This is skeleton copy — not yet lawyer-reviewed. Final version BCT-005.
Last updated: 2026-05-25 (draft)
Privacy notice
1. Who we are
The data controller is HM Cornwall Ltd, trading as Black Compass Trethow. Registered office: [Registered office address], Cornwall, UK. Company number: [CH NUMBER]. ICO registration: [ICO NUMBER]. Contact for data matters: [contact email placeholder].
2. What we collect
- Email address (orders, newsletter, support)
- Postal address and recipient name (delivery)
- Payment metadata: card brand and last four digits, billing postcode (we never see the full card number — Stripe handles that)
- Order history and product preferences
- Browsing behaviour on the site: pages viewed, items added to basket, device type (only if you accept analytics cookies)
- Commissioned-product brief content and any reference photographs you upload
3. Legal bases
- Contract — processing your order, delivering goods, handling returns
- Consent — newsletter, marketing emails, non-essential cookies
- Legitimate interest — fraud prevention, abuse detection, service improvement
- Legal obligation — tax records, accounting, dispute resolution
4. Retention periods
- Order records: 6 years from order date (HMRC requirement)
- Marketing list: until you unsubscribe
- Commission briefs and reference images: 24 months from order, then deleted
- Support correspondence: 24 months from last contact
- Analytics data: 14 months (GA4 default)
5. Third parties
We share the minimum necessary data with the following processors:
- Stripe — payment processing
- Gelato — print and fulfilment
- Royal Mail and other carriers — delivery
- Cloudflare — hosting, DNS, security
- Klaviyo or Mailchimp [TBD — provider not yet selected] — email marketing
- Sentry — error monitoring (no personal data deliberately collected)
- Etsy and eBay — for orders placed on those platforms, under their respective privacy policies
6. International transfers
Some processors (Cloudflare, Stripe, possibly Klaviyo) are based in the US. Where personal data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Agreement or Standard Contractual Clauses as appropriate.
7. Cookies
See our Cookie notice for the full list of cookies and how to change your preferences. Analytics cookies do not fire until you give consent via the banner.
8. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Have your data erased (where no overriding legal obligation applies)
- Receive your data in a portable format
- Object to processing based on legitimate interest
- Withdraw consent at any time, for any consent-based processing
To exercise any of these rights, email [contact email placeholder]. We respond within one calendar month.
9. Complaints
If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk or 0303 123 1113.
10. Contact
[contact email placeholder] · HM Cornwall Ltd, [Registered office address], Cornwall, UK · Company number [CH NUMBER] · ICO registration [ICO NUMBER].