Privacy Policy

SHOPRIDGE LIMITED (“SHOPRIDGE”, “we”, “us”, or “our”) respects your privacy and is committed to protecting your personal information.

This Privacy Policy explains how we collect, use, store, protect, and disclose personal information when you visit our website, contact us, request information, purchase our services, or otherwise interact with SHOPRIDGE.

This policy applies to our website and services, including our ecommerce store management, store optimization, ecommerce strategy and consultancy, marketplace management, and related services.

We aim to provide privacy information in a clear and accessible way, including information about why we process personal data, our lawful bases, who may receive it, how long we retain it, and the rights available to individuals.


1. About SHOPRIDGE LIMITED

Company: SHOPRIDGE LIMITED

Website: https://shopridge.co.uk/

Email: [email protected]

Telephone: +44 7735 313753

Address: 82a James Carter Road, Mildenhall, United Kingdom, IP28 7DE

For the personal data processing described in this Privacy Policy, SHOPRIDGE will generally act as the data controller where it determines why and how personal data is processed.

If a particular client engagement requires SHOPRIDGE to process personal data strictly on behalf of a client, the relevant contractual and data-processing arrangements may apply.


2. What Personal Information We Collect

The information we collect depends on how you interact with us.

We may collect the following categories of personal information.

2.1 Contact Information

This may include:

  • Full name

  • Business name

  • Email address

  • Telephone number

  • Business address

  • Correspondence address

  • Contact preferences

2.2 Enquiry Information

When you contact us or request information, we may collect:

  • Your enquiry

  • Information included in your message

  • Service requirements

  • Project requirements

  • Business information you choose to provide

  • Communication history

2.3 Client Information

If you purchase or engage our services, we may collect information required to manage the business relationship, including:

  • Name

  • Company details

  • Contact details

  • Service requirements

  • Package information

  • Project information

  • Billing information

  • Payment status

  • Contractual information

  • Communications

2.4 Technical Information

When you visit our website, certain technical information may be collected automatically, depending on the technologies installed on the website.

This may include:

  • IP address

  • Browser type

  • Device type

  • Operating system

  • General geographic information

  • Website pages visited

  • Referring website

  • Date and time of access

  • General website interaction information

  • Technical diagnostic information

2.5 Website Usage Information

Depending on the analytics and cookie technologies we use, we may collect information about:

  • Pages viewed

  • Time spent on pages

  • Navigation activity

  • Website interactions

  • General visitor behaviour

  • Website performance

Where non-essential cookies or similar technologies require consent, we will seek consent where legally required.

2.6 Payment Information

Where you purchase our services, payment may be processed by an external payment provider.

We may receive information such as:

  • Payment status

  • Transaction reference

  • Amount paid

  • Date of payment

  • Payment method type

We generally do not need to store complete payment-card details ourselves where a third-party payment processor handles payment processing.

Your payment provider may process your information under its own privacy policy.

2.7 Information You Provide During Service Delivery

When providing ecommerce services, you may voluntarily provide business information, store information, product information, marketplace information, analytics, or other materials required to perform the agreed services.

We process such information only as reasonably necessary to provide the relevant service.


3. How We Collect Personal Information

We may collect information:

  • Directly from you

  • When you complete a contact form

  • When you email us

  • When you telephone us

  • When you request a quotation

  • When you purchase a service

  • During service delivery

  • Through website interactions

  • Through cookies or similar technologies

  • From publicly available business sources

  • From third-party platforms where reasonably necessary to provide our services

  • From service providers acting on our behalf

Where we obtain personal information from sources other than the individual concerned, we will provide appropriate privacy information as required by applicable law. UK GDPR transparency requirements can differ depending on whether information is obtained directly or from another source.


4. Why We Use Personal Information

We may use personal information for the following purposes.

4.1 Responding to Enquiries

We use contact information and enquiry details to:

  • Respond to questions

  • Provide requested information

  • Discuss service requirements

  • Arrange consultations

  • Provide quotations

  • Communicate about potential projects

4.2 Providing Our Services

Where you become a client, we may use relevant information to:

  • Deliver purchased services

  • Manage projects

  • Communicate about work

  • Provide reports or recommendations

  • Manage ecommerce-related activities

  • Manage marketplace-related activities

  • Coordinate approvals

  • Complete agreed deliverables

4.3 Managing Payments

We use relevant information to:

  • Process payments

  • Confirm transactions

  • Maintain payment records

  • Manage invoices

  • Address payment issues

4.4 Managing Business Relationships

We may use information to:

  • Maintain client records

  • Communicate with clients

  • Manage contracts

  • Maintain project records

  • Provide customer support

  • Resolve service-related issues

4.5 Improving Our Website

We may use technical and website usage information to:

