Privacy policy

 Last updated: 28/10/2023

ENCORE GIFTS LTD ("we", "our", “us” or "Encore Gifts"), trading as "Encore Gifts", is committed to protecting the privacy of third parties, including its customers and all visitors to the website www.encoregifts.co.uk (the "Site"). Please read the following Privacy Policy which explains how we use and protect your information.

Key points to note

  • This Privacy Policy will apply to your use of the Site, which is operated by ENCORE GIFTS LTD ("Encore Gifts") of 18 Withnall Close, Nottingham, NG4 4LL, UK.
  • When you use our Site or request services (“Services”) from us (such as making a purchase) we may collect personal data from you. This Privacy Policy explains what personal data we collect and how we will only process this information (i) to provide our Services to you, (ii) to comply with our legal obligations, (iii) for the purposes of our legitimate business interests (namely to analyse the use of our Site and products (“Products”) to continually improve our business and your customer experience), or (iv) where we have your consent.
  • You can ask us to stop using some of your personal data at any time and have the right to ask us to delete some of the personal data that we hold about you. Just contact us at admin@encoregifts.co.uk. You can also use this email address if you have any questions about this Privacy Policy.
  • In addition to this Privacy Policy please take the time to read our Terms and Conditions.
  1. WHO CONTROLS THE COLLECTION OF PERSONAL DATA
  2. HOW TO CONTACT US
  3. PRIVACY INFORMATION
  4. TO WHOM DOES THIS PRIVACY POLICY APPLY
  5. MINORS
  6. THE PERSONAL DATA WE COLLECT ABOUT YOU
  7. HOW WE OBTAIN YOUR PERSONAL DATA
  8. FAILURE TO PROVIDE PERSONAL DATA
  9. HOW WE USE YOUR DATA
  10. MARKETING PREFERENCES, ADVERTS AND COOKIES
  11. LINKS TO OTHER WEBSITES AND THIRD PARTIES
  12. HOW WE SHARE YOUR DATA
  13. WHERE WE STORE YOUR PERSONAL DATA
  14. AUTOMATED DECISION-MAKING AND PROFILING
  15. HOW LONG WE KEEP YOUR DATA FOR
  16. DATA SECURITY
  17. YOUR RIGHTS
  18. CHANGES TO THIS PRIVACY POLICY

1. WHO CONTROLS THE COLLECTION OF PERSONAL DATA

In this Privacy Policy, “Encore Gifts”, "we", "our" or “us”, refer to ENCORE GIFTS LTD, a company registered in England and Wales (company number: 13479238) whose registered office is at 18 Withnall Close, Nottingham, NG4 4LL, UK.

We are a data controller for the purposes of General Data Protection Regulation (“GDPR”) and the Data Protection Act 2018.

2. HOW TO CONTACT US

We have appointed a Data Protection Officer (“DPO”) who is responsible for overseeing questions in relation to this Privacy Policy. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact the DPO using the details set out below.

  • By post: Data Protection Officer, ENCORE GIFTS LTD, 18 Withnall Close, Nottingham, NG4 4LL.

  • By email: admin@encoregifts.co.uk

 3. PRIVACY INFORMATION

We are committed to protecting your personal data and your privacy. This policy explains how your data is collected, used, transferred and disclosed by us. It applies to data collected when you use our Site, when you interact with us through social media, email, or phone, or when you participate in our competitions or events. It also applies to the extent that someone has purchased an E-Gift Card on your behalf.

It also describes your data protection rights, including a right to object to some of the processing which we carry out. More information about your rights, and how to exercise them, is set out in the “YOUR RIGHTS” section below.

It is important that you read this Privacy Policy together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This Privacy Policy supplements the other notices and is not intended to override them.

By visiting this Site you are accepting and consenting to the practices described in this policy.

This Privacy Policy is part of our Terms and Conditions. We reserve the right to change this Privacy Policy from time to time and you should therefore check this page frequently to ensure that you are happy with any changes.

4. TO WHOM DOES THIS PRIVACY POLICY APPLY

This Privacy Policy applies to all individuals (other than our own employees or workers) whose personal data we may process online.

Generally, we process personal data relating to our existing and potential customers, visitors to our Site and registered users of our Site (customers).

