THE DRENN Privacy Policy
How we collect, use and protect your personal data, whether you're shopping with us from the UK or from an EU market we serve.
Overview & Data Controller
This privacy policy explains how The Drenn collects, uses, shares and protects your personal data when you browse thedrenn.com, place an order, or otherwise get in touch with us. The Drenn is a trading name of NORVELLO COMMERCE LTD, a company registered in England and Wales under company number 17413994, with its registered office at 30 Calderwood Street, London SE18 6JH, United Kingdom.
NORVELLO COMMERCE LTD is the data controller responsible for your personal data. We are a UK home market business for The Drenn, and we also serve customers in EU member states, with more markets planned. This policy applies to customers in both the UK and the EU markets we serve, since the substantive protections under UK GDPR and EU GDPR are very similar.
Information We Collect
We collect the personal data needed to run our store and look after you as a customer. This includes your name, email address and phone number if you give it to us, your delivery and billing address, the items you order, order and payment references, and any messages you send us through customer support or returns requests.
We also collect some information automatically, such as your IP address, browser and device type, and how you use our website, through cookies and similar technologies. If you sign up for marketing, we record your consent status so we know whether we can email you.
We do not knowingly collect special category data, such as health information, racial or ethnic origin, or biometric data, and we do not knowingly collect data from children.
How We Use Your Information
We use your personal data to process and fulfil your order, arrange shipping and provide tracking, and handle returns, refunds and exchanges. We use it to respond to customer service enquiries and resolve any issues with your order.
We also use your data to meet our legal and accounting obligations, to detect and prevent fraud, and to keep our website secure and working properly. Where you've opted in, we use your email address to send marketing updates about new drops and offers. You can unsubscribe at any time using the link in any marketing email.
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you.
Legal Basis For Processing
Both UK GDPR and EU GDPR require us to have a lawful basis for each way we use your personal data. For processing your order, arranging delivery and providing customer support, we rely on contract, since it's necessary to fulfil the sale agreement between us.
For accounting and tax records, we rely on legal obligation, since UK and applicable EU tax law require us to keep certain records. For fraud prevention and keeping our website secure, we rely on legitimate interests, having weighed that this doesn't override your rights and freedoms. For marketing emails, we rely on your consent, which you can withdraw at any time.
Sharing With Processors & Third Parties
We never sell your personal data. We only share it with service providers who need it to help us run our store and fulfil your order, including our e-commerce platform, payment processor, delivery couriers, email service provider, and hosting and analytics providers. Each of these processors is bound by data processing agreements and confidentiality obligations.
We may also disclose your data where required by law, to respond to a valid request from a court or regulator, to enforce our terms, or as part of a merger, acquisition or sale of business assets. In each case your data stays protected under the terms of this policy.
Data Retention
We keep personal data only as long as necessary for the purpose it was collected for, or as required by law. Order and accounting records are kept for as long as UK and applicable tax and accounting rules require. Customer service communications are kept for a reasonable period after your last contact with us in case a related issue comes up again.
If you unsubscribe from marketing, we keep a record of your opt-out so we don't email you again, and we delete inactive marketing data after a reasonable period. You can ask us to delete your data at any time, see the rights section below, and we will do so unless we're legally required to keep it.
Your Rights Under UK & EU GDPR
If you're a UK customer, your personal data is protected under UK GDPR and the Data Protection Act 2018. If you're a customer in an EU member state we serve, your personal data is protected under EU GDPR (Regulation 2016/679). UK GDPR is a retained copy of EU GDPR, so the rights available to you are effectively the same wherever you're based.
You have the right to access a copy of the personal data we hold about you, request correction of inaccurate data, request erasure of your data where it's no longer needed, restrict how we process it, receive your data in a portable format, and object to processing based on legitimate interests, including direct marketing.
You also have the right to complain to your supervisory authority. The cards below set out which regulator applies to you and how to reach them.
Cookies & Consent
We use cookies and similar technologies on thedrenn.com. Necessary cookies, such as those that keep your basket working and keep the site secure, don't require your consent. Analytics and marketing cookies are only set with your permission, in line with UK and EU rules on cookies and electronic communications.
You can manage your cookie preferences through the cookie banner shown on your first visit, or by adjusting your browser settings to block or delete cookies. Turning off necessary cookies may affect how the site works, for example your basket may not save correctly.
International Transfers & Security
Our store runs on Shopify and other providers that may process or store data outside the UK and the EEA, including in the United States. Where we transfer personal data internationally, we put appropriate safeguards in place, such as the UK International Data Transfer Agreement for transfers from the UK, or the EU Standard Contractual Clauses for transfers from the EU, to keep your data protected to a comparable standard.
We protect your data with measures including HTTPS encryption across our site, secure payment processing, restricted access to personal data within our team, and data processing agreements with every processor we use. If a data breach is likely to put your rights and freedoms at risk, we will notify you and the relevant supervisory authority without undue delay, in line with our legal obligations.
Contact & Supervisory Authorities
For any question about this policy or to exercise your rights, email us at hello@thedrenn.com. We aim to respond to all privacy requests within one month, extendable by a further two months for complex requests, and we'll let you know if that's needed.
We'd always rather sort things out directly, so please contact us first. If you're not satisfied with our response, you have the right to lodge a complaint with your supervisory authority at any time. See the cards below for how to reach the ICO or your EU authority.
United Kingdom (ICO)
Governed by UK GDPR and the Data Protection Act 2018. The supervisory authority is the Information Commissioner's Office (ICO), reachable at ico.org.uk. This is your regulator if you're based in the UK.
EU Markets We Serve
Governed by EU GDPR (Regulation 2016/679). Your regulator is the competent data protection authority in your EU member state of residence, and this extends automatically as we add more EU markets.
Data & privacy
Have a question about your data?
Email us and we'll get back to you. We aim to answer every privacy request within a month.