Privacy Policy
Last updated: 1st December, 2025
This Privacy Policy explains how I collect, use, and protect your personal data when you use this website (“Site”). I am committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
If you have any questions, you can contact me at:
Data Controller: Shirley Cheung
Email: [email protected]
1. What Personal Data I Collect
I may collect the following types of information:
1.1 Information You Provide
- Email address — when you sign up to my newsletter via Mailchimp
- Order information — when you make a purchase through WooCommerce
- Name
- Billing and shipping address
- Email address
- Phone number
- Payment details (processed securely by payment providers)
1.2 Automatically Collected Data
Through analytics tools (WordPress Analytics and Google Analytics), I may collect:
- IP address (anonymised, where possible)
- Device and browser type
- Pages viewed
- Time spent on the website
- Referral source
- Interactions with pages and products
1.3 Cookies
This Site uses cookies to:
- Enable basic website functionality
- Monitor traffic and analytics
- Support e-commerce features (e.g., cart, checkout)
- Store your preferences
You can manage or disable cookies in your browser settings.
2. How I Use Your Personal Data
I use your information to:
- Provide and deliver products via WooCommerce
- Send newsletters and marketing emails (with your explicit consent)
- Improve website performance and user experience
- Process payments and detect fraud
- Comply with legal obligations
I will never sell your personal information to third parties.
3. Legal Bases for Processing (UK GDPR)
I rely on the following legal bases:
- Consent — for newsletter sign-ups and marketing emails
- Contract — to process and fulfil product orders
- Legitimate interests — to maintain and improve the Site
- Legal obligation — for tax and accounting compliance
4. Sharing Your Information
I may share your data with trusted third-party service providers, including:
4.1 Email Marketing (Mailchimp)
Used to manage email lists and send newsletters.
You can unsubscribe at any time via the link in any email.
4.2 Analytics Providers
- Google Analytics
- WordPress/Jetpack Analytics
These tools collect anonymised or pseudonymised usage data.
4.3 WooCommerce Service Providers
This may include:
- Payment gateways (e.g., Stripe, PayPal)
- Shipping providers
- Fraud prevention tools
4.4 Legal Obligations
I may share data if required by law, regulatory authorities, or to protect my rights.
5. International Data Transfer
Some service providers (e.g., Mailchimp, Google) may store data outside the UK or EEA.
When this happens, they use approved safeguards such as:
- UK GDPR Adequacy Decisions
- Standard Contractual Clauses (SCCs)
6. Data Retention
I keep your data only for as long as necessary:
- Newsletter data: until you unsubscribe
- Order data: up to 6 years for tax and accounting purposes
- Analytics data: typically 14–26 months, depending on settings
7. Your Data Protection Rights
Under the UK GDPR, you have the right to:
- Access your personal data
- Correct inaccuracies
- Request deletion
- Restrict processing
- Object to processing (including marketing)
- Request data portability
- Withdraw consent at any time
To exercise your rights, email: shirleycheung@me.com
8. Children’s Privacy
This Site is not intended for children under 16. I do not knowingly collect data from children.
9. Changes to This Privacy Policy
I may update this policy periodically. Any changes will be posted on this page with an updated “Last updated” date.
10. Contact
For questions or to request data access:
Email: [email protected]