We also process personal data relating to our business contacts. You are considered a business contact if you are a sole trader, trustee, partner in a partnership, member of an unincorporated club or association, owner, director or officer of a corporate entity or an employee of any of these, where you or your business supply goods or Services to us, provide professional Services to us, have expressed an interest in us or our business or have any other business relationship with us (including where your organisation is a public authority, an industry body, a regulatory authority or similar).

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

5. MINORS

Our supply of Products or Services, our Site, events, promotions, social media, content, blogs, materials and other Services we provide are not intended for use by anyone under the age of 18 years and generally we do not knowingly collect personal information relating to anyone under the age of 18 years old. However, we encourage parents and legal guardians to monitor their children's Internet usage and to help enforce this notice by instructing children never to provide personal data to us.

6. THE PERSONAL DATA WE COLLECT ABOUT YOU

Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store, transfer and otherwise process different kinds of personal data about you which we have grouped together as follows:

  • Identity Data includes first name, last name, social media username or similar identifier, marital status, title, date of birth and gender.
  • Contact Data includes billing address, delivery address, email address and telephone numbers.
  • Financial Data includes bank account and payment card details (solely for the purpose of processing payments).
  • Transaction Data includes details about payments to and from you and other details of Products you have purchased from us.
  • Technical Data includes information collected when you access our Site, your Internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our Site.
  • Profile Data includes your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
  • Usage Data includes information about how you use our Site, Products and Services.
  • Marketing and Communications Data includes your preferences in receiving marketing from us and your communication preferences.

7. HOW WE OBTAIN YOUR PERSONAL DATA

We may collect personal data from and about you in the following ways:

  • Direct interactions. You may give us your Identity, Contact, Financial, Transaction, Profile, and Marketing and Communications data (as described above) by filling in forms, entering information online or by corresponding with us by post, phone, email, telephone or otherwise. This includes personal data you provide, for example, when you:
    • Create an account or purchase Products on our Site;
    • Subscribe to our newsletter, social media sites or create wish lists;
    • Enter a competition;
    • Complete a voluntary market research survey;
    • Contact us with an enquiry or to report a problem (by phone, email, social media, or messaging service);
    • When you log into our Site via social media.
  • Automated technologies or interactions. As you interact with our Site, we may automatically collect the following types of data (all as described above): Technical Data about your equipment, Usage Data about your browsing actions and patterns, and Contact Data where tasks carried out via our Site remain uncompleted, such as incomplete orders or abandoned baskets. We collect this data by using cookies, server logs and other similar technologies. Please see our Cookie Policy for further details.
  • Third parties. We may receive personal data about you from various third parties, including:
    • Identity and Contact Data from another individual when they purchase an E-Gift Card for you;
    • Technical Data from third parties, including analytics providers such as Google;
    • Technical Data from affiliate networks through whom you have accessed our Site;
    • Identity and Contact Data from social media platforms when you log into our Site using such social media platforms;
    • Identity and Contact data from third parties, including organisations (including law enforcement agencies), associations and groups, who share data for the purposes of fraud prevention and detection and credit risk reduction; and
    • Contact, Financial and Transaction Data from providers of technical, payment and delivery Services.

8. FAILURE TO PROVIDE PERSONAL DATA

Where we need to collect personal data by law, or under the terms of a contract (“Contract”) we have with you, and you fail to provide that data when requested, we may not be able to perform the Contract we have or are trying to enter into with you (e.g., to provide you with Products/Services). In this case, we may have to cancel a Product/Service but we will notify you if this is the case at the time.

9. HOW WE USE YOUR DATA

The legal basis for processing your personal data

We will only collect and process your personal data where we have a legal basis to do so. As a data controller, the legal basis for our collection and use of your personal data varies depending on the manner and purpose for which we collected it.

We will only collect personal data from you when:

  • we have your consent to do so, or
  • we need your personal data to perform a Contract with you. For example, to process a payment from you, fulfil your order or provide customer support connected with an order, or
  • the processing is in our legitimate interests and not overridden by your rights, or
  • we have a legal obligation to collect or disclose personal data from you.

Uses made of your personal data

Your personal data is used by us to support a range of different activities. These are listed in the table below together with the types of data used and the legal bases we rely on when processing them, including where appropriate, our legitimate interests. Please be aware that we may process your personal data using more than one lawful basis, depending on the specific activity involved. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table here. 

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we wish to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. We may process personal data without your consent, in compliance with the above rules, where this is required or permitted by law.

