Privacy policy

Last updated: December 31, 2025

Spencer & Cole operates the online store at spencerandcole.com. We respect your privacy and are committed to protecting the personal information you share with us. This Privacy Policy explains what information we collect, why we collect it, how we use and share it, how long we keep it, the rights you have, and how to contact us.

1. Controller & contact information

Phone: +447713101793
Email: support@spencer-cole.com
Address: 70 Minterne Waye, Hayes, UB4 0PF, United Kingdom.

To exercise any privacy request (access, correction, deletion, portability, or objection), email us with the subject line “Privacy Request” and include your full name, email address and any relevant order number. We may request documentation to verify your identity before fulfilling certain requests.

2. Scope & why this matters for Google Merchant Center

Google requires that merchants clearly disclose how customer data is handled and provide accurate, easy-to-find business contact details and policies. Maintaining an accurate, public privacy policy and consistent business information reduces the risk of a “misrepresentation” suspension in Merchant Center. 

3. Information we collect

We collect personal information necessary to operate the Services and process orders, including:

  • Contact & account information: name, email, billing/shipping addresses, phone number, account username and password.

  • Payment & transaction data: card or bank account details, transaction records, payment confirmations (processed securely by third-party payment providers).

  • Order & product data: items viewed, added to cart, purchased, returned, exchanged, order history.

  • Communications: support messages, reviews, and other communications you send us.

  • Technical & device information: IP address, browser type, device identifiers, operating system.

  • Usage data: pages visited, referral source, session times, and interactions on the site.

  • Derived data: inferences we may draw (for example, product preferences used to make recommendations).

We do not knowingly collect sensitive personal information unless it is necessary to provide the Services and you have explicitly provided it.

4. How we use your information (purposes & legal bases)

We use your information for the following purposes and rely on the indicated legal bases where applicable:

  • To perform our contract with you: process orders, take payments, ship products, handle returns and refunds. (contract)

  • Customer service & communications: respond to inquiries and send transactional messages (order confirmations, shipping updates). (contract / legitimate interest)

  • Security & fraud prevention: detect and prevent fraud, protect accounts and Services. (legitimate interest / legal obligation)

  • Personalization & site improvement: personalize product recommendations and improve our Services. (legitimate interest)

  • Marketing: send promotional emails or SMS where you’ve opted in; you may withdraw consent at any time. (consent)

  • Legal compliance: comply with laws, tax and accounting obligations, and lawful requests from authorities. (legal obligation)

If you are in a region with special privacy laws (e.g., EU/UK), we will rely on the appropriate legal basis (contract performance, legal compliance, consent, or legitimate interests) for each processing activity.

5. Sharing & disclosure of personal information

We do not sell your personal information. We may share personal information with:

  • Service providers & processors: Shopify (hosting and checkout), payment processors, shipping/fulfilment partners, email and analytics providers. These parties process data on our behalf under contract. For Shopify’s processing and controls, see Shopify’s privacy pages.

  • Advertising partners: to deliver and measure advertising (for example Google or Meta). If you are shown personalized ads based on your activity, you can opt out via Google Ads Settings (adssettings.google.com) and the opt-out controls described below

  • Affiliates or in business transactions: in connection with a merger, acquisition, or sale of assets.

  • Legal & safety: to comply with legal obligations or respond to lawful requests from authorities.

When we share with processors, we require contractual commitments that the processor only uses data to provide services to us and keeps it secure.

6. Cookies & tracking technologies

We use cookies, pixel tags and similar technologies to operate the site, analyze site performance, and enable marketing and advertising. You can manage cookie preferences through your browser settings and, where available, our cookie banner or consent tool. If you use Shopify features that enable cross-merchant advertising or Shopify Enhanced Services, you must provide an opt-out mechanism for targeted advertising (Shopify provides configuration tools for this)

7. Opting out of targeted advertising & “do not sell/share.”

We do not knowingly “sell” personal information. Where we or our partners engage in data sharing for targeted advertising, you may opt out:

  • Google personalized ads: adssettings.google.com.

  • Use the Global Privacy Control (GPC) or your device/browser privacy settings; where applicable we will honor the GPC signal or other lawful opt-out signals.

  • If you prefer, submit a privacy request by emailing support@spencer-cole.com and we will assist with opt-out steps.

8. Data retention

We retain personal information only as long as necessary for the purposes described here and to meet legal obligations. Typical retention periods:

  • Transaction & payment records: up to 7 years (for tax and accounting compliance).

  • Account/profile data: while your account is active and up to 3 years after last activity unless you request deletion.

  • Support communications and logs: up to 3 years.

We will securely delete or anonymize data when it is no longer required.

9. International transfers & safeguards

Your information may be processed and stored outside your country of residence. When transfers occur to countries without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses or other lawful mechanisms to protect your personal information. 

10. Security

We implement technical and organizational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. While we work to protect your data, no system is 100% secure and we cannot guarantee absolute security.

11. Children

Our Services are not directed to individuals under 18. We do not knowingly collect personal data from children under the age of majority. If you believe a child has provided us personal data, contact us, and we will take steps to remove it.

12. Your rights & how to exercise them

Depending on where you live, you may have rights including: access, correction, deletion, restriction of processing, portability, objection to processing, and withdrawal of consent. To exercise rights, email support@spencer-cole.com with “Privacy Request” in the subject and include your name, email, and any relevant order number. We may require reasonable proof of identity before acting on certain requests. We will not discriminate for exercising your rights.

For advertising opt-outs, you can also use the Google Ads control page (adssettings.google.com) and GPC or browser privacy controls. 

13. Complaints & supervisory authority

If you have a complaint about our data handling, please contact us first at support@spencer-cole.com so we can try to resolve it. You also have the right to lodge a complaint with your local data protection authority (for UK/EEA residents).

14. Changes to this Privacy Policy

We may update this policy when necessary. We will post the revised policy at this page and update the “Last updated” date. Material changes will be communicated as required by law.

Contact Details

Phone: +447713101793
Email: support@spencer-cole.com
Address: 70 Minterne Waye, Hayes, UB4 0PF, United Kingdom.