Privacy Policy
1. INTRODUCTION
Welcome to the The Merch Desk's privacy statement.
The Merch Desk respects your privacy and is committed to
protecting your personal data. This privacy statement sets out how we collect
and process your data through your use of this website, including any data you
may provide when you sign up to our newsletter, purchase a product or service
or take part in a competition or survey.
This website is not intended for children and we do not
knowingly collect data relating to children.
It is important that you read this privacy statement so that you
are fully aware of how and why we are using your data.
Controller
The Merch Desk is the controller and responsible for your
personal data.
If you have any questions about this privacy statement, including
any requests to exercise your legal rights, please contact us using the details
set out below:
Contact details
Legal entity: The Merch Desk
Email address: info@themerchdesk.com
Postal address: PO Box 3774, Swindon,
Wiltshire SN4 4DJ
Telephone no: 0845 689 0793
You have the right to make a complaint at any time to the
Information Commissioner's Office (ICO), the UK supervisory authority for data
protection issues (www.ico.org.uk). We would, however, appreciate the chance to
deal with your concerns before you approach the ICO so please contact us in the
first instance.
Changes to the Privacy Statement and your duty to inform us of
changes
This version was last updated on 19 May 2018. We may update this
statement without notice to reflect future changes in the law. You should check
this statement from time to time for any changes.
It is important that the personal data we hold about you is
accurate and current. Please keep us informed if your personal data changes
during your relationship with us.
Third-party links
This website may include links to third-party websites, plug-ins
and applications. Clicking on those links or enabling those connections may
allow third parties to collect or share data about you. We do not control these
third-party websites and are not responsible for their privacy statements. When
you leave our website, we encourage you to read the privacy notice of every
website you visit.
2. THE DATA WE COLLECT
ABOUT YOU
Personal data, or personal information, means any information
about an individual from which that person can be identified. It does not
include data where the identity has been removed (anonymous data).
We may collect, use and store different kinds of personal data
about you, which we have grouped into the following types:
Identity data includes first name, last name,
title.
Contact data includes billing address,
delivery address, email address and telephone number(s).
Transaction data includes details about payments
to and from you and other details of products or services you have purchased
from us.
Technical data includes IP address, browser
details, and other technology on the device(s) you use to access this website.
Profile data includes purchases or orders made
by you, your interests, preferences and feedback.
Usage data includes information about how you use our
website, products and services.
Marketing and Communications data includes your preferences in receiving marketing from us and
your communication preferences.
We do not collect any Special Categories of Personal Data about
you (this includes details about your race or ethnicity, religious or
philosophical beliefs, sex life, sexual orientation, political opinions, trade
union membership, information about your health and genetic and biometric
data). Nor do we collect any information about criminal convictions and
offences.
If you fail to provide personal data
Where we need to collect personal data by law, or under the
terms of a contract we have with you and you fail to provide that data when
requested, we may not be able to perform the contract we have or are trying to
enter into with you (for example, to provide you with goods or services). In
this case, we may have to cancel a product or service you have with us but we
will notify you if this is the case at the time.
3. HOW WE COLLECT YOUR
PERSONAL DATA
We use different methods to collect data from and about you
including through:
Direct interactions You may give us your Identity and
Contact Data by filling in forms or by corresponding with us by post, phone,
email or otherwise. This includes personal data you provide when you:
• apply for our
products or services;
• create an account on
our website;
• subscribe to our
service or publications;
• request marketing to
be sent to you;
• enter a competition,
promotion or survey; or
• give us some
feedback.
Automated technologies As you interact with our website,
we may automatically collect Technical Data about your equipment, browsing
actions and patterns. We collect this personal data by using cookies, and other
similar technologies.
4. HOW WE USE YOUR
PERSONAL DATA
We will only use your personal data when the law allows us to.
Most commonly, we will use your personal data in the following circumstances:
• Where we need to
perform the contract we are about to enter into or have entered into with you.
• Where it is
necessary for our legitimate interests (or those of a third party) and your
interests and fundamental rights do
not override those interests.
• Where we need to
comply with a legal or regulatory obligation.
Generally we do not rely on consent as a legal basis for
processing your personal data other than in relation to sending marketing
communications to you via email. You have the right to withdraw consent to
marketing at any time by contacting us.
We will only store your data within the UK.
Purposes for which we use your personal data
The table below shows the ways in which we may use your data,
the legal bases for processing and what our legitimate interests are where
appropriate.
