1. Introduction
Prince Recycling Ltd. (“we”, “our”, or “us”) is committed to protecting and respecting your privacy. This privacy policy explains how we collect, use, store, and share your personal information when you visit our website https://www.princerecycling.co.uk/ (the “Website”) or use our services.
We are a company registered in England and Wales under company number 02433757 with our registered office at Gowers Farm, Dunmow Road, High Roding, Dunmow, Essex, CM6 1NL.
For the purposes of UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller.
2. Contact Information
If you have any questions about this privacy policy or our data practices, please contact us:
Data Protection Officer/Privacy Contact:
Email: admin@princerecycling.co.uk
Post: Gowers Farm, Dunmow Road, High Roding, Dunmow, Essex, CM6 1NL
Telephone: 0808 506 5036
3. Information We Collect
3.1 Information You Provide Directly
We collect information you voluntarily provide to us, including:
Contact forms and enquiries: Name, email address, telephone number, company name, job title, and any message or enquiry details you provide
Newsletter subscriptions: Email address and any preferences you specify
Account registration: Username, password, email address, and profile information
Comments and reviews: Name, email address, and content you post
Event registrations: Contact details, dietary requirements, accessibility needs, and payment information
Customer service interactions: Records of correspondence and support requests
Marketing preferences: Communication preferences and consent records
3.2 Information Collected Automatically
When you visit our Website, we automatically collect:
Technical information: IP address, browser type and version, operating system, device type, screen resolution, and time zone settings
Usage data: Pages visited, time spent on pages, click-through rates, download errors, exit pages, and referral sources
Location data: General location information derived from your IP address
WordPress data: User agent strings, login attempts, and administrative actions (for registered users)
3.3 Cookies and Tracking Technologies
We use cookies, web beacons, and similar technologies to collect information about your browsing behaviour. For detailed information, please see our Cookie Policy https://www.princerecycling.co.uk/cookie-policy/
3.4 Third-Party Sources
We may receive information about you from:
Google Analytics: Website usage statistics and demographic information
Social media platforms: If you interact with our social media accounts or use social login features
Business partners: Contact information shared for legitimate business purposes
Public sources: Publicly available business information for B2B communications
4. How We Use Your Information
We process your personal information for the following purposes:
4.1 Legitimate Business Purposes
Providing and maintaining our Website and services
Responding to your enquiries and providing customer support
Processing transactions and managing customer relationships
Improving our Website functionality and user experience
Conducting business analysis and market research
Protecting against fraud, abuse, and security threats
Complying with legal obligations and regulatory requirements
4.2 Marketing Communications (with your consent)
Sending newsletters, promotional materials, and service updates
Providing information about products, services, and events
Conducting customer satisfaction surveys
Personalising marketing content based on your interests
4.3 Website Analytics and Optimisation
Analysing Website traffic and user behaviour patterns
Testing new features and improving Website performance
Measuring the effectiveness of our marketing campaigns
Creating aggregated, anonymised reports for business intelligence
5. Legal Basis for Processing
We process your personal information under the following legal bases:
Consent: For marketing communications and non-essential cookies (you may withdraw consent at any time)
Contract performance: To provide services you have requested or to take steps prior to entering into a contract
Legitimate interests: For business operations, fraud prevention, direct marketing to existing customers, and Website improvement (where not overridden by your interests or rights)
Legal obligation: To comply with applicable laws and regulations
Vital interests: To protect life or physical safety in emergency situations
6. How We Share Your Information
We may share your personal information with:
6.1 Service Providers and Third Parties
Web hosting providers: For Website hosting and maintenance
Plugin & 3rd Party Providers: If needed for troubleshooting
Email service providers: For newsletter delivery and email communications
Analytics providers: Including Google Analytics for Website performance analysis
Payment processors: For secure transaction processing
Customer relationship management (CRM) systems: For managing customer interactions
Marketing platforms: For advertising and promotional activities
IT support providers: For technical maintenance and security services
Professional advisers: Including lawyers, accountants, and consultants
6.2 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal information may be transferred to the acquiring party.
6.3 Legal Requirements
We may disclose your information where required by law, court order, or regulatory authority, or to protect our rights, property, or safety, or that of others.
