Privacy Policy
Last updated: 24 August 2025
At Strathearn Cheese (“we”, “our”, “us”), we are committed to protecting your privacy and personal data. This Privacy Policy explains what information we collect, how we use it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies to our website www.strathearncheese.com and any related services we provide.
1. Information We Collect
When you use our website, we may collect the following information:
-
Personal information – such as your name, email address, phone number, billing/shipping address, and order details when you make a purchase, sign up for our newsletter, or contact us.
-
Payment information – such as credit/debit card or Apple Pay details. We do not store your full payment card details. Payments are securely handled by our third-party payment providers.
-
Technical information – such as your IP address, browser type, operating system, and how you interact with our website.
-
Cookies and tracking data – small files placed on your device to help our site function properly and to improve your experience. See section 8 for more detail.
2. Legal Basis for Processing Data
We only process your personal data where we have a lawful basis to do so. These include:
-
Contract – to process and deliver your orders, take payments, and provide customer service.
-
Consent – when you sign up for our newsletter or agree to receive marketing communications. You can withdraw consent at any time.
-
Legal obligation – to keep records required by law, including for tax and accounting purposes.
-
Legitimate interests – to improve our website, prevent fraud, and ensure the security of our systems.
3. How We Use Your Information
We may use your information to:
-
Process and fulfil your orders, including arranging delivery and handling payments/refunds.
-
Communicate with you regarding your orders or enquiries.
-
Send newsletters or promotions if you have opted in.
-
Improve and personalise your online experience.
-
Meet our legal and regulatory obligations.
4. Data Security
We take appropriate technical and organisational measures to protect your personal information. These include:
-
Hosting our website on Wix, which provides secure servers, firewalls, and continuous monitoring.
-
Encrypting all data transmitted between your browser and our website using SSL (Secure Socket Layer) technology.
-
Processing all payments securely through approved providers. We never store full card details.
-
Restricting access to personal information to authorised personnel only.
-
Regularly reviewing our security practices.
Please note that while we take all reasonable steps to protect your data, no method of transmission or storage is completely secure.
5. Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes outlined in this policy:
-
Order and transaction records – kept for up to 6 years to comply with tax and accounting requirements.
-
Marketing data (e.g. email subscriptions) – kept until you unsubscribe or withdraw consent.
-
Enquiry/contact form data – generally kept for 12–24 months.
After these periods, data will be securely deleted or anonymised.
6. Sharing Your Information
We do not sell, rent, or trade your personal data. We may share information only with:
-
Website host – Wix, who provide secure hosting.
-
Payment processors – for example, card and Apple Pay providers, who handle payments securely.
-
Delivery companies – to ensure your orders reach you.
-
Professional services – such as accountants, to comply with legal requirements.
-
Legal authorities – where required by law.
If any of these providers transfer data outside the UK/EEA, they do so with appropriate safeguards (such as adequacy decisions or standard contractual clauses).
7. Your Rights
Under UK GDPR, you have the right to:
-
Access the personal data we hold about you.
-
Request corrections to inaccurate information.
-
Request deletion of your data where legally possible.
-
Restrict or object to certain types of processing.
-
Withdraw consent to marketing communications at any time.
-
Request transfer of your data to another service provider.
To exercise your rights, please contact us at:
📧 Ben@strathearncheese.com
If you are unhappy with how we handle your data, you also have the right to lodge a complaint with the UK’s data protection regulator, the Information Commissioner’s Office (ICO): www.ico.org.uk.
8. Cookies
Our website uses cookies to ensure it functions properly and to enhance your browsing experience. Cookies may also be used for analytics to understand how visitors use our site.
-
Essential cookies – required for the website to operate.
-
Functional cookies – help remember your preferences.
-
Analytics cookies – if enabled, help us improve our site performance.
You can control or disable cookies through your browser settings. Please note this may affect some website functionality.
9. Third-Party Links
Our website may contain links to other websites. We are not responsible for the privacy practices or content of those sites.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The most recent version will always be available on our website.
