Privacy policy
PRIVACY POLICY
Last updated: June 2025
BuyNFlow ("we", "us", "our") is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
BuyNFlow operates the website buynflow.com. For any privacy-related enquiries, contact us at support@buynflow.com.
2. What Data We Collect
We collect the following personal data when you place an order or interact with our website:
- Full name
- Delivery address
- Email address
- Phone number
- Payment information (processed securely — we do not store card details)
- IP address and browsing behaviour (via cookies)
3. How We Use Your Data
We use your personal data to:
- Process and fulfil your orders
- Send order confirmations and shipping updates
- Respond to customer service enquiries
- Improve our website and shopping experience
- Send marketing communications (only with your consent)
- Comply with legal obligations
4. Legal Basis for Processing
Under UK GDPR, we process your data under the following legal bases:
- Contract: to fulfil your order
- Legal obligation: to comply with UK law
- Legitimate interests: to improve our services
- Consent: for marketing emails (you may withdraw at any time)
5. How We Share Your Data
We share your data only with trusted third parties necessary to fulfil your order:
- USA Drops: our fulfilment partner, to process and ship your order
- Shopify: our e-commerce platform (Shopify Inc., GDPR compliant)
- Payment processors: Stripe / PayPal / Shopify Payments
- Courier services: for delivery of your order
We do not sell your personal data to any third party.
6. International Data Transfers
As our fulfilment partners operate internationally, your data may be transferred outside the UK. Where this occurs, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
7. How Long We Keep Your Data
We retain your personal data for as long as necessary to fulfil the purposes outlined in this policy, typically:
- Order data: 7 years (legal requirement)
- Marketing data: until you withdraw consent
- Browsing data: as per our cookie policy
8. Your Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Correct inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing of your data
- Object to processing
- Data portability
To exercise any of these rights, email us at support@buynflow.com. We will respond within 30 days.
9. Cookies
We use cookies to improve your browsing experience and analyse site traffic. You can control cookie preferences through your browser settings. A full cookie policy is available on our website.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated date. Continued use of our website constitutes acceptance of the updated policy.
11. Contact & Complaints
For privacy concerns contact us at support@buynflow.com. If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.