At Small + Bright Ltd. we are committed to preserving the privacy of everyone who uses our website. This policy explains how we use any personal data that you have provided to us or that we have collected from you. Please read our policy carefully before you access or use any of our services.
What type of information do we collect?
We receive, collect and store any information you enter on our website or provide us with in any other way. This includes your name, address, email address and payment details (including credit card information).
As our boxes are for your child, you are also requested to provide us with details of your child’s first name and their age at the time of purchase. When you provide us with this information about your child you are consenting to do so on their behalf.
In addition, we collect the Internet protocol (IP) address used to connect your computer to the Internet; e-mail address; computer and connection information and purchase history. We may use software tools to measure and collect session information, including page response times, length of visits to certain pages, page interaction information, and methods used to browse away from the page.
Our website may place and access cookies on your computer, which we use to improve our customers’ experience of our website and services. The information we receive from this will not identify you personally. If you prefer to opt out of this, you can decline cookies by adjusting the settings on your computer.
How we get the information and why we have it …
Most of the personal information we process is provided to us directly by you for one of the following reasons:
When you browse any of the pages on our website
When you make a purchase
When you contact us to ask a question about, for example; our boxes, your order or delivery
When you subscribe to our newsletter
Under the General Data Protection Regulation (GDPR), the lawful bases we rely on for processing this information are:
(a) Your consent. When you provide us with the necessary data to make a purchase from us, you are providing your consent for us to use it. For example, you provide your banking details in order for a transaction to take place, your child’s details so that we can send the appropriate box and your name and address so that we can arrange delivery of the box to you.
You are able to remove your consent at any time. You can do this by contacting us (please see Contact Details at the end of this policy).
(b) We have a contractual obligation. When you place an order with us, we enter into a contract for us to fulfil that order. We use the data you provide to do this.
(c) We have a legitimate interest. We use data such as how you have used our website, pages visited etc. and may also ask your opinion, to help us improve our service to you and other future customers.
What we do with the information we have …
We use the information that you have given us in order to
Contact you to tell you about your orders
Send you marketing emails and/or information relating to child-development (if you have signed up to our newsletter)
Take a payment from you for your orders
Ship our boxes to you
Post additional marketing material to you
Recognise you when you visit or return to our website
Provide you with information you request from us
Inform you of any changes to our website, products or service
Make improvements to our website, products or service
We may share this information with ...
Third parties who supply us with services, for example; Royal Mail or couriers to enable delivery of goods, our website host (Wix.com) and our payment transaction processor (Wix Payments) in order to process purchases and refunds.
Your personal data may be shared by our payment partner to relevant third parties such as credit reference companies and fraud prevention organisations who may keep a record of that information.
We may disclose personal data we hold about you if required to do so by law or by an appropriate authority in situations where we believe our terms and conditions have been breached or that a criminal act has been committed.
How do we store your information?
The security of your personal data is very important to us and we have physical, electronic and procedural safeguards in place to maintain the safety of your data once you have passed it on to us.
Our website is hosted on the Wix.com platform. Wix.com provides us with the online platform that allows us to sell our products and services to you. Your data may be stored through Wix.com’s data storage, databases and the general Wix.com applications. They store your data on secure servers behind a firewall. All direct payment gateways offered by Wix.com and used by our company adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
Whilst we take every reasonable step possible to keep your data safe, no transmission of information across the Internet is 100% secure and we cannot guarantee your data will always be completely protected. Please consider this when you visit and use our website.
We will only keep you personal data (including your name, address, email address, you child’s name and age, your ordering history and how you have used our website) for as long as is reasonably necessary for the reasons we collected it such as legal, tax or accounting reasons.
Your basic data (your name, address and contact details) will be kept with us for a maximum of 8 years to comply with UK Tax Legislation. Other information you have supplied us with for marketing purposes will be kept until you tell us you no longer wish it to be.
All types of data we keep about you will then be securely deleted or disposed of.
Your data protection rights ...
Under data protection law, you have rights including:
Your right of access - You have the right to ask us for copies of your personal information.
Your right to rectification - You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
Your right to erasure - You have the right to ask us to erase your personal information in certain circumstances.
Your right to restriction of processing - You have the right to ask us to restrict the processing of your information in certain circumstances.
Your right to object to processing - You have the the right to object to the processing of your personal data in certain circumstances.
Your right to data portability - You have the right to ask that we transfer the information you gave us to another organisation, or to you, in certain circumstances.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Please contact us if you wish to make a request.
Our contact details …
Name: Small + Bright Ltd.
Address: Barn Cottage, High Street, Blackford, Wedmore, BS28 4NN
How to complain
You can also complain to the ICO if you are unhappy with how we have used your data.
The ICO’s address:
Information Commissioner’s Office
Helpline number: 0303 123 1113