We cover what information we collect and why, how long it is kept and where it is stored, we also cover your rights with regards to your own information.
This policy applies where we are acting as a data controller with respect to your personal data.
Which information do we collect about you?
We collect information about you when you sign up for a yarn club, use our service or at the point of ordering on the website. The data collected includes; your email address, your name, and the delivery address you provide, we also store information on your choices in regards to our yarn club. We do not collect or store any bank or card details for you as all payment transactions are carried out via the 3rd party processors; Paypal , Stripe, or Izettle if you are purchasing in person.
Why do we need this information and how is it used?
The information we collect about you such as your email address is used to (if you have opted in) provide you with updates on new products and events, as well as provide you with your subscriber privileges such as early access. It is also used (if applicable) for a yarn club or special/ custom orders to invoice you via Paypal.
Your name is used for the fulfilment of your order or for contact purposes relating to this, if it is provided with your email address when opting in to our marketing emails it is used to personalise our communication to you.
Your address is solely used for the fulfilment of your order, providing you with goods purchased or won.
We do not collect or use data/names from our social media pages and groups; Facebook, Instagram, Twitter, Ravelry. With the exception of giveaways, giveaway information is deleted/discarded after use.
We do not share your personal data with 3rd parties and do not and will not sell your information to 3 rd parties. We will not share your personal data unless we are required to by law.
How is your data is stored?
Your data is stored on private devices that are either password protected and or encrypted. These are not shared devices, and kept securely.
If you use a sign up form for yarn club or pre-order, then your email address, name and address are stored in a private Google Sheets (3rd party) spreadsheet (This will going forward be reduced to name and email address). These spreadsheets are only kept for purposes of fulfilment of your order and up to a 6 month period to answer any questions you may have in regards to your order, and are then deleted. All sheets used are password protected.
Your online order/payment details are stored with PayPal or Stripe (3rd parties).
Customer addresses and names are stored within our Royal Mail (3rd party) account, for the purpose of fulfilling and posting your orders. This is routinely cleared, with data only being stored for up to 6 months per instance, unless as a regular customer your details are reused.
The Third Vault Yarns website is supported by Create. Your order information such as your name, address and email address are all stored within the Create account. No credit or debit card information is processed or stored through the Third Vault Yarns website.
We use Hotmail (3rd party) email account, which stores all correspondence with customers, and order details.
As our yarn sales were previously solely managed through Esty (3rd party) old order information is stored as part of the business management on the Etsy account. These are kept for accounts purposes, The Etsy shop is still maintained and used for the purpose of selling our products. Orders date from around August 2015, to present day.
All of the accounts we use including but not limited to PayPal, Royal Mail, Etsy, Stripe and Google accounts, are strictly password protected, and where possible use two step authentication.
How long is your information kept by us?
All your data stored via Google sheets is kept for a period of up to 6 months from the input period closing and are then wiped.
Order emails and customer correspondence are kept for up to one year in our email account, after which they are deleted.
Order information is kept for 6 financial years, as per accounts regulations.
Cookies are text files placed on your computer to collect standard internet log information and visitor behaviour information. This information is used to track visitor use of the website and to compile statistical reports on website activity.
For further information visit www.aboutcookies.org or www.allaboutcookies.org.
You can set your browser not to accept cookies and the above websites tell you how to remove cookies from your browser. However, in a few cases some of our website features may not function as a result.
Access to your information and correction
You have the right to request a copy of the information that we hold about you. If you would like a copy of some or all your personal information, please email or write to us at the following address.
We want to make sure that your personal information is accurate and up to date. You may ask us to correct or remove information you think is inaccurate.
Right to be Forgotten
You have a "Right To Be Forgotten", which means that upon request we will remove your information from all storage, not just "unsubscribe" you. This applies to mailing lists, and other data that we store as detailed above (with the exception of order details). However, if you think that we may be storing your information unnecessarily, you as is your right can request access to your information and if you wish to be forgotten, please contact us using the following address.
As stated above, order details are required to be kept, this is classed as "lawful use", and cannot be removed from our records within the period they are required to be kept by law.
In the unlikely event of a data breach:
We do not store unnecessary data, and as a small business the data we store is not in large in capacity. However, should we be subject to a data breach, we will contact all affected persons.