  • Understand website performance

  • Identify technical problems

  • Improve navigation

  • Improve content

  • Understand general visitor behaviour

  • Improve website functionality

4.6 Security and Fraud Prevention

We may process information to:

  • Protect our website

  • Prevent unauthorized access

  • Detect suspicious activity

  • Protect our systems

  • Investigate security incidents

  • Prevent fraud or misuse

4.7 Legal and Regulatory Compliance

We may process personal information where necessary to:

  • Comply with legal obligations

  • Maintain business records

  • Respond to lawful requests

  • Establish or defend legal claims

  • Meet accounting or tax requirements

  • Protect our legal rights

4.8 Marketing

Where permitted by applicable law, we may use contact information to send information about our services, updates, or relevant business communications.

Where consent is required, we will seek consent before sending marketing communications.

You can opt out of marketing communications at any time.


5. Lawful Bases for Processing

Under UK data-protection law, we need a lawful basis for processing personal information. The appropriate basis depends on what we are doing with the information.

We may rely on the following lawful bases.

5.1 Contract

We may process personal information where necessary to enter into or perform a contract with you.

For example:

  • Providing purchased services

  • Managing a project

  • Processing payments

  • Communicating about contracted services

5.2 Legitimate Interests

We may process information where necessary for our legitimate interests, provided those interests are not overridden by your rights and interests.

Our legitimate interests may include:

  • Operating and improving our business

  • Managing client relationships

  • Improving our website

  • Maintaining website security

  • Preventing fraud

  • Communicating with existing business contacts

  • Improving our services

5.3 Consent

We may rely on consent where appropriate, such as certain forms of marketing or non-essential cookies.

Where processing is based on consent, you can withdraw your consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

5.4 Legal Obligation

We may process information where necessary to comply with a legal or regulatory obligation.

5.5 Vital Interests

In exceptional circumstances, personal information may be processed where necessary to protect someone’s vital interests.


6. Legitimate Interests

Where we rely on legitimate interests, our interests may include operating a professional ecommerce consultancy business, communicating with clients and prospective clients, protecting our systems, improving services, maintaining business records, and preventing misuse.

Before relying on legitimate interests where required, we consider whether the processing is necessary and whether the individual’s rights and interests should override our interests.


7. Who We Share Personal Information With

We do not sell personal information to third parties.

We may share personal information with appropriate third parties where necessary to operate our business or provide our services.

These may include:

Payment Providers

Payment providers may process payment and transaction information when you purchase our services.

Website and Hosting Providers

Website hosting and technical service providers may process technical information necessary to operate our website.

Email and Communication Providers

We may use email, communication, CRM, or customer-support systems to communicate with clients and manage enquiries.

Analytics Providers

Where used, analytics providers may receive website usage information to help us understand website performance.

Professional Advisers

We may disclose relevant information to professional advisers such as accountants, lawyers, insurers, or other advisers where reasonably necessary.

Government and Regulatory Authorities

We may disclose information where required by law or where necessary to comply with a lawful request.

Business Service Providers

We may use third-party providers for services such as:

  • IT support

  • Cloud storage

  • Website maintenance

  • Security

  • Software

  • Project management

  • Customer relationship management

We require appropriate service providers to handle information only for legitimate purposes and, where applicable, under appropriate contractual arrangements.

The ICO recommends that privacy notices identify recipients or categories of recipients of personal data.


8. International Transfers

Some of our service providers may process personal information outside the United Kingdom.

Where personal information is transferred internationally, we will seek to ensure that appropriate safeguards are in place as required by applicable data-protection law.

Depending on the circumstances, safeguards may include:

  • An applicable adequacy decision

  • Appropriate contractual safeguards

  • Standard contractual protections

  • Other legally recognized transfer mechanisms

Where required, information about applicable safeguards may be made available upon request.


9. How Long We Keep Personal Information

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required or permitted by law.

Retention periods may depend on:

  • The nature of the information

  • Why we collected it

  • Whether you are a client

  • Legal obligations

  • Accounting requirements

  • Contractual requirements

  • Potential disputes

  • Security requirements

Typical retention categories may include:

Enquiry information: retained for as long as reasonably necessary to respond to and manage the enquiry and for legitimate business records.

Client information: retained for the duration of the business relationship and for an appropriate period afterward.

Financial records: retained for the period required by applicable accounting and tax obligations.

Marketing information: retained until you withdraw consent or otherwise opt out, subject to applicable law.

Technical information: retained according to the relevant analytics, security, hosting, and cookie configuration.

When information is no longer required, we will securely delete it, anonymize it, or otherwise dispose of it appropriately.

