Free UK delivery on orders over £30 · Proof sent before we print

Privacy policy

How we look after your information when you shop with us.

Who we are

Duffy's Creations is the data controller for the personal information you share with us through this website. If you need to get in touch about your data, email info@duffyscreations.co.uk and we'll come back to you within five working days.

This policy explains what we collect, why, what we do with it and the choices you have. It's written in plain English on purpose — if anything's unclear, ask and we'll explain.

What we collect

The information we hold about you comes from things you give us directly:

  • Orders. Your name, delivery address, email, phone number (optional) and the details you add to personalise a print.
  • Account. If you register, we keep your login email, hashed password, saved addresses and your order history.
  • Photos you upload. If a product asks for a reference photo, we store the file you send us so the artist can work from it.
  • Contact form & emails. Whatever you send us in a message, so we can reply.
  • Analytics (only with your consent). If you accept analytics cookies, Google Analytics records anonymous data about which pages you visit, your device type and how you got to the site. We never see your name or address from analytics.

We do not store your card number. All payments go directly through Stripe, who handle the card data on their own systems.

Why we use it and the lawful basis

UK GDPR asks us to be specific about why we hold each piece of information:

  • To fulfil your order (contract). Name, address, order details, uploaded photos and email so we can make your print, send proofs and ship it.
  • To run your account (contract). Login email and password so you can sign back in and see past orders.
  • To reply to a message (legitimate interest). Whatever you send us through the contact form or by email.
  • To improve the shop (consent). Analytics, only if you accept analytics cookies in the banner.
  • To send marketing (consent). Only if you've ticked the box at checkout or signed up to the newsletter. You can unsubscribe at any time from any of our emails.
  • To keep our records straight (legal obligation). HMRC requires us to keep invoice records for six years.

Who we share it with

We share data only with the suppliers who help us run the shop. We never sell your information.

  • Stripe — processes your payment.
  • Royal Mail / our courier — for delivery.
  • Vercel and Supabase — host the website and database. Data is stored in the UK and EU.
  • Email provider — sends your order confirmation, proofs and shipping notifications.
  • Google Analytics (only with your consent) — for anonymous traffic stats.
  • HMRC / our accountant — for tax purposes.
  • Law enforcement — if we're legally required to share information.

How long we keep it

We keep your order records for six years — HMRC requires this for invoicing and tax. After that, order data is deleted.

Account information (login, addresses, wishlist) is kept while your account is open. If you close your account or ask us to delete it, we remove your information within 30 days (except for the order records HMRC needs us to retain).

Marketing email subscriptions are kept while you're subscribed. Unsubscribing removes you from future sends straight away.

Uploaded reference photos are kept for 30 days after your order is fulfilled, then deleted.

Your rights

Under UK GDPR you have the right to:

  • See what we hold about you (a subject access request).
  • Correct anything wrong in our records.
  • Have your data deleted, subject to records we have to keep for legal reasons (like HMRC invoices).
  • Restrict or object to how we're using your information.
  • Take your data elsewhere (data portability).
  • Withdraw consent for analytics or marketing at any time — analytics from the Cookie preferences link in the footer, marketing from the unsubscribe link in any of our emails.

To exercise any of these, email info@duffyscreations.co.uk. We'll respond within one calendar month.

If you're not happy with how we've handled your data, you have the right to complain to the Information Commissioner's Officeico.org.uk or 0303 123 1113.

Cookies

This site uses cookies. Strictly necessary cookies (cart session, login, secure checkout) are always on — without them the shop doesn't work. Analytics and marketing cookies only run if you say yes in the banner.

The full list and how to manage them is on the Cookies page.

Changes to this policy

If we change this policy in any material way, we'll update the “last updated” date and, where appropriate, tell you by email. The current version always lives at this URL.

Last updated: 30 May 2026.