Privacy policy


1. Who we are

Shop Level operates shop-level.shop and is the controller of personal information described in this policy. “We”, “us” and “our” refer to Shop Level. Privacy enquiries and requests may be sent to info@shop-level.shop.

This policy is intended for visitors and customers in the United Kingdom. It is written with reference to the UK General Data Protection Regulation, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and the Privacy and Electronic Communications Regulations 2003, as amended.

2. Information we collect

Depending on how a person uses the store, we may collect:

Identity and contact information: name, billing and delivery address, email address, telephone number and account details.
Order and transaction information: products ordered, amounts, currency, discounts, refunds, delivery status, correspondence and payment confirmation. Full payment-card details are normally handled by the payment provider rather than stored by us.
Technical and usage information: IP address, browser and device information, approximate location, timestamps, referral pages, pages viewed, interactions, cookie identifiers and security logs.
Preference and marketing information: communication preferences, consent records and responses to marketing.
Customer-service information: messages, photographs, reviews, return reasons, complaint details and any other information voluntarily supplied.
Fraud and compliance information: risk indicators, chargeback information and records needed to meet legal, tax, accounting or regulatory obligations.

We ask customers not to send special-category information, criminal-offence information or other unnecessary sensitive data. If such information is sent, we will handle it only where lawful and necessary.

3. How we obtain information

We collect information directly when a customer visits the website, creates an account, places an order, joins a mailing list, submits a review, contacts us or requests a return. We also receive information from service providers involved in payments, ecommerce hosting, fulfilment, delivery, fraud prevention, analytics, advertising and customer support, and from publicly available sources where lawful.

4. Why we use information and our lawful bases
Contract: to take steps requested before purchase; accept and fulfil orders; process payments, delivery, returns and refunds; provide customer service; and administer accounts.
Legal obligation: to keep tax and accounting records, respond to lawful requests, protect consumer rights, manage product-safety issues and comply with applicable law.
Legitimate interests: to secure and improve the store, prevent fraud and misuse, understand performance, manage stock and operations, establish or defend legal claims, and communicate with existing customers about similar products where permitted. We consider the impact on individuals before relying on this basis.
Consent: for non-essential cookies and similar technologies, and for electronic marketing where consent is required. Consent can be withdrawn at any time without affecting earlier lawful processing.

Where electronic marketing is permitted under the “soft opt-in” for existing customers, each message will provide a simple way to opt out. We do not sell personal information in the ordinary meaning of selling it for money.

5. Cookies and similar technologies

Strictly necessary technologies may be used to operate the basket and checkout, maintain security, remember privacy choices and provide services requested by the user. These do not ordinarily require consent, but information about them should still be provided.

Analytics, advertising, personalisation and other non-essential technologies will be used only after valid consent where required by PECR. Consent must be an active choice. Continuing to browse is not treated as consent. Users must be able to reject non-essential technologies and later change their choice as easily as they accepted. The actual cookie banner and cookie settings presented on the website provide current details of the technologies in use.

6. Sharing information

We may disclose only the information reasonably necessary to:

ecommerce, cloud-hosting, payment, fraud-prevention and IT-security providers;
warehouses, suppliers, manufacturers, delivery carriers and return processors;
customer-support, email, analytics and advertising providers, subject to the required choices and safeguards;
professional advisers, auditors, insurers and financial institutions;
courts, regulators, tax authorities, law enforcement and other bodies where disclosure is required or permitted by law; and
a buyer, investor or successor in connection with a genuine business reorganisation, sale or transfer, under appropriate confidentiality protections.

Service providers acting as processors are required to follow our instructions, keep information secure and use it only for agreed purposes. Some recipients act as independent controllers and provide their own privacy information.

7. International transfers

Some providers or recipients may be located outside the United Kingdom. Before making a restricted transfer, we use a lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU standard contractual clauses, or another mechanism permitted by law. Where required, we assess the destination and safeguards and adopt supplementary technical, contractual or organisational measures.

8. Retention

We retain personal information only for as long as reasonably necessary for the purpose collected, including order fulfilment, customer support, fraud prevention, legal compliance and claims. Retention periods depend on the type of record and legal requirements. Core transaction and tax records are normally retained for up to six years after the end of the relevant relationship or accounting period, unless a longer or shorter period is required. Marketing records are retained until opt-out and for a limited suppression period so that the preference can be respected. Security and routine website logs are retained for shorter periods unless needed to investigate an incident. Information is deleted, anonymised or securely isolated when no longer required.

9. Security

We use proportionate technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, access, disclosure or destruction. Measures may include access controls, encryption in transit, provider due diligence, backups, monitoring and incident procedures. No internet service is completely secure, so users should protect account credentials and contact us promptly if they suspect misuse.

10. Individual rights

Subject to legal conditions and exceptions, individuals may have the right to be informed, access their personal information, correct inaccurate information, request erasure, restrict processing, object to processing, receive certain information in a portable format, and not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Individuals may also withdraw consent at any time.

To exercise a right, email info@shop-level.shop. We may ask for information reasonably needed to confirm identity and understand the request. We normally respond without undue delay and within one month, although the law may allow an extension for complex or multiple requests. Rights are generally free to exercise, but the law allows a reasonable fee or refusal in limited cases involving manifestly unfounded or excessive requests.

11. Automated decisions and children

We may use automated tools to flag potentially fraudulent transactions, but we do not intend to make solely automated decisions that produce legal or similarly significant effects without an appropriate lawful basis and safeguards. The store is not directed at children, and customers must have legal capacity to make a purchase. If we learn that personal information has been collected from a child contrary to applicable law, we will take reasonable steps to delete it.

12. Complaints and changes

Please raise privacy concerns first with info@shop-level.shop so we can investigate. A person also has the right to complain to the UK Information Commissioner’s Office. Current contact and complaint details are available at ico.org.uk.

We may update this policy when our practices or legal obligations change. Material changes will be highlighted through the website or another appropriate channel. The date at the top shows the latest revision.