This Privacy Policy explains how the merchant operating brewcrew.shop under the Brew Crew trade name collects, uses, discloses, retains, and protects personal information. It also explains choices and rights. The Privacy Officer may be contacted at info@brewcrew.shop. This policy is designed for a Shopify-powered UK online store and must be kept aligned with the store's actual apps, settings, and business practices.
This policy applies when an individual visits the website, creates an account, makes or attempts a purchase, joins a mailing list, submits a form or review, communicates with support, participates in a promotion, or otherwise interacts with the store. It does not govern a third party's independent website or service, even when linked from the store.
For personal information used to operate the store and customer relationship, the merchant is responsible for deciding why and how the information is handled. Shopify provides the commerce platform and may process information for the merchant or for Shopify's own stated purposes, depending on the feature. Payment providers, carriers, app providers, analytics vendors, advertising partners, and other suppliers have their own roles and legal duties.
Personal data is handled under the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and relevant amendments made by the Data (Use and Access) Act 2025. The merchant must identify its actual controller identity, purposes, lawful bases, processors, retention periods, international transfers, and registration or fee obligations.
Core duties include lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Nothing in this policy should be read as selecting a lawful basis that does not match the store's actual processing.
The merchant is accountable for personal information under its control, including information transferred to a service provider for processing. The Privacy Officer coordinates questions, access or correction requests, complaints, incident response, retention practices, and review of service-provider arrangements. The public contact for the Privacy Officer is info@brewcrew.shop.
The merchant should maintain a privacy management program proportionate to the sensitivity and volume of information it handles. That program includes documented purposes, access controls, service-provider review, staff instructions, retention and destruction practices, incident response, complaint handling, and periodic checks that this published policy matches the technologies and actual practices in use.
We may collect identifiers and contact details such as name, billing and delivery address, email address, telephone number, account username, and communication preferences. We collect order information such as products viewed or purchased, quantities, price, discount, tax, delivery option, returns, support history, gift message, and transaction status.
When a customer contacts us, we collect the content of the message and attachments supplied, which may include photographs, video, model or serial numbers, proof of purchase, packaging, delivery labels, and information needed to diagnose or resolve an issue. A customer should avoid sending unnecessary sensitive information and should obscure unrelated payment or identity details.
Payments are generally processed by Shopify Payments or another payment provider selected at checkout. The store normally receives transaction status, amount, currency, payment method type, billing verification results, risk signals, and limited account details such as the last digits or token, but does not need to receive or store a complete card number or security code.
Payment providers collect and use information under their own terms and privacy notices, including for authorization, fraud prevention, chargebacks, regulatory checks, and settlement. If financing, instalments, digital wallets, or buy-now-pay-later services are offered, the provider may make an independent eligibility or credit decision. Customers should review the provider's notice before choosing that method.
When a person uses the site, servers and commerce tools may collect internet protocol address, browser type, device type, operating system, language, approximate location derived from network information, referring and exit pages, timestamps, session identifiers, pages viewed, searches, cart actions, checkout events, errors, and security or fraud signals.
This information helps deliver pages, remember preferences, secure accounts, keep carts functioning, measure performance, detect abuse, troubleshoot errors, understand navigation, and improve merchandising. We seek to avoid using precise location, sensitive inference, or persistent cross-site tracking unless the feature is disclosed, lawfully configured, and supported by appropriate consent or another legal basis.
The store may use cookies, pixels, local storage, tags, software development kits, and similar technologies for checkout, security, preferences, analytics, performance, and advertising. Strictly necessary technologies may be used without consent where the law permits. Non-essential storage or access technologies are used only after valid consent or another applicable exemption.
A cookie banner or preference centre should provide clear information and a genuine choice before non-essential technologies operate. Customers can change available choices through the store controls and browser settings, although blocking essential technologies may prevent checkout or account features from working. Installed Shopify apps and advertising tags must match the choices described.
We use personal information to present the store, create and maintain accounts, process payments, accept or decline orders, provide order confirmation, fulfil and deliver purchases, support returns and warranties, communicate about service issues, maintain transaction records, prevent fraud, protect customers and systems, comply with law, and establish or defend legal claims.
We also may use information to understand product demand, measure site performance, improve navigation, personalize content or recommendations, request feedback, administer promotions, and market products. Non-essential marketing, profiling, or advertising uses are subject to the consent and choice mechanisms required by applicable law. We do not condition a purchase on consent to unnecessary marketing.
We seek meaningful consent by explaining, in accessible language, what information is collected, the purposes, relevant third-party disclosures, and reasonably foreseeable consequences. Consent may be express or implied depending on sensitivity, reasonable expectations, and law. Express consent is generally used for sensitive information or an unexpected use that creates a meaningful residual risk of harm.
An individual may withdraw consent for an optional use, subject to legal or contractual restrictions and reasonable notice. Withdrawal does not invalidate earlier lawful processing and may affect a requested feature. Information necessary to complete an order, detect fraud, comply with tax or accounting duties, resolve a dispute, or protect security may still be used without optional marketing consent where law permits.
Order information is shared as reasonably necessary with warehouses, suppliers, carriers, payment providers, fraud-prevention tools, customer-service systems, and technology providers. Each receives only the categories appropriate to its role, such as a carrier receiving contact and address information needed for delivery or a warehouse receiving product and packing details.
Support records are used to authenticate the request, understand the history, document decisions, coordinate with providers, and improve service. Calls or chats are not recorded unless a notice is provided where required. Photographs or diagnostic evidence should be limited to the product and issue. We do not ask for passwords or full payment-card details through ordinary email.
The store is powered by Shopify. Shopify processes customer and merchant information to provide commerce infrastructure, checkout, hosting, security, fraud prevention, analytics, and other enabled services. In some contexts Shopify acts on the merchant's instructions, while in others it determines its own purposes under its privacy policy, for example certain Shop, Shop Pay, security, or network features.
Shopify may use vendors and infrastructure in multiple jurisdictions. Customers can review Shopify's consumer privacy notice and privacy controls for information about Shopify's own practices. Questions about this merchant's order, marketing choices, or use of data should be directed to the merchant first; questions about Shopify's independent processing may need to be directed to Shopify.
We may engage providers for hosting, commerce, payment, fraud screening, order management, warehousing, shipping, customer support, email, analytics, advertising, reviews, accounting, professional advice, security, and data storage. Providers are expected to use personal information only for authorized services or another lawful disclosed purpose and to protect it with measures appropriate to sensitivity.
Before enabling a provider, the merchant should assess what information the tool receives, where it is processed, its retention, permissions, contract, security, and privacy settings. Removing an app from Shopify does not necessarily erase information already held by the provider; offboarding should include revoking access and requesting return or deletion where appropriate.
If enabled, analytics providers may help measure visits, conversions, device patterns, and campaign performance. Advertising partners may use identifiers, cookie data, or event information to measure ads or show relevant content. Depending on applicable law, this activity may be treated as targeted advertising, sharing, profiling, or another regulated practice requiring notice, consent, or an opt-out.
The store should configure Shopify Customer Privacy settings, cookie controls, and advertising integrations for each market in which it operates. A user may change available choices through the cookie banner, privacy link, provider controls, or browser settings. Opting out of targeted advertising does not necessarily stop contextual advertising or essential measurement that law permits.
Email and text marketing to individuals is sent in accordance with the Privacy and Electronic Communications Regulations 2003 and data-protection law. We use consent or, where every condition is satisfied, the existing-customer soft opt-in for our own similar products and services. Marketing messages identify the sender and include a clear, readily usable opt-out.
We keep appropriate consent and suppression records and honour objections or opt-outs promptly. Opting out of marketing does not prevent non-promotional order confirmations, delivery updates, security notices, product recalls, warranty communications, or requested customer support.
We may disclose personal information when reasonably necessary to comply with applicable law, a court order, subpoena, warrant, regulatory requirement, tax or customs obligation, lawful request, product safety process, or to protect rights, safety, systems, customers, or the public. We assess requests and disclose only what we reasonably believe is required or permitted.
Information may also be disclosed in connection with a proposed or completed financing, merger, acquisition, reorganization, insolvency, sale of assets, or transfer of the store, subject to appropriate confidentiality and lawful-use conditions. If control changes, the successor must handle personal information consistently with applicable law and any commitments that continue to apply.
Shopify and other providers may process or store information outside the customer's part of the United Kingdom or outside the United Kingdom. While in another jurisdiction, information may be subject to that jurisdiction's laws and may be accessible to courts, law enforcement, national security, or regulatory authorities in accordance with those laws.
The merchant remains accountable for information transferred to a provider for processing to the extent required by applicable UK law. Reasonable steps may include contract terms, security review, access limits, incident duties, and transparency. A customer may ask the Privacy Officer for general information about relevant processing locations or provider categories.
