SHUTTERLUXE PRIVACY POLICY
Last Updated: 19 January 20261. Who We Are
ShutterLuxe is a family-run, Yorkshire-based business specialising in custom-made plantation shutters and blinds. We take the privacy of our customers and website visitors very seriously. For the purpose of the UK General Data Protection Regulation (UK GDPR), the Data Controller (the entity responsible for how your data is used) is ShutterLuxe. Our Contact Details (Data Controller):| Item | Details |
|---|---|
| Name of Business: | ShutterLuxe [INSERT LEGAL BUSINESS NAME & ADDRESS HERE] |
| Contact Phone: | 07394 057 613 |
| Contact Email: | hello@shutterluxe.co.uk |
2. The Personal Data We Collect
We only collect personal data directly from you when you actively provide it to us via our website forms.| Category of Data | Specific Data Collected | Purpose of Processing | Lawful Basis for Processing (UK GDPR) |
|---|---|---|---|
| Identity/Contact Data | Name, Phone Number(s), Email Address, Postcode/Address. | To contact you to discuss your enquiry, book a free home consultation, provide a quote, and fulfil the final installation contract. | Contract: Processing is necessary to take steps at your request before entering into a contract (providing a quote/consultation). |
| Marketing Data | Your preference to receive future marketing or product updates (if an opt-in box is used on the form). | To send you updates, news, and relevant product information after your initial enquiry is resolved. | Consent: You have given clear consent for us to process your personal data for a specific purpose. |
3. How Your Data is Stored and Processed
Your personal data collected via the website forms is managed and securely stored using a third-party Customer Relationship Management (CRM) platform.- CRM System: We use GoHighLevel (GHL) to store and manage your enquiry data. GHL acts as our Data Processor. We have a contractual relationship (Data Processing Agreement or equivalent terms) in place to ensure GHL handles your data according to UK GDPR standards. Your data is used solely for the purpose of managing your customer journey with ShutterLuxe.
4. Use of Google Analytics 4 (GA4) and Google Tag Manager (GTM)
We use Google Analytics 4, a web analytics service provided by Google LLC (‘Google’), to understand how visitors interact with our website.Unlike previous versions of Google Analytics, GA4 does not log or store individual IP addresses. Instead, it uses IP anonymisation by default and processes data through ‘events’ rather than sessions. This allows us to measure user interactions (such as page views, clicks, and scrolling) while protecting your privacy.
Data Retention: User-level and event-level data stored by Google Analytics is automatically deleted from Google’s servers after 14 months. Aggregated data (which does not identify individuals) may be kept for a longer period to support our long-term analytics.
Google Signals: We have not currently enabled ‘Google Signals’ in Google Analytics. If enabled in future, this feature would associate visitation information with Google information from signed-in users who have consented, for ads personalisation and cross-device insights (anonymised and aggregated). You can manage your data via ‘My Activity’ on your Google account.
Cookies Used: Google Analytics 4 uses the following first-party cookies to distinguish unique users and sessions:
- _ga: Used to distinguish users. (Expires: 2 years)
- _ga_[Your-Measurement-ID]: Used to persist session state. (Expires: 2 years)
5. How We Use Website Analytics (Plausible)
We use a privacy-focused analytics tool called Plausible Analytics to understand how our website is performing.- Data Collected: Plausible is designed to be fully compliant with UK GDPR and does not use cookies, does not track individual visitors, and does not store any personal or identifiable data (like IP addresses).
- Purpose: The data is fully aggregated and anonymous (e.g., “50 people visited the homepage”) and is used purely to help us improve the content and structure of our website.
- Consent: Because Plausible collects no personal data and uses no cookies, we are not required to obtain consent or use a cookie banner specifically for this tool under UK privacy law (PECR and GDPR).
6. Data Security
We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way. This includes encrypted connections on our website and secure password-protected access to our CRM system (GoHighLevel).7. Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purpose of satisfying any legal, accounting, or reporting requirements.- If you become a customer, we keep your data for the duration of the guarantee period plus a reasonable time to manage any future works or queries.
- If you do not become a customer, we will delete your contact information after a period of **[State a specific, reasonable period, e.g., 18 months]** unless you have consented to receive marketing emails.
8. Disclosure of Your Personal Data
We will not sell, share, or rent your personal data to any third party for marketing purposes. We may share your data with the following parties only where necessary to fulfil our contract with you:- The installer/fitter who attends your property (who is part of the ShutterLuxe family business).
- Legal/Regulatory Bodies if legally required to do so (e.g., tax authorities, if requested).
9. Your Legal Rights (UK GDPR)
Under UK GDPR, you have the right to:- Right to be informed: The right to know how your data is being used (which is the purpose of this policy).
- Right of access: The right to ask for a copy of the personal data we hold about you (a Subject Access Request).
- Right to rectification: The right to ask us to correct incomplete or inaccurate data we hold about you.
- Right to erasure: The right to ask us to delete or remove personal data where there is no good reason for us to continue processing it.
- Right to restrict processing: The right to temporarily suspend the processing of your personal data.
- Right to data portability: The right to request the transfer of your data to another party.
- Right to object: The right to object to the processing of your personal data where we are relying on a legitimate interest.
- Right to withdraw consent: Where we are relying on consent to process your personal data, you have the right to withdraw that consent at any time.
10. How to Complain
If you have any concerns about our use of your personal information, you can make a complaint to us directly using the contact details in Section 1. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues.- ICO Helpline: 0303 123 1113
- ICO Website: https://www.ico.org.uk