How The Guilded Veil collects, uses and protects your personal data when you shop with us, in line with UK GDPR and the Data Protection Act 2018.
The Guilded Veil is an online shop selling tarot and oracle decks and handmade items, shipping from the UK. For data protection purposes the data controller is MS Media Consulting Ltd, a company registered in England and Wales (company number 14888296) trading as The Guilded Veil, with its registered office at Unit 1 Derwent Business Centre, Clarke Street, Derby, DE1 2BU. You can contact us about your data any time at hello@theguildedveil.co.uk.
When you place an order we collect your name, delivery and billing address, email address, phone number (if you give one), the items you buy, and the record of your payment. We do not see or store your full card details — these are handled directly by our payment provider. If you sign up to our deck-drop emails we keep your email address. When you browse the shop we also process basic technical and usage data (such as your IP address, device and pages viewed), and — only if you consent — analytics data via cookies.
We process your order, delivery and payment data to perform our contract with you — to take payment, ship your order, handle returns and provide support. We process limited data on the basis of our legitimate interests to keep the shop secure, prevent fraud, keep proper business records and improve our service; where we do this we balance it against your rights. We send marketing email (news of new deck drops) only where you have consented, and you can withdraw that consent at any time using the unsubscribe link or by emailing us. We keep certain records to comply with our legal obligations (see Retention).
We share your data only with the service providers we need to run the shop and fulfil your order, acting on our instructions: our store and order platform (Medusa, self-hosted), our payment provider (Stripe Payments UK / Stripe, Inc., who process your payment), our delivery carrier (Royal Mail, and other carriers for international or larger items), and our email and hosting providers. Some of these providers may process data outside the UK; where they do, that transfer is protected by safeguards such as UK adequacy regulations or the International Data Transfer Agreement / Addendum. We never sell your personal data.
We keep order, payment and transaction records for at least six years after the end of the relevant tax year, because HMRC and UK accounting and consumer law require it. We keep marketing-email consent and contact data until you unsubscribe or ask us to delete it. After the applicable period we securely delete or anonymise your data.
Under UK data protection law you have the right to access a copy of your data; to have inaccurate data corrected; to have data erased; to restrict or object to processing; to data portability; and to withdraw consent at any time (without affecting processing already carried out). Where we rely on legitimate interests you can object to that processing. To exercise any of these rights, email hello@theguildedveil.co.uk. We will respond within one month.
We use a small number of essential cookies to run the cart and checkout, and — only with your consent — analytics cookies. See our Cookie Policy for the detail and for how to change your choice.
If you have a concern about how we handle your data, please contact us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority, at ico.org.uk or 0303 123 1113.
We use essential cookies to run the shop, and — only with your consent — analytics to improve it. Read our Cookie Policy.