6.4 International Transfers
Some of our service providers may be located outside the UK. Where we transfer your data internationally, we ensure appropriate safeguards are in place, including:
Adequacy decisions by the UK government
Standard contractual clauses approved by the UK authorities
Binding corporate rules or certification schemes
7. Data Retention
We retain your personal information for the following periods:
Contact form submissions and enquiries: Indefinitely, unless you request deletion
Newsletter subscriptions: Until you unsubscribe or we cease operations
Customer account data: For the duration of your account plus 7 years for legal/tax purposes
Website analytics data: 26 months (Google Analytics default retention period)
Marketing data: Until consent is withdrawn plus 3 years for compliance purposes
Financial records: 7 years from the end of the relevant financial year
Legal dispute records: Until the dispute is resolved plus applicable limitation periods
These retention periods may be extended where necessary for legal claims, investigations, or regulatory requirements.
8. Your Rights
Under UK data protection law, you have the following rights:
8.1 Right of Access
You can request a copy of the personal information we hold about you.
8.2 Right to Rectification
You can request that we correct any inaccurate or incomplete information.
8.3 Right to Erasure (‘Right to be Forgotten’)
You can request deletion of your personal information in certain circumstances.
8.4 Right to Restrict Processing
You can request that we limit how we use your information in certain situations.
8.5 Right to Data Portability
You can request to receive your personal information in a portable format or have it transferred to another organisation.
8.6 Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
8.7 Rights Related to Automated Decision-Making
You have rights regarding automated decision-making and profiling, including the right to human intervention.
8.8 Right to Withdraw Consent
Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, please contact us using the details provided in Section 2. We will respond to your request within one month, though this may be extended in complex cases.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal information, including:
Encryption: Data transmission and storage encryption
Access controls: Role-based access limitations and authentication requirements
Regular security assessments: Vulnerability testing and security audits
Staff training: Regular data protection and security awareness training
Incident response procedures: Protocols for managing data breaches
Secure hosting: Professional hosting services with robust security measures
However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Data Breaches
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will:
Notify the Information Commissioner’s Office (ICO) within 72 hours where required
Inform affected individuals without undue delay where high risk is identified
Take immediate steps to contain and mitigate the breach
Conduct a thorough investigation and implement preventive measures
11. Third-Party Websites
Our Website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies before providing any personal information.
12. Children’s Privacy
Our Website is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such information, we will take steps to delete it promptly.
13. WordPress-Specific Information
As our Website is built on WordPress, please be aware:
WordPress core: May collect technical information for security and performance purposes
Plugins and themes: May have their own data collection practices
Comments: Are stored in our WordPress database and may be publicly visible
User accounts: Include login credentials and activity logs
Automatic updates: WordPress may check for updates and send anonymous usage data
14. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of significant changes by:
Posting the updated policy on our Website
Sending email notifications to registered users
Displaying a prominent notice on our Website
The “Last updated” date at the top of this policy indicates when it was last revised. Your continued use of our Website after any changes constitutes acceptance of the updated policy.
15. Data protection complaints
If you have any concerns about how we collect, use or protect your personal information, please contact us in the first instance so that we have an opportunity to look into the matter and try to resolve it.
You can make a data protection complaint by contacting:
Email: admin@princerecycling.co.uk
Post: Gowers Farm, Dunmow Road, High Roding, Dunmow, Essex, CM6 1NL
Telephone: 0808 506 5036
Please provide details of your concern, including any relevant dates, correspondence or reference numbers, together with information that will help us identify you and the personal information concerned.
We will acknowledge your complaint within 30 days of receiving it. We will take appropriate steps to investigate your concerns, keep you informed where necessary and provide you with the outcome without undue delay.
We hope that we will be able to resolve your complaint directly. However, if you remain unhappy with our response, you have the right to make a complaint to the Information Commissioner’s Office. The ICO recommends allowing us the opportunity to complete our complaints process before contacting them.
Further information is available from the Information Commissioner’s Office.
16. Governing Law
This privacy policy is governed by English & Welsh law and subject to the jurisdiction of the English & Welsh courts.
