Privacy Policy

PRIVACY POLICY

Patch and Mix Crafts Limited
Last Updated: 21st February 2026

1. Who We Are

Patch and Mix Crafts Limited (“we”, “our”, “us”) is a company registered in England and Wales.

Company Number: 12846463
Registered Office: 5 Ruxton Close, Swanley, Kent BR8 7DA
Email: admin@patchandmixcrafts.com
Telephone: 01322619012

We are the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. How to Contact Us

If you have questions about this Privacy Policy or wish to exercise your legal rights, please contact:

Email: pnm.privacy@patchandmixcrafts.com
Post: 5 Ruxton Close, Swanley, Kent BR8 7DA
Telephone: 01322619012

3. The Personal Data We Collect

We may collect and process the following categories of personal data:

3.1 Identity Data

  • First name
  • Last name
  • Username (if account created)

3.2 Contact Data

  • Billing address
  • Delivery address
  • Email address
  • Telephone number

3.3 Financial Data

  • Payment card details (processed securely via third-party payment providers)
  • Transaction history

3.4 Technical Data

  • IP address
  • Browser type and version
  • Time zone setting
  • Operating system
  • Device type
  • Website usage data via cookies

3.5 Marketing Data

  • Preferences for receiving marketing communications
  • Communication history

4. How We Collect Your Data

We collect data when you:

  • Place an order via our website
  • Create an account
  • Subscribe to our newsletter
  • Contact us by email or phone
  • Browse our website (via cookies and analytics tools)

5. Lawful Bases for Processing (UK GDPR)

We process personal data under the following lawful bases:

Contract

To:

  • Process and fulfil orders
  • Deliver goods
  • Manage payments
  • Provide customer support

Legal Obligation

To:

  • Maintain accounting records
  • Comply with HMRC requirements
  • Respond to lawful requests from authorities

Legitimate Interests

To:

  • Improve our website
  • Prevent fraud
  • Manage customer relationships
  • Analyse website usage

Consent

For:

  • Email marketing communications
  • Non-essential cookies

You may withdraw consent at any time.

6. How We Use Your Information

We use your information to:

  • Process and dispatch orders
  • Send order confirmations and updates
  • Manage returns and refunds
  • Provide customer service
  • Send marketing emails (if opted in)
  • Improve our website and services
  • Prevent fraud and misuse

7. Payment Processing

Payments are processed securely via third-party payment providers integrated with WooCommerce.

We do not store full card details on our servers.

Payment providers may process your data in accordance with their own privacy policies.

8. Data Sharing

We may share personal data with:

  • Payment processors
  • Courier and delivery providers
  • Website hosting providers
  • IT and security providers
  • Professional advisers (accountants, legal advisers)
  • HMRC or regulatory authorities where legally required

We require all third parties to respect the security of your data and process it lawfully.

We do not sell personal data.

9. International Transfers

We primarily operate within the United Kingdom.

If any service provider processes data outside the UK, we ensure appropriate safeguards are in place, such as:

  • UK adequacy regulations
  • Standard Contractual Clauses
  • Equivalent data protection standards

10. Data Retention

We retain personal data only as long as necessary.

Typical retention periods:

  • Order and transaction records: 6 years (for tax purposes)
  • Customer service communications: up to 3 years
  • Marketing data: until you unsubscribe

After retention periods expire, data is securely deleted or anonymised.

11. Your Legal Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request erasure (“right to be forgotten”)
  • Restrict processing
  • Object to processing
  • Data portability
  • Withdraw consent at any time

To exercise these rights, contact us using the details above.

We may need to verify your identity before fulfilling your request.

12. Cookies

Our website uses cookies to:

  • Enable core website functionality
  • Process shopping cart transactions
  • Analyse website traffic
  • Store user preferences

Non-essential cookies are only placed with your consent.

You can manage cookie preferences via our cookie banner or browser settings.

A separate Cookie Policy is available.

13. Data Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • SSL encryption
  • Secure hosting
  • Restricted access controls
  • Regular software updates
  • Password protection

However, no internet transmission is completely secure.

14. Children’s Data

Our website is not intended for children under 16.

We do not knowingly collect personal data from children.

15. Complaints

If you are unhappy with how we handle your data, you have the right to lodge a complaint with:

Information Commissioner’s Office (ICO)
Website: https://www.ico.org.uk

We would, however, appreciate the opportunity to address your concerns first.

16. Changes to This Privacy Policy

We may update this policy from time to time.

The latest version will always be posted on this page with an updated revision date.