SECTION 1 - WHAT DO WE DO WITH YOUR INFORMATION?
When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address and email address.
When you browse our store, we also automatically receive your computer's internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system.
Email marketing (if applicable): With your permission, we may send you emails about our store, new products and other updates.
SECTION 2 - CONSENT
How do you get my consent?
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.
If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent, or provide you with an opportunity to say no.
How do I withdraw my consent?
If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at anytime, by contacting us at sales@jewellerybyzm.co.uk or mailing us at:
JewelleryByZM
14 Meadowlands Avenue, Bridgwater, TA6 3UG, GB
SECTION 3 - DISCLOSURE
We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.
SECTION 4 - SHOPIFY
Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
Your data is stored through Shopify's data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
Payment:
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
For more insight, you may also want to read Shopify's Terms of Service (https://www.shopify.com/legal/terms) or Privacy Statement (https://www.shopify.com/legal/privacy).
SECTION 5 - THIRD-PARTY SERVICES
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.
For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
In particular, remember that certain providers may be located in or have facilities that are located a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
Once you leave our store's website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website's Terms of Service.
Links
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
SECTION 6 - SECURITY
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
SECTION 7 - COOKIES
We use cookies and similar tracking technologies to operate our website, analyse traffic, and deliver personalised content and advertising. Below is a full list of cookies used on jewellerybyzm.co.uk, categorised by purpose.
You can manage or withdraw your cookie consent at any time using the cookie banner on our website.
Strictly Necessary Cookies
These cookies are essential for the website to function and cannot be switched off.
_session_id — Provider: Shopify — Duration: Session — Purpose: Stores information about your browsing session (referrer, landing page, etc.)
_secure_session_id — Provider: Shopify — Duration: Session — Purpose: Secure session management
_shopify_y — Provider: Shopify — Duration: 1 year — Purpose: Essential Shopify session cookie
storefront_digest — Provider: Shopify — Duration: Indefinite — Purpose: Determines if a visitor has access to a password-protected store
Analytics / Statistics Cookies
These cookies help us understand how visitors interact with our website. They are only set with your consent.
_ga — Provider: Google Analytics — Duration: 2 years — Purpose: Distinguishes unique users for Google Analytics reporting
_ga_EYD25B8NZ8 — Provider: Google Analytics 4 — Duration: 2 years — Purpose: Tracks and stores user session data and page interactions for GA4 analytics reporting
_g1523458789 — Provider: Google Analytics 4 — Duration: 2 years — Purpose: GA4 session cookie (G-EYD25B8NZ8) used to track user sessions and behaviour on the website
_gid — Provider: Google Analytics — Duration: 24 hours — Purpose: Distinguishes users for Google Analytics
_gat — Provider: Google Analytics — Duration: 1 minute — Purpose: Throttles request rate to Google Analytics
_shopify_visit — Provider: Shopify — Duration: 30 minutes — Purpose: Used by Shopify's internal stats tracker to record the number of visits
_shopify_uniq — Provider: Shopify — Duration: Midnight same day — Purpose: Counts the number of visits to a store by a single customer
Marketing Cookies
These cookies are used to deliver relevant advertisements and track campaign performance. They are only set with your consent.
_pinterest_ct_ua — Provider: Pinterest — Duration: 1 year — Purpose: Pinterest tag cookie used to track conversions and build advertising audiences
_pin_unauth — Provider: Pinterest — Duration: 1 year — Purpose: Used by Pinterest to track unauthenticated users for ad targeting
_derived_epik — Provider: Pinterest — Duration: 1 year — Purpose: Pinterest click tracking and conversion attribution
_gcl_au — Provider: Google Ads — Duration: 90 days — Purpose: Used by Google Ads to store and track conversions
_gcl_aw — Provider: Google Ads — Duration: 90 days — Purpose: Tracks Google Ads click information for conversion reporting
Preference / Functional Cookies
These cookies remember your choices and preferences to enhance your experience.
cart — Provider: Shopify — Duration: 2 weeks — Purpose: Stores information about the contents of your shopping cart
_shopify_sa_p — Provider: Shopify — Duration: 30 minutes — Purpose: Marketing and referral tracking
_shopify_sa_t — Provider: Shopify — Duration: 30 minutes — Purpose: Marketing and referral tracking timestamp
SECTION 8 - AGE OF CONSENT
By using this site, you represent that you are at least the age of majority in your country of residence, or that you are the age of majority in your country of residence and you have given us your consent to allow any of your minor dependents to use this site.
SECTION 9 - CHANGES TO THIS PRIVACY POLICY
We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
SECTION 10 - YOUR RIGHTS UNDER UK GDPR
As a UK-based business, we process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
You have the following rights regarding your personal data:
- The right to access the personal data we hold about you
- The right to rectification of inaccurate or incomplete data
- The right to erasure ('right to be forgotten')
- The right to restrict processing of your data
- The right to data portability
- The right to object to processing based on legitimate interests
- The right to withdraw consent at any time, where processing is based on consent
To exercise any of these rights, please contact us at sales@jewellerybyzm.co.uk.
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk or by calling 0303 123 1113.
SECTION 11 - LAWFUL BASIS FOR PROCESSING
Under the UK GDPR, we are required to identify the lawful basis on which we process your personal data. The table below sets out how and why we use your information:
Order fulfilment (name, address, email) — Lawful basis: Contract. We need this information to process and deliver your order.
Payment processing — Lawful basis: Contract and Legal Obligation. Required to complete your purchase and comply with financial regulations.
Fraud prevention and security — Lawful basis: Legitimate Interests. We have a legitimate interest in protecting our business and customers from fraud.
Email marketing and promotions — Lawful basis: Consent. We only send marketing emails where you have explicitly opted in. You may withdraw consent at any time.
Website analytics (e.g. Google Analytics) — Lawful basis: Legitimate Interests / Consent. We use anonymised analytics to improve our website. Where cookies are used, we rely on your cookie consent.
Customer service communications — Lawful basis: Legitimate Interests. We have a legitimate interest in responding to your enquiries and resolving issues.
Legal compliance (e.g. tax records) — Lawful basis: Legal Obligation. We are required by law (e.g. HMRC) to retain certain records.
SECTION 12 - DATA RETENTION
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The following retention periods apply:
Order and transaction records — 7 years (required by HMRC for tax purposes)
Customer account information — Retained until you request deletion of your account
Email marketing consent and communications — Retained until you withdraw consent or unsubscribe
Abandoned cart data — 90 days
Website analytics data — 26 months (in line with Google Analytics default settings)
Fraud prevention records — Up to 5 years
Customer service correspondence — 3 years from the date of last contact
After the applicable retention period, your data is securely deleted or anonymised. To request early deletion of your data, please contact us at sales@jewellerybyzm.co.uk.
QUESTIONS AND CONTACT INFORMATION
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information, please contact our Privacy Compliance Officer at sales@jewellerybyzm.co.uk or by mail at:
JewelleryByZM
14 Meadowlands Avenue
Bridgwater
TA6 3UG
United Kingdom