Privacy Policy
Last updated: [INSERT DATE BEFORE PUBLICATION]
Hawthorn & Key Ltd respects your privacy and aims to handle personal information with care, clarity and a sensible amount of restraint.
This Privacy Policy explains what personal information we collect, why we use it, who we may share it with, how long we keep it and the choices available to you.
This policy applies when you visit the Hawthorn & Key website, browse the shop or journal, place an order, create an account, join our newsletter, submit a form or contact us directly.
1. Who is responsible for your personal information?
Hawthorn & Key Ltd is the data controller responsible for the personal information described in this policy.
Hawthorn & Key Ltd
Company number: 00000000
Registered in: England and Wales
Registered office: 12 Hawthorn Lane, Little Wrenford, North Yorkshire, TEST 0AA, United Kingdom
Email: hello@hawthornandkey.co.uk
Development notice: the company number, registered office address and place of registration shown above are temporary test details for the closed development version of this website. They must be replaced before publication.
2. How to contact us about privacy
For questions, requests or complaints relating to personal information, please email hello@hawthornandkey.co.uk with the subject line Privacy enquiry.
You can also use our Contact page and select Privacy enquiry.
Please do not send passwords, full bank card details or one-time banking verification codes by email or through a contact form.
3. Personal information we may collect
The personal information we collect depends on how you use the website.
When you place an order
We may collect:
- your name;
- your billing address;
- your delivery address;
- your email address;
- your telephone number where required for delivery updates;
- the products ordered;
- the value of the order;
- delivery charges;
- order notes that you choose to provide;
- order status;
- payment status;
- refund information where applicable;
- delivery and tracking information where available;
- correspondence relating to the order.
When you use guest checkout
You may place an order without creating a customer account.
Guest checkout orders are still recorded by our shop system so that we can process the purchase, arrange delivery, provide customer support, handle returns and meet our legal and accounting obligations.
When you create a customer account
Creating an account is optional.
You may create an account during checkout or through the My Account page. Existing customers may also log in during checkout.
If you choose to create an account, we may collect:
- your name;
- your email address;
- your billing and delivery addresses;
- your order history;
- your account preferences;
- information required to maintain and secure the account.
New account holders receive an email link to set up their password.
Please use a strong password that you do not use for another website. Hawthorn & Key will never ask you to send your password to us by email.
When you contact us
If you email us, use a contact form or submit a cancellation request, we may collect:
- your name;
- your email address;
- your order number where relevant;
- the subject and content of your message;
- any photographs or files that you choose to attach;
- information reasonably required to respond to your enquiry.
When you join our newsletter
[CONFIRM NEWSLETTER TOOL AND NEWSLETTER PROCESS]
If you choose to join our newsletter, we may collect your email address and, where requested, your name and preferences.
You can unsubscribe at any time by using the unsubscribe link included in a marketing email or by contacting us.
When you browse the website
Depending on the website configuration, hosting service, security tools and cookie choices, we may collect technical information such as:
- your IP address;
- browser type;
- device type;
- operating system;
- pages visited;
- date and time of access;
- referring website;
- cookie preferences;
- information recorded for website security and error diagnosis.
More information is provided in our Cookie Policy.
When you leave a product review
[CONFIRM WHETHER PRODUCT REVIEWS WILL BE ENABLED]
If product reviews are enabled and you choose to leave a review, we may collect the name or display name you provide, the content of your review, your rating and technical information used to reduce spam or misuse.
4. Information received from other organisations
We may receive personal information from organisations involved in completing or supporting your order.
For example, we may receive:
- payment confirmation or payment status from the selected payment provider;
- delivery status or tracking information from our fulfilment or delivery partners;
- information required to investigate a failed, delayed, damaged or returned delivery;
- security or fraud-prevention information where reasonably necessary.
We do not buy personal mailing lists.