If you have any questions about how we use any of your personal data, please contact our Data Protection Officer at admin@encoregifts.co.uk

10. MARKETING PREFERENCES, ADVERTS AND COOKIES

Marketing - Your preferences

We may send you marketing communications and promotional offers:

  • if you have opened an account with us or purchased Products from us, or registered for a promotion or event, and you have not opted out of receiving that marketing (in accordance with your preferences, as explained below);
  • by email if you have signed up for email newsletters;
  • if you have provided us with your details when you entered a competition and you have consented to receiving such marketing (in accordance with your preferences, as explained below).

We may use your Identity, Contact, Technical, Transactional, Usage, Profile, and Marketing and Communications Data to form a view on what we think you may like, or what may be of interest to you, and to send you details of Products and offers which may be relevant for you.

We will ask you for your preferences in relation to receiving marketing communications by email, post, SMS and other communication channels.

From time to time we may also include with your order, inserts advertising Products, Services or offers from other third party companies that you may be interested in.

In respect of third party marketing communications, we will obtain your express opt-in consent before we share your personal data with any third party for marketing purposes.

You will always have full control of your marketing preferences. If you do not wish to continue receiving marketing information from us (or any third party, if applicable) at any time you can unsubscribe or ‘opt-out’ by using the unsubscribe button and following the link included in the footer of any marketing email. 

    We will process all opt-out requests as soon as possible, but please note that due to the nature of our IT systems and servers it may take a few days for any opt-out request to be implemented.

    Cookies

    Our Site uses cookies to distinguish you from other users of our Site and to keep track of your visits. They help us to provide you with the very best experience when you browse our Site and to make improvements to our Site. They also help us and our advertising networks to make advertising relevant to you and your interests.

    You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of our Site may become inaccessible or not function properly.

    For detailed information on the cookies which we and our third party providers use and the reasons why we use them, please refer to our Cookie Policy.

    Online ads

    We use online advertising to keep you aware of what we’re up to and to help you find our Products. Like many companies, we may target Encore Gifts banners and ads to you when you use other websites and apps, based on your Contact, Technical, Usage and Profile Data. We do this using a variety of digital marketing networks and ad exchanges, and a range of advertising technologies such as web beacons, pixels, ad tags, cookies, and mobile identifiers, as well as specific Services offered by some sites and social networks, such as Facebook’s Custom Audience Service.

    Our use of analytics and targeted advertising tools

    We use a range of analytics and targeted advertising tools to display relevant website content on our Site and online advertisements on other websites and apps (as described above) to you, deliver relevant content to you in marketing communications (where applicable), and to measure the effectiveness of the advertising provided. For example, we use tools such as Google Analytics to analyse Google's interest-based advertising data and/or third party audience data (such as age, marital status, life event, gender and interests) to target and improve our marketing campaigns, marketing strategies and Site content. We may also use tools provided by other third parties, such as Facebook and Bing, to perform similar tasks, using your Contact, Technical, Usage and Profile Data.

    In order to opt out of targeted advertising you need to disable your ‘cookies’ in your browser settings (see Cookie Policy for details) or opt-out of the relevant third party. Common links include:

    The Digital Advertising Alliance (which includes companies such as Google and Facebook) provides a tool called WebChoices that can perform a quick scan of your computer or mobile devices, find out which participating companies have enabled customised ads for your browser, and adjust your browser preferences accordingly.

    If you would like any further information about the data collected by these third parties or the way in which the data is used, please contact us.

    11. LINKS TO OTHER WEBSITES AND THIRD PARTIES

    Our Site (www.encoregifts.co.uk) may include links to and from the websites of our partner networks, advertisers and affiliates, or to social media platforms. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to their websites.

    12. HOW WE SHARE YOUR DATA

    We will not share your personal data with third parties unless we have your explicit consent, need to share this information to enable us to fulfil our Contract with you, are required by law or where otherwise necessary for our internal business processes. In particular, we may disclose your information to:

    • Companies that do things to get your purchases to you, such as payment service providers, warehouses, order packers and delivery companies;
    • Our trusted service providers, such as marketing agencies, advertising partners, website hosts and third party suppliers who provide Services to help us to tailor our marketing to you;
    • Credit reference agencies, law enforcement and fraud prevention agencies;
    • Third party business partners who sell products through our website;
    • Third party service review partners (eg Trustpilot), who collect feedback from customers on our behalf;
    • Companies approved by you, such as social media sites, including companies such as Facebook and Google; and
    • We will provide third parties with aggregated but anonymised information and analytics about our customers and, before we do so, we will make sure that it does not identify you.