The ICO expects privacy information to explain how long information is retained or the criteria used to determine the retention period.


10. Cookies and Similar Technologies

Our website may use cookies and similar technologies.

Cookies are small files or identifiers stored on or associated with your device that can help websites remember information and understand website usage.

Cookies may be used for:

  • Essential website functionality

  • Security

  • Website preferences

  • Analytics

  • Performance monitoring

  • Marketing, where applicable

Essential Cookies

These may be necessary for the website to operate properly.

Analytics Cookies

Where used, analytics cookies can help us understand how visitors use our website and identify opportunities to improve performance.

Marketing Cookies

If we use advertising or marketing cookies that are not strictly necessary, we will seek consent where required.

The ICO states that visitors should be informed about cookies and that consent is generally required for non-essential cookies.

You may be able to control cookies through your browser or our cookie-consent mechanism where available.

For more information, please refer to our Cookie Policy if one is provided separately.


11. Direct Marketing

We may communicate with you about SHOPRIDGE services where permitted by applicable law.

Marketing communications may include:

  • Service updates

  • Ecommerce insights

  • Business information

  • New service announcements

  • Relevant offers

  • Company news

Where consent is required, we will request it.

You can unsubscribe from marketing communications by:

After receiving an opt-out request, we will stop sending marketing communications except where another lawful basis allows us to contact you for non-marketing purposes.


12. Data Security

We take reasonable technical and organizational measures to protect personal information.

Security measures may include:

  • Access controls

  • Password protection

  • Account permissions

  • Secure communications

  • Device security

  • Software updates

  • Data backups

  • Access limitation

  • Monitoring for suspicious activity

However, no internet transmission or electronic storage system can be guaranteed to be completely secure.

You should also take appropriate steps to protect your own accounts, devices, passwords, and login information.


13. Client Ecommerce and Marketplace Data

Because SHOPRIDGE provides ecommerce management and consultancy services, clients may provide access to ecommerce stores, marketplaces, analytics systems, or other business platforms.

Where we access client systems, we will use that access only as reasonably necessary to perform the agreed services.

Client businesses remain responsible for:

  • Their own customer privacy notices

  • Lawful collection of customer information

  • Appropriate permissions

  • Platform compliance

  • Customer consent requirements

  • Data accuracy

  • Their own privacy and security obligations

Where SHOPRIDGE processes personal data strictly on behalf of a client, additional contractual data-processing terms may be required depending on the nature of the processing.


14. Sensitive or Special Category Data

We do not generally require sensitive or special category personal data to provide our ecommerce services.

You should not provide sensitive personal information to us unless it is genuinely necessary and we have requested it through an appropriate process.

If we ever need to process special category information, we will do so only where an appropriate lawful condition applies.


15. Children’s Privacy

Our services are primarily intended for businesses and adults.

We do not knowingly seek to collect personal information from children for marketing or service purposes.

If you believe a child has provided personal information to us without appropriate authorization, please contact us so that we can investigate and take appropriate action.


16. Automated Decision-Making and Profiling

SHOPRIDGE does not generally make decisions about individuals based solely on automated processing that produce legal or similarly significant effects.

If this changes, we will update our privacy information and provide any information required by applicable data-protection law.


17. Your Data Protection Rights

Depending on the circumstances and applicable law, you may have rights relating to your personal information.

These may include:

Right of Access

You may request a copy of personal information we hold about you.

Right to Rectification

You may ask us to correct inaccurate or incomplete information.

Right to Erasure

You may ask us to delete personal information in certain circumstances.

Right to Restriction

You may ask us to restrict processing in certain circumstances.

Right to Object

You may have the right to object to certain processing, including processing based on legitimate interests and certain forms of direct marketing.

Right to Data Portability

In certain circumstances, you may request personal information in a structured, commonly used, machine-readable format and ask us to transmit it to another controller where technically feasible.

Right to Withdraw Consent

Where we rely on consent, you may withdraw your consent at any time.

The availability of each right depends on the relevant circumstances and lawful basis. We will not incorrectly represent a conditional right as an absolute right. The ICO specifically notes that data-protection rights vary depending on the lawful basis being used.


18. How to Exercise Your Rights

To exercise a data-protection right, contact us:

Email: [email protected]

Phone: +44 7735 313753

Address: 82a James Carter Road, Mildenhall, United Kingdom, IP28 7DE

Please provide enough information to help us identify you and understand your request.

We may need to verify your identity before providing information or making certain changes.

We will handle requests within the applicable legal timeframe.


19. Withdrawing Consent

Where we process your personal information based on consent, you can withdraw that consent at any time.

