Data Controller
Signature & Stone is the data controller responsible for your personal data. We are a UK-based business and take our obligations under the UK General Data Protection Regulation seriously. If you have any questions about how we handle your data, please get in touch.
Data We Collect
We collect the following personal data when you use our contact form or place an order:
- Name
- Email address
- Phone number (if provided)
- Project details and any other information you choose to share with us through the contact form
- Delivery address and billing address (for orders)
We do not collect any special categories of personal data (such as health information or racial origin).
How We Use Your Data
We use your personal data for the following purposes:
- To respond to enquiries submitted through our contact form
- To process and fulfil your order, including delivery
- To communicate with you about your order status
- To send service-related communications (such as despatch notifications)
Legal Basis for Processing
We process your data on the following legal bases:
- Contract: Where you place an order, we process your data as necessary to fulfil that contract.
- Legitimate interests: Where you submit an enquiry, we process your data to respond to that enquiry. We consider this use proportionate and not overridden by your rights.
Data Sharing
We share your personal data only with the following third parties, as strictly necessary to fulfil your order:
- Payment processors (to handle your payment securely)
- Delivery carriers (to despatch your order to the provided address)
We do not sell, rent, or otherwise share your data with third parties for marketing purposes. Our payment processor and delivery partners are required to handle your data only for the purpose of providing their service to us.
Data Retention
We retain your personal data only for as long as is necessary for the purpose for which it was collected. For order data, this means we retain your information for a minimum of 6 years to comply with our financial record-keeping obligations. Enquiry data is retained for 12 months from the date of last contact if no order is placed.
Cookies
Our website uses minimal cookies. We use only essential session cookies required for basic site functionality. We do not use tracking cookies, analytics cookies, or advertising cookies. There is no cookie consent banner required for our site.
Your Rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you.
- Rectification: Request that we correct any inaccurate data.
- Erasure: Request that we delete your data, subject to our legal retention obligations.
- Portability: Request that we provide your data in a structured, machine-readable format.
- Object: Object to our processing of your data on grounds relating to your specific situation.
To exercise any of these rights, please contact us using the details below. We will respond to valid requests within one month.
Contact
If you have any questions about this privacy policy, wish to exercise your rights, or have a concern about how we handle your data, please use the contact section on our website. We take data protection seriously and welcome the opportunity to address any concerns.