개인정보처리방침
Last updated: June 2026
This Privacy Policy explains how Forge & Lumber Ltd collects, uses, shares and protects your personal data when you visit or make a purchase from https://forgeandlumber.com (the "Site"), and your rights in relation to that data.
We process personal data in accordance with the UK GDPR and the Data Protection Act 2018, and, where applicable, the EU GDPR and the data protection laws of the other countries in which our customers live.
Who we are (data controller)
Forge & Lumber Ltd is the controller responsible for your personal data.
- Forge & Lumber Ltd
- Registered in England & Wales, company number 14866867
- Registered office: Suite 13 The Granary, Waverley Lane, GU9 8BB, United Kingdom
- Email: info@forgeandlumber.com
If you have any questions about this policy or how we handle your data, contact us at info@forgeandlumber.com.
The personal data we collect
Information you give us. When you place an order, create an account, or contact us, we collect:
- Identity and contact details — your name, email address, billing and delivery addresses, and phone number.
- Order details — the products you buy, ring size, and (where you provide it) information relevant to your order such as a wedding date or engraving text.
- Payment information — processed securely by our payment providers. We do not store full card details ourselves.
- Account details — such as your login credentials and saved preferences.
- Communications — the content of messages you send us and our correspondence with you.
Information we collect automatically. When you use the Site, we collect:
- Device and usage data — IP address, browser type, time zone, the pages and products you view, referring site or search terms, and how you interact with the Site.
- Cookies and similar technologies — see "Cookies" below.
We do not intentionally collect special-category data (such as data revealing race, health or beliefs), and we ask that you do not send it to us.
How we use your data, and our legal bases
| Purpose | Legal basis |
|---|---|
| To process and fulfil your order, take payment, arrange delivery and provide order confirmations and support | Performance of a contract with you |
| To manage your account and respond to your enquiries | Performance of a contract / our legitimate interests |
| To detect, prevent and investigate fraud and to keep the Site secure | Our legitimate interests / legal obligation |
| To send marketing communications about our products | Your consent (you can withdraw it at any time) |
| To set non-essential cookies and measure advertising | Your consent |
| To improve the Site, analyse usage and develop products | Our legitimate interests |
| To keep accounting and tax records and meet legal obligations | Legal obligation |
Where we rely on legitimate interests, we have considered that these are not overridden by your rights and interests.
Cookies and similar technologies
We use cookies, pixels and similar technologies to operate the Site, remember your basket, understand how the Site is used, and (with your consent) to measure and deliver advertising. We set non-essential cookies — including analytics and advertising cookies — only where you have given consent through our cookie banner, which is managed using Pandectes GDPR Compliance. You can change your preferences at any time using the cookie settings on the Site, and you can control cookies through your browser settings.
Who we share your data with
We share personal data only where necessary, with:
- Our platform and hosting provider — Shopify, which powers our store (shopify.com/legal/privacy).
- Payment providers — to process your payment securely.
- Shipping and logistics partners — our carriers (Royal Mail, DHL and FedEx) and shipping software, to deliver your order and handle returns.
- Email and SMS marketing providers — Shopify and Omnisend, to send communications you have agreed to receive.
- Analytics providers — such as Google Analytics (policies.google.com/privacy); you can opt out at tools.google.com/dlpage/gaoptout.
- Advertising partners — where you have consented, to measure and deliver advertising: Google, Meta, Microsoft, Pinterest and Reddit.
- Professional advisers and authorities — where required to comply with the law, respond to a lawful request, or establish, exercise or defend legal claims.
If our business is sold or reorganised, personal data may be transferred to the new owner.
We do not sell your personal data.
International transfers
We are based in the UK, and some of our providers are located outside the UK and the European Economic Area (including in the United States). Where we transfer your personal data outside the UK/EEA, we make sure it is protected by an appropriate safeguard — such as a UK adequacy decision, the UK International Data Transfer Agreement or Addendum, or EU Standard Contractual Clauses. You can ask us for a copy of the relevant safeguards using the contact details above.
How long we keep your data
We keep your personal data only as long as necessary for the purposes set out above. Order and transaction records are kept for six years to meet our legal and accounting obligations. Marketing data is kept until you unsubscribe or ask us to delete it. After that, we delete or anonymise your data.
Your rights
Subject to certain conditions and exemptions, you have the right to:
- access a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to our processing of your data;
- data portability (receive your data in a machine-readable format); and
- withdraw consent at any time, where we rely on consent.
To exercise any of these rights, contact us at info@forgeandlumber.com. We will respond within the time limits set by law.
If you are unhappy with how we have handled your data, you have the right to complain to a data protection authority. In the UK, this is the Information Commissioner's Office (ICO), ico.org.uk. If you are in the EU, you may complain to the supervisory authority in your country.
Marketing
We send marketing only where you have agreed to receive it. You can opt out at any time using the unsubscribe link in any email, by replying STOP to a marketing text, or by contacting us. Opting out of marketing will not stop service messages relating to your orders.
Data security
We use appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or misuse. No method of transmission over the internet is completely secure, but we work to protect your information and to respond appropriately to any data security incident.
Children
Our Site and products are not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
Third-party links
The Site may link to third-party websites or services we do not control. We are not responsible for their privacy practices, and we encourage you to read their privacy policies.
Changes to this policy
We may update this policy from time to time to reflect changes in our practices or legal requirements. We will post the updated version here with a revised "Last updated" date.
Contact us
For any questions, requests or complaints about this policy or your personal data:
- Forge & Lumber Ltd
- Email: info@forgeandlumber.com
- Registered office: Suite 13 The Granary, Waverley Lane, GU9 8BB, United Kingdom