You can do this by contacting:

[email protected]

You can also use any unsubscribe or consent-management controls provided with the relevant communication or website feature.

Withdrawal of consent does not affect processing that occurred lawfully before withdrawal.


20. Right to Object to Direct Marketing

You have an absolute right to object to the processing of your personal information for direct marketing purposes.

If you object to direct marketing, we will stop processing your information for that purpose, subject to any applicable legal requirements.

The ICO requires the right to object to be clearly brought to an individual’s attention where applicable.


21. Complaints

If you have concerns about how SHOPRIDGE handles your personal information, please contact us first.

We will review your concern and attempt to resolve it appropriately.

You also have the right to complain to the UK’s data-protection supervisory authority.

Information Commissioner’s Office

The Information Commissioner’s Office (ICO) is the UK’s independent authority responsible for upholding information rights.

You can find information about making a complaint through the ICO’s official website.

Information Commissioner’s Office

The ICO recommends informing individuals that they can complain to the supervisory authority and, for UK organizations, providing information about the ICO.


22. Third-Party Websites and Services

Our website or communications may contain links to third-party websites or services.

We are not responsible for the privacy practices, security, content, or policies of third-party websites.

When you leave our website, you should review the privacy policy of the website or service you visit.


23. Social Media

We may maintain or use social media profiles for business communication and marketing.

If you interact with us through a social media platform, that platform may independently process your personal information according to its own privacy policy.

We do not control the privacy practices of third-party social media platforms.


24. Business Transfers

If SHOPRIDGE undergoes a business restructuring, merger, acquisition, sale of assets, or similar transaction, personal information may be transferred as part of that transaction where legally permitted.

Any such transfer will be handled in accordance with applicable data-protection requirements.


25. Data Breaches

We maintain reasonable security measures designed to protect personal information.

If we become aware of a personal-data breach, we will assess the incident and take appropriate action in accordance with applicable legal requirements.

Where notification to affected individuals or a supervisory authority is legally required, we will make the appropriate notification.


26. Accuracy of Personal Information

We aim to keep personal information accurate and up to date.

You should notify us if your contact information changes or if you believe information we hold about you is inaccurate.

You may request correction of inaccurate information where applicable.


27. Information You Are Required to Provide

Some personal information may be necessary for us to provide a requested service or enter into a contract.

For example, we may need certain contact and business information to:

  • Respond to an enquiry

  • Prepare a quotation

  • Enter into a service agreement

  • Deliver purchased services

  • Process payment

  • Communicate about a project

If you do not provide information that is necessary for these purposes, we may not be able to provide the requested service.

Where applicable, we will explain whether providing particular information is mandatory or optional and the consequences of not providing it. This is part of the transparency information the ICO identifies for certain processing situations.


28. Information From Public Sources

Where appropriate and lawful, we may obtain business contact information from publicly available sources.

This may include publicly available:

  • Business websites

  • Business directories

  • Professional profiles

  • Company information

  • Public business records

Where personal information is obtained indirectly, we will provide the relevant privacy information as required by applicable law.


29. Privacy of Business Information

Not all information relating to a business is personal data.

However, information relating to identifiable individuals within a business may constitute personal information.

We apply appropriate privacy protections to personal information regardless of whether the individual is acting in a personal or business capacity.


30. Changes to This Privacy Policy

We may update this Privacy Policy when:

  • Our services change

  • Our website changes

  • We introduce new technologies

  • Our data-processing activities change

  • Legal requirements change

  • Our third-party providers change

We will update the “Last Updated” date at the beginning of this policy.

Where required, we will provide additional notice about significant changes before introducing new processing activities.

The ICO recommends regularly reviewing privacy information and updating it when processing changes.


31. Contact Details

If you have questions about this Privacy Policy or how SHOPRIDGE handles personal information, please contact us.

SHOPRIDGE LIMITED

Address:
82a James Carter Road
Mildenhall
United Kingdom
IP28 7DE

Email: [email protected]

Phone: +44 7735 313753

Website: https://shopridge.co.uk/


32. Important Privacy Notice

This Privacy Policy is intended to provide comprehensive website privacy information for SHOPRIDGE LIMITED based on the services and business model described to us.

Before publishing, SHOPRIDGE should ensure that this policy accurately reflects the website’s actual technology and data practices, including the exact cookies, analytics tools, payment providers, CRM systems, hosting providers, contact-form systems, advertising tools, and other third-party services actually in use.

Privacy information should accurately describe what the business really does with personal data; the ICO advises organizations to understand what data they hold, why they process it, where it comes from, who receives it, and how long it is retained when drafting their privacy information.

This document is general informational material and is not a substitute for legal advice from a qualified UK data-protection professional.