Privacy policy

Mercer & Loxley respects your privacy. In this policy we explain which personal data we collect, why, and what your rights are under the General Data Protection Regulation (GDPR).

1. Who are we?
Mercer & Loxley
KvK: 77767500
VAT: NL003235354B26
E-mail: info@mercerloxley.co.uk

We are the data controller for your personal data.

2. What data do we collect?
When placing an order: name, email address, phone number, delivery address and billing address, payment details (processed by our payment partner — we do not store full card details), order details and history.

When visiting the website: IP address, browser type, pages visited (via analytics), cookies.

When subscribing to the newsletter: email address.

3. Why do we collect this data?
To process and deliver your order. To contact you about your order. To improve our website and service. To send you (with your consent) newsletters or offers. To comply with legal obligations (e.g. tax administration).

4. Who do we share this data with?
Shopify (e-commerce platform, US — GDPR-compliant via Standard Contractual Clauses). Payment providers (credit card, Apple Pay, Google Pay — for transaction processing). Shipping partners (to deliver your parcel). Email marketing provider (if you are subscribed).

We never sell your data to third parties.

5. How long do we keep your data?
Order data: 7 years (statutory retention period for tax purposes). Account data: as long as your account is active. Newsletter: until you unsubscribe.

6. Your rights
Under the GDPR you have the right to:
- Access your data
- Have your data corrected
- Have your data erased (insofar as legally permitted)
- Object to processing
- Request a copy of your data (data portability)
- Lodge a complaint with the supervisory authority

Send a request to info@mercerloxley.co.uk — we will respond within 30 days.

7. Cookies
Our website uses cookies for functionality, analytics and (with your consent) marketing.

8. Security
We take appropriate technical and organisational measures to secure your data. Our website uses SSL encryption (HTTPS).

9. Changes
We may update this privacy policy. The current version can always be found on this page.