Privacy policy
Privacy Policy
Last Updated: November 8, 2025
Sina Crisps Ltd ("SINA", "we", "us", or "our") operates this store and website, including all related information, content, features, tools, products, and services (collectively, the "Services"). We are powered by Shopify, which enables us to provide the Services to you. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you visit, use, or make a purchase through the Services or otherwise communicate with us. It applies to all users in the United Kingdom (UK) and complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
If there is a conflict between our Terms of Service and this Privacy Policy regarding personal data, this Privacy Policy prevails. Please read this Privacy Policy carefully. By using the Services, you acknowledge that you have read and understood how we process your personal data as described below.
We do not collect special category data (e.g., health, race, religion) unless you voluntarily provide it (e.g., in a support message), in which case it will be processed only with your explicit consent.
We do not sell your personal data. We do not share it for cross-context behavioural advertising unless you consent.
After retention periods, data is securely deleted or anonymised.
We may verify your identity before responding. You can withdraw consent at any time (e.g., unsubscribe from marketing).
Post: Data Protection, Sina Crisps Ltd, 167–169 Great Portland Street, London, W1W 5PF We respond within 1 month (extendable in complex cases).
If there is a conflict between our Terms of Service and this Privacy Policy regarding personal data, this Privacy Policy prevails. Please read this Privacy Policy carefully. By using the Services, you acknowledge that you have read and understood how we process your personal data as described below.
- Data Controller
- Company Number: 160932 (registered in Jersey)
- Registered Office: 167–169 Great Portland Street, London, W1W 5PF, United Kingdom
- VAT Number: 499 3070 51
- Email: hello@sinacrisps.com
- Postal Address: As above
- Personal Data We Collect
|
Category
|
Examples
|
|---|---|
|
Identity & Contact Data
|
Name, billing/shipping address, email address, phone number
|
|
Financial Data
|
Payment card details (processed securely via Shopify Payments – we do not store full card numbers)
|
|
Account Data
|
Username, password (hashed), security questions, preferences
|
|
Transaction Data
|
Orders, items viewed/added to cart, purchase history, returns
|
|
Communication Data
|
Emails, support tickets, feedback, reviews
|
|
Technical & Usage Data
|
IP address, browser type, device info, pages visited, time spent, referral source
|
|
Marketing Preferences
|
Consent to receive promotional emails/SMS
|
- How We Collect Your Personal Data
|
Method
|
Examples
|
|---|---|
|
Directly from you
|
When you create an account, place an order, subscribe, contact support, or leave a review
|
|
Automatically
|
Via cookies, server logs, and tracking technologies when you visit the Website
|
|
From Shopify
|
As our e-commerce platform provider (acting as a processor)
|
|
From third-party services
|
Payment gateways, shipping carriers (e.g., Royal Mail), analytics tools
|
- Legal Bases for Processing (UK GDPR Article 6)
|
Purpose
|
Lawful Basis
|
|---|---|
|
To process and fulfil your order (including shipping & payment)
|
Performance of a contract
|
|
To create and manage your account
|
Performance of a contract
|
|
To send order confirmations, dispatch updates, and delivery tracking
|
Performance of a contract
|
|
To provide customer support
|
Legitimate interests (efficient support)
|
|
To send marketing emails (with prior consent)
|
Consent
|
|
To improve the Website and Services (analytics)
|
Legitimate interests (business improvement)
|
|
To detect and prevent fraud
|
Legitimate interests (security)
|
|
To comply with tax, accounting, or food safety laws
|
Legal obligation
|
- How We Use Your Personal Data
- Fulfil your orders – process payments, arrange shipping via Royal Mail 48hr Tracked, handle returns.
- Manage your account – login, saved addresses, order history.
- Send transactional communications – order confirmations, shipping updates, subscription reminders.
- Provide customer support – respond to inquiries via email.
- Send marketing (optional) – only if you opt in. You can unsubscribe anytime via the link in any email.
- Improve our Services – analyse usage patterns (anonymised where possible).
- Prevent fraud – monitor for suspicious activity.
- Comply with legal obligations – VAT reporting, allergen record-keeping, right-to-be-forgotten requests.
- Who We Share Your Data With
|
Recipient
|
Purpose
|
Location
|
|---|---|---|
|
Shopify Inc.
|
Hosting, order processing, payments, analytics
|
Canada (adequacy decision)
|
|
Payment Providers (e.g., Stripe, PayPal)
|
Secure payment processing
|
UK / EU / US (IDTA/SCCs)
|
|
Royal Mail
|
Delivery of your order
|
UK
|
|
Proton Mail (Proton AG)
|
Secure email communications (transactional & support)
|
Switzerland (UK adequacy decision)
|
|
Cloudflare / Google Cloud
|
Website security & performance
|
UK / EU / US (IDTA/SCCs + TIA)
|
|
Accountants / HMRC
|
Tax & VAT compliance
|
UK
|
|
Legal Advisors
|
In case of disputes or compliance
|
UK
|
- International Data Transfers
- Canada & Switzerland: Recognised as providing adequate protection by the UK.
- USA: We use UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs) with suppliers, plus Transfer Impact Assessments (TIA) where required.
- Data Retention
|
Data Type
|
Retention Period
|
|---|---|
|
Order & transaction records
|
7 years (for tax/VAT compliance)
|
|
Account data
|
Until you delete your account + 30 days
|
|
Marketing consents
|
Until withdrawn
|
|
Support tickets
|
3 years
|
|
Analytics (anonymised)
|
Up to 26 months
|
- Your Rights Under UK GDPR
- Right to be informed – via this Privacy Policy
- Right of access – get a copy of your data (within 1 month)
- Right to rectification – correct inaccurate data
- Right to erasure ("right to be forgotten") – delete your data
- Right to restrict processing – limit how we use your data
- Right to data portability – receive your data in a structured format
- Right to object – to marketing or legitimate interest processing
- Rights re automated decisions – not subject to fully automated decisions
We may verify your identity before responding. You can withdraw consent at any time (e.g., unsubscribe from marketing).
- Cookies & Tracking
- Remember your cart
- Improve site performance
- Show relevant recommendations
- Measure marketing effectiveness
- Security
- End-to-end encryption via Proton Mail for all email communications
- TLS encryption in transit
- Secure Shopify infrastructure
- Access controls and staff training
- Regular security audits
- Children
- Changes to This Policy
- Complaints
- Contact us first: privacy@sinacrisps.com
-
You can complain to:
- Jersey Office of the Information Commissioner (JOIC): www.jerseyoic.org
- UK Information Commissioner’s Office (ICO): www.ico.org.uk/make-a-complaint
- Contact Us
Post: Data Protection, Sina Crisps Ltd, 167–169 Great Portland Street, London, W1W 5PF We respond within 1 month (extendable in complex cases).