Last updated: February 27, 2025
1. Introduction
Tily Blooms Ltd (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy & Cookies Policy explains how we collect, use, share, and protect your personal information when you use our website and services.
2. Who We Are
Tily Blooms Ltd is registered in the United Kingdom:
- Company Number: SC722172
- Registered Office:
Tily Blooms Ltd C/O
Bonnyrigg Business Park Ltd
3 Sherwood Ind Est
Bonnyrigg
Midlothian
EH19 3LW
- Data Protection Officer contact: dpo@tilyblooms.com
3. Information We Collect
3.1 Information You Provide
- Name and contact details
- Billing and delivery addresses
- Payment information (processed securely through our payment providers)
- Account login details
- Communication preferences
- Correspondence with our team
- Order history and preferences
3.2 Information Automatically Collected
- IP address and device information
- Browser type and settings
- Operating system
- Website usage data
- Cookies and similar technologies
- Location data (if enabled)
3.3 Information From Third Parties
- Amazon marketplace data
- Payment processor information
- Marketing partners (with consent)
- Social media platforms (if you interact with us)
4. How We Use Your Information
4.1 Primary Purposes
- Processing and fulfilling orders
- Managing your account
- Providing customer support
- Sending order updates and notifications
- Processing payments and refunds
- Preventing fraud and maintaining security
4.2 Additional Uses (With Consent)
- Marketing communications
- Product recommendations
- Newsletter distribution
- Market research and surveys
- Website and service improvements
- Analytics and performance monitoring
5. Legal Basis for Processing
We process your data under the following legal bases:
- Contract fulfillment
- Legal obligations
- Legitimate interests
- Consent (for marketing)
- Public interest
- Vital interests (in emergencies)
6. Data Sharing and Recipients
6.1 Third-Party Service Providers
- Amazon UK (order fulfillment)
- Payment processors
- Email service providers
- Analytics services
- Customer support tools
- Marketing platforms (with consent)
6.2 Legal Requirements
We may share information:
- To comply with legal obligations
- To protect rights and safety
- To enforce our terms
- In connection with a business transfer
7. Data Retention
7.1 Retention Periods
- Account information: Until account deletion
- Order information: 7 years (tax requirements)
- Payment information: As required by law
- Marketing data: Until consent withdrawal
- Cookies: Varies by type (see Cookies Policy)
7.2 Data Deletion
- Automatic deletion after retention period
- Manual deletion upon request
- Backup retention as required by law
8. Your Rights Under GDPR
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request data deletion
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent
- Lodge complaints with ICO
9. International Data Transfers
9.1 Data Location
- Primary storage: UK/EU
- Backup storage: UK/EU
- Third-party processing: As required
9.2 Transfer Safeguards
- Standard contractual clauses
- Adequacy decisions
- Privacy Shield (where applicable)
- Data processing agreements
10. Security Measures
We protect your data through:
- SSL/TLS encryption
- Secure data storage
- Access controls
- Regular security audits
- Staff training
- Incident response plans
11. Cookies Policy
11.1 What Are Cookies
Cookies are small text files stored on your device that help us provide and improve our services.
11.2 Types of Cookies We Use
Essential Cookies
- Purpose: Website functionality
- Duration: Session/Persistent
- Cannot be disabled
- Examples: Shopping cart, login status
Performance Cookies
- Purpose: Analytics and statistics
- Duration: 1-2 years
- Can be disabled
- Examples: Google Analytics, site metrics
Functionality Cookies
- Purpose: Remember preferences
- Duration: 1 year
- Can be disabled
- Examples: Language settings, user preferences
Targeting/Advertising Cookies
- Purpose: Marketing and ads
- Duration: 30-90 days
- Can be disabled
- Examples: Remarketing, ad personalisation
11.3 Cookie Management
You can manage cookies through:
- Browser settings
- Our cookie consent tool
- Third-party opt-out tools
12. Children’s Privacy
- We do not knowingly collect data from children under 16
- Parent/guardian consent required for under-16s
- Contact us to remove under-16 data
13. Changes to This Policy
- Regular policy reviews
- Update notifications on website
- Material changes notified by email
- Continued use implies acceptance
14. Contact Information
For privacy-related matters:
- Email: privacy@tilyblooms.com
- Post: Data Protection Officer, Tily Blooms Ltd C/O
Bonnyrigg Business Park Ltd
3 Sherwood Ind Est
Bonnyrigg
Midlothian
EH19 3LW
- Response time: Within 30 days
15. Complaints
If you’re unhappy with our response: Information Commissioner’s Office (ICO)