Last updated: 1st January 2025

Hi there! I’m Emma, and I want you to feel completely comfortable shopping with Little BIG Gift Co. This Privacy Policy explains how I collect, use, and protect your personal information when you visit my website or purchase my handcrafted gifts.

I believe in transparency and treating your data with the same care and respect I put into every gift I create. If you have any questions about this policy, please don’t hesitate to get in touch.

Information I Collect

Information You Provide Directly

When you interact with Little BIG Gift Co, I may collect the following information:

  • Contact Details: Your name, email address, phone number, and postal address
  • Order Information: Details about products purchased, personalisation requests, and delivery preferences
  • Payment Information: Billing address and payment details (processed securely through trusted payment providers)
  • Communication: Messages you send through contact forms, emails, or social media
  • Account Information: If you create an account, your login credentials and preferences

Information Collected Automatically

When you visit my website, I automatically collect certain technical information:

  • Device Information: Your IP address, browser type, operating system, and device identifiers
  • Usage Data: Pages visited, time spent on the site, and how you navigate through my content
  • Cookies: Small data files that help improve your browsing experience (see Cookie Policy below)

How I Use Your Information

I use your personal information for the following purposes:

Order Fulfilment

Processing your orders, creating personalised items, arranging delivery, and providing customer support throughout your shopping journey.

  • Communication: Sending order confirmations, shipping updates, and responding to your enquiries
  • Personalisation: Creating custom products according to your specifications and preferences
  • Marketing: With your consent, sending newsletters about new products, special offers, and gift inspiration
  • Website Improvement: Analysing how you use my website to make it more user-friendly and helpful
  • Legal Compliance: Meeting legal obligations and protecting both your rights and mine

Legal Basis for Processing (UK GDPR)

Under UK GDPR, I process your personal data based on the following legal grounds:

Purpose Legal Basis
Processing and fulfilling orders Contract performance
Customer service and support Contract performance / Legitimate interest
Marketing communications Consent
Website analytics and improvement Legitimate interest
Legal compliance and fraud prevention Legal obligation / Legitimate interest

How I Share Your Information

I only share your personal information in the following circumstances:

Service Providers

I work with trusted third-party service providers who help me run my business:

  • Payment Processors: Secure payment handling (e.g., Stripe, PayPal)
  • Shipping Partners: Royal Mail, courier services for order delivery
  • Email Services: Newsletter and communication platforms
  • Website Hosting: Secure hosting and maintenance services
  • Analytics: Website performance and user behaviour analysis

All service providers are carefully selected and contractually required to protect your data and use it only for the specific services they provide to me.

Legal Requirements

I may share your information if required by law, to protect my rights, or to comply with legal proceedings.

Important Promise

I will never sell, rent, or trade your personal information to third parties for their marketing purposes. Your trust is too important to me.

Data Security

Protecting your personal information is a top priority. I implement several security measures:

  • Encryption: All sensitive data is encrypted both in transit and at rest
  • Secure Payment Processing: I use industry-standard payment processors that comply with PCI DSS standards
  • Access Controls: Only authorised personnel have access to personal data, and only when necessary
  • Regular Updates: Software and security systems are regularly updated and monitored
  • Secure Storage: Physical and digital storage systems are properly secured

Data Retention

I keep your personal information for as long as necessary to fulfil the purposes outlined in this policy:

  • Order Information: Retained for 7 years for accounting and legal compliance purposes
  • Marketing Data: Until you unsubscribe or withdraw consent
  • Website Analytics: Anonymised data may be retained longer for business insights
  • Customer Communications: Retained as long as necessary to provide ongoing support

Your Rights Under UK GDPR

You have several important rights regarding your personal data:

  • Right to Access: Request a copy of the personal data I hold about you
  • Right to Rectification: Ask me to correct any inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data in certain circumstances
  • Right to Restrict Processing: Limit how I use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to certain types of processing, including marketing
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent

To exercise any of these rights, simply get in touch using the contact details below. I’ll respond within one month of receiving your request.

Cookies Policy

My website uses cookies to enhance your browsing experience. Here’s what you need to know:

Essential Cookies

These cookies are necessary for the website to function properly, including shopping cart functionality and secure checkout.

Analytics Cookies

I use analytics cookies to understand how visitors interact with my website, helping me improve the user experience.

Marketing Cookies

With your consent, I may use cookies to personalise marketing content and measure campaign effectiveness.

You can manage your cookie preferences through your browser settings. However, please note that disabling certain cookies may affect website functionality.

International Data Transfers

Your personal data is primarily processed within the UK. However, some service providers may process data in other countries. When this happens, I ensure appropriate safeguards are in place, including:

  • Data Processing Agreements with adequate protection standards
  • Transfers to countries recognised as providing adequate protection
  • Use of standard contractual clauses approved by UK authorities

Children’s Privacy

Little BIG Gift Co’s products are intended for adults purchasing gifts. I do not knowingly collect personal information from children under 16 without parental consent. If I become aware that I have collected such information, I will take steps to delete it promptly.

Changes to This Policy

I may update this Privacy Policy from time to time to reflect changes in my business practices or legal requirements. When I make significant changes, I’ll notify you by:

  • Posting the updated policy on my website with a new “last updated” date
  • Sending an email notification if you’ve subscribed to my newsletter
  • Displaying a prominent notice on my website

Questions About Your Privacy?

If you have any questions about this Privacy Policy or how I handle your personal data, I’m here to help.

Email: privacy@littlebiggiftco.com

Post: Little BIG Gift Co, Little Studio, Creative Quarter, Happiness Street, Joy Town, Smiles County, JY1 2HA

Data Protection Authority

If you believe I haven’t addressed your concerns appropriately, you have the right to lodge a complaint with the UK’s data protection authority:

Information Commissioner’s Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113