Privacy policy
Last Updated: January 2025
Positive Kitchen & Co Ltd ("Positive Bakes", "we", "us") is committed to protecting your privacy. This policy explains how we collect, use, and protect your personal data when you use our website positivebakes.com.
What Personal Data We Collect
Information You Provide:
- Name, contact details, delivery addresses
- Payment and billing information
- Account profile information and preferences
- Product reviews and feedback
- Competition entries and survey responses
- Customer service communications
Information Collected Automatically:
- Website browsing activity and preferences
- Device information (IP address, browser type, operating system)
- Location data (with your consent)
- Cookies and tracking technologies data
Third-Party Information:
- Social media interactions and profile information
- Delivery tracking and confirmation data
- Payment processor transaction records
How We Use Your Personal Data
Order Fulfilment:
- Processing payments and delivering orders
- Managing your account and order history
- Providing customer service and support
Website Improvement:
- Personalising your browsing experience
- Analysing website performance and usage
- Testing new features and functionality
Marketing and Communications:
- Sending promotional emails and offers (with consent)
- Showing targeted advertising on our website and third-party platforms
- Social media advertising through Meta, TikTok, Google platforms
- Market research and customer feedback collection
Security and Fraud Prevention:
- Authenticating your account and providing secure payment processing
- Detecting, investigating or taking action regarding possible fraudulent, illegal, unsafe, or malicious activity
- Protecting public safety and securing our services
- Maintaining the integrity of our website and services
Legal and Compliance:
- Complying with legal obligations
- Responding to valid legal process, including law enforcement requests
- Enforcing our terms of service and policies
- Protecting our business and customer interests
Legal Basis for Processing
We process your data based on:
- Contract performance (fulfilling your orders)
- Consent (marketing communications, optional account features)
- Legitimate interests (improving our services, fraud prevention, business analytics)
- Legal obligations (tax, accounting, regulatory requirements)
Marketing and Advertising
Email Marketing
We may send promotional emails based on your preferences and purchase history. Unsubscribe anytime via email links or account settings.
Social Media Advertising
We use Meta (Facebook/Instagram), TikTok, and Google platforms to show targeted ads. This may involve sharing your email address with these platforms for customer matching.
Personalised Advertising
We use cookies and similar technologies to show relevant ads based on your browsing behaviour.
Global Privacy Control
If you visit our website with the Global Privacy Control opt-out preference signal enabled, we will automatically treat this as a request to opt-out for the device and browser that you use to visit the website.
Opt-Out Options
- Adjust cookie settings in your browser
- Update social media privacy settings
- Contact us to opt out of specific marketing activities
- Use the Global Privacy Control signal in supported browsers
Relationship with Shopify
Our services are hosted by Shopify, which collects and processes personal information about your access to and use of our services in order to provide and improve the services for you. Information you submit to our services will be transmitted to and shared with Shopify as well as third parties that may be located in countries other than where you reside, in order to provide and improve the services for you.
To help protect, grow, and improve our business, we use certain Shopify enhanced features that incorporate data and information obtained from your interactions with our store, along with other merchants and with Shopify. To provide these enhanced features, Shopify may make use of personal information collected about your interactions with our store, along with other merchants, and with Shopify.
To learn more about how Shopify uses your personal information and any rights you may have, you can visit the Shopify Consumer Privacy Policy.
Who We Share Data With
Service Providers:
- Payment processors (Braintree and other secure providers)
- Delivery companies (DPD, DHL, Royal Mail)
- Cloud hosting and IT service providers (including Shopify)
- Email marketing platforms
- Customer service and live chat providers
Advertising Partners:
- Meta (Facebook/Instagram advertising)
- Google (search and display advertising)
- TikTok (social media advertising)
- Analytics and tracking service providers
Legal Requirements:
- Law enforcement or regulatory authorities when legally required
- Professional advisors (lawyers, accountants)
- Fraud prevention agencies
Business Transfers:
- Potential buyers if we sell our business (with appropriate data protection safeguards)
International Data Transfers
Some of our service providers are based outside the UK/EU. We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by data protection authorities
- Adequacy decisions for certain countries
- Other appropriate security measures
Please note that we may transfer, store and process your personal information outside the country you live in, including through our relationship with Shopify and other international service providers.
Data Retention
We keep your data only as long as necessary:
- Account data: Until you close your account or request deletion
- Order history: 7 years for tax and accounting purposes
- Marketing data: Until you unsubscribe plus reasonable period for suppression
- Website analytics: Typically 26 months
Data Security
We use industry-standard security measures:
- SSL encryption for data transmission
- Secure payment processing via certified providers
- Access controls and staff training
- Regular security assessments and updates
Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee "perfect security." Any information you send to us may not be secure while in transit. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.
Your Rights
Under UK data protection law, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data (in certain circumstances)
- Restrict processing
- Data portability (receive your data in portable format)
- Object to processing (including marketing)
- Withdraw consent at any time
We will not discriminate against you for exercising any of these rights. We may need to verify your identity before we can process your requests. You may designate an authorized agent to make requests on your behalf, subject to verification requirements.
To exercise these rights, contact us using the details below.
Cookies and Tracking Technologies
What Are Cookies?
Cookies are small text files stored on your device when you visit websites. They help websites remember your preferences and improve your browsing experience.
Types of Cookies We Use
Strictly Necessary Cookies: Essential for website functionality including shopping basket, secure login, payment processing, and security.
Performance and Analytics Cookies: Help us understand website usage through Google Analytics, site performance monitoring, and A/B testing tools.
Functionality Cookies: Remember your preferences such as language settings, delivery addresses, and accessibility preferences.
Marketing and Advertising Cookies: Used by our advertising partners (Meta, Google, TikTok) to deliver relevant advertising and measure campaign effectiveness.
Social Media Cookies: Set when you interact with social media features on our site.
Managing Cookies
You can control cookies through:
- Your browser settings (Chrome, Firefox, Safari, Edge)
- Our cookie preference controls on the website
- Third-party opt-out tools like Google Analytics opt-out browser add-on
- Industry opt-out tools at youronlinechoices.eu
Other Tracking Technologies
We may also use web beacons, local storage, and device fingerprinting for analytics and security purposes.
For detailed information about our cookie practices, see our separate [Cookie Policy].
Children's Privacy
Our website is not intended for children under 18. We do not knowingly collect personal data from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us to request deletion.
Third-Party Websites and Links
Our services may provide links to websites operated by third parties. We are not responsible for the privacy practices of these sites. Please review their privacy policies before providing any information.
Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. We will notify you of significant changes via email or website notice.
Contact Us
For questions about this privacy policy or your personal data:
Email: hello@positivebakes.com
Phone: 0116 3406599 (Monday-Friday, 9am-5pm)
Address: Leicester Food Park, 42 High View Close, Leicester, LE4 9LJ
You can also contact the Information Commissioner's Office (ICO) if you have concerns about how we handle your data.
Complaints and Appeals
If you have complaints about how we process your personal information, please contact us using the contact details above. You have the right to lodge a complaint with the Information Commissioner's Office or appeal our decisions regarding your data protection rights.