Home

Privacy Policy

Last updated · April 15, 2026

We take privacy seriously. This policy explains what we collect, why we collect it, how we use it, and the rights you have over your data. It applies to everyone who uses our site or buys from us.

1. What we collect

We collect only what we need to fulfil your order and run the site:

  • Order data: name, shipping address, email, phone (optional), and order details.
  • Payment data: processed and stored by our payment provider. We do not see or store your full card number.
  • Customisation content: the photograph you upload and the crop settings you choose, stored only for production and customer-service purposes.
  • Technical data: device, browser, language, pages visited, approximate location, cookie IDs.
  • Marketing consent: if you opt in to emails, we keep a record of when and how you consented.

2. Why we use it

  • To take your order, produce the product, and ship it to you.
  • To provide customer service, handle returns, and prevent fraud.
  • To comply with tax, invoicing, and consumer-protection laws.
  • To improve the site, measure performance, and keep it secure.
  • To send you marketing emails, only if you opt in, and only until you unsubscribe.

3. Legal bases (GDPR)

  • Contract: to fulfil your order.
  • Legal obligation: for tax, accounting, and consumer-law records.
  • Legitimate interest: to secure the site, detect fraud, and improve our product.
  • Consent: for marketing emails and non-essential cookies.

4. Who we share data with

We only share data with providers we need to run the service:

  • Payment provider: handles your payment and related compliance.
  • E-commerce platform: stores order and customer data.
  • Production and fulfilment partner: receives your photograph, crop settings, order specs, and shipping address in order to print, pack, and ship your order.
  • Shipping carriers: receive your address and contact details to deliver the order and handle tracking notifications.
  • Analytics and advertising vendors: receive pseudonymised technical data, only if you've accepted the relevant cookies.
  • Email provider: receives your address and name to send order confirmations and (if opted in) marketing.

We select providers that offer adequate data-protection guarantees.

4a. International transfers and where we operate

The business operating this site is established in the United Kingdom. Your personal data is controlled by us in the UK and is subject to UK data-protection law (the UK GDPR and the Data Protection Act 2018).

For customers in the European Economic Area (EEA): transfers of your personal data from the EEA to the United Kingdom are covered by the European Commission's adequacy decision for the UK, which recognises that the UK provides an essentially equivalent level of data protection to the GDPR. This means your data flows freely and lawfully to the UK without the need for additional transfer safeguards.

Onward transfers to our production partner in China: to print and ship your order, we transfer order details and the photograph you upload to our production and fulfilment partner located in China. This transfer is covered by:

  • The UK International Data Transfer Agreement (IDTA) and, where applicable, the EU Standard Contractual Clauses (SCCs) with our processor;
  • Supplementary technical and organisational measures — encryption in transit, limited-access processing, minimised retention, and deletion of production files after order completion.

Shipping carriers also process your delivery address in the destination country. You can request a copy of the relevant safeguards by emailing privacy@pieceful.co.uk.

5. How long we keep it

  • Order records: kept for seven years to meet tax and accounting law.
  • Uploaded photographs: kept for 180 days after the order ships, then deleted. You can request earlier deletion once your order is delivered.
  • Marketing contact: kept until you unsubscribe.
  • Cookies: as described in the cookie banner on first visit. Essential cookies are kept for the session only.

6. Your rights

Under GDPR and equivalent laws, you can:

  • Ask for a copy of the data we hold on you.
  • Ask us to correct it if it's wrong.
  • Ask us to delete it (with exceptions for legal-retention records).
  • Ask us to restrict or object to certain processing.
  • Ask us to transfer your data to another provider.
  • Withdraw your consent to marketing at any time.

To exercise any of these, email privacy@pieceful.co.uk. You also have the right to lodge a complaint with your national data-protection authority.

7. Security

We use encryption in transit (HTTPS), access controls, and segregated production environments. No system is completely immune to incidents; if a breach does occur that is likely to affect you, we will notify you and the relevant authority as required by law.

8. Children

The site and products are not intended for children under 16. We do not knowingly collect data from minors.

9. Changes to this policy

If we make material changes, we will notify users by email (for registered customers) or via a prominent banner on the site. Minor updates will simply be reflected in the "Last updated" date above.

10. Contact

Privacy questions? privacy@puzzelkoning.com.