Privacy Policy
Effective date: November 2025
1. Who we are
The Goodie Crate UK (“we”, “us”, “our”) is a UK-based sole trader business that curates and delivers artisan goodie crates from local makers.
Contact: hello@thegoodiecrate.com
We are the “data controller” of the personal information we collect, meaning we decide how and why your data is used.
2. What information we collect
We collect:
- Contact details — your name, email address, phone number, and delivery address.
- Taste preferences — information you provide about your likes/dislikes so we can tailor your crate.
- Payment details — processed securely by Stripe. We do not store your card details.
- Order history and communications — messages, feedback, or support requests.
3. How we use your information
We use your information to:
- Process and deliver your orders.
- Personalise crate contents to your preferences.
- Contact you about your order or account.
- Send occasional updates (only if you’ve opted in).
- Comply with legal and accounting obligations.
Third-Party Services
To provide and improve our services, we use the following third-party service providers:
- Stripe – securely processes your payments. We do not store your card details.
- Brevo (Sendinblue) – manages email communications and newsletters for users who opt in.
- Firebase – provides hosting, database, and authentication services. Data is stored in accordance with Firebase policies.
- PukkaHost / Stackmail – provides email services for customer communication.
We only share the minimum necessary personal data with these providers to perform their services. All third-party services we use comply with GDPR and implement appropriate security measures.
We do not sell or share your personal data for marketing purposes.
4. Legal basis for processing
Under UK GDPR, we process personal data based on:
- Contract: to fulfil your order.
- Consent: when you opt in to marketing or provide taste preferences.
- Legal obligation: for record-keeping and tax purposes.
5. How we store and protect your data
- Your data is stored securely on password-protected systems.
- We only keep data as long as necessary for order fulfilment, accounting, or legal reasons.
- Stripe securely processes payments in accordance with PCI-DSS standards.
6. Your rights
You have the right to:
- Access, correct, or delete your personal data.
- Withdraw consent at any time.
- Request a copy of your data.
To exercise your rights, contact hello@thegoodiecrate.com.
If you have concerns, you can also contact the Information Commissioner’s Office (ICO) at ico.org.uk.
7. Cookies
We may use cookies to improve your browsing experience and remember preferences. You can manage cookies in your browser settings.
8. Updates to this policy
We may update this policy from time to time. The latest version will always be posted on our website.
