Privacy Policy
Last updated: 13 May 2026
1. Who We Are
Bonvale UK Limited (company number 17142585), incorporated in England and Wales, with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom ("Bonvale", "we", "us", "our"), is the data controller for personal data collected from customers who purchase from us outside Australia, New Zealand, and the United Kingdom, through our website (bonvale.com), mobile application, and related services (our "Services"). If you are a customer in Australia, New Zealand, or the United Kingdom, please refer to the country-specific version of our Privacy Policy, which is available on our Website. Because Bonvale UK Limited is established in the United Kingdom, our processing of personal data is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where you are habitually resident in a country whose data protection law confers additional rights, those rights also apply alongside the rights described in this Policy. We may share personal data with the Bonvale group and related entities as described in Section 6. Personal data collected from you is typically transferred to the United Kingdom (where our controller is established) and to other countries in which our service providers operate. Appropriate safeguards apply (see Section 7).
2. Personal Data We Collect
2.1 Data You Provide Directly
When you create an account, place an order, contact us, or otherwise use our Services:
- Identity: full name, date of birth
- Contact: email address, telephone number, postal address
- Account: username, password (stored in hashed form), preferences
- Transaction: products purchased, order and returns history, payment method type (full card numbers are held by our payment gateway, not by Bonvale)
- Communications: messages sent to our customer care team
- Marketing preferences: email, SMS, and push notification opt-in and opt-out choices
2.2 Data We Collect Automatically
When you visit our Website or use our App:
- Device and technical: IP address, browser type and version, operating system, device identifiers, time zone
- Usage: pages viewed, products browsed, search queries, clickstream, session duration, referral source
- Tracking: data collected via cookies, pixels, and similar technologies (see Section 5)
- Location: approximate location from IP address (we do not collect GPS location unless you grant App permission)
2.3 Data We Receive From Third Parties
- Payment gateways: transaction status, fraud risk signals, and payment verification data
- Logistics providers: delivery status, confirmation, and address validation data
- Meta Platforms: aggregated advertising performance data and, where you have consented to Meta's terms, audience matching data via the Meta Pixel (see Section 5)
- Google: analytics and advertising performance data via Google Analytics and Google Ads (see Section 5)
3. How and Why We Use Your Personal Data
The table below maps our processing purposes to the lawful basis we rely on under UK GDPR and our default retention period.
| Data Collected | Purpose | Lawful Basis (UK GDPR) | Retention |
|---|---|---|---|
| Name, contact, order, payment data | Processing your order: fulfilment, dispatch, returns | Contract performance (Art. 6(1)(b)) | 6 years from transaction (UK tax compliance) |
| Account data | Creating and managing your account | Contract performance (Art. 6(1)(b)) | 3 years after last account activity |
| Contact, order data | Customer care and dispute resolution | Contract performance / Legitimate interests (Art. 6(1)(f)) | 3 years from last interaction |
| Email, phone, preferences | Transactional communications (order confirmations, dispatch, returns) | Contract performance (Art. 6(1)(b)) | Duration of customer relationship |
| Email, phone, preferences | Marketing emails, SMS, push notifications | Consent (Art. 6(1)(a)) | Until consent withdrawn |
| Browsing, purchase history | Personalised product recommendations | Legitimate interests (Art. 6(1)(f)) | 3 years from last activity |
| Device, browsing, purchase data via Meta Pixel & Google Analytics | Profiling for targeted advertising on Meta and Google | Consent (Art. 6(1)(a)) | Per Meta/Google terms; our data: 2 years |
| IP, device, transaction data | Fraud detection, security, and abuse prevention | Legitimate interests (Art. 6(1)(f)) | 2 years |
| All categories | Legal obligations (tax, AML, court orders) | Legal obligation (Art. 6(1)(c)) | As required by law (min. 6 years for UK tax records) |
| Aggregated, anonymised data | Analytics and business intelligence | Legitimate interests (Art. 6(1)(f)) | Indefinite (not personal data) |
Our legitimate interests assessments are available on request from privacy@bonvale.com.
4. Marketing Communications
We send marketing communications (email, SMS, push notifications) only where you have given consent. You may withdraw consent at any time by:
- Clicking 'unsubscribe' in any marketing email
- Replying STOP to any marketing SMS
- Adjusting push notification preferences in your device settings or Bonvale account
- Contacting us at privacy@bonvale.com
Withdrawing marketing consent does not affect transactional communications (order confirmations, dispatch, returns), which are sent under our contract with you. We comply with applicable electronic marketing laws in the jurisdictions in which we operate. Every marketing message we send identifies Bonvale as the sender and includes a functional unsubscribe facility. Unsubscribe requests are actioned promptly.