Purpose / activity |
Type of data |
Lawful basis for
processing and/or legitimate interest |
To register you as a new customer |
Identity Contact |
Performance of a contract with
you |
To process and deliver your order |
Identity Contact Transaction Marketing and Communications |
Performance of a contract with
you Necessary for our legitimate
interests |
To manage our relationship with
you |
Identity Contact Profile Marketing and Communications |
Performance of a contract with
you Necessary for our legitimate
interests Necessary to comply with a legal
obligation |
To enable you to take part in a
prize draw, competition or complete a survey |
Identity Contact Profile Usage Marketing and Communications |
Performance of a contract with
you Necessary for our legitimate
interests |
To administer and protect our
business and this website (including troubleshooting, data analysis, testing,
system maintenance, support, reporting and hosting of data. |
Identity Contact Technical |
Necessary for our legitimate
interests (for running our business, provision of administration and IT
services, network security, and to prevent fraud) Necessary to comply with a legal
obligation |
To deliver relevant website
content and advertisements to you and measure or understand the effectiveness
of any advertising we may serve to you |
Identity Contact Profile Usage Marketing and Communications Technical |
Necessary for our legitimate
interests (to study how customers use our products/services, to develop them,
to grow our business and to inform our marketing strategy) |
To use data analytics to improve
our website, products/services, marketing, customer relationships and
experiences |
Technical Usage |
Necessary for our legitimate
interests (to define types of customers for our products and services, to
keep our website updated and relevant, to develop our business and to inform
our marketing strategy) |
To make suggestions and
recommendations to you about goods or services that may be of interest to you |
Identity Contact Technical Usage Profile |
Necessary for our legitimate
interests (to develop our products/services and grow our business) |
Third-party marketing
We may share your
personal data with relevant third parties for marketing purposes.
Opting out
You can ask us or third parties to stop sending you marketing
messages at any time by unsubscribing on their website contacting us at info@themerchdesk.com
Where you opt out of receiving these marketing messages, this
will not apply to personal data provided to us as a result of a product/service
purchase or other transactions.
How we use cookies.
A cookie is a small file which asks permission to be placed on
your computer's hard drive. Once you agree, the file is added and the cookie
helps analyse web traffic or lets you know when you visit a particular site.
Cookies allow web applications to respond to you as an individual. The web
application can tailor its operations to your needs, likes and dislikes by
gathering and remembering information about your preferences.
We use traffic log cookies to identify which pages are being
used. This helps us analyse data about web page traffic and improve our website
in order to tailor it to customer needs. We only use this information for
statistical analysis purposes and then the data is removed from the system.
Overall, cookies help us provide you with a better website, by
enabling us to monitor which pages you find useful and which you do not. A
cookie in no way gives us access to your computer or any information about you,
other than the data you choose to share with us.
You can choose to accept or decline cookies. Most web browsers
automatically accept cookies, but you can usually modify your browser setting
to decline cookies if you prefer. This may prevent you from taking full
advantage of the website.
Controlling your personal information.
You may choose to restrict the collection or use of your
personal information in the following ways:
We will not sell, distribute or lease your personal information
to third parties unless we have your permission or are required by law to do
so.
You may request details of personal information which we hold
about you. No fee will be payable as a result of this request. If you would
like a copy of the information held on you please write to The Merch Desk PO
Box 3774, Swindon, Wilts. SN4 4DJ.
If you believe that any information we are holding on you is
incorrect or incomplete, please write to or email us as soon as possible, at
the above address. We will promptly correct any information found to be
incorrect.
5. Data security
We have put in place
appropriate security measures to prevent your personal data from being
accidentally lost, used or accessed in an unauthorised way, altered or
disclosed. In addition, we limit access to your personal data to only those
employees, contractors and other third parties who have an authorised business
need to know.
We have also put in
place procedures to deal with any suspected personal data breach and will
notify you and any applicable regulator of a breach where we are legally
required to do so.
6. Data retention
We will only retain
your personal data for as long as necessary to fulfil the purposes we collected
it for, including for the purposes of satisfying any legal, accounting, or
reporting requirements.
To determine the
appropriate retention period for personal data, we consider the amount, nature,
and sensitivity of the personal data, the potential risk of harm from
unauthorised use or disclosure of your personal data, the purposes for which we
process your personal data and whether we can achieve those purposes through
other means, and the applicable legal requirements.
7. Your legal rights
Under certain
circumstances, in accordance with data protection laws you have: