Privacy Policy
Privacy Policy
Effective date: 1 October 2025 | Last updated: 1 October 2025
This Privacy Policy explains how Bessie Bae Ltd (“we”, “our”, “us”) collects, uses, shares and protects your personal information when you browse our site or make a purchase.
Jump to:
- 1. Who we are & data controller
- 2. Information we collect
- 3. How we use your data (lawful bases)
- 4. Sharing your data
- 5. International transfers
- 6. Data retention
- 7. Your rights (UK GDPR)
- 8. Cookies & similar tech
- 9. Security
- 10. Contact
1. Who we are & data controller
Data Controller: Bessie Bae Ltd (trading as “Bessie Bae”).
We are responsible for the personal data we process under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information we collect
Identity & contact data: name, email, phone, billing & shipping address.
Order & transaction data: items purchased, order numbers, payment amount (payments are processed securely by third-party providers; we don’t store full card details).
Technical & usage data: device/browser info, IP address, pages viewed, interactions (via cookies/analytics).
Marketing preferences: opt-in/opt-out choices.
Communications: messages you send us (e.g., customer support).
We do not intentionally collect special category data.
3. How we use your data & lawful bases
Process and deliver your orders: confirmations, dispatch, and fulfilment. Lawful basis: Contract.
Customer care: returns, repairs, and support. Lawful basis: Contract & Legitimate Interests.
Personalise and improve our site: analytics and performance. Lawful basis: Legitimate Interests.
Legal/administrative purposes: fraud prevention, accounting, tax and audit. Lawful basis: Legal Obligation & Legitimate Interests.
Marketing: emails or ads (only with consent). Lawful basis: Consent.
4. Sharing your data
We only share data with trusted third parties to provide our services, for example:
- Shopify (ecommerce platform & hosting)
- Payment processors (e.g., PayPal, card gateways)
- Delivery partners (e.g., Royal Mail, couriers)
- Analytics & IT providers
5. International transfers
Some providers may process data outside the UK (e.g., Canada/USA). Where this occurs, we rely on appropriate safeguards such as adequacy regulations and/or Standard Contractual Clauses (SCCs).
6. Data retention
We keep data only as long as necessary. Typical periods include:
- Orders & invoices: 6 years
- Support messages: up to 24 months
- Marketing data: until consent is withdrawn
- Analytics cookies: per cookie settings
7. Your rights (UK GDPR)
You have the right to access, rectify, erase, restrict, object, request portability, and withdraw marketing consent. You can complain to the ICO if unhappy with our response.
8. Cookies & similar technologies
We use cookies for functionality, performance, and analytics. You can manage preferences via our cookie banner or browser settings. See our Cookie Policy for details.
9. Security
We use administrative, technical, and organisational measures to protect your data. Shopify provides secure, PCI-DSS compliant hosting. No online system is 100% secure.
10. Contact
Bessie Bae Ltd
89 Godley Road, London, SW18 3HA
Company Number: 16831651 (registered in England and Wales)
Email: privacy@bessiebae.co.uk
Or use our Contact Us page.