Privacy and cookies
What we collect, why, who else sees it, and how to make us stop. Including the one thing this site remembers that never reaches us at all.
Who is responsible for your data
The data controller is the trading entity — the same registered company named in the terms, with its address and, if it is UK-based, its ICO registration number. If you have a question about anything here, write to the contact email address — a real inbox somebody reads, not a form.
One thing to be clear about from the start, because it is unusual and because it is yours to know: our workshop is in India and our shop sells into the UK and Europe. Any personal data involved in getting a parcel to you therefore crosses a border. That is covered properly below rather than left implied.
What we collect
What you give us
- Your name, delivery and billing address, email address and telephone number, when you place an order.
- Your email address, if you ask us to write to you when new pieces arrive.
- Whatever you put in a message to us, and our reply.
- Your card details go directly to our payment provider and never touch our server. We can see the last four digits and the expiry date so we can help you find a payment; we cannot see the number.
What we collect automatically
- Standard web-server records: your IP address, the browser and device you used, the pages you looked at and when. Every website receives these; ours keeps them because they are how we find out that something is broken.
- Whether an analytics tool is installed, and which one. If it is Google Analytics say so; if it is a cookieless one like Plausible or Fathom say that instead, because it changes what this page has to promise.
What stays on your own device and never reaches us
The Makers page remembers which artisans you have listened to, so that it can greet you differently if you come back. That memory is stored in your own browser, under the key `hor:met`, and it is never sent to us — we could not read it if we wanted to. There is a “forget me” control on that page which erases it, and clearing your browser data does the same thing.
We mention this partly because it is honest and partly because a lot of sites describe exactly this kind of feature as “personalisation” in a way that implies a profile sitting on a server somewhere. Here there is not one.
Why we use it, and what allows us to
- To take an order, get it made, and get it to you
- Because we need to in order to do what you asked — the lawful basis is performance of a contract. This is the only reason we genuinely cannot do without.
- To answer a message
- Legitimate interests: you wrote to us and would like a reply.
- To keep the accounts and meet tax rules
- Legal obligation. This is why order records survive even after you ask us to delete your account, and it is the one deletion request we cannot fully honour.
- To send you an email about new pieces
- Consent, which you gave by asking and can withdraw with the unsubscribe link in every email, or by writing to us. We do not add customers to a mailing list automatically.
- To find out what is broken, and to keep the site up
- Legitimate interests. We have weighed this against your privacy and concluded that knowing a checkout page threw an error is worth a server log.
- To prevent fraud
- Legitimate interests, and in places a legal obligation. Our payment provider does most of this and sees more of it than we do.
Who else sees it
Nobody buys it, and nobody is sent it for their own purposes. It is shared only with the companies that make the shop work, each of which is contractually limited to doing what we ask with it:
- Hosting. Name the host — Hostinger, if that is where the site stays — and the country the servers are in.
- Payments. Name the payment providers. Stripe and PayPal are the likely pair; whoever it is, they are a separate data controller with their own privacy policy and you should link to it here.
- Shipping. Name the carriers. They receive your name, address and telephone number, and they cannot deliver a parcel without them.
- Email. Name the mailing-list provider, if there is one.
- Accounting and tax. Our accountants, and the relevant tax authority when it asks.
We will also share data where the law requires it, or to establish or defend a legal claim. If the business is ever sold, customer records would pass to the buyer, who would be bound by this policy until they told you otherwise.
Your data leaving the country
This is the section most policies for a business like ours skate over, so here it is plainly. Getting a parcel from Kumaon to a house in Britain means your name and address exist in India as well as in the UK. There is no version of this business in which that is not true.
India is not currently covered by a UK “adequacy” decision, which means that transfer needs its own safeguard — in practice the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, in place between the entities involved. Confirm which mechanism is actually in place once the trading entity is settled, and say so here. If none is in place yet, this must be fixed before the shop takes an order, not after.
How long we keep it
- Order and payment records
- Six years after the end of the tax year, if the entity is UK-based — confirm against the actual jurisdiction. This is a legal requirement rather than a choice.
- Messages you send us
- Two years, then deleted, unless they relate to an order.
- Mailing-list address
- Until you unsubscribe, and then removed within thirty days.
- Server logs
- Confirm the retention the host actually applies — typically 30 to 90 days.
What you can ask us to do
Under UK and EU data-protection law you can ask for a copy of what we hold, ask us to correct it, ask us to delete it, ask us to stop or limit a particular use, object to processing we are doing on the basis of legitimate interests, and ask for your data in a portable form. You can withdraw consent at any time without it affecting anything we did before you withdrew it.
Write to the contact email address. It is free, and we will answer within one month. If we cannot do what you have asked — usually because a tax rule says we must keep an order record — we will tell you which part we cannot do and why, rather than quietly doing the rest.
If you think we have handled your data badly you can complain to the Information Commissioner’s Office at ico.org.uk, or to your own national data protection authority if you are in the EU. We would rather you told us first, but you are not obliged to.
Cookies
A cookie is a small file a site leaves in your browser. This site uses as few as it can get away with, and the ones it does use fall into three groups.
- Strictly necessary
- The shopping basket, the checkout, and staying logged in if you have an account. These do not need your permission because the site cannot function without them, and there is nothing to consent to — refusing them means refusing to have a basket.
- Functional
- The “you have met this artisan” memory described above. Technically this is local storage rather than a cookie, it never leaves your device, and it is switched on by the act of pressing play on a greeting.
- Analytics
- Whether analytics is installed, what it sets, and how long it lasts. If an analytics tool is added that sets cookies, a consent banner becomes legally necessary under PECR — it is not optional, and it must be off until the visitor agrees. If a cookieless tool is used instead, no banner is needed and this site is better for it.
You can clear or block cookies in your browser settings. Blocking the necessary ones will break the checkout, which is a statement of fact rather than a threat.
Children
This shop is not aimed at children and we do not knowingly collect data from anyone under sixteen. If you think we have, tell us and we will delete it.
Changes
If we change this policy we will change the date below, and if the change is significant we will say so on the site rather than hoping you re-read it. Last updated date.