Oak & Outdoor is a family-run business trading at oakandoutdoor.co.uk. We take your privacy seriously. This policy explains what personal data we collect when you use our website, why we collect it, what we do with it, and what your rights are under UK data protection law.

We are registered with the Information Commissioner's Office (ICO) as required by the UK GDPR and the Data Protection Act 2018. If you have any questions about this policy, please contact us at sales@oakandoutdoor.co.uk.

1. Who We Are

Trading name:  Oak & Outdoor

Website:  oakandoutdoor.co.uk

Email:  sales@oakandoutdoor.co.uk

Registered Address:  124 City Road · London · EC1V 2NX

We are the data controller for personal information collected through this website.

2. What Personal Data We Collect

When you place an order:

        Your name

        Delivery address and billing address

        Email address

        Phone number

        Payment information (processed securely by Stripe — we do not store your card details)

When you sign up to our newsletter:

        Your email address

        Your first name (if provided)

Automatically when you browse:

        IP address

        Browser type and version

        Pages visited and time spent

        Referring website

        Device type

 

3. Why We Collect It and Our Legal Basis

To process and fulfil your order: Performance of a contract — we cannot fulfil your order without this data.

To send you order confirmation and delivery updates: Performance of a contract and legitimate interest.

To send marketing emails (newsletter): Your consent — you can withdraw this at any time by clicking unsubscribe or emailing us.

To improve our website and understand how customers use it: Legitimate interest — we use anonymised analytics data.

To comply with our legal obligations: Legal obligation — for example, maintaining transaction records for tax purposes.

 

4. Who We Share Your Data With

We do not sell your personal data. We share it only with trusted third parties who help us run our business:

Shopify Inc.: Our ecommerce platform — processes orders and stores customer data on our behalf. Data may be processed in the USA under appropriate safeguards.

Stripe: Payment processing — handles all card transactions securely. We never see or store your full card details.

Klaviyo: Email marketing — stores your email address if you subscribe to our newsletter.

Google (Analytics): Website analytics — receives anonymised data about how visitors use our site.

Zest Outdoor Living and other UK trade suppliers: Fulfilment — your delivery name and address are shared with our supplier to dispatch your order directly to you.

Royal Mail / courier services: Delivery — your name and address are shared with the delivery carrier.

 

5. How Long We Keep Your Data

Order records: 6 years — required for UK tax and accounting obligations under HMRC guidelines.

Newsletter subscribers: Until you unsubscribe. We will remove your data within 30 days of an unsubscribe request.

Website analytics: 26 months — Google Analytics default retention period.

Customer service enquiries: 2 years from the date of resolution.

 

6. Cookies

We use cookies to make our website work and to understand how it is used. Our cookie banner allows you to choose which cookies you accept. Essential cookies cannot be turned off as they are required for the website to function. You can control non-essential cookies at any time via the cookie settings link in our website footer.

For full details of the cookies we use, please see our Cookie Policy.

7. Your Rights Under UK GDPR

Under UK data protection law, you have the right to:

        Access the personal data we hold about you

        Correct any inaccurate data we hold

        Request deletion of your data (the 'right to be forgotten') where we have no legal obligation to retain it

        Object to or restrict how we process your data

        Withdraw your consent to marketing at any time

        Request that we transfer your data to another provider (data portability)

        Lodge a complaint with the ICO at ico.org.uk if you believe we have handled your data unlawfully

To exercise any of these rights, please email us at hello@oakandoutdoor.co.uk. We will respond within 30 days.

 

8. How We Keep Your Data Secure

Our website runs on Shopify, which is PCI DSS Level 1 certified — the highest level of payment security certification available. All data transmitted to and from our website is encrypted using SSL (you will see the padlock icon in your browser).

We limit access to your personal data to those within our business who need it to process your order or respond to your enquiry.

9. International Data Transfers

Some of our third-party service providers — including Shopify and Klaviyo — are based in the United States. Where data is transferred outside the UK, it is done so under appropriate safeguards including Standard Contractual Clauses approved under UK GDPR.

10. Children's Privacy

Our website is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the 'Last updated' date at the top of this page. We encourage you to review this policy periodically. Continued use of our website after any changes constitutes your acceptance of the updated policy.

12. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or how we handle your personal data, please contact us:

Email: sales@oakandoutdoor.co.uk

Website: oakandoutdoor.co.uk

 

Oak & Outdoor  ·  oakandoutdoor.co.uk  ·  sales@oakandoutdoor.co.uk

This policy applies to all data collected through oakandoutdoor.co.uk. It does not apply to third-party websites we may link to.