We retain personal information only as long as reasonably necessary for identified purposes and legal obligations. Order, invoice, tax, accounting, warranty, fraud, and dispute records may be kept for several years and are generally retained for up to seven years after the relevant transaction or longer when a specific law, claim, investigation, or hold requires it. Marketing records are kept until consent is withdrawn or the purpose ends, with suppression records retained to honour an opt-out.
Support, website, analytics, and security records have shorter or role-specific schedules where practical. When information is no longer required, we delete, securely destroy, or anonymize it, subject to backup cycles and technical constraints. Anonymization is used only where the information is not reasonably expected to identify an individual under the applicable legal standard.
We use administrative, technical, and physical safeguards proportionate to sensitivity, amount, distribution, format, and risk. Measures may include role-based access, unique accounts, multifactor authentication, encryption in transit, platform security features, secure payment processing, logging, backups, provider controls, staff instructions, patching, and procedures for verifying sensitive requests.
No internet transmission or storage system is perfectly secure. Customers should use strong unique passwords, protect devices and email accounts, sign out of shared devices, and contact us if they suspect unauthorized account activity. We will never ask a customer to send a password or complete card security code by ordinary email.
We investigate suspected loss, destruction, alteration, unauthorised disclosure of, or access to personal data; contain the incident; preserve evidence where appropriate; assess affected people and systems; and take reasonable remedial action. Relevant processors, professional advisers, insurers, payment partners, law enforcement, and regulators may be involved where lawful and necessary.
Where a breach is likely to result in a risk to individuals' rights and freedoms, the controller must notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours after becoming aware of it. Where the risk is high, affected individuals must also be informed without undue delay unless a lawful exception applies. All breaches should be documented, including the assessment and response.
We seek to keep personal information as accurate, complete, and current as necessary for the purpose. Customers can update some account information directly and should promptly correct delivery or contact details. We may verify a material correction before applying it, particularly when the request affects account access, delivery, payment, fraud risk, or another person's information.
A correction request should identify the disputed information and the accurate replacement. If we do not agree that a record should be changed, we explain the reason where required and may note the disagreement. Historical transaction records may be preserved rather than overwritten when accuracy, tax, audit, or dispute rules require an audit trail.
Subject to legal exceptions, an individual may ask whether we hold personal information about them, request access, ask for correction, withdraw optional consent, challenge compliance, or request information about our practices. Depending on applicable law, additional rights may include deletion, portability, de-indexing, cessation of dissemination, or information about automated decisions.
Send a request to the Privacy Officer at info@brewcrew.shop. Describe the request and the account or transaction involved. We may ask for proportionate identity verification and will not request more information than reasonably needed. We respond within the period required by applicable law, explain any lawful refusal, and provide information about available complaint or review channels.
Depending on the purpose, processing may rely on performance of a contract, legal obligation, legitimate interests supported by an appropriate assessment, consent, vital interests, or another lawful basis. Additional conditions are required for special-category or criminal-offence data. Consent can be withdrawn without affecting prior lawful processing.
Subject to conditions and exemptions, individuals may have rights to be informed, access, rectification, erasure, restriction, portability, objection, and safeguards relating to automated decision-making. Requests are verified proportionately and answered within the legal time limit.
If personal data is transferred outside the United Kingdom, we use an applicable adequacy regulation, recognised safeguard such as the UK International Data Transfer Agreement or UK Addendum, or another lawful transfer mechanism. The merchant must verify the actual locations and contractual arrangements of Shopify, apps, analytics, payment, support, and fulfilment providers.
The store is intended for adults and is not designed to collect personal data directly from children. Where a child uses the store, appropriate parent or guardian involvement is expected. We do not knowingly use a child's personal data for behavioural advertising.
Where consent is relied on for an information-society service offered directly to a child, the UK age and parental-authorisation rules must be considered. Age assurance must be proportionate and privacy-conscious. A parent, guardian, or young person may contact the Privacy Officer if information appears to have been provided inappropriately.
A privacy concern may be sent to the Privacy Officer at info@brewcrew.shop. Please describe the interaction, personal data, relevant dates, desired outcome, and supporting material. We will acknowledge and investigate the complaint within a reasonable time and explain the outcome or next step.
If the concern is not resolved, the individual may complain to the Information Commissioner's Office. The right to complain to the ICO does not prevent the individual from seeking another remedy available under law.
We may update this policy to reflect legal, platform, provider, technology, or business changes. The current version is posted with an effective date. If a change is material to consent or creates a new use or disclosure outside reasonable expectations, we provide additional notice and seek new consent where required. Earlier versions should be retained internally so the store can demonstrate what notice applied at a relevant time.
Thanks for subscribing!
This email has been registered!