Leaf & Loop

Policies

Privacy Policy

This privacy notice tells you what to expect us to do with your personal information.

Contact Details

Email: c-vaani@leafandloop.uk

What Information We Collect, Use, and Why

We collect or use the following information to provide services and goods, including delivery:

  • Names and contact details
  • Addresses
  • Date of birth
  • Purchase or account history
  • Payment details (including card or bank information for transfers and direct debits)
  • Account information
  • Website user information (including user journeys and cookie tracking)
  • Information relating to compliments or complaints

For the operation of customer accounts and guarantees:

  • Names and contact details
  • Addresses
  • Payment details (including card or bank information for transfers and direct debits)
  • Purchase history
  • Account information, including registration details
  • Information used for security purposes
  • Marketing preferences

To prevent, detect, investigate or prosecute crimes:

  • Names and contact information
  • Customer or client accounts and records
  • Financial transaction information

For service updates or marketing purposes:

  • Names and contact details
  • Addresses
  • Marketing preferences
  • Purchase or viewing history
  • IP addresses
  • Website and app user journey information
  • Records of consent, where appropriate

For scientific or historical research purposes, for statistical purposes, or for archiving in the public interest:

  • Addresses
  • Purchase or viewing history
  • IP addresses
  • Website and app user journey information

To comply with legal requirements:

  • Name
  • Contact information
  • Financial transaction information
  • Any other personal information required to comply with legal obligations

For dealing with queries, complaints, or claims:

  • Names and contact details
  • Address
  • Payment details
  • Account information
  • Purchase or service history
  • Customer or client accounts and records
  • Financial transaction information
  • Correspondence

Lawful Bases and Data Protection Rights

Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.

Which lawful basis we rely on may affect your data protection rights, which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website.

  • Right of access you can ask us for copies of your personal information, and details of where we get it from and who we share it with.
  • Right to rectification you can ask us to correct or delete personal information you think is inaccurate or incomplete.
  • Right to erasure you can ask us to delete your personal information.
  • Right to restriction of processing you can ask us to limit how we use your personal information.
  • Right to object to processing you can object to the processing of your personal data.
  • Right to data portability you can ask that we transfer the personal information you gave us to another organisation, or to you.
  • Right to withdraw consent where we rely on consent as our lawful basis, you can withdraw it at any time.

If you make a request, we must respond to you without undue delay and in any event within one month. To make a data protection rights request, please contact us using the details above.

Our Lawful Bases for the Collection and Use of Your Data

To provide services and goods:

  • Contract we need the information to enter into or carry out a contract with you.
  • Legitimate interests we process customer contact, order, and delivery details to manage day-to-day retail operations, coordinate logistics with carriers, send non-marketing order tracking updates, and maintain inventory records. This is limited to basic contact and address details provided at checkout, aligns with reasonable customer expectations, and presents minimal privacy risk.

For the operation of customer accounts and guarantees:

  • Contract we need the information to enter into or carry out a contract with you.
  • Legitimate interests we process account credentials, order history, and contact details to maintain secure user portals, authenticate logins, and administer product guarantees or warranty claims, so customers can manage past orders and track guarantees without repeated manual verification.

To prevent, detect, investigate or prosecute crimes:

  • Legal obligation we need the information to comply with the law.
  • Legitimate interests we process transactional and account metadata to identify suspicious transactions, verify order validity, prevent payment fraud, and resolve unauthorised chargebacks limited strictly to data necessary for risk assessment.

For service updates or marketing purposes:

  • Consent we have your permission after giving you all the relevant information you can withdraw this at any time.
  • Legitimate interests we process customer contact details and purchase histories to deliver essential service or operational updates and notify existing customers about similar products (subject to soft opt-in rules). You can opt out at any time via the unsubscribe link in every communication.

For scientific/historical research, statistical purposes, or archiving in the public interest:

  • Legitimate interests we process aggregated and pseudonymised sales, viewing history, and website interaction metrics for internal statistical analysis, demand forecasting, and inventory planning, relying on aggregated or anonymised usage patterns rather than individual profiling.

To comply with legal requirements:

  • Legal obligation we need the information to comply with the law.

For dealing with queries, complaints, or claims:

  • Contract we need the information to enter into or carry out a contract with you.
  • Legitimate interests we retain and process correspondence, order details, and support logs to respond to inquiries, resolve disputes or returns, and defend against potential legal claims, limited to relevant communication and transaction records.

Where We Get Personal Information From

  • Directly from you
  • Publicly available sources
  • Suppliers and service providers
  • Third parties for example, sales data and customer delivery information passed to us from marketplaces like Amazon

How Long We Keep Information

For more information on how long we store your personal information, or the criteria we use to determine this, please contact us using the details above.

Who We Share Information With

Data Processors

  • E-commerce platform and website hosting providers (technology sector, UK/EEA/US) they host our online store, process customer orders, manage account registrations, and securely store customer database records.
  • Online payment service providers and financial processors (fintech & financial services sector, UK/EEA/US) they securely process card payments, detect and prevent transaction fraud, and manage refunds.

Others We Share Personal Information With

  • Financial or fraud investigation authorities
  • Relevant regulatory authorities
  • Professional consultants
  • Organisations we’re legally obliged to share personal information with
  • Order fulfilment, warehousing, and parcel courier providers (logistics and postal sector, UK/international) they handle inventory storage, pack customer orders, and deliver purchased goods to customer addresses.
  • Email marketing, transactional notification, and customer support software providers (cloud software sector, UK/EEA/US) they send order confirmation and tracking emails, manage customer service correspondence, and deliver newsletters to consented subscribers.
  • Web analytics and website optimisation service providers (information technology sector, UK/EEA/US) they collect aggregate browsing metrics, analyse user journeys, and help us monitor and improve website performance.
  • HM Revenue & Customs (HMRC) and statutory regulatory bodies (public sector / tax authority, UK) to comply with mandatory tax accounting and financial auditing requirements.
  • Professional accounting, tax, and legal advisors (professional services sector, UK) to manage statutory financial filings and obtain legal advice.

Sharing Information Outside the UK

Where necessary, we will transfer personal information outside of the UK. When doing so, we comply with the UK GDPR, making sure appropriate safeguards are in place.

  • International delivery couriers and cross-border marketplace platforms (logistics, postal, and e-commerce marketplace sector) personal information is sent to the European Economic Area (EEA), the United States, and worldwide customer destinations. The country or sector has been assessed as providing adequate protection to data subjects (Adequacy Regulations / UK data bridge).

Where necessary, our data processors may also share personal information outside of the UK, complying with the UK GDPR and ensuring appropriate safeguards are in place.

  • Cloud hosting, payment gateway, and email delivery service providers (e.g. AWS, Stripe, Shopify, Google) cloud software, financial technology, and web analytics providers personal information is sent to the United States and the European Economic Area (EEA). The country or sector has been assessed as providing adequate protection to data subjects (Adequacy Regulations / UK data bridge).

How to Complain

If you have any concerns about our use of your personal information, you can make a data protection complaint to us at c-vaani@leafandloop.uk.

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk/make-a-complaint