← Help Centre Privacy & GDPR
🔒

Help Centre

Privacy & GDPR Centre

Your data belongs to you. Here's everything about what we collect, how we use it, and how to exercise your rights under UK GDPR.

📋

What Data We Collect

What information do you collect when I create an account? +

When you register, we collect:

  • Your name and email address
  • A hashed (never plain-text) password
  • Your billing and shipping address(es)
  • Your phone number, if you choose to add one

Sellers also provide bank or payment account details so we can transfer payouts. This is processed securely and never stored in plain text.

Do you collect data when I'm just browsing? +

Yes. Like most websites, we automatically collect certain technical data when you visit, including:

  • Your IP address and approximate location (country/city)
  • Browser type and operating system
  • Pages visited and time spent on each
  • Referring URL (e.g. which search engine or site led you here)

This data is collected via cookies and analytics tools. See the Cookies section for full details and how to opt out.

What order and transaction data do you hold? +

When you place an order, we record:

  • Items purchased, quantities and prices
  • Payment method type (e.g. Visa ending in 4242) — we never store full card numbers
  • Delivery address and tracking information
  • Any messages exchanged with the seller about the order

Full card details are handled exclusively by our payment processor and are never stored on our servers.

🎯

How We Use Your Data

What is your lawful basis for processing my data? +

Under UK GDPR, we must have a lawful basis for every type of processing. We rely on:

  • Contract performance — to fulfil your orders, manage your account and communicate with sellers on your behalf
  • Legal obligation — to retain financial records for HMRC and comply with consumer law
  • Legitimate interests — to prevent fraud, secure our platform, and improve our service
  • Consent — for marketing emails and non-essential analytics cookies (you can withdraw this at any time)
Will you send me marketing emails? +

Only if you've opted in. We may send you:

  • New listings and promotions matching your saved searches or favourites
  • Seller announcements from shops you follow
  • Platform news and feature updates (you can opt in/out individually)

You can unsubscribe from any marketing email at any time using the link at the bottom of the email, or via Account → Notifications in your dashboard.

Do you use my data for automated decision-making? +

We use automated systems to detect fraud and flag suspicious activity (e.g. unusual login locations). These checks may temporarily restrict an account. If your account is restricted as a result, you have the right to request human review — contact our support team and we will manually review the decision within 5 working days.

⚖️

Your Rights Under UK GDPR

You have eight rights. We take all of them seriously.

To exercise any right, email our Data Protection Officer at privacy@ratch.uk or use the contact form below. We will respond within 30 days — the legal maximum.

Right of Access — can I see all the data you hold about me? +

Yes. You can make a Subject Access Request (SAR) at any time. We will provide a copy of all personal data we hold about you, free of charge, within 30 days.

Some data may be redacted where disclosure would affect the rights of another person (e.g. a seller's private messages to us about your order). We will explain any such redactions clearly.

Right to Erasure — can I have my account and data deleted? +

Yes — this is your "right to be forgotten". You can request deletion of your account and personal data. We will erase your data within 30 days, except where we are legally required to keep it.

What we must keep: Transaction records (invoices, VAT data) must be retained for 7 years under UK tax law. These will be anonymised as far as legally possible.

Sellers: If you have an active shop with outstanding payouts or open disputes, your account cannot be fully deleted until these are resolved. We will guide you through the process.

Right to Rectification — can I correct inaccurate data? +

Yes. You can update most personal data yourself in Account → Settings. For data you cannot edit directly (such as historical order records), contact us and we will correct inaccuracies promptly.

Right to Portability — can I export my data? +

Yes. You can request a machine-readable export (JSON or CSV) of the data you have provided to us and which we process on the basis of contract or consent. This includes your profile, purchase history, saved items, and messages.

Request a data export via our DPO contact form or at Account → Settings → Download my data.

Right to Object — can I stop you processing my data? +

You can object to processing carried out on the basis of legitimate interests or for direct marketing. For direct marketing, we will always stop immediately. For other processing, we will assess whether our legitimate interests override your right and respond within 30 days.

