We are committed to safeguarding and protecting the rights and privacy of individuals, customers and others in accordance with The Data Protection Act 1998; this policy outlines how we will treat your personal information.
What information do we collect?
Xupes may collect, store and process the following kinds of personal data:
- Information about your computer and about your visits to and use of this website (including your IP address, geographical location, connection data, browser type and version, operating system, referral source, length of visit, page views, and navigation data).
- Information relating to any transactions carried out between you and us on or in relation to this website, including information relating to any purchases you make of our goods or services (including history of orders, transactions, claims, incidents, information relating to delivery, correspondence on our site).
- Information that you provide to us for the purpose of registering with us (including email, title, first name, last name, country, password, addresses, telephone number(s), date of birth, preferences). Upon collection, you are informed by an Asterix (*) whether the data to be provided is compulsory.
- Information that you provide to us for the purpose of subscribing to our website services, email notifications and/or newsletters.
- Any other information that you choose to send to us.
- Your bank details may be kept in a secured way for you to not have to retype them the next time you order. If you do not wish for your bank details to be kept, you can delete them after each order in the "my account" section. If you do not delete your bank details, they will be kept in "my account" until the credit card expiry date. We may also keep your bank details on file if you have previously sold an item or consigned an item to us. The purpose of said automatic data processing is to improve your experience with us, to identify the persons carrying out a payment and to fight against credit card fraud. You are entitled, at any time, to a right of access, modification and objection by writing a letter to us at Xupes Handbags & Jewellery LTD, The Victorian Barn, Wickham Hall, Hadham Road, Bishop's Stortford, Hertfordshire, CM23 1JG.
Some of the data is collected automatically depending on your actions on the website (see paragraph relating to cookies). We collect the information that you provide us with when:
- you create your profile form.
- you purchase or sell a product on the site.
- you browse the site and consult products.
- you take part in a competition.
- you contact our customer service.
Using Your Personal Information
The data that is collected on the site is intended for Xupes. Xupes neither sells nor shares your personal data to third parties for marketing purposes. However, we may share non-personally identifiable information, such as aggregated user statistics, with third parties without your consent. The data may be transferred to sub-contracting companies with whom Xupes can work within the framework of the performance of its services.
We may use your personal information:
- to administer the website.
- to improve your browsing experience by personalising the website.
- to enable your use of the services available on the website.
- to send to your goods purchased via the website, and supply to you services purchased via the website.
- to send statements and invoices to you and collect payments from you.
- to send you general (non-marketing) commercial communications.
- to send you email notifications which you have specifically requested.
- to send to you our newsletter and other marketing communications relating to our business which we think may be of interest to you by post or, where you have specifically agreed to this, by email or similar technology (you can inform us at any time if you no longer require marketing communications).
- to provide third parties with statistical information about our users. This information will not be used to identify any individual user.
- to send TrustPilot communications to review us.
All our website financial transactions are handled through our payment services provider, Adyen. We will share information with Adyen only to the extent necessary for the purposes of processing payments you make via our website and dealing with complaints and queries relating to such payments.
TrustPilot act as a data processor to assist with collecting feedback from people who have had a buying or service experience with us.
The main purpose of personal data collection is to offer you an optimal, efficient and personalised experience. You authorise us to use your personal data to:
- provide our services or process transactions that you have requested or agreed to receive.
- solve possible problems and disputes.
- personalise, value, improve our services and content.
- keep you informed of our services and those of our partners, by means of targeted marketing and/or promotional offers, with your consent.
- prevent, detect and enquire about all possible forbidden or illegal activities and have all our general conditions of sale and use applied.
- comply with our statutory, legal and regulatory obligations.
- contact you regarding your use of the site and, in our discretion, changes to the site and/or site's policies.
- perform internal business purposes.
Xupes Online Advertising
Like most companies selling products and services online, we engage in online advertising that appears on third party websites to keep you aware of what we're up to and to help you see and find our products and access our services. We target Xupes banners and ads to you when you are on other websites and apps. We do this using a variety of digital marketing networks and a variety of advertising technologies like pixels, ad tags, cookies and mobile identifiers, as well as specific services offered by some sites and social networks, such as Facebook Custom Audience Service.
The banners and ads you see will be based on information we hold about you, from what you've bought in the past or browsed on our website.
- In addition, we may disclose your personal information:
- to the extent that we are required to do so by law.
