Privacy Policy
Last updated: 16.12.25
1. INTRODUCTION
1.1 This Privacy Policy explains how Palms Customs ("we", "us", "our") collects, uses, and protects your personal data when you use our website [www.palmscustoms.co.uk] ("Website"), place an order, or otherwise interact with us.
1.2 We are committed to protecting your privacy and handling your personal data in accordance with:
- the UK General Data Protection Regulation ("UK GDPR"); and
- the Data Protection Act 2018 and other applicable UK data protection laws.
1.3 We are the data controller for the purposes of data protection law.
2. CONTACT DETAILS
2.1 If you have any questions about this Privacy Policy or our data practices, please contact us at:
- Business name: Palms Customs
- Email: contact@palmscustoms.com
3. THE DATA WE COLLECT
3.1 We may collect and process the following types of personal data:
- Identity data: name, title, username or similar identifier.
- Contact data: billing address, delivery address, email address, telephone number.
- Order data: details of products you have purchased, order dates, delivery details.
- Payment data: payment method, partial card details or transaction references (we do not store full card details; these are processed by our payment providers).
- Account data: login details, passwords (stored in encrypted form), account preferences, wishlist items.
- Technical data: IP address, browser type and version, time zone setting, device identifiers, operating system, and other technology on the devices you use to access our Website.
- Usage data: information about how you use our Website, such as pages visited, click paths, and time spent on pages.
- Marketing and communication data: your preferences for receiving marketing from us, and your communication preferences.
- Correspondence data: information contained in messages you send us, such as emails, contact form submissions, or social media messages.
4. HOW WE COLLECT YOUR DATA
4.1 We collect personal data in different ways, including:
- Directly from you:
- when you place an order on our Website;
- when you create an account;
- when you sign up to our newsletter;
- when you contact us by email, social media, or via our contact form; or
- when you leave reviews or comments.
- Automatically:
- as you interact with our Website, we may automatically collect technical and usage data using cookies and similar technologies.
- From third parties:
- analytics providers (for example, Google Analytics);
- payment providers (for example, Stripe, PayPal) who provide us with payment confirmation-related information;
- delivery and courier partners who provide delivery status information; and
- social media platforms if you interact with us via their services.
5. HOW WE USE YOUR PERSONAL DATA
5.1 We will only use your personal data where we have a lawful basis. We may use your data for the following purposes:
- To process and fulfil your orders:
- to take payment and provide refunds;
- to deliver products to you;
- to send order updates, delivery information, and transactional emails.
Lawful basis: performance of a contract; legal obligation; legitimate interests (operating our business).
- To manage your account:
- to create and maintain your account;
- to manage your preferences and saved details.
Lawful basis: performance of a contract; legitimate interests.
- To provide customer service:
- to respond to your enquiries and requests;
- to handle complaints and returns.
Lawful basis: performance of a contract; legitimate interests.
- To improve our Website and services:
- to analyse how visitors use our Website;
- to troubleshoot, test, and improve our Website and products.
Lawful basis: legitimate interests (to develop our business and improve our offerings).
- To send marketing communications:
- to send you news, offers, and updates by email or other channels where you have agreed to receive them or where we are otherwise permitted by law.
Lawful basis: consent; legitimate interests (to promote our business), subject to your rights to opt out.
- To protect our business:
- to detect and prevent fraud and abuse;
- to comply with applicable laws, regulations, and legal processes.
Lawful basis: legal obligation; legitimate interests.
6. MARKETING COMMUNICATIONS
6.1 We may send you marketing communications by email or other electronic means if:
- you have opted in to receive them; or
- you are an existing customer and we are marketing similar products, subject to your right to opt out.
6.2 You can stop receiving marketing messages at any time by:
- clicking the "unsubscribe" link in any marketing email; or
- contacting us at [contact email].
6.3 Even if you opt out of marketing messages, we may still send you non-marketing messages such as order confirmations, delivery updates, and other service-related communications.
7. COOKIES AND SIMILAR TECHNOLOGIES
7.1 Our Website uses cookies and similar technologies to:
- make the Website work properly;
- remember your preferences (for example, items in your cart);
- analyse Website usage; and
- support our marketing and advertising.
7.2 We will present a cookie banner where required by law, giving you options to accept, reject, or manage cookies (except for strictly necessary cookies).
7.3 Further information about the cookies we use and how to manage your preferences can be found in our Cookie Policy, available on our Website.
8. SHARING YOUR PERSONAL DATA
8.1 We may share your personal data with trusted third parties, including:
- Payment service providers:
- to process payments securely and to handle refunds.
- Delivery and courier companies:
- to deliver your orders and provide delivery updates.
- IT and hosting providers:
- to host our Website, store data, and provide technical support.
- Analytics and marketing providers:
- to help us understand how our Website is used and to run marketing campaigns (for example, Google Analytics, email marketing providers).
- Professional advisers:
- such as accountants, lawyers, and insurers, where necessary for our business operations.
- Authorities or law enforcement:
- where required by law or necessary to protect our rights or the rights of others.
8.2 We require all third parties to respect the security of your personal data and to treat it in accordance with the law. They may only process your personal data on our instructions and for specified purposes.
9. INTERNATIONAL TRANSFERS
9.1 Some of our service providers may be located outside the UK, including in countries that may not provide the same level of data protection as the UK.
9.2 Where we transfer your data outside the UK, we will ensure that appropriate safeguards are in place, such as:
- using countries that the UK government has recognised as providing an adequate level of protection; or
- using standard contractual clauses or other legally recognised safeguards.
9.3 You can contact us for more information about the specific safeguards we use for international transfers.
10. DATA SECURITY
10.1 We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or damage.
10.2 However, no method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee its absolute security.
11. DATA RETENTION
11.1 We will keep your personal data only for as long as reasonably necessary to:
- fulfil the purposes for which we collected it;
- satisfy any legal, accounting, or reporting requirements; and
- resolve disputes and enforce our agreements.
11.2 The retention period will depend on factors such as:
- the nature of the data;
- legal obligations (for example, keeping tax records for a minimum period); and
- whether you have an ongoing relationship with us (such as having an account).
11.3 When we no longer need your personal data, we will delete or anonymise it.
12. YOUR RIGHTS
12.1 Under data protection laws, you have various rights in relation to your personal data, including:
- Right of access:
- You can request a copy of the personal data we hold about you.
- Right to rectification:
- You can ask us to correct inaccurate or incomplete data about you.
- Right to erasure:
- You can ask us to delete your personal data in certain circumstances.
- Right to restrict processing:
- You can ask us to suspend the processing of your data in certain circumstances.
- Right to data portability:
- You can request that we provide your data in a structured, commonly used, and machine-readable format or transfer it to another service provider where technically feasible.
- Right to object:
- You can object to our processing of your personal data where we rely on legitimate interests, including for direct marketing.
- Right to withdraw consent:
- Where we rely on your consent to process your data, you can withdraw that consent at any time.
12.2 To exercise any of these rights, please contact us using the contact details in section 2. We may need to verify your identity before acting on your request.
13. COMPLAINTS
13.1 If you have concerns about how we handle your personal data, please contact us first so we can try to resolve the issue.
13.2 You also have the right to make a complaint to the UK Information Commissioner's Office (ICO), the UK supervisory authority for data protection:
- Website: www.ico.org.uk
- Telephone: 0303 123 1113
14. THIRD-PARTY LINKS
14.1 Our Website may include links to third-party websites, plug-ins, or applications. Clicking those links or enabling those connections may allow third
