Privacy and cookies
Last updated 4 October 2026
Who we are
Trace & Grow, United Kingdom, is the controller of the personal information collected through this website. If you have any question about your data, email hello@traceandgrow.co.uk.
What we collect, why, and our lawful basis
| What | Why | Lawful basis (UK GDPR) |
|---|---|---|
| Name, email, phone, delivery address, order details | To take, make, deliver and support your order, and send order emails | Contract |
| Personalisation, such as a child’s name on a label or backpack | Only to make that item | Contract |
| Order and invoice records | Accounts and tax | Legal obligation |
| Email address for our newsletter | News, offers and new books, only if you sign up and confirm by email. Sign-ups not confirmed within 30 days are deleted. | Consent (withdraw any time with the unsubscribe link) |
| Waiting-list email | One email when that item is available | Your request (legitimate interests) |
| Messages you send us (contact, wholesale, WhatsApp) | To reply and keep a record of what was agreed | Legitimate interests |
| Reviews (name and comment) | To show other parents what you thought | Consent |
| A scrambled form of your IP address | To stop spam, password guessing and fraud | Legitimate interests |
We never see or store your card details: payments are taken by Stripe on its own secure page. We don’t sell your data, use it for advertising profiles, or make automated decisions about you.
Children
This shop is for parents, carers and educators, not for children to use. We only hold a child’s name when you enter it for a personalised item. We use it to make that item and remove it from our records one year after the order.
Who we share it with
Only the companies we need to run the shop, each under a contract that protects your data:
- Stripe: card payments and fraud checks
- Our printers and makers: book printing (BookVault, UK) and posters and calendars (Prodigi, UK) and printed stickers, labels and clothing (Printful). They get your delivery details and the personalisation only.
- Royal Mail or the courier delivering your order
- Resend: sends our emails
- Vercel and Neon: website hosting and database
- postcodes.io: checks that a UK delivery postcode exists. Only the postcode is sent, never your name or address.
- WhatsApp (Meta): only if you choose to message us there
Some of these companies are based in, or use servers in, the United States. Where data leaves the UK it is protected by UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework) or the ICO’s International Data Transfer Addendum.
How long we keep it
| Order and invoice records (amounts, dates, VAT) | 6 years after the end of the financial year, for HMRC; names and addresses are then removed |
| Children's names and gift messages on orders | 1 year after the order, then removed (the order itself is kept) |
| Contact and wholesale enquiries | 2 years after the last message |
| Email log | 2 years |
| Customers with no orders and no newsletter consent | 3 years after they last got in touch, then deleted |
| Newsletter sign-ups | Until they unsubscribe. Sign-ups never confirmed by email are deleted after 30 days |
| Security records (sign-ins, rate limits) | Rate limits 1 day; sign-in and admin activity log 2 years |
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to limit how we use it, to object to how we use it, or to receive it in a file you can take elsewhere. You can withdraw consent at any time. Email hello@traceandgrow.co.uk and we’ll reply within one month. It’s free.
Complaints
If you’re unhappy with how we’ve handled your data, please tell us first at hello@traceandgrow.co.uk. We’ll acknowledge your complaint within 30 days and tell you what we’re doing about it. You can also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
Keeping it safe
The site only works over an encrypted connection (HTTPS). Our back office needs a strong password, sign-in attempts are limited, and every access to customer data is logged. Our database is encrypted and backed up by our hosting provider.
Cookies
We only use what the site needs to work, so we don’t need to ask for consent and don’t show a cookie banner:
- Your basket is saved in your own browser (local storage) so it’s still there when you come back. It never leaves your device until you check out.
- tg_admin is a cookie for our staff when they sign in to the back office. Customers never get it.
- Stripe sets its own fraud-prevention cookies on its checkout page.
No analytics, advertising or tracking cookies are used. If we ever add any, we’ll ask for your permission first.
Changes
If we change this notice we’ll update the date at the top.