Privacy Policy
Last updated: 16 April 2026
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your rights under UK data protection law.
1. Who we are
This Privacy Policy is issued by Manzora Ltd (trading as Newman Bands), a company registered in England and Wales under company number 04203239. Manzora Ltd is VAT registered.
- Registered office: 3 Shortsfield Close, Horsham, West Sussex, RH12 2NA, United Kingdom
- Trading address (all customer correspondence): Newman Bands, 10A Middle St, Horsham, West Sussex, RH12 1NW, United Kingdom
We are the data controller responsible for your personal data when you use newmanbands.com or place an order with us.
If you have any questions about this policy or how we handle your data, please contact us:
- Email: clare@newmanbands.com
- Phone: 01403 626130
- Post: Newman Bands, 10A Middle St, Horsham, West Sussex, RH12 1NW (trading address โ please do not post to our registered office)
2. Personal data we collect
We collect the following categories of personal data:
Information you give us when you place an order:
- Name
- Billing and shipping addresses
- Email address
- Phone number
- Engraving text (where you order an engraved ring)
Payment information:
- Card and payment details are collected directly by our payment providers (Stripe and PayPal) and are not stored on our systems. We receive a transaction confirmation only.
Information you give us when you contact us:
- Name, email, and the content of your message when you email, call, or message us
Information collected automatically when you visit the site:
- IP address
- Browser type and version
- Device type and operating system
- Pages viewed and actions taken on the site
- Referring website or search term
- Date and time of access
We collect this automatic information through cookies, server logs, tracking pixels, and similar technologies. Non-essential cookies are only set after you give consent through our cookie banner.
3. Why we use your data and our legal basis
Under UK GDPR, we can only process your personal data where we have a valid legal basis. Here’s what we do and why:
| Purpose | Legal basis |
|---|---|
| Processing your order and delivering your ring | Performance of a contract |
| Taking payment and preventing fraud | Performance of a contract and legitimate interest |
| Sending order confirmations, dispatch notifications, and delivery updates | Performance of a contract |
| Handling returns, exchanges, and customer service | Performance of a contract |
| Cart abandonment emails to existing customers | Legitimate interest (to complete an order you started) |
| Review request emails after purchase | Legitimate interest under the soft opt-in rules (PECR Regulation 22(3)) |
| Keeping records for accounting and tax purposes | Legal obligation |
| Site analytics (understanding how visitors use the site) | Consent (via cookie banner) |
| Advertising (Google Ads, Meta retargeting) | Consent (via cookie banner) |
| Ad fraud detection (ClickCease) | Consent (via cookie banner) |
| Marketing emails in future (newsletters, promotions) | Consent โ you’ll only receive these if you explicitly opt in |
You can opt out of cart abandonment and review emails at any time using the “unsubscribe” link in every email, or by emailing clare@newmanbands.com. You can withdraw cookie consent at any time by updating your cookie preferences. Withdrawing consent doesn’t affect the lawfulness of processing we did before you withdrew.
4. Who we share your data with
We share your personal data with trusted third parties who help us run our business. Each provider only receives what they need and is contractually required to protect it.
Hosting and website infrastructure
- Rocket.net โ website hosting and server infrastructure
- Cloudflare โ content delivery, security, and caching
Payment processing
- Stripe โ card payments (stripe.com/gb/privacy)
- PayPal โ PayPal payments (paypal.com/uk/legalhub/privacy-full)
Shipping and fulfilment
- Royal Mail โ delivery
Analytics and site improvement
- Google Analytics โ site usage analytics (policies.google.com/privacy)
Advertising
- Google Ads โ search and display advertising
- Meta (Facebook/Instagram) Pixel โ retargeting and future advertising (facebook.com/policy.php)
- TikTok Pixel โ TikTok advertising (tiktok.com/legal/privacy-policy)
- ClickCease โ ad click fraud protection (clickcease.com/privacy-policy.html)
Customer support and reviews
- GrooveHQ โ customer support ticketing
- Reviews.io โ independent review collection and publishing (reviews.co.uk/privacy-policy)
Cookie consent and compliance
- CookieScript โ cookie consent management (cookie-script.com/privacy-policy)
Technical contractors
- Freelance developers and technical contractors with access to the site or database, where required for development, maintenance, or support. All contractors work under written Data Processing Agreements that require them to protect your data and use it only for the purposes we specify.
