This Policy explains when and why we collect personal information, how we use it, the conditions under which we may disclose it to others and what choices you have.

We may change this Policy from time to time so please check this page occasionally to ensure that you’re happy with any changes. By using our website and ordering our products, you’re agreeing to be bound by this Policy.

Any questions regarding this Policy and our privacy practices should be sent via one of the methods on our contact page.

1. Who are we?

We are Virtual Vintage, a business providing vintage clothing and accessories online. Full contact details can be found here: https://www.virtualvintageclothing.co.uk/contact-virtual-vintage

2. How do we collect information from you?

We obtain information about you when you contact us to enquire about our services or order online.

3. What information do we collect & how is it used?

We collect information to allow us to fulfil our delivery of our products to customers, and to respond to enquiries. The table in section 3.3 below outlines exactly what information we collect, and for what purpose.

3.0. Sensitive Data

We do not gather sensitive personal data (e.g. health, genetic, biometric data; racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sexual orientation, and criminal convictions). We expressly request that you do not provide any such sensitive data to us.

3.1. Children’s information

Our services are not directed to children under 13. If you learn that a child under 13 has provided us with personal information without consent, please contact us.

3.2. Third Parties

We will not sell or rent your information to third parties.

We will not share your information with third parties for marketing purposes.

We may pass your information to third party service providers who we have engaged for the purpose of completing tasks and providing services to you on our behalf. We disclose only the personal information that is necessary to deliver the service.

We also use a number of 3rd party services to help us fulfil our contractual obligations – for example, our products are often delivered using a 3rd party courier service such as Royal Mail. These 3rd party services are listed in full below; we have verified that these 3rd party services are GDPR compliant (or are working towards GDPR compliance), and are certified under the EU-US Privacy Shield Framework (or are working towards certification) where these organisations are based outside of the EU.

3.3. Details

The following table outlines the personal data we collect and for what purpose. The table also outlines the 3rd parties the data is processed by or shared with, and how long the data is stored for:

Name What Legal Ground Purpose 3rd Parties Data Retention
Email Prospect, customer & supplier contact information Contract To allow initial and ongoing contact with prospects, customers, suppliers, etc. Zoho Mail Until request for deletion.
Orders & Customer Data Prospect, customer contact information & orders Contract To manage our orders and customer account history. Woocommerce hosted on Linode.
Until request for deletion apart from essential order information that may be required to fulfil our legal obligation for accountancy requirements.
Server Logs IP address Legal obligation To help prevent DoS (Denial of Service) attacks; for website security and diagnostics. Linode, website managed by GetSited Ltd
Server logs are stored for up to 1 year.
Analytics Website visitor behaviour (anonymised) Legitimate interests To analyse popular content, website performance, etc – so we can further improve. Google Analytics
We anonymise IP addresses
14 months
Email Marketing Email addresses & names Legitamate Interests To send newsletters to our subscribers Mailchimp Until request to un-subscribe
Email Services Email addresses Contract To send transactional emails from orders, enquiries and activites on our website Sendgrid Short term mail logs for successful email delivery.
Payment Services Payment Information Contract We use these secure third party payment providers to accept payments through this website. No credit card information is stored or submitted to our servers. PayPal & Stripe
PayPal’s Privacy Policy is available here.
Stripe’s Privacy Policy is available here.
DNS Log Data IP address, system configuration information, etc Legitimate interests Cloudflare provides DNS, web optimization and security services for our websites Cloudflare Stored indefinitely
Courier Services Delivery Name & Address Contract To deliver your products Royal Mail Royal Mail Group has internal data retention policies which cover the requirements for data retention and secure disposal/destruction of information waste in compliance with the Group’s legal and regulatory obligations.

4. Controlling your information

You have certain rights concerning the information we hold about you, as defined under the General Data Protection Regulation. If you wish to exercise these rights, please contact us, including your email address in the first instance (this is the unique identifier we use to identify and collate personal information).

4.0. Requesting a copy of your information

You may request a copy of any data we hold about you. Upon request, we will provide the personal data we hold on record about you within one month of receipt.

4.1. Updating or correcting your information

The accuracy of your information is important to us. If you change email address, or any of the other information we hold is inaccurate or out of date, please contact us so we may correct our records.

4.2. Deleting your information

You have the right to request erasure of your personal information. Unless there is a compelling reason for the data not to be erased (for example, if we need to use that data to fulfil our contractual or legal obligations), your personal data will be deleted on request.

4.3. Automated decision making

We do not use any personal information for automated decision making or profiling; your data is not subject to automated decision making or profiling.

5. Use of ‘cookies’

Like many other websites, the Virtual Vintage website uses cookies. Cookies are small pieces of information that are stored on your computer or mobile device when you visit a website. Some of these are essential to provide website functionality.

The following list outlines what we use cookies for:

  • Google Analytics: Google Analytics sets cookies to help us accurately estimate the number of visitors to the website and what content is most popular. This helps to ensure that our website is responding to your needs in the best way possible. The Google Analytics data collected and stored is anonymous and does not contain any personal data or identify you. Google Analytics Cookie Policy is available here. This tracking is not compulsory and you can opt out by following this link:
    https://tools.google.com/dlpage/gaoptout
  • To keep track of cart data, WooCommerce (our eCommerce software) makes use of 3 cookies:
    woocommerce_cart_hash
    woocommerce_items_in_cart
    wp_woocommerce_session_
    The first two cookies contain information about the cart as a whole and helps WooCommerce know when the cart data changes. The final cookie (wp_woocommerce_session_) contains a unique code for each customer so that it knows where to find the cart data in the database for each customer. No personal information is stored within these cookies.
  • AddThis – Social Sharing Tool
    We use AddThis, a popular social bookmarking toolbar, to allow you to share content such as news releases via social media sites including Facebook and Twitter. It uses cookies to find out how pages are shared so website owners can find out what their visitors like, and it may also use that data to deliver tailored advertising on other websites you go on to visit. When you click to share content via social media, these sites may set a cookie if you are also logged in to their service. We don’t control third party cookies but we recommend you visit the relevant website for more information. The __atuvc cookie is created by AddThis in order to make sure the user sees the updated count if they share a page and return to the page before the AddThis share count cache is updated. No data from this cookie is sent back to AddThis and removing it when disabling cookies would cause unexpected behavior for users.

By using and browsing the Virtual Vintage website, you consent to cookies being used in accordance with this Policy.

If you do not consent, please use the provided Google Analytics opt-out tool, turn off cookies, or refrain from using the site. Most browsers allow you to turn off cookies. To do this, look at the ‘help’ menu on your browser.

6. Security

Virtual Vintage takes security seriously. In order to protect your information from loss, misuse or unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect.

7. Data Breaches

Where appropriate, Virtual Vintage will promptly notify you of any unauthorized access to your personal information.

8. Complaints

If you wish to raise a complaint on how we have handled your personal information, you can contact us directly and we will investigate the matter.