← Home

Privacy
Policy

We respect your privacy and are committed to protecting your personal data. This policy explains what we collect, why, and your rights under UK GDPR and the Data Protection Act 2018.

UK GDPR Compliant DPA 2018 Effective 2025
Download Policy (PDF)
Contents

Jump to
any section

1Who We Are 2What We Collect 3Why We Use It 4Photography 5Marketing 6Cookies & Ads 7Who We Share With 8Retention 9Your Rights 10Security 11Policy Changes
Before You Read

Written in
plain English

We only collect what we need. We never sell your data. Your rights under UK law are always respected.

1
Section OneWho We Are (Data Controller)

The data controller is Castle Jewellery Ltd, Mow Cop, Cheshire. We decide how and why your personal data is processed.

  • Email: sales@castle-jewellery.com
  • Phone: 07353 306 767
  • Website: castle-jewellery.com
2
Section TwoWhat Personal Data We Collect
Contact & Order Information
  • Full name, address, email and phone number
  • Ring size, style preferences and order details
  • Payment information (processed securely via Square — we never store card details)
  • Invoice records and correspondence
Enquiry & Marketing Data
  • Name and email collected at wedding fairs or via our website enquiry form
  • Preferences and notes from consultation conversations
Website Data
  • IP address, browser type, pages visited and time on site (via Google Analytics)
  • Ad interaction data (via Meta/Facebook Pixel, where you have consented)
Photography
  • Photographs taken during home consultations, where you have given verbal consent at the time
3
Section ThreeWhy We Use It & Our Lawful Basis

Under UK GDPR, we must have a lawful basis for every use of your personal data.

PurposeLawful Basis
Processing your order and delivering your ringContract performance
Responding to enquiries and pre-sale communicationLegitimate interests
Sending marketing emails to wedding fair leadsConsent (at point of sign-up)
Keeping financial and invoice recordsLegal obligation
Improving our website using Google AnalyticsLegitimate interests / Cookie consent
Serving targeted ads via MetaConsent (cookie banner)
Using consultation photos on our website & social mediaConsent (verbal, at time of photography)
Post-purchase customer care callsLegitimate interests
4
Section FourPhotography & Use of Your Image

During home consultations we may take photographs of rings being tried on or of the consultation itself. We always ask for your verbal consent before taking any photographs.

These photos may appear on our website, Instagram, Facebook, or other marketing materials. We are mindful not to publish images that clearly identify individuals without their knowledge.

Our practice: We ask verbally at the time of the consultation. You are always free to say no — this will have absolutely no effect on your order or our service to you.

Your rights regarding photos
  • You may withdraw consent at any time by emailing sales@castle-jewellery.com
  • On withdrawal, we will remove identifiable photos from our platforms as soon as reasonably practicable
  • Please let us know at the time of the consultation if you do not wish your photos to be used — or contact us at any point afterwards

A note on best practice: Verbal consent is valid under UK GDPR. If you would like written confirmation of how your photos will be used, just ask us at the consultation and we will be happy to confirm in writing.

5
Section FiveMarketing & Email Communications

We use Sendr to send marketing emails to people who have expressed interest in our products — typically couples we have met at wedding fairs who have provided their contact details and agreed to hear from us.

We do not send bulk marketing emails to existing customers after purchase. We may call you after delivery to check you are happy with your ring — this is customer care, not marketing.

  • Unsubscribe at any time using the link in any marketing email
  • Or email sales@castle-jewellery.com to be removed from our list
  • We process unsubscribe requests promptly
6
Section SixCookies, Analytics & Advertising
Google Analytics

We use Google Analytics to understand how visitors use our website. Cookies collect anonymised data about pages visited and time on site. No personally identifiable information is shared with Google through this.

Meta Pixel (Facebook & Instagram Ads)

We use (or plan to use) the Meta Pixel to measure ad performance and show relevant ads to people who have visited our website. This requires your consent via our cookie banner.

Opting out: Adjust your browser settings, use the Google Analytics Opt-out Add-on, or update your preferences in Meta Ad Settings at any time.

7
Section SevenWho We Share Your Data With

We never sell your personal data. We share it only where necessary with trusted partners who must handle it securely and lawfully:

  • Square — secure payment processing (PCI-DSS compliant)
  • Sendr — email marketing to enquiry leads
  • Google — anonymised analytics data
  • Meta (Facebook / Instagram) — ad performance data, where consented
  • Our ring manufacturers — name and ring specification only, to fulfil your order
  • Legal or regulatory authorities — if required by law
8
Section EightHow Long We Keep Your Data
Data TypeRetention Period
Order records and invoices7 years (legal/tax obligation)
Enquiry and marketing dataUntil unsubscribed, or 2 years of inactivity
Consultation photographsUntil consent withdrawn, or no longer needed
Website analytics dataPer Google Analytics settings (default 26 months)
Customer care notes12 months
9
Section NineYour Rights Under UK GDPR
  • Access — request a copy of data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — ask us to delete your data (subject to legal obligations)
  • Restriction — ask us to limit how we process your data
  • Portability — request your data in a portable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — at any time, for photos, cookies, or marketing emails

Email sales@castle-jewellery.com to exercise any right — we respond within 30 days. If unsatisfied, complain to the ICO at ico.org.uk or call 0303 123 1113.

10
Section TenData Security

We take reasonable steps to protect your personal data against unauthorised access, loss, or disclosure. Payment processing is handled entirely by Square (PCI-DSS compliant) — we never see or store your full card details.

11
Section ElevenChanges to This Policy

We may update this Privacy Policy from time to time. The current version will always be at castle-jewellery.com/privacy-policy. Material changes will be communicated with reasonable notice.

Your data,
your rights

Under UK GDPR and the Data Protection Act 2018, you have clear rights over your personal information. We are committed to honouring them.

UK GDPR · DPA 2018 · ICO
Privacy Questions?

Get in
touch with us

Emailsales@castle-jewellery.com
Phone07353 306 767
RegulatorInformation Commissioner’s Office — ico.org.uk