Last updated: 23.05.2018 - To be reviewed a maximum of every 3 years.
The Vegan Crowd (Sophie Lamb) ("us", "we", or "our") operates (the "Site"). This page informs you of our policies regarding the collection, use and disclosure of Personal Information we receive from users of the Site. We use your Personal Information only for providing and improving the Site. By using the Site, you agree to the collection and use of information in accordance with this policy. Your privacy is protected by the Data Protection Act 1998, this act regulates the use of your personal data. We reserve the right to update and amend this policy during our policy reviews.
Purpose of policy:
We obtain your consent when you:
Contact us via email (Implicit consent)
Place an order or attempt to place an order
Sign up to our email newsletters
Except from the information stated below, we do not share, sell or disclose your information to anybody out of the business, including 3rd parties.
We use various methods to keep things secure including:
Password Protected Accounts
2 Step Verification Accounts
Computer Scanning Software
Identification Verification (When requesting Information)
Use of Secure Internet Connections
Use of website Encryption. (SSL/ Closed Padlock Symbol on a web browser)
Not storing card details
Not sharing customer details outside the business. (Exception: Name & Address you provide is written on your shipping label)
When placing an order you will be redirected to either PayPal or Stripe using HTTPS, so you can feel confident in the security of your information. All payment is taken securely (PCI compliant.) Our online store host (Ecwid) is a PCI-DSS validated Level 1 Service Provider which is the gold standard for e-commerce solutions worldwide.
Our website hosts (Wix) a SSL certificate. A Secure Sockets Layer, or SSL certificate, allows site visitors to view the site over an HTTPS connection. It secures the connection between your browser and the site you’re visiting. Hyper Text Transfer Protocol Secure (HTTPS) is the secure protocol through which your browser communicates with sites. When using HTTP sites, any data that is transferred can potentially be accessed or manipulated by attackers. However, when using HTTPS sites, data is encrypted and authenticated and therefore secured. Regular security and antivirus checks are done on our computer systems to help protect the site.
Data Recording/ Storage:
We rely on users to ensure the information they provide about themselves is accurate.
For example: When making a purchase our payment system vendors automatically check the billing address provided against the bank account information provided to prevent fraudulent activity. If for any reason this information has been input incorrectly, your transaction will be denied.
If your information needs to be updated you can let us know at firstname.lastname@example.org or you can update it on your online account if you choose to have one.
Your data is stored on cloud based systems with the exception of when labels are made to dispatch/ ship your products. Cloud based data such as your order information is retained on our store vendor to fulfil orders. PDF made labels will be deleted 1 month after use.
Use of our website is not intended for minors. If you are a minor and wish to use our services and purchase anything from our website you should get a responsible parent or guardian to do so for you.
Data usage outside of the European Union:
The Vegan Crowd is based in the United Kingdom. Sometimes we outsource services in other countries, for example, our online store platform Ecwid is based in the United States.
The services we use also abide by the same binding corporate rules regarding data processing, also known as the GDPR. You can see there individual policies via the links displayed in the section "Your Data: What we use and how we use it."
Right Of Access:
The right of access, commonly referred to as subject access, gives individuals the right to obtain a copy of their personal data as well as other supplementary information.
You may request:
confirmation that your personal data is being processed.
a copy of you personal data.
Requesting Information: You can request to see what data is held about you by contacting us at email@example.com To protect your information we will require Proof of Identification. When contacting us please state what information you would like to see and likely dates the information was processed. Requesting information is free of charge. However we reserve the right to charge a reasonable fee when a request is manifestly unfounded or excessive, particularly if it is repetitive.
Rectification: If there is inaccurate information we have held about you, you can let us know by contacting us. You can also update your information on your online account if you choose to have one.
Receiving your Information: We will provide the requested information once your Identification has been verified via the data we have held. Information will be sent via email. Requests will be responded to within one month.
Objection: You can object how we use your data. For example, if you wish for us to no longer send your email newsletters, you can opt out by changing your preferences. You can do this by emailing us for us to manually change or by clicking unsubscribe at the footer of any newsletter you have received from us.
Erasure: You may request we erase your data from our records when there is no legitimate reason for us to continue processing it. If data is required for legitimate interests requests may be declined.
Order reasons why you request may be declined:
If the request discloses information about another individual who can be identified from that information.
If a request is manifestly unfounded or excessive.
By creating an account on our online store, purchasing products or a service from us or otherwise agree to our terms and conditions a contract is formed. We lawfully and legitimately process your information on the basis of the contract formed. We will continue to process this information until the contract ends or is terminated by either part under the terms within the contract.
When signing up to our email newsletter subscription service we are processing your data on the lawful basis of consent, as you have chosen to opt into this service separate from our dispatch fulfilment processing. You can opt out of this whenever you wish to.
(For example: you have placed an order, but wish to cancel that order within 14 days of purchase. In this circumstance, after the transaction has been canceled and refunded under our terms and conditions, we can then delete your data if you wish. / If you place an order, and want to receive that order (ie. not cancel the order), we must use the information you have provided to fulfil that order.)
Consent can be withdrawn, but not retrospectively. There may be occasions where there is no choice but to retain data for a certain length of time, even though consent for using it has been withdrawn.
We may be required to share information, including personal information, when required to do so by the authorities.