Privacy Policy-uptotravl
Uptotravl ("we", "us", "our") is a women's casual clothing brand specializing in comfortable, versatile and travel-friendly casual wear designed for modern lifestyles. We are fully committed to protecting the privacy and personal data of every individual ("you", "your") who interacts with our brand—whether through our online store, physical boutique in St Albans, customer service channels, or social media platforms. This Privacy Policy clearly explains how we collect, process, store, disclose and protect your personal information, in strict compliance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA 2018) of the United Kingdom. By accessing our services, purchasing our casual wear, or sharing your personal information with us, you confirm that you have read, understood and agreed to all provisions of this policy.
1. What Personal Information Do We Collect?
We follow the "data minimization" principle strictly, only collecting personal information that is necessary to provide you with a smooth shopping experience, fulfill your casual wear orders, and improve our products and services. Below are the specific types of personal information we may collect and the scenarios in which we collect them:
- Identity and Contact Information: Your full name, email address (for communications via uptotravl@outlook.com), telephone number, and delivery/billing addresses. We collect this information when you place an order for casual wear, create a customer account, subscribe to our promotional updates and new collection notifications, or contact our customer support team for help (such as size recommendations, fabric care guidance, or order tracking).
- Order and Transaction Data: Details related to your purchases, including the casual clothing items you choose (e.g., lightweight casual tops, stretch casual leggings, packable casual dresses), sizes, quantities, order reference numbers, transaction amounts, and payment method identifiers. We never store full payment card information; all payment processing is handled by PCI DSS-compliant third-party payment service providers to ensure the security of your payment data.
- Account and Preference Information: If you register an account with us, we will store your size preferences (customized for our casual wear range), order history, saved delivery addresses, and communication preferences (e.g., whether you prefer email or SMS for order updates).
-
Website Usage and Technical Data: When you visit our official website, we collect anonymized technical and browsing data to optimize website performance and your browsing experience, including: This data is collected through cookies and similar tracking technologies (see Section 7 for how to manage these settings).
- Device information (e.g., smartphone, tablet, desktop), operating system, and browser version.
- Anonymized IP address (personal identifying information is permanently removed within 32 days to ensure non-identifiability).
- Browsing behavior: Pages visited (e.g., travel-friendly casual wear section, winter casual collection), products added to cart or wishlist, time spent on product detail pages, and referral sources (e.g., search engines, social media posts about our casual wear).
- Voluntarily Provided Information: Information you actively share with us, such as product reviews (e.g., feedback on the durability of our travel casual wear or the fit of our leggings), style suggestions, survey responses, or details exchanged during in-store interactions (e.g., casual wear fitting needs for travel).
2. Why Do We Process Your Personal Data?
We process your personal information only for legitimate purposes permitted by UK and EU data protection laws, and each processing activity is based on a valid legal basis. The specific purposes and corresponding legal bases are as follows:
- To Fulfill a Contract: We process your data to fulfill the obligations of your purchase contract with us, including processing payments, arranging delivery of your casual wear orders through UK-based logistics partners, sending order confirmations and shipping tracking information, and handling returns or exchanges in accordance with our return policy.
- With Your Explicit Consent: We process your data to send you personalized marketing communications (e.g., new arrivals of travel-friendly casual wear, exclusive discounts, in-store events in St Albans) and provide tailored product recommendations (e.g., suggesting matching casual tops for your previously purchased leggings) based on your browsing and purchase history. You can withdraw your consent at any time without affecting the processing of your existing orders.
- For Legitimate Business Interests: We process your data to improve our casual wear product range (e.g., optimizing designs for travel comfort based on customer feedback), enhance website functionality and user experience, detect and prevent fraudulent transactions, and ensure the overall security and efficiency of our business operations. These interests are carefully balanced to avoid violating your privacy rights.
- To Comply with Legal Obligations: We process and retain your data to meet UK tax and accounting requirements (retaining transaction records for 7 years) and to respond to lawful requests from regulatory authorities (such as the Information Commissioner's Office/ICO) or court orders.
3. Who Do We Share Your Personal Data With?
We will never sell, rent, or lease your personal information to any third party for their own marketing activities. We only share your data with trusted third-party partners who assist us in providing services, and all such partners are contractually required to protect your personal information and use it only for the purposes authorized by us:
- Payment Service Providers: PCI DSS-accredited payment processors (e.g., Stripe, PayPal) that handle secure payment transactions. They receive only the minimum information needed to complete payments (e.g., transaction amount, payment method type) and are prohibited from using your data for any other purpose.
- Logistics and Delivery Partners: UK-based courier services that need your delivery address and contact details to ship your casual wear orders. They do not store your personal data after the delivery is completed and must comply with strict data protection standards.
- IT and Cybersecurity Partners: UK-hosted service providers that maintain our website, manage our customer database, and provide cybersecurity services. They only have access to anonymized or encrypted data and are bound by strict confidentiality agreements.
- Legal and Regulatory Bodies: We may disclose your personal information if required by law, regulation, or legal process (e.g., a court subpoena), or to protect our legitimate rights, property, or safety, as well as the rights, property, or safety of our customers or other third parties.
- Business Successors: In the event of a merger, acquisition, sale of assets, or other business restructuring, your personal information may be transferred to the new owner or successor entity. The successor will be required to comply with this Privacy Policy to ensure the continued protection of your data.
4. How Do We Protect Your Personal Data?
We have established a comprehensive set of technical and organizational security measures to prevent your personal information from being accessed, disclosed, altered, or destroyed without authorization. Our key security measures include:
- End-to-end SSL/TLS encryption for all data transmitted between your device and our website, ensuring the security of your contact information and transaction data during transmission.