5. Cookies, Pixels, and Tracking Technologies
5.1 What We Use
Essential Cookies Strictly necessary for core functionality including shopping basket, login, security, and fraud prevention. Cannot be disabled. Analytics Cookies (Google Analytics) We use Google Analytics (Google LLC) to understand how visitors use our Website including pages visited, session duration, referral source, and device. This aggregated data improves our Services. Data is transferred to Google's servers, which may be outside the United Kingdom and your country of residence (see Section 7). You may opt out via the Google Analytics Opt-Out Browser Add-on at tools.google.com/dlpage/gaoptout or by rejecting analytics cookies in our consent banner. Advertising and Targeting Cookies (Meta Pixel) We use the Meta Pixel (Meta Platforms, Inc.) to measure advertising effectiveness, build audiences, and track conversions. When active, it collects your IP address, browser data, page URL, and on-site actions (such as product views and purchases). This data is transmitted to Meta and used to serve targeted advertisements on Facebook, Instagram, and the Meta Audience Network ('retargeting'). Meta may also use it for its own purposes under its Privacy Policy. We activate the Meta Pixel only with your consent; you may withdraw consent at any time via your cookie preferences.
5.2 Consent Management
We use Shopify's native cookie consent banner to manage cookie consent on our Website. On your first visit, our cookie banner presents the categories of cookies in use. Non-essential cookies, including analytics and advertising categories, do not activate until you actively accept them. Your consent choice is recorded with a timestamp and the version of this Policy in force at the time, so we can demonstrate valid consent if required. You can review or change your preferences at any time via the "Cookie Settings" link in the footer of our Website. Withdrawing consent for a category takes effect immediately. Any tracking scripts relying on that consent will stop firing for your session.
5.3 Your Cookie Choices
Manage preferences via our cookie preference centre (footer of our Website), your browser settings, or the opt-out tools provided by Google and Meta. Restricting certain cookies may affect Website functionality.
6. Who We Share Your Personal Data With
We do not sell or rent your personal data. We share it only as described below.
6.1 Service Providers
We share data with service providers acting under our instruction, including:
- Shopify Inc.: storefront platform, transactional emails, order notifications, and native cookie consent management.
- Shopify Payments and Klarna Bank AB (publ): payment processing, fraud screening, and Buy Now, Pay Later (where available). Your full card details are held by the relevant payment provider, not by Bonvale.
- KEC and KLN: outbound logistics from our fulfilment warehouse and inbound returns logistics.
- International and local last-mile carriers: delivery to your specified address in your country of residence.
- Loop Returns, Inc. (with EasyPost for return label generation): returns and exchanges portal.
- Gorgias, Inc.: customer support and ticketing.
- Klaviyo, Inc.: marketing emails, SMS, and push notifications.
- Amazon Web Services, Inc.: cloud infrastructure for custom apps and integrations.
- Google LLC (Google Analytics): Website usage analytics.
- Meta Platforms, Inc. (Meta Pixel): advertising measurement and audience targeting, subject to consent.
6.2 Legal and Regulatory Disclosure
We disclose personal data to law enforcement, courts, or regulators only where required by law, court order, or regulatory direction. We will notify you of such disclosures where legally permitted.
6.3 Business Transfers
If Bonvale UK Limited undergoes a merger, acquisition, or asset sale, your data may transfer to the relevant entity. We will notify you and ensure equivalent protections apply.
6.4 Group Companies
We may share data with the Bonvale group and related entities for the purposes set out in this Policy, including group-wide analytics, IT infrastructure, and customer support. All intra-group transfers are covered by an intra-group data transfer agreement incorporating the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, as applicable (see Section 7).
7. International Transfers of Personal Data
Bonvale UK Limited is established in the United Kingdom. If you are not resident in the United Kingdom, your personal data will be transferred to the United Kingdom (and may be processed by our group companies and service providers located in further countries, including Singapore and the United States), which may have data protection laws that differ from those of your country of residence. Where we transfer your personal data internationally, we rely on appropriate safeguards under Chapter V UK GDPR (and, where the EU GDPR applies, Chapter V EU GDPR), which may include:
- Transfers to a country that is the subject of UK or EU adequacy regulations;
- UK International Data Transfer Agreements (IDTAs);
- The UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses themselves;
- Equivalent safeguards approved under your local data protection law; and/or
- Other approved safeguards (for example, Binding Corporate Rules).
