1. INTRODUCTION

Meg Skincare (operated as a sole proprietor by Meghan, based in London, United Kingdom) is committed to protecting your privacy and ensuring transparent data practices. This Privacy Policy explains:

  • What personal data we collect
  • How we use your data
  • How we protect your data
  • Your rights regarding your data
  • How long we retain your data
  • How to contact us

This Privacy Policy applies to megskincare.co.uk and all services provided.


2. DATA CONTROLLER INFORMATION

Data Controller: Meg Skincare (Sole Proprietor) London, United Kingdom Email: [email protected]

We are responsible for processing your personal data in accordance with the General Data Protection Regulation (GDPR) and UK data protection laws.


3. WHAT DATA WE COLLECT

3.1 Data You Provide Directly

When you place an order or interact with our Website, we collect:

Account & Contact Information:

  • Full name
  • Email address
  • Phone number (if provided)
  • Delivery address
  • Billing address

Payment Information:

  • Credit card details (processed securely by Stripe—we do NOT store this)
  • Billing name and address
  • Card holder information

Communication Data:

  • Messages sent through contact forms
  • Email correspondence
  • Customer service inquiries
  • Support tickets

Product Preferences:

  • Products purchased
  • Wishlist items
  • Product reviews or feedback (if provided)

3.2 Data Collected Automatically

Website Usage Data:

  • IP address
  • Browser type and version
  • Operating system
  • Pages visited and time spent
  • Referring website
  • Device type (desktop, mobile, tablet)
  • Approximate location (country/region level)

Cookies & Tracking:

  • Session cookies
  • Analytics cookies
  • Preference cookies
  • Marketing cookies (if you opt-in)

See Section 7 for details on cookies.

3.3 Data from Third Parties

We may receive data from:

  • Stripe (payment processor) – confirms successful transactions
  • Shipping carriers (Royal Mail, couriers) – delivery status updates
  • Marketing partners (if you opt-in) – for promotional purposes

4. HOW WE USE YOUR DATA

4.1 Order Processing & Fulfillment

We use your data to:

  • Process and confirm your order
  • Collect payment via Stripe
  • Arrange shipment and delivery
  • Track your package
  • Provide order updates via email
  • Handle returns and refunds
  • Resolve order issues

Legal basis: Contract performance (necessary to fulfill your order)

4.2 Customer Service & Support

We use your data to:

  • Respond to inquiries
  • Provide customer support
  • Resolve complaints
  • Improve service quality
  • Follow up on orders or deliveries

Legal basis: Contract performance and legitimate interest

4.3 Communications & Marketing

We use your data to:

  • Send transactional emails (order confirmations, shipping updates, refund notices)
  • Send marketing communications (only if you opt-in)
  • Announce new products or promotions
  • Provide skincare tips and education

Legal basis: Consent (for marketing) and legitimate interest

Your choice: You can opt-out of marketing emails at any time by:

  • Clicking “unsubscribe” in any email
  • Emailing [email protected] requesting removal
  • Updating your preferences (when account features become available)

4.4 Legal & Compliance

We use your data to:

  • Comply with legal obligations
  • Enforce Terms and Conditions
  • Protect against fraud or misuse
  • Maintain records for tax/accounting purposes
  • Respond to legal requests

Legal basis: Legal obligation, fraud prevention, legitimate interest

4.5 Analytics & Improvement

We use your data to:

  • Understand Website usage patterns
  • Improve Website functionality
  • Analyze customer preferences
  • Develop new products
  • Enhance customer experience

Legal basis: Legitimate interest


5. PAYMENT PROCESSING & STRIPE

5.1 Stripe Integration

Payment processing is handled by Stripe, a certified PCI Level 1 service provider.

Important: We do NOT:

  • Store your credit card details
  • Have access to your full card number
  • Retain payment information after transaction

Stripe does:

  • Securely process payments
  • Encrypt card information
  • Meet international security standards
  • Comply with PCI DSS requirements

Stripe’s Privacy Policy: https://stripe.com/privacy

5.2 Your Payment Data

When you make a payment:

  1. Your card details go directly to Stripe
  2. We receive confirmation of successful transaction
  3. Stripe handles all card security
  4. Your card details are never stored on our servers

5.3 Recurring Payments

If you authorize recurring payments (for future orders):

  • Stripe securely stores your payment method
  • We can only charge with your explicit authorization
  • You can update or cancel anytime
  • You control payment frequency

6. DATA SHARING & DISCLOSURE

6.1 We Do NOT Sell Your Data

We do not sell, rent, or trade your personal data to anyone.

