Privacy Policy
How we collect, use and share personal data on this store. Written for UK law as at 14 August 2026.
This notice explains how Fluffy Friends (“we”, “us”) uses personal data when you visit this website, create an account, place an order, contact us or subscribe to emails. It is written for UK consumers as at 14 August 2026.
It covers the UK GDPR, the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025) and the Privacy and Electronic Communications Regulations 2003 (PECR). It is our public privacy information under Articles 13 and 14 of the UK GDPR. It is not personal legal advice.
1. Who is responsible for your data
The controller of personal data collected through this store is the trader operating as Fluffy Friends (also shown as FluffyFriends Pets). We use that data for orders, customer service, marketing you have asked for, and running this website.
This is an online-only shop. We do not have a public store. Privacy questions, access requests and data-protection complaints are handled by email and through the contact form — that is our normal and complete contact route.
- Email: hello@fluffyfriendspets.co.uk
- Contact / complaints form: Contact us
- Hours: Monday to Saturday, 9am to 6pm UK time
We do not appoint a Data Protection Officer. That is not required for a shop of this size whose core activity is selling goods, not large-scale monitoring of people.
Shopify provides the store, checkout, customer accounts and hosting. For those services Shopify acts as our processor under Shopify’s Data Processing Addendum. Payment brands you choose at checkout (for example PayPal, Apple Pay or Klarna) are typically independent controllers of the data they need to take payment. Their own privacy notices apply to that processing.
2. Whose data this notice covers
This notice applies to personal data we collect on this website, including fluffylucyfriends.myshopify.com and any custom domain that points to this store, and to emails or messages you send us about those visits or orders.
It does not govern purchases you make on eBay or TikTok Shop. Those platforms have their own notices. If you email us about a marketplace order we will still handle that correspondence under this notice.
We do not knowingly sell to children. This store is aimed at adults buying pet products. If we learn we hold data about a child under 13, we will delete it unless we must keep it for law.
3. What we collect and why
We only collect what we need for the purposes below. You do not have a statutory duty to give us data. If you want to buy, some details are necessary for the contract (name, delivery address, email, payment). Without them we cannot complete the order.
| What we collect | Where it comes from | Why we use it | Lawful basis |
|---|---|---|---|
| Name, delivery and billing address, email, phone, order contents, notes, payment status | You, at checkout | Take and fulfil the order, send confirmations and tracking, handle returns, prevent fraud, keep tax and consumer-law records | Contract; legal obligation (tax and consumer records); legitimate interests (fraud prevention) |
| Account email, password (held by Shopify), saved addresses, order history | You, if you create an account | Let you sign in and reuse details | Contract; legitimate interests (account security) |
| Email address, marketing tag | You, via the newsletter form (this sets “accepts marketing”) | Send shop news and offers you asked for | Consent (UK GDPR and PECR) |
| Name, email, phone, message | You, via the contact form or email | Answer the query, handle a complaint or a data-protection request | Legitimate interests; legal obligation (where the message is a rights request or statutory complaint) |
| Search terms, pages viewed, cart contents, device/browser type, IP address, approximate location, cookie identifiers | Your device and Shopify’s storefront logs | Run the site and checkout, security, diagnose faults. Analytics and advertising pixels only if you allow them | Legitimate interests (strictly necessary store operation); consent (non-essential cookies and similar tech — PECR) |
| Cookie and tracking preferences | You, via our cookie banner; also stored in your browser as ff_cookie_consent and passed to Shopify’s Customer Privacy API |
Remember and honour your choice | Legal obligation (PECR / UK GDPR accountability) |
We do not ask for special category data (health, religion, biometrics and similar) and we do not want it in free-text fields. If you include it anyway, we will only keep what we need to deal with your message.
Card numbers are entered on Shopify’s checkout. We do not store full card details on our own systems.
4. Lawful bases in plain terms
- Contract — we need the data to sell and deliver the goods you ordered, or to run an account you asked for.
- Legal obligation — we keep invoices and some order records for tax and consumer law; we must handle data-protection requests and complaints.
- Legitimate interests — keeping the store secure, stopping fraud, answering customer service, improving how the shop works using information that does not require PECR consent. You can object (see section 10).
- Consent — email marketing you opt into, and non-essential analytics or marketing cookies. You can withdraw consent at any time. Withdrawal does not affect processing already done.
Where we rely on legitimate interests we have judged that the processing is reasonably expected for an online shop and is not overridden by your interests, rights or freedoms.
5. Cookies and similar technologies
PECR requires consent before we store or access non-essential information on your device. Essential cookies (cart, checkout, security, fraud prevention, remembering your cookie choice) do not need that consent.
On this theme we show our own cookie banner. Your choice is stored in the browser under ff_cookie_consent and, where the Shopify Customer Privacy API is available, we pass analytics and marketing signals to Shopify so its pixels follow your decision.
As at 14 August 2026 we have not added a separate Google Analytics, Meta or TikTok advertising pixel in the theme code. Shopify may still run first-party store analytics and Shopify pixels for analytics or marketing if they are enabled in the Shopify admin and consent allows it. If we later add a named advertising pixel, we will update this notice and the Cookie Policy before it goes live.
Shopify checkout and some forms may use bot-protection (for example hCaptcha). That is treated as security for the form, not as advertising.
Full category detail is on the Cookie Policy. You can change your mind by clearing site data for this domain and using the banner again, or by browser settings. Essential cookies cannot be switched off if you want the shop to work.