Right to Restrict Processing — can I pause how you use my data? +

In certain circumstances (e.g. you've contested the accuracy of data while we verify it), you can ask us to restrict processing. We'll keep the data but only process it for limited purposes (storage, legal claims, or with your consent) until the restriction is lifted.

🍪

Cookies & Tracking

What types of cookies do you use? +

We use three categories of cookie:

TypeConsent?Purpose
Essential Not required Login sessions, shopping basket, security (CSRF tokens). Cannot be disabled without breaking the site.
Analytics Required Understand how pages are used, measure performance, and identify errors. Data is aggregated and anonymised where possible.
Marketing Required Personalised adverts and retargeting. You can opt out at any time via your Cookie Settings.
How do I change or withdraw my cookie consent? +

You can update your cookie preferences at any time:

  • Click the Cookie Settings link in the footer of any page
  • Go to Account → Privacy Settings if you're logged in
  • Clear cookies in your browser settings (this resets all preferences)

Withdrawing consent does not affect the lawfulness of processing carried out before your withdrawal.

Do you use tracking pixels or third-party scripts? +

Only with your consent for marketing/analytics cookies. Third-party scripts currently on the site may include Google Analytics and Meta Pixel. Each third party's data use is governed by their own privacy policy. Our full list of data processors is available on request via our DPO.

🤝

Who We Share Data With

Do you sell my data to third parties? +

No. We never sell your personal data. We only share it when strictly necessary to deliver our service or comply with the law.

Who can see my name and address? +

Your delivery address is shared only with the seller who fulfilled your order, so they can ship your item. Sellers are bound by our seller agreement and UK GDPR to process this data solely for fulfilment.

Your address is not displayed publicly on your profile.

Which third-party services process my data? +

We work with the following categories of processor, all under a data processing agreement:

  • Payment processors — handle card data securely (PCI DSS compliant)
  • Cloud hosting providers — store our databases and files
  • Email / transactional SMS providers — send order confirmations and account notifications
  • Fraud detection services — analyse transactions for suspicious patterns
  • Analytics platforms — only where you've consented to analytics cookies

For a full list of processors, email privacy@ratch.uk.

Is my data transferred outside the UK? +

Some of our processors operate servers in the US or EEA. Where data is transferred outside the UK, we ensure one of the following safeguards is in place:

  • An ICO adequacy decision for the destination country
  • UK International Data Transfer Agreements (IDTAs)
  • UK-approved binding corporate rules
📅

How Long We Keep Data

How long do you keep my account data? +

We hold your account data for as long as your account is active. If you delete your account (or we close it), your personal profile data is erased within 30 days.

Inactive accounts (no login for 3 years) receive an email reminder before we begin deletion. We will always give you 30 days' notice.

How long do you keep transaction records? +

Financial and transaction records (invoices, payment records) must be retained for 7 years to comply with HMRC requirements, even after account deletion. These records are anonymised as much as the law permits.

How long are support messages and complaints kept? +

Support tickets are retained for 3 years to enable us to assist with follow-up queries and identify recurring issues. Complaints and any associated decisions are retained for 6 years in case of legal proceedings.

📧

Contact Our Data Protection Team

Data Protection Officer

privacy@ratch.uk

We respond to all privacy requests within 30 days — the legal maximum under UK GDPR.

For Subject Access Requests, account deletion, data exports, and any other data-related queries.

How do I complain to the ICO if I'm unhappy with our response? +

If you are unhappy with how we've handled a privacy request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection supervisory authority.

We would always prefer the chance to resolve your concern directly first — please contact us before escalating to the ICO.

Is there a full Privacy Policy I can read? +

Yes. Our full legal Privacy Policy is available at Privacy Policy. This Privacy Centre is designed to answer common questions in plain English — the full policy is the authoritative legal document.

Can't find the answer?

Still need help?

Our support team is available Monday – Friday, 9am–5pm (GMT). We typically reply within a few hours.

Made in the UK

Support local sellers

Satisfaction Guaranteed

Deal direct with Seller

Shop Local

Find sellers nationwide

100% Secure Checkout

Encrypted / MasterCard / Visa

We use cookies to give you the best online experience. By agreeing you accept the use of cookies in accordance with our cookie policy.