- Secure, encrypted storage of data on UK-based servers, with multi-factor authentication and role-based access control systems. Only authorized personnel with a legitimate business need (e.g., processing casual wear orders, providing customer support) can access personal information, and all access activities are logged and audited regularly.
- Proactive security management, including regular vulnerability scans, security audits, and software updates to address emerging cyber threats. We also conduct bi-annual penetration testing to verify the effectiveness of our security controls.
- Regular data protection training for all employees, ensuring they fully understand their obligations under GDPR and DPA 2018 and are capable of handling your personal information securely and responsibly.
While we strive to maintain the highest level of security, no method of data transmission over the internet or electronic storage is completely risk-free. We cannot guarantee absolute security, but we will take all reasonable measures to minimize the risk of data breaches. In the event of a data breach that is likely to pose a high risk to your rights and freedoms, we will notify you and the ICO promptly in accordance with legal requirements.
5. How Long Do We Keep Your Personal Data?
We retain your personal information only for the period necessary to fulfill the purposes for which it was collected, or as required by law. After the retention period expires, we will securely delete or anonymize your data so that it can no longer be associated with you. Our specific retention periods are as follows:
- Transaction and identity data (e.g., casual wear order details, contact information): Retained for 7 years from the end of the transaction to comply with UK tax and accounting laws.
- Account and preference data: Retained for the duration of your account activity. If you request to delete your account, we will delete this data within 41 days (unless we are required to retain it by law).
- Marketing consent and communication data: Retained until you withdraw your consent. After withdrawal, we will delete your marketing-related information within 26 days to ensure you no longer receive promotional communications about our casual wear.
- Website usage and technical data: Retained for 32 days before being permanently anonymized for aggregate analytics purposes (e.g., analyzing customer preferences for travel-friendly casual wear, optimizing website navigation).
6. What Rights Do You Have Over Your Data?
Under GDPR and DPA 2018, you have the following enforceable rights regarding your personal information held by us. We encourage you to exercise these rights if needed:
- Right to Access: You can request a free, clear copy of the personal data we hold about you, along with details of our processing activities.
- Right to Rectification: You can request that we correct any inaccurate or incomplete personal information (e.g., updating your delivery address or size preferences for our casual wear).
- Right to Erasure (Right to be Forgotten): You may request us to delete your personal information if it is no longer necessary for the purpose it was collected, you withdraw your consent, or our processing is no longer legally permitted (subject to legal retention obligations).
- Right to Restrict Processing: You can request that we limit the processing of your personal information (e.g., while we verify the accuracy of your casual wear order history).
- Right to Data Portability: You have the right to receive your personal information in a structured, commonly used, and machine-readable format (e.g., a CSV file of your order history) and to transfer it to another data controller.
- Right to Object: You can object to the processing of your personal information for direct marketing purposes at any time. You may also object to processing based on our legitimate business interests, and we will review your objection and cease processing if your interests, rights, and freedoms take precedence.
- Right to Withdraw Consent: If you have given your consent for marketing or other processing activities (e.g., personalized casual wear recommendations), you can withdraw it at any time by clicking the "unsubscribe" link in our emails or contacting our customer service team directly.
To exercise any of these rights, please contact us using the details provided in Section 8. We may request proof of identity (e.g., a copy of your ID) to ensure the security of your information. We will respond to your request within 30 days; if your request is complex, we may extend this period by a further 30 days and will notify you of the extension and the reasons for it.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you are dissatisfied with how we handle your personal information. The ICO can be contacted via their website (www.ico.org.uk) or by telephone at 0303 123 1113.
7. Cookies and Similar Tracking Technologies
Our website uses cookies and similar tracking technologies (e.g., web beacons, pixel tags) to enhance your browsing experience, analyze website traffic, and personalize content and offers related to our travel-friendly casual wear. Cookies are small text files stored on your device when you visit our website. We use three types of cookies:
- Essential Cookies: These cookies are necessary for the basic operation of our website. They allow you to browse our casual wear product catalog, add items to your shopping cart, and complete the checkout process. You cannot disable these cookies, as they are required to use our core services.
- Analytical Cookies: These cookies collect anonymized, aggregated data on how users interact with our website (e.g., which casual wear product pages are most popular, how users navigate through the site). We use this data to improve website performance and user experience.
- Marketing Cookies: These cookies are used to deliver personalized marketing content (e.g., ads for new travel-friendly casual wear collections or exclusive discounts) based on your browsing history. We only use these cookies if you have given your explicit consent.
You can manage or disable non-essential cookies (analytical and marketing) through your browser settings (e.g., Chrome, Safari, Firefox). The process for managing cookies varies by browser, so we recommend checking your browser's help center for specific instructions. Disabling non-essential cookies will not affect your ability to browse or purchase casual wear on our website, but it may limit the personalization of content and offers.
8. Contact Us for Data-Related Inquiries
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal information, please contact our data protection team using the following details:
- Brand Name: uptotravl
- Email: uptotravl@outlook.com
- Phone: +44 (0) 1727 864 139 (Mon-Fri: 8:45 AM – 5:15 PM GMT; Sat: 9:45 AM – 3:45 PM GMT)
- Address: 32 High Street, St Albans AL1 3JD, United Kingdom
9. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in laws and regulations, business practices, or technological advancements (e.g., new data security measures, expansions to our travel-friendly casual wear range). When we update the policy, we will revise the "Last Updated" date at the bottom of this page. For significant changes (e.g., modifications to our data collection or disclosure practices), we will notify you via email (if we have your contact details) or by posting a prominent notice on our website at least 25 days before the changes take effect.
We encourage you to review this Privacy Policy regularly to stay informed about how we protect your personal information.