Intra-group transfers to other members of the Bonvale group and related entities are made under intra-group data transfer agreements using the UK IDTA or UK Addendum, as applicable. You may request a copy of the relevant mechanism by contacting privacy@bonvale.com.
8. How Long We Keep Your Personal Data
We retain personal data only as long as necessary for the relevant purpose and our legal obligations.
| Data Category | Retention Period |
|---|---|
| Order, transaction, and payment records | 6 years from date of transaction (UK tax record-keeping); longer where required by the local tax law of your country of residence |
| Account data | 3 years after last account activity or closure (whichever is later) |
| Customer care communications | 3 years from last interaction |
| Marketing preferences and consent records | Until consent withdrawn, plus 1 year (to demonstrate compliance under UK GDPR and applicable local marketing law) |
| Fraud and security logs | 2 years from the relevant event |
| Cookies and tracking data | 2 years from collection (see also Meta and Google terms) |
| Legal hold data (disputes, SARs, litigation) | Duration of matter plus applicable limitation period |
| Anonymised/aggregated analytics data | Indefinite (not personal data) |
On expiry of the retention period, we securely delete or anonymise data. Where immediate deletion is not possible (e.g. backup systems), we isolate the data and restrict access until deletion occurs.
9. How We Protect Your Personal Data
We implement technical and organisational measures to protect your data, including:
- Encryption in transit (TLS/SSL) and at rest
- Access controls and role-based permissions
- Regular security assessments and penetration testing
- Staff data protection training
- Incident response procedures (see Section 10)
Payment card data is processed by our PCI-DSS certified payment gateway. We do not store full card numbers. If you believe your account has been compromised, contact us at privacy@bonvale.com immediately.
10. Data Breach Notification
On becoming aware of a personal data breach likely to pose a risk to you, we will:
- Investigate its nature and scope
- Notify the UK Information Commissioner's Office (ICO) within 72 hours where notifiable under UK GDPR Article 33
- Notify affected individuals without undue delay where the breach poses a high risk under UK GDPR Article 34
- Notify any other supervisory authority required by the mandatory law of your country of residence, within the timeframes prescribed by that law
- Document the breach and our response
Information Commissioner's Office (ICO): ico.org.uk · +44 (0)303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom.
11. Your Rights
Under the UK GDPR (which applies to our processing as the controller is established in the United Kingdom), you have the following rights:
| Right | What It Means |
|---|---|
| Right of Access | Request a copy of the personal data we hold about you. We respond within one month (extendable by two further months for complex requests). |
| Right to Rectification | Ask us to correct inaccurate or incomplete data. Most account data can be updated directly in your account. |
| Right to Erasure | Ask us to delete your data where we have no legitimate reason to retain it, subject to legal obligations (e.g. financial records). |
| Right to Restrict Processing | Ask us to pause processing in certain circumstances, e.g. while you contest accuracy. |
| Right to Data Portability | Receive your data in a portable, machine-readable format where processed by automated means under consent or contract. |
| Right to Object | Object to processing for direct marketing (absolute right), advertising profiling, or legitimate interests. Marketing objections are actioned immediately. |
| Right to Withdraw Consent | Withdraw consent at any time where processing is consent-based. Withdrawal does not affect prior lawful processing. |
| Right re Automated Decisions | Not to be subject to solely automated decisions with legal or similarly significant effects. We do not currently make such decisions. |
Additional rights under your local law. Where the data protection law of your country of habitual residence confers additional rights (for example, the EU GDPR for individuals in the European Economic Area, or other national data protection laws), those rights also apply alongside the UK GDPR rights above. To exercise any right, contact privacy@bonvale.com. We respond within one month and may ask you to verify your identity. We do not charge for requests unless manifestly unfounded or excessive.
12. Complaints & Supervisory Authority
If you have a concern about how we handle your personal data, we ask that you contact us first at privacy@bonvale.com so we can attempt to resolve your concern directly. You have the right to lodge a complaint with our lead supervisory authority, the UK Information Commissioner's Office, at any time:
- Website: ico.org.uk
- Telephone: +44 (0)303 123 1113
- Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
You may also lodge a complaint with the data protection supervisory authority of the country in which you are habitually resident, if applicable.
13. Children's Privacy
Our Services are for individuals aged 18 and over. We do not knowingly collect data from under-18s. If you believe a child has provided us with their data, contact privacy@bonvale.com and we will promptly delete it unless retention is required by law.
14. Third-Party Links
Our Website and App may link to third-party sites. This Policy does not cover those sites and we are not responsible for their privacy practices.
