Privacy Policy
Last updated: 23 March 2026
1. Introduction
IT Wheel Ltd ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you visit our website itwheel.co.uk or use our services.
We are the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our registered address is in London, United Kingdom.
If you have any questions about this policy or our data practices, please contact us at [email protected].
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, and password when you register an account.
- Order information: billing and delivery addresses, phone number, and order details when you make a purchase.
- Uploaded content: logos, images, or design files you upload for custom product printing.
- Communications: messages you send to us via the contact form or email.
- Reviews: product reviews and ratings you submit on our website.
2.2 Information Collected Automatically
- Usage data: pages visited, time spent, referring URL, browser type, device type, and IP address.
- Cookies and similar technologies: see Section 5 below for details.
2.3 Information From Third Parties
- Social login: if you sign in using Google or Facebook, we receive your name, email address, and profile picture from those services. We do not receive or store your social media password.
- Payment processor: Stripe processes your payment card information on our behalf. We do not store your full card number. See Section 4 below.
3. How We Use Your Information
We use your personal data for the following purposes and legal bases:
| Purpose | Legal Basis |
|---|---|
| Processing and fulfilling your orders | Contract performance |
| Managing your account | Contract performance |
| Sending order confirmations and delivery updates | Contract performance |
| Responding to your enquiries | Legitimate interest |
| Sending marketing emails (with your consent) | Consent |
| Improving our website and services | Legitimate interest |
| Fraud prevention and security | Legitimate interest |
| Complying with legal obligations | Legal obligation |
4. Payment Processing
We use Stripe as our payment processor. When you make a purchase, your payment card details are sent directly to Stripe's secure servers and are not stored on our systems. Stripe is PCI DSS Level 1 certified, the highest level of security certification available.
For more information, please refer to Stripe's Privacy Policy.
5. Cookies
Our website uses the following types of cookies:
| Cookie Type | Purpose |
|---|---|
| Essential cookies | Required for the website to function (e.g., session management, CSRF protection, shopping cart). |
| Analytics cookies | Help us understand how visitors use our website (e.g., Google Analytics). These cookies collect anonymised data. |
| Marketing cookies | Used to deliver relevant advertisements and track campaign performance (e.g., Facebook Pixel). |
You can control cookie preferences through your browser settings. Please note that disabling essential cookies may affect the functionality of the website.
6. Social Login
We offer the option to sign in using your Google or Facebook account. When you use social login, we receive basic profile information (name and email address) from the chosen provider to create or link your IT Wheel account.
We do not post to your social media accounts or access your contacts. You can disconnect social login at any time by updating your account settings or contacting us.
7. Email Marketing
With your consent, we may send you marketing emails about new products, special offers, and company news. You can unsubscribe at any time by clicking the "unsubscribe" link in any marketing email or by contacting us at [email protected].
We will always send transactional emails related to your orders regardless of your marketing preferences, as these are necessary for contract performance.
8. Data Sharing
We may share your personal data with the following categories of third parties:
- Payment processors: Stripe, for processing payments securely.
- Delivery partners: Royal Mail, couriers, or other carriers to fulfil your orders.
- Analytics providers: Google Analytics, for website usage analysis.
- Social login providers: Google and Facebook, if you choose to sign in via social login.
- Email service providers: for sending transactional and marketing communications.
- Legal authorities: when required by law or to protect our rights.
We do not sell your personal data to any third party.
9. International Transfers
Some of our third-party service providers are based outside the UK. Where we transfer your data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the Information Commissioner's Office (ICO) or an adequacy decision.
10. Data Retention
- Account data: retained for as long as your account is active. If you close your account, we delete your personal data within 30 days, except where we are required to retain it by law.
- Order data: retained for 7 years after the date of purchase for tax and accounting purposes, as required by UK law (HMRC requirements).
- Marketing preferences: retained until you withdraw consent.
- Analytics data: anonymised and aggregated data may be retained indefinitely.
- Uploaded files: logos and design files are retained for 12 months after your last order to facilitate reorders, then deleted.
11. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your personal data (subject to legal obligations).
- Right to restrict processing: request that we limit how we use your data.
- Right to data portability: receive your data in a structured, commonly used format.
- Right to object: object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: withdraw consent for processing at any time, where consent is the legal basis.
To exercise any of these rights, please email us at [email protected]. We will respond to your request within one month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
12. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- SSL/TLS encryption for all data transmitted between your browser and our servers.
- Encrypted storage of passwords using industry-standard hashing algorithms.
- Regular security reviews and software updates.
- Access controls limiting data access to authorised personnel only.
13. Children's Privacy
Our website and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us so we can delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "last updated" date. We encourage you to review this policy periodically. If we make significant changes, we will notify you by email or through a prominent notice on our website.
15. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:
- Email: [email protected]
- Website: itwheel.co.uk
- Business: IT Wheel Ltd, London, United Kingdom