Privacy Policy
Last updated: 6 July 2026
Discretion is part of what we sell. This policy explains what data we collect, why, and how we protect it — under the UK GDPR and the Data Protection Act 2018.
1. Who is responsible
The data controller is SaintSinners. Contact: hello@saintsinners.co.uk.
2. What we collect and why
- Orders — name, delivery address, email, phone (optional), items ordered. Used to fulfil your contract with us (lawful basis: contract).
- Payments — handled entirely by our payment providers (Stripe, PayPal). We never see or store your full card details.
- “After Dark” email list — your email address, joined by your explicit action. Used to send early-access and drop announcements (lawful basis: consent). Unsubscribe at any time.
- Site usage — basic technical data (IP, browser) in server logs for security and troubleshooting (lawful basis: legitimate interests).
3. Discretion
- All orders ship in plain, unbranded packaging.
- We never publish, share or sell customer lists. We will never disclose what you purchased to anyone but you, except where required by law.
- Bank/card statements show the descriptor set by our payment provider.
4. Who we share data with
Only what’s necessary, only to run the store: payment processors (Stripe, PayPal), our hosting provider, and delivery carriers (name and address only). We do not sell personal data.
5. Cookies
We use strictly necessary cookies for the cart and checkout to function. If we add analytics or marketing cookies in future, we will ask for your consent first.
6. How long we keep data
Order records are kept for 6 years to meet tax and accounting obligations. Email-list data is kept until you unsubscribe. Server logs rotate automatically.
7. Your rights
You have the right to access, correct, delete, restrict or object to our use of your data, and to data portability. Email hello@saintsinners.co.uk and we will respond within one month. You can also complain to the Information Commissioner’s Office (ico.org.uk).
8. Security
The site is served over HTTPS. Access to customer data is limited to those who need it. Payment data never touches our servers.