6.2 Shared Data

We share your data only with:

Necessary Service Providers:

  • Stripe – Payment processing (payment data only)
  • Shipping Carriers – Royal Mail, couriers (delivery address only)
  • Email Providers – For sending order updates (email address)

Legal Requirements:

  • Law enforcement (if legally required)
  • Tax authorities (for compliance)
  • Courts (if legally compelled)

Data Processors Agreement: All service providers have signed data processing agreements ensuring they:

  • Use data only for specified purposes
  • Maintain confidentiality
  • Implement security measures
  • Comply with GDPR

6.3 International Transfers

Your data is processed in the United Kingdom and the EU (for Stripe processing). We ensure appropriate safeguards for international transfers compliant with GDPR.


7. COOKIES & TRACKING

7.1 What Are Cookies?

Cookies are small text files stored on your device that help us recognize you and remember preferences.

7.2 Types of Cookies We Use

Essential Cookies:

  • Session cookies (keep you logged in)
  • Security cookies (protect against fraud)
  • Functionality cookies (remember preferences)

Cannot be disabled – necessary for Website function.

Analytics Cookies:

  • Google Analytics (tracks Website usage)
  • Helps us understand user behavior
  • Anonymized data (no personal information)

Marketing Cookies:

  • Retargeting pixels (show relevant ads)
  • Social media integration
  • Only used if you opt-in

7.3 Cookie Consent

When you first visit, you’ll see a cookie consent banner. You can:

  • Accept all cookies
  • Accept essential only
  • Customize cookie preferences
  • Change preferences anytime

7.4 Disabling Cookies

You can disable cookies through your browser settings. However:

  • Some Website features may not work properly
  • You may need to log in more frequently
  • Preferences won’t be remembered

7.5 Third-Party Cookies

Some cookies come from:

  • Google Analytics – usage statistics
  • Facebook/Instagram – social media integration
  • Payment processors – for transaction security

These providers have their own privacy policies:


8. DATA PROTECTION & SECURITY

8.1 Security Measures

We implement:

  • SSL/TLS encryption – for data in transit
  • Stripe security – for payment processing
  • Access controls – limiting who accesses data
  • Regular backups – protecting against loss
  • Security audits – reviewing protections
  • Employee training – ensuring proper handling

8.2 Payment Security

  • All payment pages use HTTPS encryption
  • Credit card processing uses Stripe’s PCI-compliant systems
  • Your card details are never stored on our servers
  • Transactions are encrypted end-to-end

8.3 Limitations

While we implement strong security, no system is 100% secure. We:

  • Cannot guarantee absolute protection
  • Recommend strong passwords
  • Encourage you to report security concerns immediately
  • Are not liable for data breaches caused by your actions or third parties

8.4 Reporting Security Issues

If you discover a security vulnerability:

  • Email [email protected] immediately
  • Do not publicly disclose the vulnerability
  • Provide details to help us address it

9. DATA RETENTION

9.1 How Long We Keep Your Data

Order & Transaction Data:

  • Retained: 7 years (for UK tax/accounting purposes)
  • Purpose: Statutory compliance, order history, refund processing

Customer Contact Data:

  • Retained: Until you request deletion or unsubscribe
  • Purpose: Communication, future orders, customer service

Email Communications:

  • Retained: 2 years (or until you unsubscribe)
  • Purpose: Marketing, communication history

Cookies:

  • Retained: Session duration or until you clear cookies
  • Purpose: Website functionality, preferences

Website Analytics:

  • Retained: 26 months
  • Purpose: Usage patterns, improvements

9.2 Data Deletion

When we delete data:

  • We securely remove it from our systems
  • We request service providers delete copies
  • Some data retained longer if required by law

10. YOUR DATA RIGHTS (GDPR)

Under UK data protection laws, you have rights over your personal data:

10.1 Right to Access

You can request a copy of all personal data we hold about you. We’ll provide it within 30 days.

10.2 Right to Rectification

You can request we correct inaccurate data (e.g., wrong address).

