Privacy policy
Privacy & Cookies Notice – Beautiful Cosmetics
The online store BeautifulCosmetics.co.uk is operated by Fab Trade Group LTD / TA Beautiful Cosmetics, 112 High Street, TW3 1NA London, United Kingdom; e-mail: orders@fabtrade.co.uk (the “Controller”, “we”). This Notice explains how we process personal data under the UK GDPR, the Data Protection Act 2018 and PECR (Privacy and Electronic Communications Regulations), and how we use cookies.
§ 1. Definitions
- Personal data – information relating to an identified or identifiable natural person.
- UK GDPR – the United Kingdom General Data Protection Regulation.
- PECR – the UK Privacy and Electronic Communications Regulations.
- User/Customer – any person visiting or using the Store (including purchasers).
- Device – a computer, phone, tablet or other device used to access the Store.
§ 2. Controller and contact
- The Controller is Fab Trade Group LTD / TA Beautiful Cosmetics, 112 High Street, TW3 1NA London; e-mail: orders@fabtrade.co.uk.
- You can contact us at the above address or e-mail regarding data protection matters.
§ 3. Data we collect
- We process in particular: name, e-mail address, phone number, delivery and billing addresses, order and payment data, account number, order history, communications, as well as technical data (IP address, cookie identifiers, activity logs, server logs).
- For online payments, we process transaction identifiers received from payment operators (e.g., PayPal, Stripe).
§ 4. Purposes and legal bases
- Contract performance & order handling – Art. 6(1)(b) UK GDPR (concluding and performing sales contracts, creating and managing accounts).
- Payment processing – Art. 6(1)(b) and (f) UK GDPR (processing payments and preventing fraud) – through PayPal and Stripe.
- Support & communications (contact forms, e-mail) – Art. 6(1)(b) or (f) UK GDPR (responding and maintaining correspondence).
- Newsletter & marketing communications – Art. 6(1)(a) UK GDPR (consent) and in line with PECR (marketing consents).
- Own marketing, analytics & statistics – Art. 6(1)(f) UK GDPR (legitimate interests – business development and promotion; we only use cookies/analytics requiring consent where PECR mandates it).
- Legal obligations (accounting, tax, complaints) – Art. 6(1)(c) UK GDPR.
- Establishment, exercise or defence of claims – Art. 6(1)(f) UK GDPR.
§ 5. Data recipients and categories
- Processors and partners: hosting/IT providers, e-commerce platform, couriers/logistics, accounting services, mailing systems, anti-fraud tools, payment operators: PayPal, Stripe.
- Public authorities where legally required.
§ 6. Transfers outside the UK
- Where services involve processing outside the UK, we ensure appropriate safeguards – e.g., the International Data Transfer Agreement/Addendum (IDTA) or other transfer mechanisms required under the UK GDPR.
§ 7. Retention periods
- Contract & accounting data – for the duration of the contract and as required by law (e.g., accounting/tax).
- Communications – until the matter is resolved.
- Marketing (newsletter) – until consent is withdrawn.
- Cookies/analytics – as per cookie settings and until consent is withdrawn or cookies expire.
- Claims – until limitation periods expire.
§ 8. Your rights
- You have the right to: access, rectification, erasure, restriction, portability, objection to processing based on our legitimate interests, and to withdraw consent at any time (without affecting the lawfulness of processing before withdrawal).
- You have the right to lodge a complaint with the ICO (Information Commissioner’s Office).
§ 9. Requirement to provide data
- Providing data is not mandatory, but necessary to conclude and perform the contract (purchases, delivery, payments). For marketing purposes – voluntary.
§ 10. Automated decision-making and profiling
- We do not take decisions producing legal effects solely by automated means. We may conduct basic profiling (e.g., newsletter segmentation) based on consent and our legitimate interests – without producing significant legal effects for you.
§ 11. Cookies and similar technologies
- The Store uses first-party and third-party cookies. Where required by PECR, we obtain consent via our cookie banner/preferences centre.
- Cookies may be essential (functional – necessary for the site/cart), analytics/statistics and marketing. Some operate only with your consent.
- Manage cookies via your browser settings and our cookie banner/preferences centre.
- Examples: session management, remembering settings, traffic analysis, campaign effectiveness, fraud prevention.
§ 12. Final provisions
- We may update this Notice due to legal or functional changes. Material changes will be communicated prominently in the Store.
- Privacy contact: orders@fabtrade.co.uk.
