Privacy Policy
Who We Are
Buddly Crafts is a VAT registered (GB985870261) UK partnership. For more information about the history of Buddly Crafts please see our about us page.
Data You Provide To Us
When Placing an Order
If you place an order with us we will ask for data including your name, address, e-mail, phone number, and billing information. This data is used to process and deliver your order. We are legally required to keep this data for at least ten years to prove that the correct taxes were collected and in some circumstances it may also be kept for longer for anti-fraud purposes.
Billing information such as your card number, expiry date, and CVV are not stored and never go through our servers. We only receive a tokenised version of your card data from our payment processor. The tokenised data cannot be used by anyone else if it were to be stolen.
If required then your name, address, e-mail, and phone number will be passed to our shipping partners to deliver your order. They may use your e-mail or phone to contact you with delivery information such as tracking updates. For international orders we may also be required to provide the value and contents of your order for customs clearance.
When Using Stock Notifications
If you setup a stock notification for a product then we will ask for your e-mail address. We use this e-mail to contact you when the item is back in stock after which your e-mail will be deleted and not used again. If a product has been discontinued for over six months then all pending notifications will be deleted.
When Entering Giveaways
If you enter one of our giveaways we will ask for a method to contact you which may be your e-mail or a social network profile. This data is not used for anything else but may be kept for an indefinite period to help detect fraud and ensure the integrity and fairness of our competitions.
When Contacting Us
If you contact us by e-mail or contact form then your message and related contact data will be stored in our help desk system. If you contact us by phone a record of your phone number will appear in our incoming calls log. If the data is available then your browser version and general location (which may include your IP address) will also be stored to help us answer any IT or shipping questions. This data is kept for an indefinite period to help provide the best customer support we can.
When Joining our Marketing Maillist
If you join our marketing maillist we will store your e-mail address and use it to send you our newsletter. Additional data such as the date, your IP address, and where on our site you entered your e-mail will also be stored in order to keep a legally required record of how and when your e-mail was added to our list.
You can unsubscribe from our list at any time using the unsubscribe link at the bottom of all marketing e-mails we send out. You may also be automatically unsubscribed if your e-mail address bounces or you report our e-mails as spam. Please note that unsubscribing is not the same as deleting the data as we are legally required to keep a copy of your e-mail address on a suppression list to prevent it from being accidentally re-subscribed to the active list.
Data Collected Automatically On Our Website
When Visiting Our Website
When you visit our website we will automatically collect data such as your browser's user agent and your general location. This data is used to measure the performance of our website on different devices and from different countries. This data is only stored in an anonymised and aggregated form and cannot be used to identify you.
If your visit to our website triggers an error or similar then the previously mentioned data will also be stored in a non-anonymised form and additional data such as your IP address and any Javascript errors may be recorded for a longer period of time. This information allows us to find the cause and fix the problem. This data is deleted once we're confident that the problem has been resolved.
If you came to our website via one of our marketing campaigns then we will attempt to record this to measure the performance of our campaigns. If you don't go on to place an order then this data remains anonymous and cannot be used to identify you.
Additionally we have the following third party components embedded on some or all pages of our website. It is possible that these services are also collecting data about you.
- Disqus - blog comments
- Facebook - page widget & like buttons
- Google Fonts - fonts
- Pinterest - board widget & pin buttons
- reCAPTCHA - anti-bot captcha
- Vimeo - videos
- YouTube - videos
When Placing an Order
If you place an order we will automatically collect data such as your browser's user-agent, IP address, and your general location. This data is stored alongside the previously mentioned data you provide to us when placing an order. It is used both for anti-fraud purposes and also as additional legally required proof that the correct taxes were collected.
If you came to our website via one of our marketing campaigns then we will attempt to record this alongside your order to measure the performance of our campaigns.
Data Collected Automatically In Our E-mails
Transactional E-mails
Our transactional e-mails (e.g. "thanks for your order", "password reset", etc.) include tracking which will collect data including your e-mail client's user agent, the time you opened the e-mail, and if you clicked on any links in the e-mail. This data is used to ensure that our e-mails are being successfully delivered and can be read. This data is deleted after 30 days and only remains afterwards as part of anonymised and aggregated statistics.
Marketing E-mails
The same data for transactional e-mails is also collected for marketing e-mails but is not automatically deleted after 30 days. Additionally if you place an order with us soon after clicking a link in a marketing e-mail then this fact will be recorded and used to measure the performance of our marketing e-mails. This data is kept for an indefinite period unless you ask us to delete it.
Data Sharing
We use the following third party services to provide our services and your data may be shared with them as required.
- Amazon Web Services - web servers
- Braintree (PayPal) - payment processor
- Google AdWords - marketing (only if you came to us via AdWords)
- Google Analytics - anonymised visitor analytics
- Google Mail - e-mail servers
- Mailchimp - transactional and marketing e-mails
- New Relic - server performance and error monitoring
- Report URI - client side error monitoring
- Sentry - client side error monitoring
- Zendesk - customer support help desk
- Shipping partners - Royal Mail, Swiss Post, La Poste, Deutsche Post DHL, DPD, etc.
If requested to do so then we would also be required to share your data with law enforcement or regulatory agencies.
Cookies
Please see our cookie policy page.
Retrieving, Updating, or Deleting Data
Please contact us through our regular methods.