Privacy policy
Privacy Policy
Last Updated: June 2026
Helen Russell Creations is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store and protect your personal data when you visit our website, purchase products from us, subscribe to our newsletters, contact us, or otherwise interact with our business.
This policy is designed to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable UK data protection laws.
1. Data Controller
Helen Russell Creations is the Data Controller responsible for your personal data.
Contact Details
Helen Russell Creations
Email: helen@helenrussellcreations.com
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us using the details above.
2. What Is Personal Data?
Personal data means any information that can identify an individual directly or indirectly. Examples include:
- Name
- Postal address
- Email address
- Telephone number
- Order history
- Payment-related transaction information
- Website usage information
We only collect personal data that is necessary for legitimate business purposes.
3. How We Collect Personal Data
We may collect personal data when:
- You place an order through our website
- You create a customer account
- You subscribe to our newsletter
- You contact us by email, telephone or social media
- You comment on blog posts
- You purchase products at events or exhibitions
- You visit our website
4. Categories of Personal Data We Process
Consumer Customers
We may collect:
- Name
- Billing address
- Delivery address
- Email address
- Telephone number (where provided)
- Order history
- Product preferences
- Customer account information
Trade Customers and Stockists
We may collect:
- Contact names
- Business names
- Business addresses
- Email addresses
- Telephone numbers
- Purchase history
Suppliers
We may collect:
- Contact names
- Business contact details
- Business addresses
- Email addresses
- Telephone numbers
Website Users
We may collect:
- IP address
- Browser type
- Device information
- Website usage information
- Cookie data
5. Why We Process Your Personal Data
Under UK GDPR, we must have a lawful basis for processing personal data.
Contract
We process personal data to:
- Fulfil customer orders
- Deliver products
- Process payments
- Respond to enquiries
- Manage commissions and bespoke orders
Legitimate Interests
We may process personal data to:
- Improve our products and services
- Analyse website performance
- Understand customer purchasing trends
- Manage business relationships with stockists and suppliers
- Prevent fraud and misuse of our services
We always balance our legitimate interests against your privacy rights.
Consent
We rely on consent for:
- Marketing emails and newsletters
- Certain cookies and analytics technologies where required
You may withdraw consent at any time.
Legal Obligations
We may process personal data to:
- Meet tax and accounting requirements
- Comply with legal or regulatory obligations
- Respond to lawful requests from public authorities
6. Payment Processing
We do not store or have access to your full payment card details.
Payments are processed securely through third-party payment providers including Shopify Payments, PayPal and Square.
These providers act as independent data controllers and process payment information in accordance with their own privacy policies.
7. Email Communications and Marketing
Newsletters
We use Mailchimp to manage our email marketing.
We will only send marketing emails where:
- You have provided your consent; or
- We are otherwise permitted to do so under applicable electronic marketing laws.
You may unsubscribe at any time by:
- Clicking the unsubscribe link in any marketing email; or
- Contacting us directly.
Customer Service Communications
Where you have made an enquiry or placed an order, we may contact you regarding:
- Orders
- Deliveries
- Commissions
- Customer support requests
These communications are necessary for the performance of our contract with you.
8. Website Analytics and Cookies
We use cookies and analytics tools, including Google Analytics, to understand how visitors use our website.
Cookies may collect information such as:
- Website usage patterns
- Device information
- Browser information
- Approximate location information
Where required by law, we will request your consent before placing non-essential cookies on your device.
You can manage cookie preferences through your browser settings and our website cookie controls.
Cookies and Similar Technologies
Our website uses cookies and similar technologies provided by Shopify and selected third-party providers to ensure the website functions correctly, improve user experience, analyse website performance and support marketing activities.
Cookies are small text files stored on your device when you visit a website.
Strictly Necessary Cookies
We use essential cookies that enable:
- Secure checkout and payment processing
- Shopping cart functionality
- Website security and fraud prevention
- Storage of cookie consent preferences
- Customer account and Shop Pay functionality
Examples may include:
- _shopify_test
- cart_currency
- CookieConsent
- consentHeader
- _shop_app_essential
- _shopify_essential
- login_with_shop_finalize
- bugsnag-anonymous-id
These cookies cannot be disabled through our cookie management system because the website would not function correctly without them.