- in connection with any legal proceedings or prospective legal proceedings.
- in order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk).
International Data Transfers
Information which you provide may be transferred to countries which do not have data protection laws equivalent to those in force in the European Economic Area. You expressly agree to such transfers of personal information.
Security of Your Personal Information
We will take reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information. All electronic transactions you make to or receive from us will be encrypted using SSL technology. Of course, data transmission over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet.
- You may instruct us to provide you with any personal information we hold about you. Provision of such information will be subject to:
the payment of a fee (currently fixed at £10.00).
- the supply of appropriate evidence of your identity for this purpose, we will usually accept a photocopy of your passport certified by a solicitor or bank plus an original copy of a utility bill showing your current address.
We may withhold such personal information to the extent permitted by law.
You may instruct us not to process your personal information for marketing purposes by email at any time. In practice, you will usually either expressly agree in advance to our use of your personal information for marketing purposes, or we will provide you with an opportunity to opt-out of the use of your personal information for marketing purposes.
Third Party Websites
The website contains links to other websites. We are not responsible for the privacy policies or practices of third-party websites.
Information You Provide About a Third Party
If you send someone else a communication from the site, such as sending an invitation to a friend, the information you provide (names, email addresses, etc.) is used to facilitate the communication and is not used by us for any other marketing purpose unless we obtain consent from that person, or we explicitly say otherwise. Please be aware that when you use any send-to-a-friend functionality on our Site, your e-mail address and/or name may be included in the communication sent to your addressee(s).
Please let us know if the personal information which we hold about you needs to be corrected or updated.
The data controller responsible in respect of the information collected on this website is Xupes Handbags & Jewellery LTD.
In addition to any personal information or other information that you choose to submit to us, we may use a variety of technologies that automatically (or passively) collect certain information whenever you visit or interact with the site ("usage Information"), which technologies may be downloaded to your device (defined below) and may set or modify settings on your device. This usage Information may include the browser that you are using, the URL that referred you to our site, the areas within our site that you visit and your activities there, your device location, your device characteristics and certain device data, and the time of day, among other information. We may use usage information for a variety of purposes, including to assess, enhance or otherwise improve the site or our activities in connection with them. In addition, we may collect your IP address or other unique identifier ("device Identifier") for your computer or other device used to access the site (any, a "device"). A device Identifier is a number that is automatically assigned to your device used to access the site, and our computers identify your device by its device Identifier. We may access and use device identifiers that have already been associated with your device, may modify such identifiers to create a new identifier or associate a wholly new identifier with you or your device. Usage information may be non-identifying or may be associated with you. Whenever we associate usage information or a device identifier with your personal information, we will treat it as personal information. We may use various new and hereafter developed technologies to collect device identifiers and usage information about you ("tracking technologies"). A few of the methods that may be used to collect usage information include, without limitation, the following (and subsequent technology and methods hereafter developed).
A cookie consists of information sent by a web server to a web browser and stored by the browser. The information is then sent back to the server each time the browser requests a page from the server. This enables the web server to identify and track the web browser. We may use both "session" cookies and "persistent" cookies on the website. We will use the session cookies to keep track of you whilst you navigate the website. We will use the persistent cookies to enable our website to recognise you when you visit. Session cookies will be deleted from your computer when you close your browser. Persistent cookies will remain stored on your computer until deleted, or until they reach a specified expiry date. By default, cookies are not automatically installed except for cookies that are necessary for the functioning of the Xupes website and services. Pursuant to applicable regulations, Xupes will need your authorisation before installing any other type of cookies. In order to avoid any disruption due to these systematic authorisation requests, and to benefit from uninterrupted browsing, we can memorise your refusal or authorisation relating to certain cookies. It should be noted that without certain cookies, Xupes cannot guarantee certain orders.
An embedded script is programming code that is designed to collect information about your interactions with the site, such as the links you click on. The code is temporarily downloaded onto your Device from our web server or a third-party service provider, is active only while you are connected to the site and is deactivated or deleted thereafter.
ETags or Entirety Tags
ETags or Entirety Tags are a feature of the cache in browsers. It is an opaque identifier assigned by a web server to a specific version of a resource found at a URL. If the resource content at that URL ever changes, a new and different ETag is assigned. Used in this manner, ETags are a form of device identifier. ETag tracking may generate unique tracking values even where the consumer blocks HTTP, Flash, and HTML5 cookies.