The Snug SpotTheSnugSpot Back to shop

Legal

Privacy Policy

Last updated: April 8, 2026

Contents

  1. Overview
  2. Information We Collect
  3. How We Use Your Information
  4. Sharing Your Information
  5. Cookies & Tracking
  6. Data Security
  7. Data Retention
  8. Your Rights
  9. Children's Privacy
  10. Changes to This Policy
  11. Contact Us
Your privacy matters to us. This policy explains clearly what data we collect, why we collect it, and how you can control it. We never sell your personal data to third parties.

1. Overview

Data Controller

The data controller responsible for your personal information is:

  • Name: Milene Borges de Moura (trading as The Snug Spot)
  • Address: 58 Sydney Road, London SW20 8EF
  • Email: support@thesnugspot.com

The Snug Spot ("we," "us," or "our") is committed to protecting your personal information. This Privacy Policy describes how we collect, use, store, and share information when you visit our website at thesnugspot.com (the "Site") or make a purchase from us.

This policy applies to all information collected through the Site, as well as any related communications, including emails, order confirmations, and customer support interactions.

2. Information We Collect

Information You Provide Directly

We collect information you provide when you:

  • Place an order (name, email address, shipping address, payment details)
  • Create an account (name, email, password)
  • Contact our customer support team
  • Sign up for our newsletter or promotional emails

Information Collected Automatically

When you visit our Site, we automatically collect certain technical information:

Data Type Examples Purpose
Device & browser info Browser type, operating system, screen resolution Optimise Site display
Usage data Pages visited, time on site, clicks, referral URL Improve Site experience
IP address Approximate geographic location Security, fraud prevention
Cookies Session tokens, preference data Cart persistence, analytics

Payment Information

All payment processing is handled by Stripe, Inc. We do not store your full credit card number, CVV, or bank details on our servers. Stripe's privacy policy governs the handling of your payment data and is available at stripe.com/privacy.

3. How We Use Your Information

We use the information we collect for the following purposes. Under UK GDPR Article 6, every use of personal data must have a lawful basis. We have set out the lawful basis for each purpose below:

Purpose Description Lawful Basis (Art. 6)
Order fulfilment Processing purchases, arranging delivery, order confirmations and updates Performance of a contract (Art. 6(1)(b))
Customer support Responding to enquiries, resolving disputes, handling returns Performance of a contract (Art. 6(1)(b))
Account management Creating and maintaining your account, authenticating your identity Performance of a contract (Art. 6(1)(b))
Marketing Promotional emails, new arrivals, special offers — only if you have opted in Consent (Art. 6(1)(a))
Site improvement Analysing usage patterns to improve functionality and content Legitimate interests (Art. 6(1)(f))
Fraud prevention Detecting, investigating, and preventing fraudulent transactions Legitimate interests (Art. 6(1)(f))
Legal compliance Meeting tax, accounting, and other legal obligations Legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms. You have the right to object to processing based on legitimate interests (see Your Rights).

Where we rely on consent, you may withdraw your consent at any time by unsubscribing from emails or contacting us at support@thesnugspot.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Email Marketing & PECR Compliance

We only send marketing emails to individuals who have given explicit, informed consent via our newsletter signup form (which includes an unticked consent checkbox). In compliance with the Privacy and Electronic Communications Regulations 2003 (PECR):

  • Every marketing email will contain a clear, working unsubscribe link
  • Unsubscribe requests will be processed within 48 hours
  • We will never share your email address with third parties for their marketing purposes
  • We maintain a suppression list of unsubscribed addresses to prevent future mailings

4. Sharing Your Information

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We may share your information with trusted third parties only as necessary to operate our business:

  • Stripe: Payment processing and fraud prevention
  • Shipping carriers: Fulfilment of your order (name, address, contact details shared with carrier)
  • GitHub Pages: Hosting and infrastructure services
  • Email service providers: Sending transactional and marketing emails (only data necessary for delivery)
  • Analytics providers: Aggregated, anonymised usage data only

All third-party service providers are required to maintain appropriate security measures and are prohibited from using your personal information for their own purposes.

International Data Transfers

Some of our third-party service providers (including Stripe and GitHub) are based in the United States. When your personal data is transferred outside of the United Kingdom, we ensure that appropriate safeguards are in place, including:

  • UK adequacy regulations: Transfers to countries recognised by the UK Secretary of State as providing an adequate level of data protection
  • Standard Contractual Clauses (SCCs): Where no adequacy decision exists, our providers operate under International Data Transfer Agreements or UK Addendum to EU SCCs approved by the ICO
  • Supplementary measures: Encryption in transit and at rest, access controls, and contractual obligations

You may request a copy of the safeguards in place by contacting us at support@thesnugspot.com.

We may also disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the rights, property, or safety of The Snug Spot, our customers, or others.

5. Cookies & Tracking

What Are Cookies

Cookies are small text files placed on your device when you visit our Site. They help us provide you with a better experience by remembering your preferences and understanding how you use the Site.