5. Why we use personal information
We use personal information only where we have a lawful reason to do so.
| Purpose | Examples of information used | Lawful basis |
|---|---|---|
| To process and fulfil your order | Name, contact details, billing address, delivery address, products ordered and order details | Performance of a contract |
| To arrange payment and confirm payment status | Order value, billing information, payment status and payment reference | Performance of a contract |
| To dispatch and deliver your order | Name, delivery address, contact details and delivery instructions | Performance of a contract |
| To deal with cancellations, returns, refunds and customer support | Order details, correspondence, photographs and return information | Performance of a contract, legal obligation and legitimate interests |
| To maintain business, accounting and tax records | Order, payment and refund records | Legal obligation |
| To maintain customer accounts | Name, email address, addresses, account details and order history | Performance of a contract and legitimate interests |
| To protect the website, prevent misuse and investigate suspicious activity | Technical logs, account information, IP address and transaction-related information where relevant | Legitimate interests and, where applicable, legal obligation |
| To respond to questions, complaints and editorial enquiries | Name, email address, message content and any information you choose to provide | Legitimate interests, performance of a contract or legal obligation depending on the enquiry |
| To send newsletters and marketing emails where permitted | Email address, name and marketing preferences where applicable | Consent or another lawful basis permitted by applicable law |
| To understand website use and improve the website where permitted | Cookie and analytics information | Consent or another lawful basis permitted by applicable law, depending on the technology used |
6. Our legitimate interests
Where we rely on legitimate interests, we use personal information only where this is reasonably necessary and where our interests are not overridden by your rights and interests.
Our legitimate interests may include:
- responding to enquiries;
- providing helpful customer support;
- maintaining customer accounts;
- improving the website;
- maintaining website security;
- preventing misuse and fraud;
- keeping appropriate records;
- understanding how the shop and journal are used where permitted.
7. Payments
Payments are processed using:
[CONFIRM PAYMENT PROVIDER]
Information required to process or support a payment may be shared with the selected payment provider. This may include your name, billing information, contact details, order value and a payment reference.
[CONFIRM HOW CARD DETAILS ARE HANDLED]
Please read our Payment & Security page for further information.
8. Fulfilment and delivery
Each item is selected for the Hawthorn & Key collection and dispatched directly from our trusted UK fulfilment partner.
To fulfil and deliver your order, we may share the information reasonably required for delivery, such as:
- your name;
- your delivery address;
- your email address where required;
- your telephone number where required;
- the products ordered;
- delivery instructions where applicable.
The fulfilment partner or delivery carrier may use this information to prepare the parcel, arrange delivery, provide tracking updates and investigate delivery issues.
[CONFIRM WHETHER TO NAME THE FULFILMENT PARTNER PUBLICLY]
9. Other organisations we may share information with
We may share personal information with organisations that help us operate the website, fulfil orders and meet our legal obligations.
These may include:
- our fulfilment partner;
- delivery carriers;
- our payment provider;
- our website hosting provider;
- our email delivery provider;
- our newsletter provider where you subscribe;
- our cookie consent provider;
- analytics providers where enabled and permitted;
- website security, backup and anti-spam providers;
- accountants, professional advisers and insurers where reasonably necessary;
- public authorities, regulators or law-enforcement bodies where disclosure is required or permitted by law.
We do not sell your personal information.
10. Website services and providers
The final version of this section must reflect the services actually used by the website.