6. Who we share data with
We do not sell your personal data. We share it only where needed:
- Shopify — hosting, storefront, checkout, customer accounts, order admin, store analytics and (where enabled and consented) pixels. See Shopify’s privacy policy and DPA.
- Payment providers you select — Shopify Payments and any enabled method such as PayPal, Apple Pay or Klarna. They process payment data as independent controllers or as Shopify’s processors, depending on the method.
- Carriers — name, address and phone so the parcel can be delivered and tracked.
- Dropship or warehouse partners — name, address and the line items they must pick and pack. They may only use this to fulfil that order for us.
- Professional advisers and authorities — accountants, insurers, HMRC, Trading Standards, the courts or the ICO, if the law or a genuine dispute requires it.
- A buyer of the business — if we sell or restructure the shop, customer records may transfer so orders and accounts can continue. We would still expect the buyer to use them for the same kinds of purpose.
Everyone we use as a processor is required to keep the data secure and use it only on our instructions, except where they are a controller in their own right (typical for card schemes and some wallets).
7. International transfers
This is a UK-facing store. Shopify and some payment or security providers process data outside the UK, including in Canada, the United States, Ireland and other countries where Shopify or its subprocessors operate.
Where the UK has made an adequacy decision (for example Canada for commercial organisations, and US organisations certified to the UK Extension to the Data Privacy Framework / “UK–US data bridge”), we rely on that. Otherwise Shopify’s DPA uses the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK addendum, and Shopify’s own transfer tools. You can read Shopify’s current transfer position in its DPA.
PayPal, Apple, Klarna and similar brands apply their own transfer safeguards. We do not control those.
8. How long we keep data
We keep data only as long as we need it for the purpose, including legal claims and tax. Typical periods:
| Record | How long |
|---|---|
| Orders, invoices, refunds, delivery and returns correspondence | At least 6 years after the end of the tax year of the order (HMRC and consumer-claim limitation in England and Wales). We may keep a shorter or longer copy if a live dispute needs it. |
| Customer account | While the account is open, then deleted or anonymised when you ask us to close it or after a long period of inactivity, unless an order record must stay. |
| Newsletter | Until you unsubscribe or we stop that list. We may keep a suppression record of the email so we do not mail you again by mistake. |
| Contact-form and support emails | Usually up to 24 months after the last message, longer if the thread is a complaint, return or legal claim. |
| Cookie consent stored in your browser | Until you clear site data. Shopify consent cookies follow Shopify’s retention. |
| Security and storefront logs | As retained by Shopify for operating and securing the platform. |
When we no longer need personal data we delete it or irreversibly anonymise it.
9. Automated decisions
We do not make solely automated decisions that produce legal or similarly significant effects about you (UK GDPR Article 22), such as automatically refusing to sell to you without a human review.
Shopify checkout and payment providers may run automated fraud or risk checks. If a payment is declined, that decision is usually taken by the payment provider. You can try another method or contact us and we will look at the order with a person if we can.
10. Your rights
Under the UK GDPR you can ask us to:
- access the personal data we hold about you (a subject access request);
- correct inaccurate or incomplete data;
- erase data in the cases the law allows (this does not override tax or claim records we must keep);
- restrict how we use data in certain cases;
- receive data you gave us in a portable format, where the basis is consent or contract and the processing is automated;
- object to processing based on legitimate interests, including any profiling related to that;
- object to direct marketing at any time — we will stop;
- withdraw consent where we rely on it (newsletter; non-essential cookies);
- not be subject to a solely automated decision with legal or similarly significant effects, in the limited cases Article 22 applies.
We will respond within one month. We can extend by two further months for complex or numerous requests; if we do, we will tell you within the first month. We may need to verify it is you. There is no fee unless a request is manifestly unfounded or excessive.
The Data (Use and Access) Act 2025 (in force for this duty from 19 June 2026) also gives you a right to complain to us as controller if you think we have infringed the UK GDPR. We must:
- make it easy to complain, including by electronic means;
- acknowledge the complaint within 30 days of receiving it; and
- investigate and tell you the outcome without undue delay.
To do that, email hello@fluffyfriendspets.co.uk with the subject line Data protection complaint, or use the contact form and start the message with those words. That contact form is our electronic complaint form for section 164A of the Data Protection Act 2018.
You can also complain to the UK regulator, the Information Commissioner’s Office: ico.org.uk/make-a-complaint, or write to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You may also bring a claim in the courts.
11. Email marketing (PECR)
We only send promotional email if you have opted in through the newsletter form, or if another PECR exception clearly applies (for example a narrow “soft opt-in” to existing customers about similar products, with a simple unsubscribe — we do not currently rely on that as our main method).
Every marketing email will include an unsubscribe link. You can also email hello@fluffyfriendspets.co.uk. Transactional messages about an order you already placed (confirmation, dispatch, return) are not marketing and we will still send those.
12. Security
Checkout and customer accounts run on Shopify’s platform, which uses HTTPS and Shopify’s security controls. Access to the store admin is limited to people who need it to run the shop. No website is completely secure. If we become aware of a personal-data breach that must be reported, we will notify the ICO and affected people as the UK GDPR requires.
13. Changes to this notice
If we start a new purpose, add a new advertising pixel, or change who we are as controller, we will update this page first and, where the change is material, we will highlight it on the site or by email where we can lawfully contact you. The date at the bottom is the date of the current version.
14. How to contact us
For access requests, corrections, unsubscribe, or a data-protection complaint:
Related pages: Cookie Policy, Delivery & Returns, Terms & Conditions.