Skip to content
Every set you love helps someone else shine — give a set today

Privacy Policy

Last updated: 18 August 2026

This policy explains what personal data Fruity & Frilly collects when you use fruityandfrilly.co.uk or our app, why we collect it, who we share it with, and the rights you have over it. We are the “data controller” for that information under the UK GDPR and the Data Protection Act 2018.

We keep this deliberately plain. If anything here is unclear, email info@fruityandfrilly.co.uk and we'll explain it properly.

What we collect

Depending on how you use the site, we may hold:

  • Account details — your name, email address and a securely hashed password. We never store your password itself.
  • Order information — what you bought, delivery and billing address, phone number if you give one, order value, and delivery tracking details.
  • Payment information — handled entirely by Stripe. Card numbers never reach our servers; we only receive a payment reference and whether it succeeded.
  • Marketing preferences — whether you've opted in to emails or SMS, and when you gave or withdrew that consent.
  • Things you create — reviews, wishlist items, your basket, gift-card purchases, and Give a Set donations.
  • Technical data — a session cookie so you stay signed in, and basic server logs (including IP address) used for security and diagnosing faults.

Why we use it, and our lawful basis

  • To fulfil your order — taking payment, sending confirmations, delivering your parcel and handling returns. Lawful basis: performance of a contract.
  • To run and protect the shop — preventing fraud, keeping the site secure, and fixing problems. Lawful basis: our legitimate interests.
  • To send marketing — only where you've opted in, and you can unsubscribe from any email or by changing your account settings. Lawful basis: consent.
  • To meet our legal duties — keeping records of sales for tax and accounting. Lawful basis: legal obligation.

We do not sell your personal data, and we do not use it to make automated decisions that have a legal or similarly significant effect on you.

Who we share it with

We share only what each provider needs to do its job:

  • Stripe — to take payments securely, and to process refunds. Stripe is the controller of your card data.
  • Our email provider — to send order confirmations, delivery updates, password resets and (if you opted in) marketing.
  • Delivery carriers — your name, address and contact details so your parcel can be delivered and tracked.
  • Our own team — new orders trigger an internal alert (which includes the order number, total and your email address) so we can pack quickly.

Our website and database run on our own servers rather than a third-party shop platform. Where a provider processes data outside the UK, that transfer is covered by UK-approved safeguards such as the International Data Transfer Agreement or adequacy regulations.

Cookies

We set a small number of essential cookies — to keep you signed in, remember your basket, and keep checkout secure. These don't need consent because the site cannot work without them.

Anything non-essential (such as analytics) is switched off until you opt in via the cookie banner, and you can change your mind at any time. Full detail is in our Cookie Policy.

How long we keep it

  • Order and payment records — six years after the end of the relevant tax year, which UK law requires us to keep.
  • Your account — for as long as you keep it. Delete it and we remove your personal details, keeping only what we must for the records above.
  • Marketing lists — until you unsubscribe or withdraw consent.
  • Server logs — a short rolling period for security and diagnostics.

Your rights

Under UK GDPR you have the right to:

  • ask for a copy of the personal data we hold about you;
  • have inaccurate details corrected;
  • ask us to delete your data (“the right to be forgotten”);
  • receive your data in a portable, machine-readable format;
  • restrict or object to how we use it, including for marketing;
  • withdraw consent at any time, without affecting anything done beforehand.

You can do the two most common ones yourself, immediately, from your account settings — export your data, or delete your account. For anything else, email info@fruityandfrilly.co.uk and we'll respond within one month.

Children's data

We sell children's swimwear, but our accounts are for adults. We don't knowingly create accounts for under-16s or market to them. Where you give us a child's size or name for an order, we use it only to fulfil that order. If you believe a child has given us personal data, contact us and we'll remove it.

Keeping it safe

The whole site runs over encrypted HTTPS. Passwords are stored as salted hashes, card details never touch our systems, and access to customer data is limited to the people who need it to run the shop. No system is perfect — if a breach ever affected your rights or freedoms, we would tell you and the ICO without undue delay.

Contact and complaints

For any privacy question, or to exercise a right, email info@fruityandfrilly.co.uk. Fruity & Frilly is based in York, United Kingdom; our full registered details are available on request.

If you're unhappy with how we've handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

Changes to this policy

If we change how we use your data, we'll update this page and the date at the top. Where the change is significant, we'll tell you directly.