Types of Cookies We Use

  • Essential cookies: Required for the Site to function (cart contents, session data). Cannot be disabled.
  • Preference cookies: Remember your settings and preferences across visits.
  • Analytics cookies: Help us understand how visitors interact with the Site (e.g., pages visited, time spent). Data is aggregated and anonymised. Only set if you consent.

Specific Cookies We Set

Cookie Name Type Purpose Duration
snugspot_cart Essential Stores your shopping cart contents so items are remembered between pages 7 days
snugspot_cart_ts Essential Timestamp for cart expiry calculation 7 days
snugspot_cookies Essential Cookie preferences — stores your cookie consent choices so we do not ask again Persistent (until cleared)

We use localStorage (browser-based storage) rather than traditional HTTP cookies for the items above. They are never sent to our servers automatically and are only accessible on your device.

Consent & Withdrawal

Non-essential cookies (analytics and personalisation) are only set after you give consent via our cookie preferences modal, which appears on your first visit. The lawful basis for non-essential cookies is consent (UK GDPR Art. 6(1)(a) and PECR Regulation 6).

You can withdraw your consent at any time by clicking "Cookie Preferences" in the footer of any page and changing your selections. Withdrawal of consent will take effect immediately — no further non-essential cookies will be set. Withdrawal does not affect the lawfulness of processing carried out before you withdrew consent.

Managing Cookies

You can also control cookies through your browser settings. Most browsers allow you to refuse new cookies, delete existing cookies, or be notified when a new cookie is set. Disabling essential cookies may affect the functionality of the Site, including your ability to complete a purchase.

6. Data Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • HTTPS encryption for all data transmitted between your browser and our Site
  • Secure, encrypted payment processing via Stripe
  • Access controls limiting who can access customer data within our organisation
  • Regular review of our data collection and storage practices

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, as required by UK GDPR Article 33
  • Where the breach is likely to result in a high risk to your rights and freedoms, notify you directly without undue delay (UK GDPR Article 34)
  • Document all breaches, including those not reported to the ICO, as part of our accountability obligations

7. Data Retention

We retain your personal information for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required or permitted by law.

  • Order and transaction data: Retained for 7 years for tax and accounting purposes
  • Account data: Retained until you close your account, plus a 90-day deletion window
  • Marketing preferences: Retained until you unsubscribe or request deletion
  • Analytics data: Aggregated, anonymised data may be retained indefinitely

When personal data is no longer needed, we securely delete or anonymise it.

8. Your Rights

Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights regarding your personal information:

  • Access (Art. 15): Request a copy of the personal data we hold about you
  • Correction (Art. 16): Request correction of inaccurate or incomplete data
  • Deletion (Art. 17): Request deletion of your personal data ("right to be forgotten"), subject to legal obligations
  • Restriction (Art. 18): Request that we restrict the processing of your personal data in certain circumstances — for example, if you contest the accuracy of your data or object to processing pending verification
  • Portability (Art. 20): Request your data in a structured, commonly used, machine-readable format
  • Objection (Art. 21): Object to processing based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will stop immediately
  • Withdrawal of consent: Withdraw consent at any time (for marketing emails, click "unsubscribe" in any email; for cookies, click "Cookie Preferences" in the footer; or contact us directly). Withdrawal does not affect the lawfulness of processing carried out before withdrawal
  • Automated decision-making (Art. 22): We do not carry out any automated decision-making or profiling that produces legal or similarly significant effects on you

How to Make a Request (Including Subject Access Requests)

To exercise any of these rights, please email us at support@thesnugspot.com with:

  • Your full name and the email address associated with your order or account
  • A description of the right you wish to exercise
  • Any details that will help us locate your data (e.g., order number)

We may ask you to verify your identity before processing your request. This is to protect your data from being disclosed to someone who is not entitled to it. We will not charge a fee for standard requests. We will respond without undue delay and in any event within one calendar month of receipt, as required by UK GDPR Article 12(3). In exceptional circumstances (complex or numerous requests), we may extend this by a further two months, but we will inform you within the first month and explain why.

Your rights above are provided under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

9. Children's Privacy

The Site is not directed to children under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us at support@thesnugspot.com and we will promptly delete such information.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this page.

If we make significant changes to how we process your personal data, we will notify you by email or prominent notice on our website and, where required, seek your consent before the changes take effect.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

  • Email: support@thesnugspot.com
  • General enquiries: support@thesnugspot.com
  • Response time: We will acknowledge privacy-related requests within 5 business days and provide a full response within one calendar month, as required by UK GDPR.

For our Terms of Service, please visit thesnugspot.com/terms.

© 2026 The Snug Spot is a trading name of Milene Borges de Moura (Sole Trader). 58 Sydney Road, London SW20 8EF. All rights reserved. support@thesnugspot.com

Privacy Policy Terms Returns Accessibility Back to Shop