Privacy Policy
DIVINE LACESS
Hair Extensions & Wigs Store
PRIVACY POLICY
Effective Date: 29 March 2026
This Privacy Policy explains how DIVINE LACESS ("we", "our", or "us") collects, uses, stores, and protects your personal data when you visit our website at www.divinelacess.com or make a purchase from our online store. We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Please read this policy carefully. By using our website or placing an order, you acknowledge that you have read and understood this Privacy Policy.
1. WHO WE ARE
The data controller responsible for your personal information is:
Business Name: DIVINE LACESS
Address: 3-5 Portland Street, Cheltenham, GL52 2NZ, United Kingdom
Email: contact@divinelacess.com
Phone: +44 7487 238227
Website: www.divinelacess.com
2. INFORMATION WE COLLECT
We may collect the following categories of personal information:
2.1 Information You Provide Directly
• Full name
• Email address
• Delivery and billing address
• Phone number
• Payment information (processed securely via Shopify Payments – we do not store card details)
• Account login credentials (if you create an account)
• Messages or enquiries submitted via email or contact forms
2.2 Information Collected Automatically
• IP address and browser type
• Pages visited and time spent on our website
• Referring website or search terms
• Device type and operating system
• Cookies and similar tracking technologies
2.3 Information from Third Parties
• Payment processors (Shopify Payments, PayPal)
• Shipping and courier partners
• Social media platforms (if you interact with us via social media)
3. HOW WE USE YOUR INFORMATION
We use your personal data for the following purposes and legal bases:
To process and fulfil your orders
Legal basis: Performance of a contract. We need your information to process payments, arrange delivery, and send order confirmations.
To communicate with you
Legal basis: Legitimate interests / Contract. We may contact you regarding your order, respond to enquiries, or send service-related notifications.
To send marketing communications
Legal basis: Consent. If you have opted in, we may send you promotional emails, offers, and product updates. You can unsubscribe at any time.
To improve our website and services
Legal basis: Legitimate interests. We analyse usage data to enhance the customer experience and improve our product offerings.
To comply with legal obligations
Legal basis: Legal obligation. We may retain certain data to comply with tax, accounting, and regulatory requirements.
4. COOKIES
Our website uses cookies to enhance your browsing experience. Cookies are small text files stored on your device. We use:
• Essential cookies – required for the website to function (e.g. shopping cart, checkout)
• Analytics cookies – to understand how visitors use our site (e.g. Google Analytics)
• Marketing cookies – to deliver relevant advertisements and track campaign performance
You can manage or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website. By continuing to use our website, you consent to our use of cookies in accordance with this policy.
5. SHARING YOUR INFORMATION
We do not sell, rent, or trade your personal data. We may share your information with trusted third parties only where necessary:
• Shopify – our e-commerce platform provider, for order processing and website hosting
• Payment processors (PayPal, Shopify Payments) – for secure payment handling
• Courier and delivery partners – to fulfil and track your orders
• Email marketing platforms – if you have consented to receive marketing communications
• Legal and regulatory authorities – where required by law or to protect our legal rights
All third parties are required to handle your data securely and in accordance with applicable data protection law.
6. INTERNATIONAL DATA TRANSFERS
As we use Shopify and other third-party services, your data may be transferred to and processed in countries outside the UK or European Economic Area (EEA). Where such transfers occur, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions, to protect your personal data in line with UK GDPR requirements.
7. DATA RETENTION
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including:
• Order records – retained for up to 7 years for tax and accounting purposes
• Customer account data – retained for as long as your account remains active
• Marketing preferences – retained until you unsubscribe or withdraw consent
• Enquiry and complaint records – retained for up to 3 years
Once data is no longer required, it is securely deleted or anonymised.
8. YOUR RIGHTS
Under UK GDPR, you have the following rights regarding your personal data:
• Right of access – request a copy of the personal data we hold about you
• Right to rectification – request correction of inaccurate or incomplete data
• Right to erasure – request deletion of your personal data (the 'right to be forgotten')
• Right to restrict processing – request that we limit how we use your data
• Right to data portability – receive your data in a structured, machine-readable format
• Right to object – object to processing based on legitimate interests or for direct marketing
• Rights related to automated decision-making – not be subject to solely automated decisions
To exercise any of these rights, please contact us at contact@divinelacess.com. We will respond within 30 days of receiving your request. You will not be charged for exercising your rights.
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk or by calling 0303 123 1113.
9. SECURITY
We take the security of your personal data seriously. We implement appropriate technical and organisational measures to protect your information against unauthorised access, loss, destruction, or alteration. These measures include:
• SSL encryption on all pages of our website
• Secure payment processing via Shopify's PCI-DSS compliant gateway
• Limited access to personal data on a need-to-know basis
• Regular review of our data security practices
However, no method of transmission over the internet is completely secure. While we strive to protect your data, we cannot guarantee absolute security.
10. CHILDREN'S PRIVACY
Our website and services are not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected information from a child, please contact us immediately at contact@divinelacess.com and we will take steps to delete such data promptly.
11. THIRD-PARTY LINKS
Our website may contain links to third-party websites or social media platforms. We are not responsible for the privacy practices or content of those websites. We encourage you to read the privacy policies of any third-party sites you visit.
12. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The updated policy will be posted on our website with a revised effective date. We encourage you to review this policy periodically. Your continued use of our website after any changes constitutes your acceptance of the updated policy.
13. CONTACT US
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:
DIVINE LACESS
3-5 Portland Street, Cheltenham, GL52 2NZ, United Kingdom
Phone: +44 7487 238227
Email: contact@divinelacess.com
Website: www.divinelacess.com
© 2026 DIVINE LACESS – All Rights Reserved | 3-5 Portland Street, Cheltenham GL52 2NZ | contact@divinelacess.com