such as direct marketing
- Portability: Request we transfer your data to another service provider, where applicable
- Withdrawal of Consent: Where processing is based on consent, you may withdraw this at any time
To exercise your rights, please contact us using the methods provided on our website. If you believe your data has been processed incorrectly, you also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) or your local supervisory authority.
Changes to This Privacy Policy
We reserve the right to update this Privacy Policy from time to time to reflect changes in the law or our data practices. Where changes are significant, we will notify customers via updates on our website or within order confirmation communications. We encourage you to periodically review this policy.
Contacting Us
If you have any questions or concerns about how your personal data is processed, or if you wish to exercise any of your rights under GDPR, please reach out through our official website’s contact information. Our team is committed to your privacy and will respond promptly to your enquiry.