Privacy Policy
Effective Date: 5 November 2025
This Privacy Policy explains how Roselyn Oxford (“we”, “us”, “our”) collects and processes personal data in accordance with the UK GDPR and the Data Protection Act 2018.
1. Who We Are
Website: www.roselynoxford.co.uk
Operated by: EB Collective
Address: Geurdeland 17 G, 6673 DR Andelst, The Netherlands
Email: info@roselynoxford.co.uk
We are the data controller for all personal data collected through our website.
2. Data We Collect
• Name
• Address
• Email
• Phone number
• Payment details (processed by third-party providers)
• IP address and device information
• Order history
• Communication history
• Cookie data
3. How We Use Your Data
• Process and deliver orders
• Provide customer support
• Send essential order updates
• Improve website performance
• Fraud prevention
• Marketing with your consent
Legal bases: contract performance, legal obligations, legitimate interests, or consent.
4. Payments and Security
All payments on our website are processed exclusively through Shopify Payments, a PCI-DSS–compliant payment service provider. Shopify Payments securely handles your card details on our behalf. We do not store or have access to your full payment card information.
We implement appropriate technical and organisational measures to protect your personal data, including SSL encryption and secure data handling practices.
5. Data Sharing
We share personal data only where necessary for the purposes described in this Privacy Policy, or where we are legally required to do so. This may include sharing information with:
• payment processors
• fulfilment partners (including partners located in China)
• analytics and service providers
• authorities when required
6. International Transfers
Where data is transferred outside the UK, appropriate safeguards (such as UK Standard Contractual Clauses) are applied.
7. Data Retention
We retain personal data only as long as necessary for the stated purposes or as required by law (e.g., tax retention periods).
8. Your Rights
You may have the right to request access, correction, deletion, restriction, or portability of your personal data, where applicable under UK GDPR. You may also withdraw consent where processing is based on consent.
Contact: info@roselynoxford.co.uk
We respond within 30 days.
You may lodge complaints with the Information Commissioner’s Office (www.ico.org.uk).
9. Cookies
We use essential and non-essential cookies.
For details, see our Cookie Policy.
10. Marketing
Marketing messages are sent only with consent or within the lawful “soft opt-in” framework.
You can unsubscribe at any time.