    We use Shopify to power our online store. You can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy.

    We will only share your information with third party suppliers where it is necessary for them to provide us with the Services we need. We require all third parties to respect the security of your personal data and to treat it in accordance with the law.

    We may disclose your information to other companies in connection with any merger, acquisition, insolvency situation or otherwise, in which case we will only disclose your information so far as is necessary.

    We may also need to disclose personal data to third parties to comply with a legal or regulatory obligation, or if necessary for legal proceedings.

    13. WHERE WE STORE YOUR PERSONAL DATA

    The data that we collect from you may be transferred to, and stored at, a destination outside of the UK and the European Economic Area (“EEA”). It may also be processed by staff operating outside the UK or EEA who work for us or for one of our suppliers, business partners or affiliates. Such parties may be engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of support Services. By submitting your personal data, you agree to this transfer, storing or processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.

    14. AUTOMATED DECISION-MAKING AND PROFILING

    As part of the processing of personal data relating the sale of our Products, decisions may be made by automated means in connection with the assessment of fraud risk. This means we may automatically decline to accept a payment or automatically decide you pose a fraud risk if our processing reveals your behaviour to be consistent with that of known fraudsters, or if you appear to have deliberately hidden your true identity.

    Our processor Shopify uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you. Services that include elements of automated decision-making include:

    • Temporary denylist of IP addresses associated with repeated failed transactions. This denylist persists for a small number of hours.
    • Temporary denylist of credit cards associated with denylisted IP addresses. This denylist persists for a small number of days.

    We use automated profiling for our marketing and Product development purposes but such profiling does not produce a legal or similarly significant effect.

    15. HOW LONG WE KEEP YOUR DATA FOR

    We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Once it is no longer necessary, we will either delete the data, or anonymise it. The use of anonymised data helps us to optimise our customer service.

    To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. Further details of the periods for which we retain data are available on request.

    Where we process personal data for marketing purposes or with your consent, we process the data until you ask us to stop and for a short period after this (to allow us to implement your request).

    16. DATA SECURITY

    We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. We have also put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

    Please note, that the transmission of information via the Internet is not completely secure and, although we will take steps to protect your personal data, we cannot guarantee the security of your personal data transmitted via the Site – any transmission is therefore at your own risk.

    17. YOUR RIGHTS

    Your personal data is protected by legal rights, which include your rights to:

    • Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
    • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
    • Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, following your request.
    • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes.
    • Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: if you want us to establish the data's accuracy; where our use of the data is unlawful but you do not want us to erase it; where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
    • Request the transfer of your personal data to you or to a third party (data portability). We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a Contract with you.
    • Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain Products or Services to you. We will advise you if this is the case at the time you withdraw your consent.
    • Request human intervention for automated decision-making and profiling. You have the right to request human intervention where we are carrying out automated decision-making when processing your personal data. This form of processing is permitted where it is necessary as part of our Contract with you, providing that appropriate safeguards are in place or your explicit consent has been obtained.

    These rights may be limited, for example if fulfilling your request would reveal personal data about another person, where they would infringe the rights of a third party (including our rights), or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping. Relevant exemptions are included in data protection laws in the UK. We will inform you of relevant exemptions we rely upon when responding to any request you make.

    If you wish to exercise any of these rights, please email us at admin@encoregifts.co.uk. Please include in your request, your name, email address, postal address, a copy of a utility bill showing your current address or other proof of address, and a copy of your identity card or passport certified by a solicitor or bank. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

    We will try to respond to all legitimate requests within one month. Occasionally, it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

    Right to lodge a complaint

    If you have any concerns or complaints regarding the way in which we process your data, please email us directly at admin@encoregifts.co.uk. You also have the right to make a complaint to the Information Commissioner’s Office (ICO), the data protection regulator in the UK. We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please do contact us in the first instance.

    18. CHANGES TO THIS PRIVACY POLICY

    From time to time we may update this Privacy Policy and will notify you of changes where we are required to do so by law. It is your responsibility to ensure that you are aware of the latest version of this Privacy Policy and your continued use of our Site will be deemed to be your acceptance of any revised terms.

    Shopify may also collect information in line with their own privacy policy.