| Purpose | Provider | Information that may be involved |
|---|---|---|
| Website hosting | [CONFIRM HOSTING PROVIDER] | Website data, technical logs, IP address and information submitted through the website |
| Online shop platform | WordPress and WooCommerce | Order, account and website information required to operate the shop |
| Payment processing | [CONFIRM PAYMENT PROVIDER] | Billing details, order value, payment status and payment reference |
| Order fulfilment | [CONFIRM FULFILMENT PARTNER WORDING] | Name, delivery address, contact details, products ordered and delivery instructions |
| Email delivery | [CONFIRM EMAIL DELIVERY PROVIDER] | Email address, message content and technical delivery information |
| Newsletter | [CONFIRM NEWSLETTER PROVIDER] | Email address, name and subscription preferences where applicable |
| Cookie consent | [CONFIRM COOKIE CONSENT TOOL] | Cookie preferences and technical information used to remember those choices |
| Analytics | [CONFIRM ANALYTICS TOOL OR STATE THAT NONE IS USED] | Website usage and technical information where enabled and permitted |
| Anti-spam protection | [CONFIRM ANTI-SPAM TOOL OR STATE THAT NONE IS USED] | Form content and technical information where required to identify spam |
| Website security | [CONFIRM SECURITY TOOL OR STATE THAT NONE IS USED] | Technical logs, IP address and security-related information |
| Backups | [CONFIRM BACKUP SERVICE] | Copies of website data retained for recovery and security purposes |
11. Cookies and similar technologies
The Hawthorn & Key website may use cookies and similar technologies.
Some cookies are necessary for the website to function. For example, they may help the shop remember the contents of your basket, support checkout or remember your cookie preferences.
Other cookies may be used for analytics or additional features where enabled and permitted.
[CONFIRM COOKIE CONSENT TOOL AND COOKIE CATEGORIES]
Please read our Cookie Policy for a fuller explanation and for information about managing your choices.
12. Newsletters and marketing emails
[CONFIRM NEWSLETTER PROCESS BEFORE PUBLICATION]
Where you have asked to receive our newsletter or where another lawful basis applies, we may send occasional emails about Hawthorn & Key articles, collections and news.
You can unsubscribe at any time by using the unsubscribe link included in a marketing email or by contacting us.
We may retain a minimal suppression record where necessary to make sure that we respect an unsubscribe request.
13. International transfers
Some service providers may process or store personal information outside the United Kingdom.
[CONFIRM WHETHER ANY PERSONAL INFORMATION IS TRANSFERRED OUTSIDE THE UNITED KINGDOM AND INSERT THE APPROPRIATE SAFEGUARD WORDING]
Where personal information is transferred internationally, we will take appropriate steps required by applicable data protection law.
14. How long we keep personal information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including where records are required for legal, accounting, tax, fraud-prevention or dispute-resolution purposes.
Our WooCommerce shop is configured to use the following retention periods:
| Type of information | Retention period | Reason |
|---|---|---|
| Inactive customer accounts | 24 months after the account was last used | To avoid retaining unused customer profiles indefinitely |
| Pending orders | 7 days | To allow time to resolve an incomplete or pending purchase |
| Failed orders | 30 days | To allow time to investigate payment or technical issues |
| Cancelled orders | 90 days | To allow time for customer support and dispute handling |
| Refunded orders | 84 months | To maintain appropriate accounting, tax and dispute-resolution records |
| Completed orders | 84 months | To maintain appropriate accounting, tax and dispute-resolution records |
| Contact form and customer support correspondence | [CONFIRM CONTACT RETENTION PERIOD] | To respond to enquiries and maintain appropriate support records |
| Cancellation and return correspondence | [CONFIRM RETURNS RETENTION PERIOD] | To manage returns, refunds and disputes |
| Newsletter subscription records | Until you unsubscribe or the newsletter service is discontinued, subject to any minimal suppression record required to respect your preference | To manage your subscription choices |
| Cookie preferences | [CONFIRM COOKIE CONSENT RETENTION PERIOD] | To remember your cookie choices |
| Website security logs | [CONFIRM SECURITY LOG RETENTION PERIOD] | To protect the website and investigate suspicious activity |
| Backups | [CONFIRM BACKUP RETENTION PERIOD] | To support website recovery and security |
When an applicable WooCommerce retention period expires, the website system may delete or anonymise information according to the configured settings.
Some records may need to be retained for longer where this is required by law, reasonably necessary to deal with a dispute or required for another legitimate purpose.
