Privacy policy
Privacy Policy
1. What this policy covers
This policy explains how Fortiva Furnishing Ltd collects, uses, stores and shares personal information when you visit our website (fortivafurnishing.co.uk), request a quote, place an order, sign up to our mailing list, or otherwise interact with us. It also covers personal data we may hold about business contacts as part of our B2B outreach activity.
Our website is hosted by Shopify Inc. Shopify processes certain data on our behalf as a data processor. For information about Shopify's own data practices, visit shopify.com/legal/privacy.
2. Information we collect
We may collect and process the following categories of personal information:
- Identity data — name, job title, organisation name
- Contact data — email address, telephone number, postal address
- Transaction data — details of orders placed, quotes requested, products purchased
- Financial data — payment information processed securely via Shopify Payments or third-party processors. We do not store full card details.
- Communications data — emails, enquiries and messages you send us
- Technical data — IP address, browser type, device information, pages visited, collected via cookies and analytics tools (Google Analytics 4)
- Marketing data — your preferences regarding receiving marketing from us and your interaction with our emails
- B2B prospecting data — publicly available business contact information (name, work email, organisation, role) used for legitimate B2B outreach
3. How and why we use your information
We only use your personal data where we have a lawful basis to do so under UK GDPR. The table below sets out our main processing activities and the legal basis for each:
| Purpose | Legal basis |
|---|---|
| Processing your order or quote request | Performance of a contract |
| Responding to enquiries and providing customer support | Legitimate interests / contract |
| Sending you our newsletter (where you have subscribed) | Consent |
| B2B cold outreach to business contacts (work email addresses only) | Legitimate interests (PECR reg. 6) |
| Website analytics and performance monitoring (GA4) | Legitimate interests / consent (cookies) |
| Fraud prevention and security | Legitimate interests / legal obligation |
| Complying with legal and regulatory obligations | Legal obligation |
| Maintaining accounting and financial records | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms. You may object to processing based on legitimate interests at any time — see Section 7.
4. B2B outreach — our lawful basis
We conduct targeted outreach to business professionals at organisations that may have a legitimate interest in our commercial outdoor furniture products. This includes schools, local authorities, hospitality venues and leisure operators.
Where we contact individuals at business addresses, we do so under the legitimate interests basis (UK GDPR Article 6(1)(f)) and in compliance with the Privacy and Electronic Communications Regulations 2003 (PECR). Business-to-business electronic marketing to corporate subscribers is permitted under PECR where there is a relevant commercial relationship or genuine business interest.
We only use work email addresses for outreach. We do not contact personal email addresses (e.g. Gmail, Hotmail) without prior consent. Every outreach email includes a clear and easy opt-out mechanism, and we process opt-out requests promptly and without question.
If you have received an email from us and wish to opt out, simply reply with "unsubscribe" or use the opt-out link provided. We will remove you within 10 working days and will not contact you again.
5. Who we share your information with
We do not sell your personal data. We may share it with the following categories of third parties, only to the extent necessary:
- Shopify Inc — our e-commerce platform provider, acting as data processor
- UK manufacturers and suppliers — to fulfil your order (dropship delivery). Only your delivery name, address and order details are shared.
- Payment processors — Shopify Payments and connected gateways (e.g. Stripe, PayPal). Card data is processed directly by these providers and not stored by us.
- Google LLC — Google Analytics 4 for website analytics; Google Workspace for email
- Brevo (Sendinblue) — email marketing platform
- Streak CRM — customer relationship management, integrated with Google Workspace
- Professional advisers — accountants, solicitors, where required
- HMRC and regulatory authorities — where required by law
Where third parties process data on our behalf, we ensure appropriate data processing agreements are in place. Some providers are based outside the UK; where this is the case, we rely on adequacy decisions or Standard Contractual Clauses to protect your data.
6. Cookies and tracking
Our website uses cookies — small text files placed on your device — to enable core functionality, remember your preferences, and collect analytics data. We use:
- Essential cookies — required for the site and shopping cart to function. No consent required.
- Analytics cookies — Google Analytics 4, to understand how visitors use the site. These are set only where consent is given via our cookie banner.
- Marketing cookies — used if you interact with our social media or advertising integrations. Set only with consent.
You can manage or withdraw cookie consent at any time via our cookie settings. You can also control cookies through your browser settings.
7. Your rights under UK GDPR
As a UK resident, you have the following rights in relation to your personal data:
8. How long we keep your data
We retain personal data only for as long as necessary for the purposes it was collected, or as required by law. Our standard retention periods are:
- Order and transaction records — 7 years (HMRC legal requirement)
- Enquiries and correspondence — 3 years from last contact
- Marketing opt-outs and suppression lists — indefinitely (to prevent re-contacting)
- Website analytics data — 26 months (GA4 default)
- B2B prospecting data — deleted within 30 days of an opt-out request
9. Data security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration or disclosure. These include encrypted data transmission (HTTPS), access controls, and use of reputable third-party platforms with their own security certifications.
No method of transmission over the internet is 100% secure. While we use commercially reasonable means to protect your data, we cannot guarantee absolute security.
10. Children's data
Our website and services are directed at businesses and business professionals. We do not knowingly collect personal data from anyone under the age of 18. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. When we do, we will update the "last updated" date at the top of this page. Continued use of our website after changes are posted constitutes acceptance of the updated policy.
Questions about this policy?
Contact us directly — we're happy to explain how we use your data or to process any rights request.
Fortiva Furnishing Ltd · Company No. 17125242
5 Wood Terrace, Rowlands Gill, NE39 2AQ