Privacy policy
Privacy Policy
Introduction
Crestholm Ltd. ("Crestholm", "we", "our", "us") operates crestholm.com and is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and the rights available to you as a customer or visitor.
By accessing our website or placing an order, you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please refrain from using our services.
Information We Collect
We collect the following categories of personal data when you interact with our website or services:
| Category | Examples |
|---|---|
| Identity data | First name, last name |
| Contact data | Email address, shipping address, phone number |
| Transaction data | Order details, products purchased, payment confirmation |
| Technical data | IP address, browser type, device, pages visited, time spent |
| Marketing data | Preferences, communication opt-ins, ad interactions |
We do not store payment card details. All transactions are processed securely by certified third-party payment providers (Stripe, PayPal, Shopify Payments).
How We Use Your Information
Your personal data is used exclusively for the following purposes:
- Processing and fulfilling your orders
- Sending order confirmations, shipping updates and delivery notifications
- Responding to customer service enquiries and support requests
- Preventing fraud, chargebacks and unauthorised account activity
- Improving website performance, user experience and product offering
- Sending marketing communications where you have opted in
- Complying with legal obligations and resolving disputes
Legal Basis for Processing
Under UK GDPR and applicable data protection law, we process your personal data under the following legal bases:
- Contract performance — to fulfil orders you have placed with us
- Legitimate interests — to protect our business from fraud, disputes and misuse
- Legal obligation — to comply with applicable laws and regulations
- Consent — for marketing emails and cookies where applicable
Sharing Your Information
We do not sell, rent or trade your personal data. We may share it only with trusted third parties strictly necessary to operate our business:
- Shopify Inc. — our e-commerce platform provider
- Payment processors — Stripe, PayPal, and Shopify Payments
- Logistics and courier partners — for order fulfilment and delivery
- Email and marketing platforms — where you have opted in to communications
- Legal and regulatory authorities — when required by law or court order
All third-party partners are contractually obligated to handle your data securely and in accordance with applicable data protection legislation.
Cookies & Tracking
Our website uses cookies and similar tracking technologies to enhance your browsing experience and measure the performance of our marketing campaigns. These include:
- Essential cookies — required for the website to function correctly
- Analytics cookies — to understand how visitors interact with our site (Google Analytics)
- Marketing cookies — to deliver relevant ads on platforms such as Meta and TikTok
You may manage or disable cookies through your browser settings at any time. Note that disabling certain cookies may affect the functionality of our website.
Data Retention
We retain your personal data for as long as necessary to fulfil the purposes outlined in this policy, including for legal, accounting and dispute resolution requirements.
- Order and transaction records — retained for a minimum of 6 years
- Customer support communications — retained for 3 years
- Marketing opt-in records — retained until consent is withdrawn
Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right to access — request a copy of the data we hold about you
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your data where no legal basis exists for retention
- Right to restrict processing — request that we limit how we use your data
- Right to data portability — request your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests or for marketing
To exercise any of these rights, contact us at support@crestholm.com. We will respond within 30 days. We may request proof of identity before processing your request.
Third-Party Links
Our website may contain links to third-party websites. Crestholm is not responsible for the privacy practices or content of any external sites. We encourage you to review the privacy policy of any site you visit.
Children's Privacy
Our website and products are intended for adults aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided us with personal data, please contact us immediately and we will take steps to delete it.
Changes to This Policy
We reserve the right to modify this Privacy Policy at any time. Changes will be posted on this page with an updated effective date. Your continued use of our website after any changes constitutes acceptance of the revised policy.
Privacy enquiries