Last updated: 23 September 2026
1. Who we are
Isaac’s Bazaar is a UK-based surface pattern design studio selling fabric, wallpaper and homeware online. We are the data controller responsible for your personal information.
- Business name: Isaac’s Bazaar
- Address: Merseyside, UK
- Email: [email protected]
- ICO registration: 00013507980
This policy explains how we collect, use and protect your personal data when you visit our website, place an order, or interact with us in any way. It applies to all visitors and customers of https://www.isaacsbazaar.com.
We handle your data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What information we collect
Information you give us directly
- Name, email address, delivery and billing address, and phone number when you place an order
- Payment information, handled securely by PayPal or WooPayments — we never see or store your full card details
- Messages and enquiries sent through our forms or by email, including Trade Club applications and bespoke commission enquiries
- Your first name and email address if you join our mailing list or claim a discount code
- Account details if you create a customer account
Information collected automatically
- IP address, browser type, device type and operating system
- Pages visited, time spent on the site and referring websites
- Clicks and interactions recorded by our analytics tools
- Cookie identifiers and advertising identifiers (see our Cookie Policy)
- Advertising click identifiers — Google (GCLID) and Meta (FBCLID) — when you arrive from an advert
Information from third parties
- Aggregated audience and performance data from Google and Meta
- Order and transaction data from our payment processors
Information stored when you use our forms
When you submit the newsletter pop-up, a Trade Club application or a bespoke enquiry, we store your entry in our website database. Alongside what you typed, we record your IP address, browser information, the page you were on and any advertising click identifier, so we can prevent spam and understand which marketing works.
3. How we use your information
| Purpose | Lawful basis |
|---|---|
| Processing and fulfilling your order | Contract performance |
| Sending order confirmations and despatch notifications | Contract performance |
| Responding to customer enquiries | Legitimate interests |
| Preventing fraud and verifying payments | Legitimate interests / Legal obligation |
| Sending marketing emails and discount codes | Consent |
| Improving our website and understanding visitor behaviour | Legitimate interests |
| Serving personalised adverts on Google and Meta | Consent |
| Measuring the effectiveness of our advertising | Legitimate interests / Consent |
| Complying with legal and regulatory obligations | Legal obligation |
| Accounting and tax record keeping | Legal obligation |
4. Cookies and tracking technologies
We use cookies to keep the shop working, to understand how the site is used, and — only with your consent — for advertising. Only strictly necessary cookies are set before you make a choice.
Our Cookie Policy lists every cookie we use, who sets it, what it does and how long it lasts.
You can change or withdraw your consent at any time using the Cookie Settings link in the footer. You can also opt out of personalised advertising directly with Google, Meta or via Your Online Choices.
Measurement from our own server
Much of our tracking runs through a subdomain of this website rather than sending your browsing data straight to advertising companies. This means we can see what is collected and limit what is passed on, and it is why several of our cookies are set by us rather than by Google.
5. Third parties we share data with
We do not sell your personal data. We share it only with the suppliers who help us run the shop, and only so they can do that job for us.
| Who | What they receive | Purpose | Location |
|---|---|---|---|
| PayPal | Payment and billing details | Taking payment, fraud prevention | EU / USA (SCCs) |
| WooPayments (Stripe) | Payment and billing details | Taking card payment | USA (SCCs) |
| Royal Mail and our couriers | Name, delivery address, phone, email | Delivering your order | UK |
| Google LLC | Site usage data; hashed customer details (see section 6) | Analytics, advertising, Merchant Center product listings | USA (SCCs) |
| Meta Platforms | Site usage data from the Meta pixel | Advertising and retargeting | USA (SCCs) |
| SendFox | First name and email address of subscribers | Sending our mailing list | USA (SCCs) |
| Elastic Email | Email address and message content | Delivering order, account and discount-code emails | EU / USA (SCCs) |
| Cloudflare | IP address and request data | Site security, bot protection, performance | Global (SCCs) |
| Cloudways (DigitalOcean) | All website and order data | Website hosting | UK / EU |
| WooCommerce / Automattic | Order and account data | E-commerce platform | USA (SCCs) |
| Bright Acre | Site usage and order data | Marketing and analytics support on our behalf | UK |
SCCs = Standard Contractual Clauses with the UK addendum, the approved mechanism for transferring personal data outside the UK. We may also disclose personal data to law enforcement or regulators where required by law.
6. Advertising, hashed data and customer lists
We advertise on Google and Meta. This section explains, in plain terms, what that involves. All of it happens only with your consent, given through our cookie banner, and you can withdraw that consent at any time.
What hashing means
Before we share any customer detail with an advertising platform, it is converted into an irreversible scrambled code using a technique called hashing (SHA-256). That happens on our own server, before anything is sent onward. The platform compares that code against its own equally scrambled records. Google and Meta never receive your email address, phone number or address in readable form, and the codes cannot be turned back into your details.
Measuring which ads lead to orders (enhanced conversions)
When you complete an order, the details you entered at checkout — email address, phone number, name and address — are hashed and sent to Google so it can tell us whether that order came from one of our ads.
Customer lists (Customer Match and similar audiences)
We may upload lists of customer details, again only as hashed codes, to Google and Meta so we can:
- show ads to people who have bought from us before, or to people with similar interests (lookalike audiences);
- stop showing ads to people who have already bought; and
- measure our advertising more accurately.
These lists are built from our order and subscriber records. They are not readable as customer details by the platforms, and are never shared with other advertisers.
Remarketing and offline conversions
We show adverts to people who have previously visited the site, based on cookie data. We may also upload order data to Google Ads so we can measure the effect of our campaigns on actual sales.
Opting out
To be removed from all advertising lists, email [email protected] and we will action it. Withdrawing your advertising cookie consent stops future data being collected.
7. Your rights
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate or incomplete data
- Erasure — ask us to delete your data where there is no lawful reason to keep it
- Restrict processing — ask us to limit how we use your data while a dispute is resolved
- Data portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests, including direct marketing
- Withdraw consent — at any time, without affecting processing already carried out
- Complain — to the Information Commissioner’s Office
To exercise any of these rights, email [email protected]. We will respond within 30 days.
8. Data retention
- Order data — 7 years, to comply with HMRC requirements
- Customer accounts — while your account is active, or until you ask us to delete it
- Mailing list records — until you unsubscribe or withdraw consent
- Form and enquiry records — up to 24 months after resolution
- Analytics data — in line with Google Analytics retention settings (up to 14 months)
- Advertising data — hashed data shared for Customer Match is deleted after campaign use, in line with Google and Meta retention policies
9. Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss or disclosure, including:
- SSL/TLS encryption on all data sent to and from our website
- Secure, access-controlled hosting
- Payment data handled exclusively by PCI-DSS compliant processors
- Bot and spam protection on our forms
- Regular software and security updates
No method of transmission over the internet is completely secure. If a breach is likely to risk your rights, we will notify you and the ICO as required by law.
10. Children’s privacy
Our website and products are not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it promptly.
11. Changes to this policy
We update this policy to reflect changes in our practices, technology or legal requirements. When we make material changes we update the date at the top of this page.
12. Contact us
Questions about this policy or how we handle your data:
- Isaac’s Bazaar, Merseyside, UK
- [email protected]
If you are not satisfied with our response, you can complain to the Information Commissioner’s Office: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — ico.org.uk · 0303 123 1113.