Last updated: 10 October 2025 

 

1. Who We Are 

This privacy policy explains how we collect, use, and protect your personal data when you use our website and services. 

Data Controller: 

 

2. What Personal Data We Collect 

We may collect and process the following categories of personal data about you: 

Personal Information 

 

Technical Data 

 

Usage Data 

 

Marketing and Communications Data 

 

Transaction Data 

 

3. How We Collect Your Personal Data 

We collect personal data through: 

 

4. Legal Basis for Processing Your Personal Data 

We only process your personal data when we have a legal basis to do so. The legal bases we rely on include: 

Purpose 

Legal Basis 

Processing orders and providing services 

Contract performance - necessary to fulfil our contract with you 

Customer service and support 

Contract performance and legitimate interests (providing quality service) 

Sending marketing communications 

Consent - you have given clear consent for us to process your data for marketing purposes 

Improving our website and services 

Legitimate interests - to keep our website updated and relevant 

Market research 

Consent or legitimate interests (understanding customer needs) 

Security and fraud prevention 

Legitimate interests (protecting our business and customers) 

Legal compliance 

Legal obligation - to comply with applicable laws 

 

Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms and are satisfied they are not overridden. 

Where we rely on consent, you have the right to withdraw it at any time by contacting us. 

 

5. How We Use Your Personal Data 

We use your personal data for the following purposes: 

Essential Purposes 

 

Marketing and Communications 

 

Improvement and Analysis 

 

Legal and Security 

 

You can opt out of marketing communications at any time by: 

 

6. Who We Share Your Personal Data With 

We may share your personal data with the following categories of recipients: 

Service Providers 

We work with trusted third-party service providers who process data on our behalf, including: 

These providers are contractually bound to process data only in accordance with our instructions and UK GDPR requirements. 

 

Legal Requirements 

We may disclose your personal data if required by law, court order, or governmental authority, or to protect our rights, property, or safety. 

 

Business Transfers 

If we sell or reorganise our business, your personal data may be transferred to the new owner. 

 

We will never sell or rent your personal data to third parties for their marketing purposes without your explicit consent. 

 

7. International Data Transfers 

Some service providers process data outside the UK/EEA. We ensure appropriate safeguards including UK adequacy regulations, Standard Contractual Clauses (SCCs), or other approved mechanisms.  

 

8. How Long We Keep Your Personal Data 

We retain personal data only as long as necessary to fulfil the purposes for which it was collected, typically no longer than 7 years. Specific retention periods depend on: 

 

9. Your Data Protection Rights 

Under UK GDPR, you have the following rights: 

 

Right of Access 

You have the right to request a copy of the personal data we hold about you. This is free of charge in most circumstances. 

 

Right to Rectification 

You have the right to have inaccurate personal data corrected and incomplete data completed. 

 

Right to Erasure (Right to be Forgotten) 

You have the right to request deletion of your personal data in certain circumstances, such as: 

 

Right to Restrict Processing 

You have the right to request that we restrict processing of your personal data in certain circumstances, such as when you contest its accuracy. 

 

Right to Data Portability 

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller. 

 

Right to Object 

You have the right to object to: 

 

Rights Related to Automated Decision-Making 

We use automated systems to detect and prevent fraud. Orders may be automatically cancelled if our system identifies high-risk indicators such as unusual purchasing patterns, mismatched information, or other fraud signals.  

If your order is automatically cancelled, you have the right to: 

To appeal an automated cancellation, email support@boopbeauty.co.uk with your order number and explanation. We will conduct a human review and respond within 72 hours. 

If you choose Klarna or Clearpay as payment methods, these services conduct automated credit checks to approve or decline your application. These automated decisions are made by Klarna/Clearpay (not by us) and may affect your ability to complete your purchase.  

For information about their automated decision-making and your rights: 

You should contact Klarna or Clearpay directly to exercise your rights regarding their automated decisions. 

 

Right to Withdraw Consent 

Where we rely on consent, you can withdraw it at any time by contacting us. This will not affect the lawfulness of processing before withdrawal. 

 

10. How to Exercise Your Rights 

To exercise any of your rights, please: 

We will respond to your request within one month. In complex cases, we may extend this by up to two months and will notify you of the extension. 

We may need to verify your identity before processing your request to protect your personal data. 

 

11. Cookies and Similar Technologies 

What Are Cookies? 

Cookies are small text files placed on your device when you visit our website. They help us provide a better user experience. 

 

Types of Cookies We Use 

Necessary Cookies 

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies. 

Legal basis: These are necessary for the website to function (legitimate interest). 

 

Preference Cookies 

Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in. 

Legal basis: Your consent (you can opt out). 

 

Statistics Cookies 

Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously. 

Legal basis: Your consent or legitimate interest. 

 

Marketing Cookies 

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers. 

Legal basis: Your consent (you can opt out). 

 

Managing Cookies 

You can control cookies through: 

  1. Our cookie consent tool: You will be asked for your consent when you first visit the website and you can change your preferences at any time by clicking on ‘Cookies Settings’ at the bottom of the homepage. 

  1. Browser settings: Most browsers allow you to refuse or delete cookies. Instructions vary by browser:  

Note: Blocking cookies may affect website functionality and your user experience. 

 

Third-Party Cookies 

A list of third-party cookies and links to their privacy policies can be found in ‘Cookies Settings’ at the bottom of the homepage. 

 

12. Security 

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures, including: 

 

Data Breach Notification 

In the event of a data breach that poses a risk to your rights and freedoms, we will: 

 

13. Children's Privacy 

Our website is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. 

If you are under 16, please do not provide any personal data through our website. If we become aware that we have collected data from a child under 16 without parental consent, we will delete it promptly. 

If you believe we have inadvertently collected data from a child under 16, please contact us immediately. 

 

14. Links to Other Websites 

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of these external sites. 

When you click on a link to leave our website, we encourage you to read the privacy policy of every website you visit. This privacy policy applies only to our website. 

 

15. Changes to This Privacy Policy 

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. 

Any changes will be posted on this page with an updated "Last updated" date at the top. If we make significant changes, we may notify you by: 

We encourage you to review this policy periodically. 

 

16. How to Complain 

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the supervisory authority. 

Information Commissioner's Office (ICO) 

We would appreciate the opportunity to resolve your concerns before you contact the ICO, so please contact us first at support@boopbeauty.co.uk. 

 

17. Contact Us 

If you have any questions about this privacy policy or how we handle your personal data, please contact us: 


Your trust is important to us. We are committed to protecting your privacy and handling your personal data responsibly and transparently in accordance with UK data protection laws.