15. Requests to delete personal information
You may ask us to delete personal information in certain circumstances.
Requests are reviewed individually. We do not automatically remove personal information from every order record when an account is deleted or an erasure request is received.
This is because some information may still be required for legal, accounting, tax, fraud-prevention, customer-support or dispute-resolution purposes.
Where information is no longer required and deletion is appropriate, we will take reasonable steps to remove or anonymise it.
To make a request, email hello@hawthornandkey.co.uk with the subject line Privacy request or use our Contact page and select Privacy enquiry.
16. Keeping your information secure
We take reasonable steps to protect personal information against unauthorised access, loss, misuse, alteration or disclosure.
These steps may include appropriate website security measures, access controls, software updates, backups and the use of reputable service providers.
No online system can be guaranteed to be completely secure. Please use a strong password if you create an account and do not send passwords or full bank card details through email or contact forms.
17. Your data protection rights
Depending on the circumstances, you may have the right to:
- ask whether we hold personal information about you;
- request a copy of your personal information;
- ask us to correct inaccurate or incomplete information;
- ask us to delete personal information in certain circumstances;
- ask us to restrict the use of your information in certain circumstances;
- object to certain uses of your information;
- ask for certain information in a portable format where the right applies;
- withdraw consent where we rely on consent;
- object to direct marketing at any time.
These rights are not absolute in every situation. For example, we may need to keep some order information where this is required for legal, accounting or dispute-resolution purposes.
To make a request, email hello@hawthornandkey.co.uk with the subject line Privacy request or use our Contact page and select Privacy enquiry.
We may need to ask for information reasonably necessary to confirm your identity before responding.
We will respond without undue delay and normally within one calendar month after receiving a valid request. Different timing may apply where the law permits an extension.
18. Data protection complaints
If you have a concern about how Hawthorn & Key uses your personal information, please contact us so that we can look into it.
You can submit a data protection complaint by:
- emailing hello@hawthornandkey.co.uk with the subject line Data protection complaint;
- using our Contact page and selecting Privacy enquiry;
- writing to our registered office address.
Please explain what has happened and include any information that may help us understand the issue.
We will acknowledge receipt of a data protection complaint within 30 days and respond without undue delay after making appropriate enquiries.
19. Complaining to the Information Commissioner’s Office
You also have the right to raise a concern with the Information Commissioner’s Office, the United Kingdom regulator for data protection matters.
You can find further information on the ICO website:
We would appreciate the opportunity to look into your concern first, but contacting us does not remove your right to approach the ICO.
20. Children
The Hawthorn & Key website is intended for a general audience, but purchases may only be made by people aged 18 or over.
We do not knowingly ask children to provide personal information for the purpose of placing an order.
If you believe that a child has provided personal information inappropriately, please contact us.
21. Automated decision-making
[CONFIRM WHETHER ANY SOLELY AUTOMATED DECISION-MAKING OR PROFILING WITH LEGAL OR SIMILARLY SIGNIFICANT EFFECTS IS USED]
Unless clearly stated otherwise after the website configuration has been reviewed, Hawthorn & Key does not intend to use personal information to make solely automated decisions that produce legal or similarly significant effects.
22. External websites
The website may contain links to external websites.
An external website will have its own privacy practices. Hawthorn & Key is not responsible for the privacy notice or content of another website.
23. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in the website, service providers, business arrangements or legal requirements.
The date at the top of this page will show when the policy was last updated.
Where a change materially affects how personal information is used, we will take reasonable steps to bring the change to your attention where required.
24. Contact details
Hawthorn & Key Ltd
Company number: 00000000
Registered in: England and Wales
Registered office: 12 Hawthorn Lane, Little Wrenford, North Yorkshire, TEST 0AA, United Kingdom
Email: hello@hawthornandkey.co.uk
Development notice: replace the temporary company details and complete every [CONFIRM …] marker before the website is opened to the public.