Last updated: March 2026
When you register for an account, we collect your name, email address, and password (stored securely as a hash — we never store your actual password). You may also optionally provide your phone number and delivery address. When you make a purchase, we collect payment information. We also collect browsing data such as pages visited and search queries to improve our service.
When you submit a contact form or quote request, we collect your name, email address, and the content of your message. We process this data only with your explicit consent, which you provide by ticking the consent checkbox on each form.
We will never sell your personal data to third parties. We do not use your data for automated decision-making or profiling.
Under UK GDPR, we process your data on the following legal bases:
We retain your data for the following periods:
We take data security seriously. Payment information is processed securely by our payment provider (Shopify Payments) and is never stored on our servers. We use SSL/TLS encryption for all data transmission. Passwords are hashed using industry-standard algorithms and cannot be viewed by anyone, including our staff.
We use essential cookies to enable core website functionality (shopping basket, authentication). We also use functional cookies for personalisation and third-party cookies for embedded content. Non-essential cookies are only set with your consent via our cookie banner.
For full details on the cookies we use, their purposes, and how to manage them, please see our Cookie Policy.
We share data with the following third-party services as necessary to operate our business:
| Service | Purpose | Data Shared |
|---|---|---|
| Shopify | E-commerce platform, checkout and payment processing | Order details, billing and shipping address, payment information |
| Royal Mail | Order delivery and tracking | Shipping name and address |
| Elfsight | Instagram feed widget (requires cookie consent) | No personal data (public Instagram content only) |
| Supabase | Database hosting for user accounts | Account information (name, email, hashed password) |
Each service has its own privacy policy governing how they handle data.
Your account data (name, email, phone, and address) is stored securely in our database. You can update your profile information at any time from your account page. If you wish to delete your account and all associated data, please contact us at support@ethanscards.co.uk and we will process your request within 30 days.
Under UK GDPR, you have the following rights:
To exercise any of these rights, contact us at support@ethanscards.co.uk. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Our website and products are intended for users aged 16 and over. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
We may update this policy from time to time. Any changes will be posted on this page with an updated “Last updated” date. We encourage you to review this policy periodically.
For any privacy-related enquiries, please contact us at support@ethanscards.co.uk.
Data controller: Ethan's Cards (sole trader), United Kingdom.