All sample legal documents

Sample Privacy Policy

A worked England and Wales privacy policy explaining data collected by a fictional online retailer, uses, sharing, retention, rights and security.

Jurisdiction: Illustrative England and Wales and United Kingdom privacy example — UK GDPR, Data Protection Act 2018 and sector rules must be reviewed

Download Sample

An editable Microsoft Word version is available from the interactive page.

Important: This sample provides general legal information only and is not legal advice. Check the law, prescribed forms and signing requirements that apply to your exact jurisdiction and circumstances before use.

PRIVACY POLICY

Important jurisdiction and legal compliance warning

This fictional policy is an illustrative worked example, not legal advice and not a universally compliant privacy notice. It is written for a small online retailer established in England and Wales. The correct notice depends on the organisation’s processing, technologies, locations, suppliers, age profile and regulatory obligations. The controller must verify its lawful bases, cookies consent, direct-marketing permissions, international-transfer safeguards, retention periods and procedures under the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications rules and any other applicable law. A policy must match actual practice and should be reviewed by a suitably qualified adviser.

1. Who we are

This policy applies to Cedar & Finch Homeware Limited, company number 15180427, whose registered office is at 42 Kingfisher Yard, Bristol BS2 0RX. We sell home textiles and kitchen accessories through cedarfinch.example.test and by telephone. We are the controller of personal data described here unless we tell you otherwise. References to we, us and our mean Cedar & Finch Homeware Limited.

Our privacy contact is Elise Rowan, Privacy Manager, at privacy@cedarfinch.example.test or Cedar & Finch Homeware Limited, 42 Kingfisher Yard, Bristol BS2 0RX.

2. Information we collect

We may collect your name, billing and delivery address, email address, telephone number, account login details, order history, returns information and communications with us. When you pay, our payment provider handles card details; we receive a transaction reference, payment status and limited card information but do not store the full card number or security code.

When you browse our site, we may receive device, browser, approximate location, IP address, pages visited, referral information and security logs. Our cookie notice explains which cookies are necessary, which require consent and how to change your choices. We may receive information from delivery companies, fraud-prevention services, customer-review providers or a person who buys a gift for you. We do not intentionally collect special-category data unless you choose to provide it for a specific support request and we have a lawful basis.

3. How and why we use data

We use order and contact information to create an account, process a purchase, take payment, deliver goods, handle returns, answer questions, prevent fraud, keep business records and communicate about a transaction. The legal basis is generally performance of a contract, compliance with a legal obligation, or our legitimate interest in operating a secure and accountable business.

We may use information to improve products, understand demand, test site performance, manage suppliers, recover debts, defend or bring legal claims, and maintain network and premises security. We rely on legitimate interests where appropriate and consider the impact on individuals. We may send marketing emails only where we have consent or another lawful route. You can unsubscribe through each marketing message or by contacting us, without affecting service communications.

4. Sharing information

We share necessary information with payment processors, website and hosting providers, delivery companies, customer-service tools, accountants, insurers, auditors, professional advisers and fraud-prevention providers. They must process data under appropriate instructions or their own lawful responsibilities. We may disclose information to courts, regulators, police, tax authorities or other public bodies where required or permitted by law, and to a buyer or adviser in a genuine business sale subject to appropriate safeguards.

Some providers may process data outside the United Kingdom. Before making a restricted transfer, we will use an adequacy regulation, approved safeguards or another lawful mechanism, and consider any required supplementary protection. Contact us for a summary of the relevant safeguard where disclosure is permitted.

5. Retention and security

We keep order, invoice and tax records for the period required by law, normally six years after the relevant financial year. We normally keep an inactive customer account for two years, support correspondence for three years after closure, and marketing preferences until you withdraw consent or we no longer need them. We may retain a record of an objection, suppression request or legal claim for as long as needed to respect it or establish a defence. We securely delete or anonymise data when the applicable period ends.

We use access controls, multi-factor authentication for administrative accounts, encryption in transit, supplier checks, backups and staff confidentiality commitments. No transmission or storage system is guaranteed to be completely secure. If a personal-data breach creates a legal reporting duty or significant risk, we will take the steps required by applicable law and notify affected people where appropriate.

6. Your rights

Subject to legal exceptions, you may ask for a copy of your personal data, correction of inaccurate data, deletion, restriction of processing, data portability, or information about processing based on legitimate interests. You may object to direct marketing at any time and may object to other legitimate-interest processing where your circumstances justify it. Where processing relies on consent, you may withdraw consent at any time.

Send a request to privacy@cedarfinch.example.test and provide enough information for us to verify your identity. We normally respond within one month, although a lawful extension may apply to complex requests. You may complain to the Information Commissioner’s Office at ico.org.uk if you are dissatisfied. We ask that you contact us first so we can investigate, but you are not required to do so.

7. Children, changes and contact

Our online shop is intended for adults and we do not knowingly invite children to create accounts. If you believe a child has provided personal data, contact us so that we can assess and remove it where appropriate. We may update this policy when our processing or the law changes. The page will show the effective date and a summary of material changes.

This policy took effect on 1 October 2026. It describes our intended practice, does not replace a contract or statutory right, and does not claim universal legal validity. The law of England and Wales is the intended governing framework only to the extent applicable; data-protection rights may also arise under the law of another place where you live or where processing occurs.

Create a version for your situation

Create a tailored Privacy Policy