Document Version: 1.0
Effective Date: 29th July 2026
WooCommerce Privacy Policy Supplement
This supplement forms part of our main Privacy Policy and should be read in conjunction with it.
1. E-Commerce Data Collection
1.1 Customer Account Information
When you create an account or make a purchase, we collect:
- Account details: Username, password, email address, and account preferences
- Billing information: Full name, company name, address, telephone number, and email address
- Shipping information: Delivery address, special delivery instructions, and recipient details
- Payment information: Payment method preferences (card details are processed securely by our payment processors and are not stored on our servers)
- Order history: Complete records of all purchases, including products, quantities, prices, dates, and order status
- Customer communications: Order enquiries, support requests, product reviews, and feedback
1.2 Transaction Data
For each purchase, we retain indefinitely:
- Order details: Products purchased, quantities, prices, discounts applied, and total amounts
- Payment information: Transaction IDs, payment status, refund records, and payment method used (excluding card details)
- Shipping records: Tracking numbers, delivery dates, shipping methods, and delivery confirmations
- Tax information: VAT calculations, tax exemptions, and invoice details
- Promotional usage: Coupon codes used, loyalty points earned/redeemed, and promotional campaign responses
1.3 Behavioural and Preference Data
We automatically collect:
- Shopping behaviour: Products viewed, items added to basket, abandoned cart contents, and purchase patterns
- Website interactions: Time spent on product pages, search queries, filter preferences, and navigation patterns
- Device and technical data: Browser fingerprints, device characteristics, and performance metrics specific to our shop
- Location data: IP-based location for tax calculations, shipping estimates, and fraud prevention
- Preference data: Wishlists, favourite products, notification preferences, and personalisation settings
2. How We Use E-Commerce Data
2.1 Order Processing and Fulfilment
- Processing and fulfilling your orders
- Managing payments, refunds, and financial reconciliation
- Coordinating shipping and delivery services
- Providing order status updates and delivery notifications
- Managing returns, exchanges, and warranty claims
- Maintaining comprehensive transaction records for accounting and legal purposes
2.2 Customer Service and Support
- Providing customer support and resolving enquiries
- Processing returns, refunds, and warranty claims
- Managing customer complaints and feedback
- Maintaining service quality and customer satisfaction records
- Investigating and resolving payment disputes
2.3 Business Operations and Analytics
- Inventory management and stock level optimisation
- Sales reporting and business performance analysis
- Financial accounting, tax reporting, and audit requirements
- Fraud detection and prevention measures
- Product performance analysis and merchandising decisions
- Customer lifetime value analysis and segmentation
2.4 Personalisation and Recommendations
- Providing personalised product recommendations
- Customising website content based on browsing and purchase history
- Tailoring promotional offers and pricing
- Creating personalised email campaigns and newsletters
- Improving user experience through behavioural analysis
2.5 Marketing and Communication (with appropriate consent)
- Sending order confirmations and shipping notifications (legitimate interest)
- Cart abandonment recovery emails (legitimate interest for existing customers)
- Product recommendations based on purchase history
- Promotional emails and special offers (requires consent)
- Customer satisfaction surveys and feedback requests
- Loyalty programme communications and rewards notifications
3. Third-Party Integrations and Data Sharing
3.1 Payment Processors
We work with secure payment processors including:
- Stripe, PayPal, Square (or other processors)
- Data shared: Transaction amount, currency, customer details for fraud prevention
- Purpose: Secure payment processing and fraud protection
- Retention: As per payment processor policies (typically 7+ years for financial records)
3.2 Shipping and Logistics Partners
- Courier services: Royal Mail, DPD, Hermes, UPS, FedEx (as applicable)
- Data shared: Delivery addresses, contact details, package contents, and special instructions
- Purpose: Package delivery and tracking services
- Tracking: Third-party tracking systems may collect delivery confirmation data
3.3 Marketing Automation Platforms
3.3.1 Email Marketing Services (e.g., Mailchimp)
- Data shared: Email addresses, names, purchase history, browsing behaviour, and demographic information
- Purpose: Automated email campaigns, newsletters, and promotional communications
