Legal
Privacy policy.
What we collect when you shop with us, why we need it, who we share it with and how to take it back. Written in plain language, because it concerns you.
Last updated: October 2026
Who we are
My Store sells ready-to-wear clothing online. When you visit this website, place an order, create an account or write to us, we act as the data controller for the personal data described below.
You can reach us about anything in this policy through our contact page.
What we collect
We only collect what we need to run the shop:
- Order and delivery data — name, delivery and billing address, email address, telephone number, the items ordered, their sizes and prices.
- Payment data — the result of the transaction, the payment method type and the last digits of the card. Full card numbers are handled by our payment provider and never reach our systems.
- Account data — if you create an account: your email address, an encrypted password, your saved addresses and your order history.
- Correspondence — the messages you send us about sizing, an order or a return, and our replies.
- Technical and usage data — device type, browser, approximate location derived from your IP address, pages viewed and items added to the basket. Beyond what is strictly necessary to serve the site, this is collected only with your consent.
We do not knowingly collect data from children, and we do not collect special categories of data (health, beliefs, biometrics).
Why we use it, and on what basis
| Purpose | Legal basis |
|---|---|
| Taking payment, preparing and delivering your order, handling returns | Performance of our contract with you |
| Order confirmations, dispatch notices and service emails | Performance of our contract with you |
| Answering your messages and advising on sizing or care | Legitimate interest in serving our customers |
| Preventing fraudulent orders and payments | Legitimate interest in protecting the business |
| Keeping accounting, tax and sales records | Legal obligation |
| Audience measurement and marketing cookies | Your consent, withdrawable at any time |
| Newsletters and promotional emails | Your consent, withdrawable at any time |
Where we rely on consent, you may withdraw it at any time — through the Manage cookies link in the footer for cookies, or the unsubscribe link in any marketing email. Withdrawing consent does not affect what was lawful before.
International transfers
Some of our providers operate outside the United Kingdom and the European Economic Area. Where data is transferred to such a country, we rely on an adequacy decision or on the Standard Contractual Clauses (with the UK Addendum where applicable), together with appropriate technical safeguards such as encryption in transit and at rest.
How long we keep it
- Order and invoicing records — for the period required by accounting and tax law, normally several years from the end of the financial year of the sale.
- Account data — for as long as your account is open, and deleted or anonymised after a long period of inactivity or when you ask us to close it.
- Customer service messages — generally up to three years after the last contact.
- Marketing consent — until you withdraw it, and we record the withdrawal itself so that we can honour it.
- Cookie data — for the lifetimes set out in our Cookie Policy; consent choices are kept for up to twelve months before we ask again.
Your rights
Under the UK GDPR and the EU GDPR you may ask us to: give you a copy of your data; correct it; delete it; restrict or object to how we use it; send it to another provider in a portable format; and withdraw a consent you gave. You may also object at any time to direct marketing.
Contact us through our contact page and we will reply within one month. We may ask you to confirm your identity before acting, so that nobody else can obtain your data.
If you believe we have handled your data wrongly, you can complain to your supervisory authority: in the United Kingdom the Information Commissioner’s Office, in France the CNIL, or the authority of the EU country you live in.
How we protect it
The site is served over an encrypted connection, passwords are stored hashed, access to customer data is limited to the people who need it, and payment details are processed by a PCI-DSS compliant provider. No system is perfect, so if a breach ever affected your rights we would notify the competent authority and, where required, you.
A question about your data?
Write to us and we will come back to you. We answer every message.
