Last updated: June 2026
We believe you have a right to know exactly what happens to your personal information when you shop with us. This policy explains it clearly — no legal jargon, no small print tricks.
Keldwick & Byrne is the data controller for the personal information you share with us. If you have any questions about this policy or how we handle your data, please contact us at keldwickandbryne@gmail.com
1. What Information We Collect
When you shop with us or interact with our website, we may collect the following types of personal information:
- Identity information: your name
- Contact information: email address, phone number, delivery and billing address
- Payment information: card details (processed securely by our payment provider — we never store your full card number)
- Order information: what you bought, when, and how much you paid
- Account information: if you create an account, your login credentials and order history
- Browsing data: pages you visit on our site, how long you spend on them, your device type and browser, and your approximate location (via IP address)
- Marketing preferences: whether you’ve opted in to receive emails from us
- Communications: any emails or messages you send us
2. Why We Collect It & Our Legal Basis
Under UK GDPR, we must have a lawful reason for using your personal data. Here’s what we use your data for and why we’re allowed to:
| Purpose | Legal Basis |
|---|---|
| Processing and fulfilling your order | Contract performance |
| Sending order confirmations and delivery updates | Contract performance |
| Processing payments securely | Contract performance |
| Handling returns, refunds, and customer service | Contract performance / Legitimate interest |
| Improving our website and understanding how customers use it | Legitimate interest |
| Preventing fraud and keeping our site secure | Legitimate interest / Legal obligation |
| Sending marketing emails, new arrivals, and offers | Consent (you must opt in) |
| Complying with legal and tax obligations | Legal obligation |
We will never use your data for purposes that are incompatible with the reasons listed above, and we will never sell your personal data to third parties.
3. How Long We Keep Your Data
We only keep your personal data for as long as we need it:
- Order and transaction records: 7 years (required by UK tax law)
- Customer accounts: for as long as your account is active, plus 2 years after your last interaction
- Marketing preferences: until you unsubscribe or ask us to delete your data
- Customer service communications: 3 years
- Browsing and analytics data: up to 26 months (anonymised after this point)
When data is no longer needed, we delete it securely or anonymise it so it can no longer be linked to you.
4. Who We Share Your Data With
We only share your data with trusted third parties who help us run our business. We do not sell your data. The third parties we work with are:
- Shopify Inc. — our e-commerce platform, which stores and processes order and customer data on our behalf. Shopify is GDPR-compliant and processes data under a Data Processing Agreement with us.
- Payment processors (e.g. Shopify Payments, Stripe, PayPal) — to securely process your payment. We never see or store your full card details.
- Delivery and courier companies — we share your name and delivery address with our courier partners solely to fulfil your order.
- Email marketing platform — if you’ve opted in to marketing, your email address is stored with our email provider to send you newsletters and offers.
All third parties are required to handle your data securely and in accordance with UK GDPR. We do not allow them to use your data for their own marketing purposes.
5. Your Rights
Under UK GDPR, you have the following rights regarding your personal data. You can exercise any of these rights by contacting us at keldwickandbryne@gmail.com
- Right of access: You can ask us for a copy of the personal data we hold about you.
- Right to rectification: You can ask us to correct any inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”): You can ask us to delete your personal data, subject to any legal obligations we have to retain it.
- Right to data portability: You can ask us to provide your data in a structured, machine-readable format so you can transfer it to another service.
- Right to object: You can object to us processing your data for marketing purposes at any time. You can also object to processing based on legitimate interest.
- Right to restrict processing: In certain circumstances, you can ask us to pause processing your data.
- Right to withdraw consent: Where we rely on your consent (e.g. for marketing emails), you can withdraw it at any time by clicking “unsubscribe” in any email or contacting us directly.
We will respond to all requests within 30 days. We will never charge you for exercising your rights.
6. Cookies
Our website uses cookies — small text files stored on your device — to make the site work properly and to help us understand how it’s being used. Here’s what we use:
| Cookie Type | Purpose | Required? |
|---|---|---|
| Essential cookies | Keep your shopping cart working, remember your login, process payments securely | Yes |
| Analytics cookies | Help us understand which pages are popular, how customers navigate the site, and where we can improve | Optional |
| Preference cookies | Remember your preferences (e.g. currency, language) so you don’t have to set them each visit | Optional |
| Marketing cookies | Used to show you relevant adverts on other websites (only if you consent) | Optional |
You can manage or withdraw your cookie consent at any time via the cookie banner on our website, or by adjusting your browser settings. Please note that disabling essential cookies may affect how the site functions.
7. How We Keep Your Data Safe
We take data security seriously. Our website uses SSL encryption (the padlock in your browser), and we work with Shopify — one of the world’s most trusted e-commerce platforms — to store and process your data securely. We regularly review our security practices and limit access to personal data to only those who need it to do their job.
In the unlikely event of a data breach that affects your rights or freedoms, we will notify you and the Information Commissioner’s Office (ICO) as required by law.
8. Contact Us & How to Complain
If you have any questions about this privacy policy or how we handle your data, please get in touch:
Keldwick & Byrne
Email: keldwickandbryne@gmail.com
We aim to respond to all privacy-related enquiries within 5 working days.
If you’re not satisfied with how we’ve handled your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) — the UK’s independent data protection authority:
ICO website: ico.org.uk
ICO helpline: 0303 123 1113
We would always prefer to resolve any concerns directly with you first, so please do reach out to us before contacting the ICO.
Keldwick & Byrne • Privacy Policy last updated June 2026 • This policy applies to personal data collected via our website at orlivya.shop and any associated communications.