- Personalisation: Product recommendations, abandoned cart recovery, and targeted offers
- Retention: Until consent is withdrawn or as required for legitimate business purposes
- International transfers: May involve transfers to US-based services with appropriate safeguards
3.3.2 Customer Relationship Management (CRM) and Marketing Platforms (e.g., GoHighLevel or white-label alternatives)
- Data shared: Complete customer profiles, purchase history, communication preferences, and interaction data
- Purpose: Lead management, customer journey automation, and multi-channel marketing campaigns
- Features: Email marketing, SMS marketing, social media integration, and sales funnel tracking
- Analytics: Customer behaviour analysis, conversion tracking, and lifetime value calculations
- Retention: Customer data retained indefinitely for ongoing relationship management and historical analysis
3.4 Analytics and Performance Tools
- Google Analytics Enhanced E-commerce: Detailed purchase data, product performance, and customer journey analysis
- Facebook Pixel/Meta Pixel: Purchase events, product interests, and conversion tracking for advertising
- Google Ads conversion tracking: Purchase confirmation data for advertising effectiveness
- Hotjar or similar: User session recordings and heatmap data (anonymised where possible)
3.5 Customer Support Tools
- Live chat platforms: Conversation history, contact details, and support ticket records
- Help desk systems: Support requests, resolution history, and customer satisfaction scores
- Knowledge base analytics: Article usage and search query data
3.6 Inventory and Business Management
- Accounting software: Sales data, customer information, and financial records
- Inventory management systems: Purchase patterns, stock level data, and supplier information
- Business intelligence tools: Aggregated sales data, customer segments, and performance metrics
4. Customer Rights Specific to E-Commerce Data
4.1 Access to E-Commerce Data
You can request access to:
- Complete order history and transaction records
- Account information and preferences
- Marketing communications and consent records
- Personalisation data and behavioural profiles
- Data shared with third-party integrations
4.2 Data Portability for E-Commerce
You have the right to receive in a portable format:
- Order history in CSV or JSON format
- Customer account data
- Communication preferences and consent records
- Wishlist and preference data
4.3 Rectification of E-Commerce Data
You can request correction of:
- Billing and shipping address information
- Contact details and communication preferences
- Account information and marketing consents
- Product reviews and feedback
4.4 Erasure Considerations for E-Commerce
Please note: Complete erasure may be limited due to:
- Legal obligations: Tax and accounting requirements (typically 7 years retention)
- Legitimate interests: Fraud prevention and financial reconciliation
- Contractual obligations: Warranty, returns, and customer service obligations
We can anonymise your data while retaining transaction records for legal compliance.
4.5 Restricting E-Commerce Data Processing
You can request restriction of:
- Marketing communications and personalisation
- Behavioural analysis for recommendations
- Data sharing with marketing platforms
- Non-essential analytics and tracking
5. Data Retention for E-Commerce
5.1 Order and Transaction Data
- Customer orders: Retained indefinitely for business analysis, customer service, and legal compliance
- Payment records: Minimum 7 years for tax and accounting purposes
- Shipping records: 7 years for warranty, returns, and dispute resolution
- Communication history: Retained indefinitely for ongoing customer relationship management
5.2 Marketing and Behavioural Data
- Email marketing data: Until consent is withdrawn plus 3 years for compliance purposes
- CRM data: Retained indefinitely for customer relationship management and business intelligence
- Website analytics: 26 months for Google Analytics, longer for internal business analytics
- Personalisation data: Retained while account is active plus 3 years for customer re-engagement
5.3 Account Data
- Active accounts: Data retained while account remains active
- Inactive accounts: Deleted after 3 years of inactivity (unless legal obligations require retention)
- Closed accounts: Personal identifiers removed but transaction history retained for legal compliance
6. Security Measures for E-Commerce Data
6.1 Payment Security
- PCI DSS Compliance: Our payment processors maintain PCI DSS certification
- SSL encryption: All payment pages use SSL encryption
- Tokenisation: Card details are tokenised and not stored on our servers
- Fraud monitoring: Automated systems monitor for suspicious transactions
6.2 Customer Data Protection
- Database encryption: Customer data encrypted at rest and in transit
- Access controls: Role-based access to customer information