Preference Cookies
We use preference cookies to remember settings such as language, region and localisation preferences.
Example:
- localization
Analytics Cookies
Analytics cookies help us understand how visitors interact with our website by collecting information about page visits, navigation patterns and website performance.
Examples may include:
- _shopify_analytics
- _shs_state
- wpm-ri-#
- ri-#
These cookies are only used where you have provided consent.
Marketing Cookies
Marketing cookies help us understand the effectiveness of our advertising and email marketing campaigns.
Examples may include:
- _shopify_y
- _shopify_s
- _shopify_marketing
- mailchimp-pixel:context
- intuit_pixel_sdk_user_data
- intuit_pixel_sdk_session_data
These cookies may track interactions across websites and marketing communications to help us improve our services and marketing activities.
These cookies are only used where you have provided consent.
Managing Cookie Preferences
You can manage or withdraw your cookie consent at any time using our cookie preference tool.
You can also configure your browser settings to block or delete cookies. Please note that some parts of the website may not function correctly if essential cookies are disabled.
9. Who We Share Data With
We only share personal data where necessary.
Recipients may include:
- Shopify
- PayPal
- Square
- Mailchimp
- Website hosting providers
- Professional advisers and accountants
- Delivery and courier companies
- Regulatory authorities where legally required
We do not sell personal data to third parties.
10. International Transfers
Some of our service providers may process personal data outside the United Kingdom.
Where international transfers occur, we ensure that appropriate safeguards are in place, including:
- UK International Data Transfer Agreements (IDTAs)
- UK Addendum to Standard Contractual Clauses
- Adequacy Regulations approved by the UK Government
- Other legally recognised safeguards
11. Data Security
We take appropriate technical and organisational measures to protect personal data.
These measures include:
- Password-protected systems
- Multi-factor authentication where available
- Secure hosting environments
- SSL encryption on our website
- Restricted access to personal data
- Regular software and security updates
- Physical security measures for paper records
No method of transmission or storage is completely secure; however, we work to maintain appropriate levels of protection.
12. Data Retention
We retain personal data only for as long as necessary.
Typical retention periods include:
Financial and Tax Records
Retained for up to 7 years to comply with legal and accounting obligations.
Customer Order Information
Retained for as long as reasonably necessary to administer customer relationships, fulfil legal obligations and manage business records.
Marketing Information
Retained until you withdraw consent or unsubscribe.
Supplier and Stockist Information
Reviewed periodically and deleted when no longer required.
When information is no longer required, it is securely deleted or destroyed.
13. Your Rights
Under UK GDPR you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your personal data
- Restrict processing
- Object to processing
- Request transfer of your data to another organisation (data portability)
- Withdraw consent at any time where processing relies on consent
- Not be subject to automated decision-making that has legal or similarly significant effects
Some rights may be subject to legal exemptions.
To exercise any of these rights, please contact:
helen@helenrussellcreations.com
14. Data Breaches
In the event of a personal data breach, we will:
- Investigate the incident promptly inline with ICO guidelines
- Take steps to minimise any impact
- Notify the Information Commissioner's Office (ICO) where legally required
- Notify affected individuals where required by law
15. Complaints
If you have concerns about how we handle your personal information, please contact us first using the details provided in this Privacy Policy so that we can try to resolve your concerns.. We will investigate your concern and aim to respond within 30 days. If you remain dissatisfied, you may lodge a complaint with the Information Commissioner's Office (ICO).
16. Changes to This Policy
We may update this Privacy Policy from time to time.
The latest version will always be available on our website and will include the date of the most recent update.
Third-Party Privacy Policies
Shopify: https://www.shopify.com/legal/privacy
PayPal: https://www.paypal.com/uk/legalhub/privacy-full
Square: https://squareup.com/gb/en/legal/general/privacy
Mailchimp: https://mailchimp.com/legal/privacy
Google Privacy Policy: https://policies.google.com/privacy
Google Analytics: https://policies.google.com/technologies/partner-sites