Privacy Notice
Draft -- review with a UK e-commerce solicitor before launch.
This notice explains how we handle the personal data you give us when you shop at myCollectors. The data controller is the business identified in the site footer.
What we collect
When you place an order we collect: your name, email address, billing and shipping addresses, phone number (if provided), the products you bought, and the payment provider's transaction reference (we do not see or store your card details -- those go directly to PayPal).
When you register an account we also store a hashed password (we never store the plaintext).
Why we collect it
- To process your order and dispatch your goods (legal basis: contract performance, UK GDPR Art 6(1)(b)).
- To comply with HMRC record-keeping requirements (legal obligation, Art 6(1)(c)) -- we retain order data for 6 years.
- To send you marketing email about new stock IF you opted in at checkout (consent, Art 6(1)(a)) -- you can withdraw at any time.
Who we share it with
- PayPal (payment processing).
- Royal Mail / our courier (to deliver your goods).
- HMRC (when legally required).
We do not sell your data to third parties.
Your rights
Under UK GDPR you have the right to:
- See the personal data we hold about you (Subject Access Request).
- Correct inaccurate data.
- Have your data erased (subject to our HMRC retention obligation -- order records are kept anonymised after erasure).
- Object to or restrict processing.
- Withdraw marketing consent.
To exercise any of these, email us. We will respond within one month.
Cookies
See our Cookie Policy.
Complaints
If you're not happy with how we've handled your data, you can complain to the Information Commissioner's Office: https://ico.org.uk/.
Version: 2026.06-DRAFT · Effective from: 26 May 2026