Privacy Policy
Last updated: February 2026
At The Gleanery, we are committed to protecting your privacy and handling your personal data with transparency and care. This Privacy Policy explains how we collect, use, and safeguard your information when you visit our website or place an order with us. We operate in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Information We Collect
We collect information that you provide directly to us when you create an account, place an order, or get in touch. This includes:
- Personal details — your name, email address, telephone number, and delivery address.
- Payment information — payment processing is handled entirely by Stripe. We do not store your card details on our servers. Stripe operates as an independent data controller and processes your payment data in accordance with their own privacy policy.
- Browsing data — we automatically collect certain technical information when you visit our site, including your IP address, browser type, device information, pages visited, and referring URLs. This data helps us understand how our site is used and improve your experience.
How We Use Your Information
We use the information we collect for the following purposes:
- Order processing and fulfilment — to process your purchases, arrange delivery, send order confirmations, and handle returns or refunds.
- Communication — to respond to your enquiries, send essential service updates about your orders, and (where you have opted in) share news about new products, seasonal collections, and offers from The Gleanery.
- Service improvement — to analyse how visitors use our site so we can improve navigation, product listings, and overall performance.
Information Sharing
We do not sell, rent, or trade your personal information to third parties. We only share your data with trusted service providers who help us operate our business:
- Payment processing — Stripe handles all payment transactions securely on our behalf.
- Delivery partners — we share your name and delivery address with our courier services to fulfil your orders.
- Analytics — we may use privacy-focused analytics tools to understand site usage in aggregate.
All third-party providers are contractually bound to process your data only for the purposes we specify and in compliance with applicable data protection legislation.
Data Security
We take the security of your personal data seriously. We implement appropriate technical and organisational measures to protect your information, including:
- Encryption of data in transit using TLS/SSL protocols across our entire site.
- Secure storage of account information with access restricted to authorised personnel only.
- Regular review of our data collection, storage, and processing practices to guard against unauthorised access, alteration, or disclosure.
While no method of electronic transmission or storage is completely secure, we strive to use commercially reasonable means to protect your personal data.
Your Rights
Under the UK GDPR, you have a number of rights in relation to your personal data. You may exercise any of these rights by contacting us:
- Right of access — you can request a copy of the personal data we hold about you.
- Right to rectification — you can ask us to correct any inaccurate or incomplete data.
- Right to erasure — you can request that we delete your personal data where there is no compelling reason for us to continue processing it.
- Right to data portability — you can request a machine-readable copy of the data you have provided to us.
- Right to restrict processing — you can ask us to limit how we use your data in certain circumstances.
- Right to object — you can object to our processing of your data for direct marketing purposes at any time.
We aim to respond to all legitimate requests within one month. If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Children's Privacy
Our website and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently gathered information from a child under 16, we will take steps to delete that data as promptly as possible. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make material changes, we will notify you by posting the revised policy on this page with an updated "Last updated" date. Where changes are significant, we may also notify you by email or through a notice on our website. We encourage you to review this page periodically.
Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how we handle your personal information, please get in touch through our contact page. We will do our best to address your enquiry promptly and thoroughly.
For formal data protection enquiries, you may also write to us at:
Data Protection OfficerThe Gleanery
info@thegleanery.uk