15. Cookie Policy
What are cookies? Cookies are small text files placed on your device when you visit our Website. They allow the site to remember your actions and preferences over time, and help us and our third-party partners understand how visitors interact with our content. Similar technologies, including pixels and device identifiers, work in an equivalent way. The cookies we use We use three categories of cookies. The tables below list each cookie, who sets it, what it does, and how long it remains on your device. Category 1: Strictly Necessary These cookies are essential for our Website to function. They cannot be disabled. No consent is required to set them.
| Cookie Name | Set By | Purpose | Duration |
|---|---|---|---|
_shopify_session |
Shopify | Maintains your shopping session, keeps you logged in, and supports checkout security | Session (deleted when browser closes) |
_shopify_y |
Shopify | Assigns a unique visitor ID used to support analytics and personalisation within Shopify's platform | 1 year |
cart |
Shopify | Stores the contents of your shopping cart so items are retained as you browse | 2 weeks |
secure_customer_sig |
Shopify | Verifies that you are logged into your account securely | 20 years |
_ab |
Shopify | Tracks whether you were directed to a specific storefront variant (used internally by Shopify) | 2 years |
_tracking_consent |
Shopify | Records your cookie consent preferences, including which categories you accepted or rejected and the date and version of the policy at the time | 1 year |
Category 2: Analytics These cookies help us understand how visitors use our Website including which pages are visited, how long sessions last, and where visitors come from. The data is aggregated and not used to identify you personally. These cookies are set only with your consent.
| Cookie Name | Set By | Purpose | Duration |
|---|---|---|---|
_ga |
Google LLC (Google Analytics 4) | Assigns a unique identifier to distinguish visitors and aggregate usage data | 2 years |
_ga_[ID] |
Google LLC (Google Analytics 4) | Stores and maintains session state for a specific GA4 property | 2 years |
_gid |
Google LLC (Google Analytics 4) | Distinguishes individual users for a 24-hour session | 24 hours |
_gat |
Google LLC (Google Analytics 4) | Throttles the rate of analytics data requests to Google's servers | 1 minute |
Google Analytics data is transferred to Google's servers, which may be located outside the United Kingdom and your country of residence. See Section 7 of this Policy on international transfers. You may opt out of Google Analytics tracking at any time using the Google Analytics Opt-Out Browser Add-on or by adjusting your preferences in our cookie banner. Category 3: Marketing and Advertising These cookies are used to deliver targeted advertising based on your browsing and purchase behaviour on our Website, and to measure the effectiveness of our advertising campaigns. They are set only with your consent.
| Cookie Name | Set By | Purpose | Duration |
|---|---|---|---|
_fbp |
Meta Platforms, Inc. | Identifies browsers for advertising measurement and retargeting via Facebook and Instagram (Meta Pixel) | 3 months |
_fbc |
Meta Platforms, Inc. | Stores the click identifier when you arrive at our Website via a Facebook or Instagram advertisement | 3 months |
fr |
Meta Platforms, Inc. | Used by Meta to deliver, measure, and improve targeted advertisements shown on Meta platforms | 3 months |
Meta Pixel data is transferred to Meta's servers in the United States. See Section 7 on international transfers and Section 5.1 for a full description of how the Meta Pixel operates. Managing your preferences You can review and change your cookie preferences at any time by clicking Cookie Settings in the footer of our Website. You can also:
- Use your browser settings to block or delete cookies. Note that blocking strictly necessary cookies will affect core Website functionality.
- Opt out of Google Analytics via the Google Analytics Opt-Out Browser Add-on.
- Manage your Meta advertising preferences at facebook.com/ads/preferences.
Withdrawing consent for analytics or advertising cookies takes effect immediately. It does not affect the lawfulness of any processing that took place while consent was in place. Keeping this table up to date We review and update this cookie table whenever we add, change, or remove tracking technologies from our Website. The "Last Updated" date at the top of this Policy reflects the most recent revision. A live and automatically updated version of this table is also accessible via your cookie preference centre.
16. Updates to This Policy
We may update this Policy to reflect changes in our data practices, applicable law, or our Services. The updated Policy will be published with a revised 'Last Updated' date. For material changes, we will notify you by email or prominent Website notice before the change takes effect. Continued use of our Services after the effective date constitutes acceptance of the updated Policy.
17. Contact Us
For all privacy queries, requests, and complaints: Email: privacy@bonvale.com We aim to respond within one month. If unsatisfied, you may escalate to the UK Information Commissioner's Output (see Section 12), or to the data protection supervisory authority of your country of habitual residence, if applicable.