Privacy Policy
ZipCarts is committed to protecting your personal data and handling it responsibly. This policy explains what personal information we collect, how we use it, and your rights in relation to it. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using zipcarts.co.uk and our services, you acknowledge that you have read and understood this policy.
Who We Are
ZipCarts operates zipcarts.co.uk and all related content, features, products, and services. We are the data controller for personal data collected through this website. Our store is hosted and powered by Shopify — please see the section below regarding Shopify's role in processing your data.
Personal Information We Collect
We may collect and process the following categories of personal information depending on how you interact with us:
Information you provide directly:
- Contact details including your name, email address, telephone number, billing address, and delivery address
- Financial information including payment card details, processed securely by our payment providers — we do not store full card details
- Account information including username, password, and account preferences
- Communications you send us including customer support enquiries and feedback
Information collected automatically:
- Device and browser information including IP address, browser type, and unique identifiers
- Usage data including pages visited, time spent on site, and how you navigate our website
- Transaction information including items viewed, added to cart, purchased, or returned
- Cookie and tracking data as detailed in our Cookies Policy
How We Use Your Personal Information
We use your personal information for the following purposes:
To provide and fulfil our services: processing your orders, handling returns and exchanges, managing your account, arranging delivery, and sending order-related notifications.
To improve and personalise your experience: remembering your preferences, tailoring product recommendations, and improving how our website functions.
For marketing and advertising: sending promotional communications by email where you have consented or where we have a legitimate interest, and showing relevant online advertising on our website and other platforms based on your activity.
For security and fraud prevention: authenticating accounts, protecting against fraudulent or malicious activity, and securing our services.
For legal compliance: complying with applicable law, responding to lawful requests from authorities, and enforcing our terms and policies.
We rely on the following lawful bases under UK GDPR:
- Contract: Processing necessary to fulfil your order
- Legal obligation: Complying with applicable laws
- Legitimate interests: Improving our services, fraud prevention, and direct marketing where proportionate
- Consent: Marketing communications and non-essential cookies
How We Share Your Personal Information
We do not sell your personal data. We may share your information in the following circumstances:
- With Shopify and other service providers who perform services on our behalf, including payment processing, order fulfilment, data analytics, customer support, and cloud storage
- With courier and logistics partners to fulfil and track your delivery
- With business and marketing partners to deliver relevant advertising, where permitted
- With professional advisers including legal and accounting services where required
- With regulatory or law enforcement bodies where we are legally required to do so
- In connection with a business transaction such as a merger or acquisition
- Where you have directed or consented to us sharing your information with a third party
All third parties are required to handle your data in accordance with applicable data protection law.
Our Relationship With Shopify
Our store is hosted by Shopify, which collects and processes personal information about your access to and use of our services in order to provide and improve them. Information you submit through our store will be transmitted to and shared with Shopify, and may be processed in countries other than where you reside.
Shopify may also make use of data from your interactions with our store and other Shopify merchants to provide enhanced features and services. In these circumstances, Shopify acts as a data controller for that processing. To learn more about how Shopify uses your personal information and to exercise any related rights, visit the Shopify Consumer Privacy Policy at privacy.shopify.com.
Third-Party Websites
Our website may contain links to third-party websites or platforms. We are not responsible for the privacy practices or content of those sites. We recommend you review their privacy policies independently before providing any personal information.
Children's Data
Our services are not intended for use by children under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with their personal data, please contact us at sales@zipcarts.co.ukand we will take steps to delete it.
Security
We take reasonable technical and organisational measures to protect your personal data. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security. We recommend you do not use unsecured channels to communicate sensitive information to us.
Data Retention
We retain your personal data only for as long as necessary for the purposes set out in this policy or as required by applicable law. Order and transaction records are typically retained for up to 7 years for accounting and legal purposes.
International Transfers
Your personal information may be transferred to, stored, or processed outside the United Kingdom. Where we transfer data outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR, such as the use of Standard Contractual Clauses or transfers to countries with an adequacy decision.
Your Rights
Under UK GDPR you have the following rights in relation to your personal data:
- Right to access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your data in certain circumstances
- Right to restriction: Request that we limit how we process your data
- Right to portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent: Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
To exercise any of these rights, email sales@zipcarts.co.uk. We will respond within 30 days and may need to verify your identity before processing your request. We will not discriminate against you for exercising your rights.
Marketing Communications
If you have opted in to receive marketing emails, you can unsubscribe at any time using the unsubscribe link in any email or by contacting us directly. We will continue to send you non-promotional communications related to your orders and account.
Changes to This Policy
We may update this policy from time to time to reflect changes in our practices or applicable law. The most current version will always be available at zipcarts.co.uk/pages/privacy-policy.
Complaints
If you have concerns about how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Contact us: sales@zipcarts.co.uk
Last updated: March 2025