Privacy Policy
Version: 2.0
Last Updated: 18 November 2025
Lawful Basis for Processing
This Privacy Notice sets out the lawful basis for processing and discloses the types of information we gather, how we use it, and the rights you have regarding your data. We process your personal data under the lawful bases of:
- Contract – to fulfil your orders, process payments, provide finance options, and deliver the services you request.
- Legal Obligation – to comply with legal, tax, and accounting requirements.
- Legitimate Interests – to operate and improve our business, including fraud prevention, service quality monitoring, and marketing (where permitted).
- Consent – for activities such as email marketing, where you have explicitly opted in. You may withdraw consent at any time.
Information We Collect
We may collect the following types of personal data when you use our website, place an order, or contact us:
- Name, billing address, delivery address, email address, and telephone number
- Payment details (card or alternative payment provider references)
- Order details, including products purchased and transaction history
- Communication records (emails, calls, webchat)
- Technical information, such as IP address, browser type, and cookies (see our Cookie Policy)
If you apply for finance, we will collect and share the necessary information with Black Horse to process your application.
How We Use Your Information
- Process and fulfil your orders
- Take payment and provide refunds
- Deliver goods and manage returns
- Respond to your queries and provide customer service
- Process finance applications with Black Horse
- Improve our website, products, and services
- Send marketing communications where you have consented
We do not sell your data to third parties.
Third-Party Processing
We share your personal data with trusted service providers where necessary to operate our business. These include:
- Payment processors – SagePay, Stripe, and PayPal, to securely process payments
- Finance provider – Black Horse, to process finance applications
- Couriers and logistics providers – to deliver your orders
- IT, hosting and security providers – to run and protect our website and internal systems
- Email and telephony systems – to communicate with you and manage customer service
- Analytics and marketing tools – to understand how customers use our website and improve services
- Review platform – Trustpilot, to invite you to review your purchase
Our payment processors may store limited personal and transaction data as required to prevent fraud, process refunds, and comply with financial regulations.
Where these providers process data outside the UK/EEA, we ensure appropriate safeguards (such as adequacy regulations or standard contractual clauses) are in place.
Finance Option (Black Horse)
If you choose to apply for finance, we will share your information with Black Horse to process your application and manage your finance agreement. Black Horse acts as a separate data controller and will provide you with its own privacy notice explaining how it processes your data.
Personalised Recommendations and Profiling
In the future, we may use automated systems to analyse your order history and send personalised product recommendations. This profiling is designed to enhance your shopping experience and does not produce legal or similarly significant effects. You may opt out of profiling at any time.
Information Storage and Retention
- Order records: kept for 6 years to comply with HMRC regulations
- Enquiries: kept for 12 months to allow us to respond to any follow-up queries
- Payment data (gateways): retained by our payment processors (e.g., SagePay, Stripe, PayPal) in line with their own policies and legal obligations. We only store transaction references/tokens and do not store full card numbers.
Once retention periods expire, data will be securely deleted or anonymised.
Security
We implement appropriate technical and organisational measures to protect your personal data, including encryption, secure hosting environments, and strict access controls. All payments are processed through PCI DSS-compliant providers, and our website uses SSL encryption to keep transactions secure.
In the unlikely event of a personal data breach that affects your rights or freedoms, we will notify you and the relevant supervisory authority where legally required.
Children’s Data
Our website and services are not directed at children under 16, and we do not knowingly collect personal data relating to children.
Your Data Rights
- Request a copy of any personal information we hold about you
- Request correction of inaccurate data
- Request erasure of your data where legally permissible
- Object to processing for certain purposes, including marketing
- Request restriction of processing or data portability
- Withdraw consent for processing where we rely on consent
To exercise any of these rights, please contact us by post or email:
E D Elson Ltd
Unit 1 Brick Knoll Park, Ashley Road, St Albans, Hertfordshire, AL1 5UG, United Kingdom
Email: [email protected]
We may request proof of ID to verify your identity before fulfilling a data request. If we are unable to action your request, we will explain the reason for our decision.
External Links
Our website may contain links to external websites. We are not responsible for the privacy practices of these other sites and encourage you to read their privacy policies.
Business Transfers
If our business is sold, merged, or undergoes a reorganisation, your personal data may be transferred to the new owners so that they can continue to provide services to you.
Policy Changes
We may update this Privacy Notice from time to time to reflect changes in law, technology, or our business operations. Significant changes will be communicated on this page or by email where appropriate.
Complaints
If you have a concern about how we use your data, you can: