Privacy Policy
Last updated: January 19, 2026
1. Overview
This Privacy Policy explains how BuyNoveltyCards (“we”, “us”, “our”) collects, uses, shares, and protects your personal data when you visit or make a purchase from BuyNoveltyCards (the “Website”), contact us, or otherwise interact with our services.
We aim to be transparent and to process personal data in accordance with applicable privacy laws, including the UK GDPR / EU GDPR where relevant.
2. Who We Are (Data Controller)
Unless stated otherwise, BuyNoveltyCards is the “data controller” for the personal data described in this Privacy Policy.
3. Personal Data We Collect
3.1 Data you provide to us
- Order & account data: name, email, billing/shipping address, order history, account login details (if you create an account).
- Payment data: payment status and limited payment metadata (we typically do not store full card numbers; payments are handled by our payment processors).
- Customer support: messages you send us, attachments you choose to provide, and our replies.
- Customisation data (if applicable): details you submit for personalisation/custom printing (only what you choose to provide).
3.2 Data we collect automatically
- Device & usage data: IP address, browser type, pages viewed, approximate location (from IP), timestamps, referring URLs, and interactions.
- Cookies & similar technologies: used for essential site functionality, preferences, analytics, and (where enabled) marketing.
4. How We Use Your Data (Purposes & Legal Bases)
We process personal data only when we have a lawful basis. Depending on the context, we rely on: (a) performance of a contract, (b) legitimate interests, (c) legal obligations, and/or (d) your consent.
A) To provide our services and fulfill orders
Examples: processing checkout, manufacturing/fulfillment, shipping updates, handling returns, and providing customer support.
Legal basis: contract performance; legitimate interests.
B) To operate, secure, and improve the Website
Examples: debugging, preventing fraud/abuse, account security, monitoring performance, and improving usability.
Legal basis: legitimate interests; legal obligation (where applicable).
C) Marketing and communications (where applicable)
Examples: sending newsletters/promotions if you opt in, responding to inquiries, and transactional emails (order confirmations, receipts).
Legal basis: consent (for marketing where required); legitimate interests (for transactional/service messages).
D) Compliance and legal requests
Examples: tax/accounting compliance, chargeback disputes, and responding to valid legal requests from authorities.
Legal basis: legal obligation; legitimate interests.
5. Sharing Your Data
We do not sell your personal data. We may share it with trusted third parties only when necessary to operate our services, process your orders, or comply with legal obligations.
5.1 Service providers
We may share data with vendors who help us run the Website and fulfill orders. These providers are authorized to process personal data only as needed to perform services for us and are required to protect it.
- Payment processors
- Fraud prevention and security providers
- Shipping and fulfillment providers
- Customer support tools
- Website analytics and performance tools
- Email/SMS delivery providers (if you opt in)
- Hosting and infrastructure providers
5.2 Legal and compliance disclosures
We may disclose information if required to comply with applicable law, regulation, legal process, or a valid request from competent authorities, or to protect our rights, users, and the public.
6. International Data Transfers
If we transfer personal data outside the UK/EEA (for example, where a service provider is located abroad), we will use appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, or other lawful transfer mechanisms to help protect your data.
7. Data Retention
We keep personal data only as long as necessary for the purposes described in this policy, including to fulfill orders, provide support, comply with legal obligations, resolve disputes, and enforce agreements.
- Order and support records: retained for a period appropriate for returns, disputes, and accounting/tax requirements.
- Analytics data: retained according to the settings of the analytics tools we use and minimized where possible.
- Marketing data (if applicable): retained until you unsubscribe or request deletion.
You may request deletion where applicable (see “Your Rights” below).
8. Security
We use technical and organisational measures designed to protect personal data, including access controls, secure hosting, encryption in transit where supported, and limited-access workflows. However, no method of transmission or storage is 100% secure.
9. Your Rights
Depending on where you live (including the UK/EEA), you may have rights over your personal data. These can include:
- Access to the personal data we hold about you
- Correction of inaccurate or incomplete personal data
- Deletion of personal data (in certain circumstances)
- Restriction or objection to processing (in certain circumstances)
- Data portability (in certain circumstances)
- Withdraw consent where we rely on consent (this won’t affect prior processing)
To exercise these rights, contact us. We may need to verify your identity before responding.
10. Complaints
If you have a concern about how we handle your data, please contact us first and we’ll try to resolve it. You may also have the right to lodge a complaint with your local data protection authority.
11. Children's Privacy
Our Website is not intended for children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us so we can take appropriate steps.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we do, we will update the “Last updated” date at the top of this page.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact:
BuyNoveltyCards