Privacy policy
This policy explains what we do with personal data when you visit this store, buy from it, write to us or install our companion app. It is written to be read, not to be skimmed past.
Who is responsible for your data
The controller is [Company name], registered in [Country] under [Company number], registered office [Registered office]. For anything to do with privacy, write to [Privacy email] or to that address, marked for the attention of [Data protection contact].
What we collect
- Order details. Your name, delivery and billing address, email address, telephone number if you give one, what you ordered and what you paid.
- Payment data. Handled by our payment provider. We see the last four digits, the card type and whether the payment succeeded, never the full number.
- Your personalisation text. The line you ask us to print or engrave, kept with the order because it is part of what you bought.
- Account data, if you create one: your saved addresses and order history. Checkout works perfectly well as a guest.
- Correspondence. The messages you send us and our replies.
- Browsing data. Pages viewed, referring site, approximate location from your IP address, device and browser type, and what you added to the basket. Collected through cookies and similar technologies.
- Marketing preferences, if you subscribe.
Why we use it, and on what legal basis
- To perform our contract with you: taking and dispatching orders, printing what you asked for, handling returns, warranty claims and refunds, and answering questions about an order.
- To meet legal obligations: keeping invoices and tax records, and responding to lawful requests.
- For our legitimate interests: preventing fraud, keeping the site secure, understanding which pages work, and improving the products. We weigh those interests against your rights, and you can object at any time.
- With your consent: marketing email, and any cookie that is not strictly necessary. You may withdraw consent whenever you like, and doing so does not affect what was done beforehand.
The companion app sends us nothing
The SneakPen app is a web app you install from your browser. There is no account, nothing to sign up for and nothing to log into. Every card you write is stored in your browser's storage, on that device, and it never leaves it. We receive no copy, no analytics and no crash reports from the app, and we cannot read what you write in it. Export JSON gives you the whole library as one file so you can back it up or move it yourself. Delete the app and the data goes with it, which is also why the backup matters. Printing happens over a direct Bluetooth connection between your device and the printer — nothing routes through us.
Who else handles it
We use a small number of providers, each bound by contract to process data only on our instructions:
- Shopify, which hosts the store, the checkout and our order records, and screens orders automatically for fraud. A flagged order is always reviewed by a person before anything is cancelled.
- [Payment provider], which processes payments and runs its own fraud checks as a controller in its own right.
- Carriers — Royal Mail inside the United Kingdom, DHL elsewhere — which receive the name, address, telephone number and email needed to deliver the parcel and send tracking updates.
- [Email provider], for order confirmations, dispatch notices and, if you asked for it, our newsletter.
- [Analytics provider], for audience measurement, set only where the law requires consent and you have given it.
- Our accountants and, where we are legally obliged, public authorities.
We do not sell personal data, and we do not share it with anyone for their own marketing.
How long we keep it
- Order and invoice records: for as long as tax and accounting law requires, which is usually between six and ten years depending on the country ([Statutory retention period]).
- Personalisation text: kept with the order record. Ask us once your return window has closed and we will delete it from our systems.
- Support correspondence: three years from the last message, so we can pick up a warranty claim where it left off.
- Account data: until you close the account, then deleted apart from what the order records must keep.
- Marketing data: until you unsubscribe, after which we keep the minimum needed to make sure we do not write to you again.
- Cookie and analytics data: no more than thirteen months.
Data sent outside the European Economic Area
Some of our providers, Shopify among them, are established outside the European Economic Area and the United Kingdom, so your data may be processed there. Those transfers rely either on an adequacy decision for the country concerned, or on the European Commission's standard contractual clauses together with the UK international data transfer addendum. Ask us at [Email] and we will tell you which applies to a given provider.
Your rights
Wherever the GDPR applies to you, you may ask us to:
- Give you access to the personal data we hold about you, and a copy of it.
- Correct anything inaccurate or incomplete.
- Erase your data, where we no longer need it for the reasons set out above.
- Restrict how we use it while a dispute about accuracy or lawfulness is resolved.
- Port the data you gave us to another provider, in a structured, machine-readable file.
- Object to processing based on our legitimate interests, and to direct marketing at any time and without giving a reason.
- Withdraw consent you previously gave, at any time.
Write to [Privacy email] and we will answer within one month. We may ask for something that confirms who you are, so we do not hand your data to somebody else. If you think we have got it wrong, you can complain to your supervisory authority — [Data protection authority] — or to the one where you live or work. We would rather you told us first, but that is your choice, not a condition.
Cookies
We use cookies that are strictly necessary to run the store and keep the basket working, and — only with your consent — cookies that measure how the site is used. What each one does, how long it lasts and how to change your mind is set out on our cookie policy.
Children
This store is not aimed at children. We do not knowingly collect data from anyone under sixteen, or under the local age of digital consent if it is lower. If you believe a child has given us personal data, write to [Email] and we will delete it.
Security
The site runs over an encrypted connection, payments are handled in a PCI-DSS compliant environment, and card numbers never reach us. Access to order data is limited to the people who need it and protected by two-factor authentication. No system is perfect; if a breach ever put your rights at risk, we would tell you and the supervisory authority within the time the law allows.
Changes to this policy
When this policy changes we update the date below, and for anything significant we say so by email or on the site.
Last updated: 1 August 2026