Accounting and legal
- HMRC and other regulatory bodies where required by UK law
- Our accountants and legal advisors, where needed to run the business or comply with legal obligations
We never sell your personal data to anyone.
5. International transfers
Some of the providers listed above (particularly Google, Meta, TikTok, Stripe, PayPal, ClickCease, GrooveHQ, Reviews.io, and CookieScript) are based outside the UK and may transfer your data to the United States, the EU, or other countries.
Where we transfer personal data outside the UK, we rely on one of the following safeguards required by UK GDPR:
- UK adequacy regulations โ for countries the UK has deemed to offer an adequate level of protection (including EU/EEA countries)
- UK International Data Transfer Agreement (IDTA) โ a standard contract approved by the ICO
- Standard Contractual Clauses with the UK Addendum โ approved data transfer contracts
All the providers above have published their compliance with these safeguards. You can request more details about the specific safeguards for any transfer by emailing clare@newmanbands.com.
6. How long we keep your data
We keep your personal data only for as long as necessary to fulfil the purposes for which it was collected, to provide our services to you, and to meet our legal obligations.
This means in practice:
- Order records (name, address, order details, engraving text) are kept for at least 7 years from the date of your order to comply with UK tax and accounting law
- Email correspondence is kept for as long as we may reasonably need it to handle follow-up queries, warranty claims, or disputes
- Analytics and cookie data is kept in line with the retention settings of each provider (generally 14โ26 months)
- Marketing consent records are kept for as long as you remain subscribed, plus a record of when you unsubscribed
If you’d like us to delete data we no longer have a legal obligation to retain, email clare@newmanbands.com and we’ll do so.
7. Your rights
You have the following rights under UK GDPR:
- Right of access โ ask us for a copy of the personal data we hold about you
- Right to rectification โ ask us to correct inaccurate or incomplete data
- Right to erasure (“right to be forgotten”) โ ask us to delete your data, subject to exceptions (for example, we must keep order records for tax purposes, and we may retain data needed for ongoing disputes or fraud prevention)
- Right to restrict processing โ ask us to limit how we use your data in certain circumstances
- Right to data portability โ ask us to provide your data in a machine-readable format
- Right to object โ object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent โ at any time, where we rely on consent
- Rights in relation to automated decision-making โ we don’t make decisions about you using solely automated processing
To exercise any of these rights, email clare@newmanbands.com. We’ll respond within one month. There’s no charge in most cases.
8. Your right to complain to the ICO
If you’re unhappy with how we handle your personal data, please contact us first so we can try to fix it.
If you’re still not satisfied, you have the right to complain to the UK data protection regulator:
Information Commissioner’s Office (ICO) Wycliffe House, Water Lane Wilmslow, Cheshire, SK9 5AF United Kingdom Phone: 0303 123 1113 Website: ico.org.uk
9. Cookies and tracking technologies
We use cookies and similar technologies to run the site, understand how it’s used, and show relevant ads. Non-essential cookies are only set after you give consent through our cookie banner (powered by CookieScript).
Cookie categories we use:
- Strictly necessary cookies โ needed for the site to work (for example, your shopping cart). These don’t require consent.
- Analytics cookies โ help us understand how the site is used (Google Analytics). Set only with consent.
- Marketing cookies โ used for advertising and retargeting (Google Ads, Meta Pixel, TikTok Pixel, ClickCease). Set only with consent.
You can manage your cookie preferences at any time by clicking Cookie Settings at the bottom of any page, or by clearing cookies in your browser.
10. Data security
We use appropriate technical and organisational measures to protect your personal data, including:
- HTTPS encryption for all data transmitted to and from the site
- Secure hosting with Rocket.net and Cloudflare
- Payment data handled entirely by PCI-DSS compliant providers (Stripe, PayPal) โ we never store card details
- Access to customer data limited to our team and technical contractors under written Data Processing Agreements
- Regular review of our security practices
No system is 100% secure. If a data breach affects your rights and freedoms, we’ll notify both you and the ICO within the timescales required by UK GDPR.
11. Children
This site is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, please contact us and we’ll delete it.
12. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or the law. The “last updated” date at the top shows the current version.
If we make significant changes, we’ll highlight them clearly on the site or notify you directly.
13. Contact us
For any questions about this policy or to exercise your data protection rights:
- Email: clare@newmanbands.com
- Phone: 01403 626130
- Post: Newman Bands, 10A Middle St, Horsham, West Sussex, RH12 1NW, United Kingdom (trading address โ please do not post to our registered office)