Privacy policy
Cookie Policy for Wonky Cards
Effective Date: [20/10/2025]
This Privacy Policy explains how Wonky Cards collects, stores, and uses information when you interact with our website, https://www.wonkycards.com (our website), or when we obtain personal data and cookies from you for purposes including personalizing advertisements.
It should be read alongside our Cookie Policy.
Summary
Data Controller: Wonky Cards
How We Collect Information: Directly from you (e.g., via contact, orders, cookies) and occasionally from third parties.
Information Collected: Name, contact details, payment information, IP address, cookie data, device information, website usage details, geographical location, company name (if applicable), VAT number (if applicable).
How We Use Information: Business administration, order processing, website improvement, advertising, analytics, and legal compliance.
Disclosure: Service providers for contractual or business purposes; legal requirements.
Sale of Information: We do not sell your information.
Retention Period: As required legally or for business purposes.
Cookies & Tracking: Used for essential, functional, analytical, and advertising purposes. See our Cookie Policy.
Transfers Outside EEA: Done only with appropriate safeguards.
Automated Decision-Making & Profiling: Limited to analytics, advertising, and personalization.
Your Rights: Access, correction, deletion, restriction, portability, objection, consent withdrawal, no automated decision-making impact, complaint to a supervisory authority.
Information We Collect
When You Visit Our Website
We collect server log information including your IP address, pages visited, request timestamps, source of access, browser, and operating system.
Purpose: Ensuring network and IT security, detecting unauthorized access, malicious code, and other cyber threats.
Legal Basis: Compliance with legal obligations (GDPR Art. 6(1)(c)) and our legitimate interests (Art. 6(1)(f)).
Cookies & Similar Technologies
Our website uses cookies and similar technologies for essential, functional, analytical, and advertising purposes. You may reject some or all cookies via your browser, which may impact website functionality. For details, see Cookie Policy.
When You Contact Us
We collect information when you contact us via:
- Email: Your email address, name, phone number, and signature details.
- Contact Form: Name, email, phone number, and any additional information.
- Phone Calls: Phone number and information provided during conversation (calls may be recorded).
- Post: Information provided in postal communications.
Storage: Data is stored within the EEA via third-party providers such as Gsuite, mailer lite, Shopify, and BT (telephone services).
Legal Basis: Legitimate interests (Art. 6(1)(f)) and contractual necessity (Art. 6(1)(b)).
When You Interact with Our Website
- E-Newsletter Sign-up: Name, email address, and consent to receive communications.
- Account Registration: Name, email, phone, and other registration details.
Storage & Providers: Managed via mailer lite and Shopify servers within the EEA.
Legal Basis: Consent (Art. 6(1)(a)) and contractual necessity (Art. 6(1)(b)).
When You Place an Order
We collect mandatory information: name, email, billing/shipping address, phone, company name, VAT number. Payment is processed via Shopify Payments & PayPal.
Storage & Transfer: Within the EEA, safeguarded by providers’ protocols.
Legal Basis: Contractual necessity (Art. 6(1)(b)) and compliance with legal obligations (Art. 6(1)(c)).
Marketing Communications
You can opt-in or opt-out of marketing during checkout or via links in communications.
Legal Basis: Legitimate interests (Art. 6(1)(f)) and/or consent.
Information from Third Parties
We may receive information from affiliates, business partners, or public sources (e.g., Companies House, directories).
Legal Basis: Contractual necessity (Art. 6(1)(b)), consent (Art. 6(1)(a)), or legitimate interests (Art. 6(1)(f)).
Automated Decision-Making & Profiling
- Used for advertising personalization and web analytics.
- Does not have legal or significant effects on individuals.
- You can object to profiling or automated decision-making via cookie settings, VPN, or platform opt-outs.
Tools Used: Google Analytics (anonymized data, cookies-based).
Disclosure of Information
- Service Providers: Email, hosting, analytics, and telecommunication services.
- Legal Requirements: Criminal investigations, legal disputes, court orders, or regulatory obligations.
- Third-Party Analytics: Google Analytics, for aggregated and anonymized website data.
Disclosure of Information
- Service Providers: Email, hosting, analytics, and telecommunication services.
- Legal Requirements: Criminal investigations, legal disputes, court orders, or regulatory obligations.
- Third-Party Analytics: Google Analytics, for aggregated and anonymized website data.
Data Retention
- Orders: 6 years (financial/legal obligations).
- Correspondence/Enquiries: Until resolved.
- E-Newsletter: Until unsubscribed or service canceled.
- Other Information: Retained no longer than necessary considering purpose, legal obligations, and risks
Security
- Access limited to essential personnel.
- Technical and organizational measures implemented.
- Transmission over the internet carries inherent risk.
Transfers Outside the EEA
- Google Analytics and other providers may store data outside EEA (e.g., USA) with safeguards (Privacy Shield, contractual clauses).
Your Rights
You may exercise the following by contacting Wonky Cards at weare@wonkycards.com:
- Access, correction, deletion, restriction, portability of your data
- Object to processing for marketing or legitimate interest purposes
- Withdraw consent
- Object to automated decision-making or profiling
- Lodge a complaint with the UK Information Commissioner’s Office: ICO Contact
Children’s Privacy
We do not knowingly collect data from individuals under 18. If discovered, data will be deleted or parental consent obtained where legally required.
Do Not Track
We currently do not respond to browser Do Not Track signals. Other tracking technologies may still be used as described in our Cookie Policy.
Copyright & Logo
This Privacy Policy is based on GDPR-compliant templates and all intellectual property rights are reserved.