10.3 Right to Erasure (“Right to Be Forgotten”)

You can request we delete your data, except where:

  • We have legal obligation to retain it
  • You have outstanding orders
  • Deletion would prevent fraud detection

10.4 Right to Restrict Processing

You can ask us to limit how we use your data while disputes are resolved.

10.5 Right to Data Portability

You can request your data in a structured format for transfer to another service.

10.6 Right to Object

You can object to:

  • Marketing communications (unsubscribe anytime)
  • Certain types of processing
  • Automated decision-making

10.7 Right to Withdraw Consent

For processing based on consent (like marketing), you can withdraw anytime.

10.8 Exercising Your Rights

To exercise any of these rights:

  • Email [email protected] with “Data Subject Request” in the subject line
  • Include specific details of your request
  • Provide proof of identity

Response time: Within 30 days (may extend to 90 days for complex requests)


11. CHILDREN’S DATA

Our Website is not directed to children under 13. We do not knowingly collect data from children under 13.

If we discover we’ve collected data from a child under 13:

  • We’ll delete it immediately
  • We’ll notify parents/guardians
  • We’ll comply with COPPA (if applicable)

Parental Consent: If you’re under 18, parental consent is required for certain data processing. Please have a parent/guardian contact us.


12. THIRD-PARTY LINKS

The Website may contain links to third-party sites. We:

  • Are not responsible for third-party privacy practices
  • Do not control third-party data handling
  • Recommend reviewing their privacy policies separately

13. MARKETING & COMMUNICATIONS

13.1 Marketing Emails

We only send marketing emails to those who:

  • Explicitly opted-in
  • Provided consent during signup
  • Subscribed to our mailing list

13.2 Unsubscribing

Every marketing email includes an “unsubscribe” link. To unsubscribe:

  • Click the link in any email
  • Email [email protected] requesting removal
  • Update preferences when accounts become available

13.3 Transactional Emails

You’ll receive transactional emails regardless of preferences:

  • Order confirmations
  • Shipping updates
  • Refund notices
  • Important account notifications

These are necessary for order fulfillment, not marketing.


14. AUTOMATED DECISION-MAKING

We do not use automated decision-making or profiling that significantly affects you (e.g., automatic credit decisions).

Any automated processes are for:

  • Fraud detection
  • Order processing
  • Analytics

You have the right to human review of any significant automated decisions.


15. DATA BREACH NOTIFICATION

In the event of a data breach:

  • We’ll investigate immediately
  • We’ll notify affected individuals within 72 hours (as required by law)
  • We’ll notify the Information Commissioner’s Office (ICO)
  • We’ll provide details of the breach and remediation steps

16. CHANGES TO THIS POLICY

We may update this Privacy Policy periodically. Changes will be:

  • Posted on this page with updated “Last Updated” date
  • Effective immediately upon posting
  • Effective retroactively only for data processed after the change

Your continued use of the Website constitutes acceptance of updated policies.


17. CONTACT & COMPLAINTS

17.1 Questions About This Privacy Policy

Email: [email protected]

Address: Meg Skincare London, United Kingdom

Response Time: 24-48 hours

17.2 Filing a Complaint

If you believe your data rights have been violated, you can:

Contact us first: [email protected]

Or file with the Information Commissioner’s Office (ICO): Website: https://ico.org.uk Helpline: 0303 123 1113 Email: [email protected]

The ICO is the UK’s independent authority for data protection.


18. CONTROLLER VS. PROCESSOR

We are the Data Controller – we determine how and why your data is processed.

Our service providers are Data Processors – they process data only on our instructions.

All processors have signed Data Processing Agreements ensuring GDPR compliance.


19. LEGITIMATE INTERESTS

Where we rely on “legitimate interest” as legal basis for processing, our interests include:

  • Operating the Website efficiently
  • Improving products and services
  • Fraud and security prevention
  • Complying with legal obligations
  • Business continuity

We balance these interests against your privacy rights.


20. SPECIAL CATEGORIES OF DATA

We generally do not collect special categories of data (race, ethnicity, health, religion, etc.).

Exception: If you disclose health information in support communications:

  • We process it only to help address your concern
  • We delete it after resolution
  • You should not provide unnecessary sensitive data

21. DATA PROTECTION OFFICER

As a sole proprietor, we are not required to appoint a Data Protection Officer. However, we maintain high standards of data protection and have trained staff in GDPR compliance.