Privacy Policy
Effective Date: 8 Sptember 2025
Last Updated: 10 October 2025
1. Introduction
Welcome to Sophia & Grace London, operated by Back on Rails | Digital Marketing (Chamber of Commerce: 66815797, VAT: NL002415478B23).
We respect your privacy and are committed to protecting your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This Privacy Policy explains how we collect, use, disclose and safeguard your personal information when you visit https://sophiagracelondon.com (the “Website”).
2. Information We Collect
We collect the following personal data to process your orders and improve your shopping experience:
- Name, billing and shipping address
- Email address and phone number
- Payment and transaction details
- IP address, browser information and device identifiers
- Order history and account preferences
- Marketing preferences and feedback
3. How We Use Your Data
We use your data to:
- Fulfil and deliver your orders
- Process secure payments
- Provide customer support and respond to enquiries
- Send marketing communications (with your consent)
- Improve our website and user experience
- Detect and prevent fraud
Legal bases for processing: contract performance, legal obligation, consent, and legitimate interest.
4. Sharing of Information
We only share personal data with trusted third parties essential for operating our business:
- Payment providers (e.g. Shopify Payments, PayPal)
- Shipping carriers (e.g. DHL, FedEx)
- Analytics and advertising partners (Google Analytics, Meta Pixel)
All third parties are required to process data securely and in accordance with the UK GDPR.
Our store is hosted on Shopify Inc., which provides the e-commerce platform enabling us to sell our products. Shopify processes your data on our behalf in accordance with the UK GDPR and its Data Processing Addendum.
5. Data Retention
We keep order and billing records for up to seven (7) years to meet tax and legal obligations. Data used for marketing is retained until you unsubscribe or request deletion.
6. International Data Transfers
When transferring data outside the UK or EEA, we rely on lawful safeguards such as Standard Contractual Clauses approved by the UK ICO.
7. Your Rights
Under the UK GDPR you have the right to:
- Access, correct or delete your personal data
- Restrict or object to processing
- Withdraw consent at any time
- Request data portability to another provider
- Lodge a complaint with the Information Commissioner’s Office (ico.org.uk)
To exercise these rights, email info@sophiagracelondon.com.
8. Cookies and Tracking
We use cookies to operate our store, analyse performance and deliver personalised offers.
You can manage your preferences at any time via the Cookie Settings link in our footer.
For full details, see our Cookie Policy.
9. Security
We apply appropriate technical and organisational measures to secure your data against loss, misuse or unauthorised access.
All payment information is processed via PCI-DSS certified providers, and sensitive details such as full card numbers are never stored on our servers.
10. Third-Party Links
Our website may contain links to external websites not operated by us. We are not responsible for their privacy practices and encourage you to review their policies.
11. Updates to This Policy
We may update this Privacy Policy to reflect operational or legal changes. The latest version will always appear on this page.
12. Contact Information
Data Protection Officer:
Sophia & Grace London
Hekelhof 18, 2201 ET Noordwijk aan Zee, The Netherlands
Email: info@sophiagracelondon.com | Tel: +31 6 5289 2379
This policy applies exclusively to Sophia & Grace London and not to any other entities managed by Back on Rails | Digital Marketing.
Related Policies:
Shipping Policy | Return & Refund Policy | Cookie Policy