Privacy Policy

Data Controller: AllHourChic.co.uk

Data Collection Purposes:

Data CategoryProcessing PurposeLegal Basis
Identity (name/email)Account creation; personalised shopping alerts; newsletter delivery (opt-in)Consent; Contractual
Technical (IP/device ID)Security monitoring; regional content optimisation; analyticsLegitimate Interest
CookiesBasket retention; affiliate attribution; UX personalisationConsent (via banner)
User-generated contentComment moderation; community engagementConsent

Third-Party Data Sharing:

  • Payment Processors: Stripe (PCI-DSS compliant) for premium guides.
  • Analytics: Self-hosted Plausible.io (EU-based, anonymised tracking).
  • Marketing: MailerLite (GDPR-compliant, EU servers) for newsletters.
  • Required Disclosures: Legal authorities under UK Investigatory Powers Act 2016.

Retention Schedule:

Data TypeRetention Period
Account data3 years post-account deletion
Financial records7 years (HMRC compliance)
Newsletter contactsUntil withdrawal of consent
Server logs12 months (rotated deletion)

Security Protocols:

  • Technical: AES-256 encryption; WAF protection; quarterly pentests.
  • Organisational: Staff GDPR training; data minimisation principles; breach notification within 72 hours.