Privacy Policy

Last updated: 01-09-2025


1. Introduction

Welcome to Secret7Candles.co.uk (“we”, “us”, “our”). We understand that your privacy is important. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website, purchase our products, sign up for our services, or otherwise interact with us. We are committed to complying with UK data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

By using our website or providing us with your personal data, you agree to the practices described in this policy.


2. Who We Are & Contact Details

  • Controller: Secret7Candles.co.uk

  • Address: BB5 2HR Lancashire, UK

  • Email: Info@secret7candles.co.uk

  • Phone:+44 7462 454066

If we appoint a Data Protection Officer (DPO), or other privacy contact, their details will be provided here.


3. What Information We Collect

We may collect and process the following types of personal data:

  • Identity Data: name, title

  • Contact Data: email address, telephone number, postal address

  • Payment Data: card details, billing address (via secure payment processors)

  • Transaction Data: details of products you purchase, order history

  • Technical Data: IP address, browser type, operating system, referral website, pages visited, your usage of the website

  • Marketing & Communications Data: preferences for receiving marketing communications, whether you have opted in or out


4. How We Collect Your Information

We collect your personal data in several ways:

  • When you place an order or make a purchase on our website

  • When you register an account, contact us, or subscribe to our newsletter

  • When you use our website, including via cookies and similar technologies

  • When you participate in promotions, surveys or reviews

  • From third parties and publicly available sources (if applicable)


5. Purpose & Lawful Basis for Processing

We will only process your personal data when we have a lawful basis. Typical lawful bases we rely on include:

Purpose Lawful Basis
To process and fulfill your order, deliver products, manage payments Performance of a contract
To communicate with you about your order, to provide customer support Necessary for our legitimate interests and/or performance of a contract
To send marketing communications (if you opt in) Consent
To improve our website, products, services Legitimate interest
To comply with legal obligations Legal obligation

6. Use of Cookies & Tracking Technologies

We use cookies and similar technologies to improve your experience on our website, analyze usage, and for advertising and marketing purposes. You can control or disable cookies via your browser settings, but this may affect some functionality. We will provide a cookies notice or banner describing which types of cookies we use, what purposes they serve, and how you can opt out where required under UK law.


7. How We Share Your Information

We may share your personal data with:

  • Service providers and payment processors who help us run our business (e.g. shipping, fulfilment, email providers)

  • Third parties for analytics, marketing (where you have consented)

  • Legal or regulatory bodies if required by law or to protect our legal rights

  • Other businesses in case of sale, merger, reorganisation

We ensure that any third party we share data with has appropriate safeguards in place to protect your data.


8. International Data Transfers

If any of your data is transferred outside the UK or European Economic Area (“EEA”), we will ensure that such transfers comply with applicable legal requirements (for example, using standard contractual clauses or ensuring the recipient country has adequate protections in place).


9. Retention of Data

We will retain your personal data only for as long as is necessary for the purposes for which it was collected, or otherwise required by law. When data is no longer required, it will be securely deleted or anonymised.


10. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • The right to access the data we hold about you

  • The right to correct inaccurate or incomplete data

  • The right to erase data (“right to be forgotten”) in certain circumstances

  • The right to restrict processing of your data

  • The right to object to processing (including for direct marketing)

  • The right to data portability, where applicable

  • The right to withdraw consent at any time (if processing is based on consent)

If you wish to exercise any of these rights, please contact us using the details above.


11. Security

We take appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, misuse, alteration, or destruction. This includes using secure connections (HTTPS), secure servers, encryption, access controls and staff training.

However, no method of transmission over the internet, or method of electronic storage, is 100% secure, so we cannot guarantee absolute security.


12. Children

Our services are not intended for children under 16 without parental consent. We do not knowingly collect personal information from children under this age. If you believe we may have collected data from a child under 16, please contact us so we can delete it.


13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will post the updated policy on this page with the date of revision. If changes are significant, we may give you additional notice (for example, via email or via a notice on our website).