Last Updated: January 2026
1. Introduction
Welcome to the Privacy Policy of chomchom.co.uk (“we”, “us”, or “our”).
We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you as to how we look after your personal data when you visit our website (regardless of where you visit it from) and tell you about your privacy rights and how the law protects you.
This policy is compliant with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Who We Are
Controller
For the purposes of the UK GDPR, chomchom.co.uk is the controller and responsible for your personal data.
Contact Details
If you have any questions about this privacy policy, please contact us:
- Email address: [email protected]
- Website: https://chomchom.co.uk
3. The Data We Collect About You
We may collect, use, store, and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data: Includes first name, last name, username, or similar identifier.
- Contact Data: Includes billing address, delivery address, email address, and telephone number.
- Financial Data: We do not store your full credit card details. Payment transactions are processed via secure third-party payment providers (e.g., PayPal, Stripe, Apple Pay).
- Transaction Data: Includes details about payments to and from you and other details of products you have purchased from us.
- Technical Data: Includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
4. How We Use Your Personal Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Performance of Contract: Where we need to perform the contract we are about to enter into or have entered into with you (e.g., processing your order and delivering the goods).
- Legitimate Interests: Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests (e.g., for fraud prevention or improving our website).
- Legal Obligation: Where we need to comply with a legal obligation (e.g., tax and accounting purposes).
5. Disclosures of Your Personal Data
We may share your personal data with the parties set out below for the purposes set out in Section 4:
- Service Providers: Acting as processors who provide IT and system administration services.
- Delivery Partners: Third parties such as Royal Mail, Evri, or DPD for the purpose of delivering your order.
- Payment Processors: Such as PayPal or Stripe to facilitate secure payments.
- Professional Advisers: Including lawyers, bankers, auditors, and insurers.
- HM Revenue & Customs (HMRC): Regulators and other authorities based in the United Kingdom who require reporting of processing activities in certain circumstances.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law.
6. International Transfers
If we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data.
- Where we use certain service providers, we may use specific contracts approved for use in the UK which give personal data the same protection it has in the UK.
7. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know.
8. Data Retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.
9. Your Legal Rights
Under the UK GDPR, you have rights in relation to your personal data, including the right to:
- Request access to your personal data.
- Request correction of your personal data.
- Request erasure of your personal data.
- Object to processing of your personal data.
- Request restriction of processing your personal data.
- Request transfer of your personal data.
- Right to withdraw consent.
If you wish to exercise any of the rights set out above, please contact us at [email protected].
10. Third-Party Links
This website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements.
Cookie Policy
Please refer to our Cookie Banner/Settings to manage your consent regarding cookies used on this website.
