At WareStore (“we”, “us”, or “our”), we are committed to protecting your privacy and handling your personal data responsibly and transparently. This Privacy Policy explains what information we collect, the purposes and lawful bases for which we process it, how long we keep it, and the rights available to you under applicable data-protection laws — including the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act, as amended by the CPRA (CCPA/CPRA).
For the purposes of the GDPR, WareStore acts as the data controller in respect of the personal data described below. If you do not agree with this policy, please do not use our services.
We practise data minimisation and collect only what we need to operate the store:
Under Article 6 of the GDPR, we rely on the following lawful bases:
We do not sell or rent your personal information, and we do not “sell” or “share” it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. We disclose data only to the processors required to run the store — our payment providers (SellAuth, PayPal, and Revolut), email-delivery provider, and hosting infrastructure — under appropriate contractual safeguards, and only to the extent necessary. Each payment provider processes your data in accordance with its own privacy policy. We may also disclose information where required to do so by law, regulation, or valid legal process, or to protect our rights and the safety of others.
Our service providers may process data in countries outside your own, including outside the EEA or the UK. Where personal data is transferred internationally, we take steps to ensure an adequate level of protection — for example, through the European Commission’s Standard Contractual Clauses (or the UK equivalent) or reliance on an applicable adequacy decision.
We retain order and replacement records for as long as necessary to provide support, resolve disputes, enforce our agreements, and meet our legal, accounting, and tax obligations. Security and log data are retained for a limited period proportionate to those purposes and are then deleted or anonymised.
We use only a small number of strictly necessary cookies to keep you logged in and to protect our forms against cross-site request forgery. We do not use third-party advertising or behavioural-tracking cookies. As these cookies are essential to providing the service, they are not subject to a consent requirement.
We implement appropriate technical and organisational measures to safeguard your data: all connections are encrypted in transit with HTTPS, sensitive credentials are encrypted at rest, and administrative access is protected with multi-factor authentication. While no method of transmission or storage is completely secure, we work to protect your information against unauthorised access, loss, or misuse.
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact us through the channels on our contact page. We will respond within the timeframe required by applicable law. We may need to verify your identity before acting on a request, and certain records may be retained where we are legally required or permitted to keep them. You also have the right to lodge a complaint with your local data-protection supervisory authority.
Our services are not directed to, and we do not knowingly collect personal data from, children under the age of 16 (or the minimum age required in your jurisdiction). If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. Any changes will be posted on this page with a revised “last updated” date, and material changes will take effect upon posting.
If you have any questions about this policy, wish to exercise your rights, or want to raise a concern about how your data is handled, please visit our contact page.