Privacy Policy
Last Updated: October 14, 2025
1. Introduction
Welcome to Ordify Direct Ltd ("we," "us," or "our"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you use our e-commerce platform and services.
Ordify Direct Ltd is the data controller responsible for your personal data. We are registered in the United Kingdom and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect
2.1 Information You Provide to Us
- Account Information: Name, email address, password, phone number, and date of birth when you create an account
- Payment Information: Billing address, delivery address, and payment card details (processed securely through our payment providers)
- Order Information: Details of products purchased, order history, and transaction records
- Communications: Information you provide when you contact our customer service team, leave reviews, or participate in surveys
- Marketing Preferences: Your choices regarding marketing communications
2.2 Information We Collect Automatically
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages visited, products viewed, search queries, time spent on site, clickstream data
- Location Data: General location based on IP address
- Cookies and Tracking Technologies: See our Cookie Policy for detailed information
2.3 Information from Third Parties
- Payment processors (such as Stripe or PayPal)
- Delivery and logistics partners
- Social media platforms (if you choose to connect your account)
- Fraud prevention and credit reference agencies
3. How We Use Your Information
We use your personal data for the following purposes under the legal bases provided by UK GDPR:
3.1 Contract Performance
- Processing and fulfilling your orders
- Managing payments, fees, and charges
- Providing customer service and support
- Sending order confirmations and delivery updates
3.2 Legitimate Interests
- Improving our website, products, and services
- Personalizing your shopping experience
- Fraud prevention and security monitoring
- Analytics and business intelligence
- Managing our business operations
3.3 Legal Compliance
- Complying with legal obligations
- Responding to law enforcement requests
- Protecting our legal rights
3.4 Consent
- Sending marketing communications (you can withdraw consent at any time)
- Using certain cookies and tracking technologies
4. Sharing Your Information
We may share your personal data with the following categories of recipients:
- Service Providers: Third-party companies that help us operate our business (payment processors, delivery services, hosting providers, customer service platforms)
- Business Partners: Companies we work with to provide integrated services (e.g., Avasam, Syncee, Appscenic)
- Legal Authorities: When required by law or to protect our rights
- Business Transfers: In the event of a merger, acquisition, or sale of assets
We ensure all third parties respect the security of your personal data and treat it in accordance with the law. We only allow them to process your data for specified purposes and in accordance with our instructions.
5. International Transfers
Some of our service providers may be based outside the UK or European Economic Area (EEA). When we transfer your data internationally, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the UK Government
- Transfers to countries with adequate data protection laws
- Other appropriate safeguards as required by UK GDPR
6. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of sensitive data (including payment information)
- Secure server infrastructure with regular security updates
- Access controls and authentication mechanisms
- Regular security audits and vulnerability assessments
- Staff training on data protection and security
While we strive to protect your personal data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law:
- Account Data: Retained while your account is active and for a reasonable period after account closure
- Order Information: Retained for 7 years to comply with accounting and tax requirements
- Marketing Data: Retained until you unsubscribe or withdraw consent
- Website Usage Data: Typically retained for up to 2 years
8. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data (subject to certain conditions)
- Right to Restrict Processing: Request limitation of how we use your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or for marketing purposes
- Rights Related to Automated Decision-Making: Not be subject to decisions based solely on automated processing
- Right to Withdraw Consent: Withdraw consent at any time where we rely on consent
To exercise any of these rights, please contact us using the details in Section 13. We will respond to your request within one month.
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on our website. Cookies are small text files stored on your device that help us:
- Remember your preferences and settings
- Keep you logged into your account
- Understand how you use our website
- Improve website performance and functionality
- Deliver personalized content and advertisements
You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of our website.
10. Marketing Communications
With your consent, we may send you marketing communications about products, services, and special offers. You can opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in any marketing email
- Updating your preferences in your account settings
- Contacting us directly using the details in Section 13
Please note that even if you opt out of marketing communications, we will still send you transactional emails related to your orders and account.
11. Children's Privacy
Our services are not intended for children under 18 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:
- Posting the updated policy on our website
- Sending you an email notification (for significant changes)
- Updating the "Last Updated" date at the top of this policy
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Officer: For specific data protection queries, you can contact our Data Protection Officer at [email protected]
Supervisory Authority: You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection issues:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Phone: 0303 123 1113
Website: www.ico.org.uk
14. Your Consent
By using our website and services, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your personal data as described herein.