- Regular backups: Secure, encrypted backups of all customer data
- Security monitoring: 24/7 monitoring for unauthorised access attempts
6.3 Third-Party Security
- Vendor assessment: All third-party integrations assessed for security standards
- Data processing agreements: Formal agreements with all data processors
- Regular audits: Periodic security reviews of integrated platforms
- Incident response: Coordinated response procedures for any security incidents
7. International Transfers for E-Commerce
7.1 Marketing Platform Transfers
- US-based services: Mailchimp, GoHighLevel, and similar platforms may transfer data to the US
- Safeguards: Standard Contractual Clauses and adequacy decisions where applicable
- Data minimisation: Only necessary data shared for specific marketing purposes
7.2 Payment Processing Transfers
- Global payment networks: Visa, Mastercard networks may involve international transfers
- Fraud prevention: International sharing for fraud detection and prevention
- Regulatory compliance: Transfers necessary for financial compliance and reporting
8. Cookies and Tracking for E-Commerce
8.1 E-Commerce Essential Cookies
- Shopping cart: Maintains items in your basket across sessions
- Checkout process: Enables secure completion of purchases
- Account login: Maintains your login session
- Currency and language: Remembers your preferences
8.2 E-Commerce Analytics Cookies
- Enhanced E-commerce: Google Analytics tracking of purchase behaviour
- Conversion tracking: Advertising platform conversion pixels
- A/B testing: Cookies for testing different website versions
- Performance monitoring: Site speed and functionality tracking
8.3 Marketing and Personalisation Cookies
- Product recommendations: Cookies to personalise product suggestions
- Retargeting: Advertising cookies for showing relevant ads
- Email capture: Tracking for newsletter signup incentives
- Customer journey: Cross-device tracking for marketing attribution
9. Age Verification and Restrictions
For age-restricted products, we may collect and verify:
- Date of birth information
- Age verification documentation
- Delivery restrictions and ID requirements
- Records of age verification checks
This data is processed for legal compliance and retained as required by applicable regulations.
10. Automated Decision Making in E-Commerce
We may use automated systems for:
10.1 Fraud Detection
- Automated screening: Orders automatically screened for fraud indicators
- Risk scoring: Algorithmic assessment of transaction risk
- Account restrictions: Automatic restrictions on suspicious accounts
- Right to human review: You can request human review of any automated decisions
10.2 Personalisation and Recommendations
- Product recommendations: Algorithmic suggestions based on browsing and purchase history
- Dynamic pricing: Automated pricing adjustments based on various factors
- Content personalisation: Automated customisation of website content and offers
10.3 Marketing Automation
- Email triggers: Automated emails based on behaviour (cart abandonment, purchase follow-up)
- Segmentation: Automatic customer categorisation for targeted marketing
- Campaign optimisation: AI-driven optimisation of marketing campaigns
11. Customer Communication Preferences
11.1 Transactional Communications
These are necessary for order processing and cannot be opted out of:
- Order confirmations and receipts
- Shipping and delivery notifications
- Payment confirmations and receipts
- Returns and refund notifications
- Essential account security communications
11.2 Marketing Communications (Consent Required)
- Promotional emails: Special offers, sales, and new product announcements
- Newsletter subscriptions: Regular updates and company news
- Personalised recommendations: Tailored product suggestions
- SMS marketing: Text message promotions and alerts
- Social media retargeting: Advertising on social platforms
11.3 Preference Management
You can manage your communication preferences by:
- Updating your account settings
- Using unsubscribe links in emails
- Contacting our customer service team
- Adjusting cookie preferences
12. Third-Party Product Reviews and Social Features
If our platform includes review systems or social features:
- Product reviews: Content, ratings, and reviewer information may be publicly displayed
- Social sharing: Integration with social media platforms may share purchase information
- User-generated content: Photos, videos, and content may be used for marketing purposes
- Community features: Forum posts, Q&A responses, and community interaction data
13. Compliance and Updates
This supplement will be updated to reflect:
- Changes in e-commerce functionality
- New third-party integrations
- Updates to data protection regulations
- Changes in business practices
For questions specific to your e-commerce data, please contact us using the details provided in our main Privacy Policy.
Document Version: 1.0
Effective Date: 29th July 2026