Privacy policy for Thorn & Oath
Last updated: 17 September 2025
Introduction and who we are
- This privacy policy explains how Thorn & Oath (“we”, “us” or “our”) collects, uses and protects your personal data when you visit our website at www.examplejewellery.co.uk or make a purchase from us.
- We are a data controller responsible for your personal data. Our registered address is 1 Example Street, London, W1D 4AB, United Kingdom. Our ICO reference is ZA123456. If you have any questions about this policy or how we handle your data, please contact us at privacy@examplejewellery.co.uk or 020 1234 5678.
What information we collect We may collect and process the following personal data:
- Identity and contact data: name, title, billing and delivery address, email address, telephone number.
- Transaction data: details of orders, products purchased, returns, payments (note: we do not store full card numbers; payments are processed securely by our payment processors).
- Payment data: payment method and transaction details processed by our payment processors (e.g., Stripe, PayPal). We do not retain full card details on our systems.
- Technical data: IP address, browser type, device information, time zone, cookie data and pages you view on our site.
- Marketing and communications data: your preferences in relation to receiving marketing from us and your communications with us.
- Other information you choose to provide: e.g., if you contact us with a query, enter a competition, or participate in surveys.
How we use your information We use your personal data to:
- Process and fulfil orders (including order confirmations, shipping, and after-sales support).
- Communicate about your orders and respond to enquiries.
- Manage and improve our website and your shopping experience (e.g., personalised product recommendations).
- Send you marketing communications (where you have consented or where we have a lawful basis to do so) and manage your preferences.
- Prevent fraud, protect, investigate and enforce our legal rights.
- Comply with legal obligations (e.g., accounting, tax requirements).
Lawful bases for processing We rely on the following legal bases to process your data:
- Contract: to perform or prepare for a contract (e.g., processing your order).
- Legal obligation: to comply with laws (e.g., tax and record-keeping requirements).
- Legitimate interests: to run, grow and improve our business (e.g., security, fraud prevention, direct marketing with appropriate opt-outs).
- Consent: for certain types of direct marketing or cookies (where required by law).
Who we share your information with We may share your data with:
- Service providers who help us run our business (e.g., payment processors, courier/shipping companies, IT support, hosting, analytics, email marketing platforms).
- Professional advisers (e.g., accountants, legal advisers).
- Third parties as required by law (e.g., regulatory or law enforcement authorities).
- Our group companies or business associates where necessary to deliver our services. We require all recipients to protect your data and to use it only for the purposes described in this policy.
International transfers of your data Some of our service providers may be located outside the UK/EEA. When we transfer your personal data to countries outside the UK/EEA, we rely on appropriate safeguards (for example, Standard Contractual Clauses) or adequacy decisions to protect your information.
How we protect your data
- We implement appropriate technical and organisational measures to protect your data (e.g., encryption, access controls, secure servers, regular security reviews).
- We restrict access to your data to those employees, officers and contractors who need it to perform their duties.
How long we keep your data
- We retain order information for as long as required for tax, accounting and legal purposes, typically 6 years after the end of the financial year to which it relates.
- We retain account and communication data for as long as you keep an account or as long as necessary to fulfil the purpose it was collected for (e.g., marketing preferences, unresolved issues).
- Marketing data will be kept until you opt out or request to be removed.
Your rights You have rights regarding your personal data, including:
- Right to be informed about how we use your data.
- Right of access to your data (subject to certain exemptions).
- Right to rectify inaccurate or incomplete data.
- Right to erasure (the right to be forgotten) in certain circumstances.
- Right to restrict or object to processing (including direct marketing).
- Right to data portability (to obtain and reuse your data across different services).
- Right to withdraw consent (where processing is based on consent).
- Right to lodge a complaint with the Information Commissioner’s Office (ICO).
To exercise any of these rights, please contact us at privacy@examplejewellery.co.uk. We will respond within one month, which may be extended in certain circumstances.
Direct marketing and cookies
- We may contact you with marketing information if you have consented or if you are our customer and a similar product/service is offered (subject to applicable laws). You can opt out at any time via the unsubscribe link in marketing emails or by updating your account preferences.
- Cookies: We use cookies to enhance your experience, analyse site usage, and for marketing. You can manage cookies via the cookie banner on our site or your browser settings. For details, see our separate Cookies Policy or Cookie Notice.
Children
- We do not knowingly collect personal data from children under 16. If you are under 16, please obtain parental or guardian consent before providing any personal data to us. If you become aware that a child has provided us with personal data, please contact us so we can delete it.
Changes to this policy
- We may update this privacy policy from time to time. We will notify you of material changes by updating the “Last updated” date and, where required by law, obtaining consent or providing notice.
How to contact us
- If you have questions about this privacy policy or our privacy practices, please contact:
- You can also contact our ICO via ico.org.uk if you have unresolved concerns about how we handle your data.
Notes for tailoring to your business
- Replace all placeholders with your actual company name, registered address, ICO number, and contact details.
- If you use specific processors (e.g., Stripe, Shopify, Klaviyo, Google Analytics), you may wish to add explicit mentions of those providers and link to their privacy notices.
- If you operate outside the UK or collect data from customers outside the UK, ensure you address cross-border transfers and any additional legal considerations.
- Consider adding a separate, customer-facing Cookies Policy with more detail on each cookie category and expiry.