Data protection
Privacy notice
This notice explains what personal data we collect when you use this site or buy from us, why we collect it, how long we keep it, and what you can require us to do about it. It is written to the UK GDPR and the Data Protection Act 2018.
Last updated 12 August 2026
Who is responsible for your data
The data controller is THE JEWELLERS LTD, a Private Limited Company registered in England and Wales, trading as Everyworn.
22 The Square
The Millfields
Plymouth, Devon
PL1 3JX
United Kingdom
Email support@thejewellersuk.shop · Telephone +44 7338 821417
Data protection enquiries and rights requests go to the same address, marked for the attention of the data protection contact.
What we collect and why
We collect the minimum needed to sell you a piece of jewellery and get it to you. We do not build profiles, we do not sell data, and we do not use automated decision-making or profiling that produces legal or similarly significant effects.
| Category | What it contains | Lawful basis | Kept for |
|---|---|---|---|
| Order details | Name, email, phone, delivery address, items ordered, order value | Performance of the contract (UK GDPR Art. 6(1)(b)) | 6 years from the end of the tax year of the transaction |
| Engraving text | The words you ask us to cut into a piece | Performance of the contract (Art. 6(1)(b)) | Deleted 90 days after dispatch, or sooner on request once the order is complete |
| Payment confirmation | The fact of payment, amount, last four digits and card type as supplied by the payment provider | Performance of the contract and legal obligation (Art. 6(1)(b) and (c)) | 6 years from the end of the tax year of the transaction |
| Contact messages | Name, email, optional phone, subject, message content | Legitimate interests — answering enquiries (Art. 6(1)(f)) | 24 months from the last message in the thread |
| Sizing enquiries | Name, email, finger measurement, existing ring diameter, preferences | Legitimate interests — giving you a size recommendation (Art. 6(1)(f)) | 12 months |
| Marketing list | Email address and the date you opted in | Consent (Art. 6(1)(a)), PECR Reg. 22 | Until you unsubscribe, then a suppression record indefinitely so we do not email you again |
| Site analytics | Pages viewed, approximate region, device and browser type | Consent (Art. 6(1)(a)) — set only if you accept in the cookie banner | 14 months |
| Server logs | IP address, timestamp, request path, user agent | Legitimate interests — security and fraud prevention (Art. 6(1)(f)) | 30 days |
We do not knowingly collect data from children. Orders may only be placed by adults aged 18 or over. If you believe a child has given us data, tell us and we will delete it.
We do not collect special category data. Please do not send us health information — including any account of a skin reaction — beyond what is necessary for us to help, and be aware that if you do send it, it will be held with your enquiry.
A note on legitimate interests
Where we rely on legitimate interests we have balanced our interest against your rights. For enquiries, our interest is being able to answer you; the data is minimal, you supplied it deliberately, and you can ask us to delete it. For server logs, our interest is keeping the site secure; the data is short-lived and is not used to identify individuals for any other purpose. You can object to either — see your rights.
How long we keep things
Retention periods are in the table above. The six-year period on order and payment records is set by our obligations under UK tax law, and we cannot delete those records earlier even on request — but we will restrict their use to that legal purpose alone if you ask.
Engraving text is treated more strictly than the rest of the order because it is often personal in content. It is used for production and is deleted 90 days after dispatch, or immediately on request once the order is complete and the withdrawal period has passed.
Transfers outside the UK
Our hosting and email providers may process data outside the United Kingdom, including in the European Economic Area and the United States. Where that happens the transfer is protected either by UK adequacy regulations, or by the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. You can ask us for details of the mechanism used for any specific transfer.
Security
The site is served over HTTPS. Access to order data is restricted to the people who need it to fulfil orders, protected by individual accounts and multi-factor authentication. Card data never reaches our systems. We keep only what is listed above, because the most reliable way to protect data is not to hold it.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where the risk is high, tell you directly and without undue delay.
Your rights
Under the UK GDPR you have the right to:
- Be informed — this notice.
- Access a copy of the personal data we hold about you.
- Rectification of data that is inaccurate or incomplete.
- Erasure where we no longer need the data, or where you withdraw consent and there is no other basis for keeping it.
- Restrict processing while a dispute about accuracy or legitimate interests is resolved.
- Data portability — a machine-readable copy of the data you gave us where processing is based on consent or contract.
- Object to processing based on legitimate interests, and to direct marketing at any time and absolutely.
- Withdraw consent at any time where consent is the basis, without affecting processing already carried out.
To exercise any of these, email support@thejewellersuk.shop. We respond within one month. That can be extended by two further months for complex requests, and we will tell you within the first month if it is. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to confirm your identity before releasing data.
Complaining to the ICO
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection.
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
Helpline 0303 123 1113 · ico.org.uk/make-a-complaint
Complaining to the ICO does not affect any other legal remedy available to you.
Changes to this notice
We update this notice when what we do with data changes. The date at the top shows when it last changed. Where a change materially affects you we will tell you directly. See also our cookie notice.