Privacy Policy

Home-X Labs Limited Privacy Policy
Last Updated: 21.10.2020

Our contact details
Name: Home-X Labs Limited
Address:16 Charlotte Square, Edinburgh, United Kingdom, EH2 2DF
E-mail: dpo@home-x.com

What is this privacy policy for?
This Privacy Policy tells you how we deal with your "personal data" (i.e. technical term for information about any identified or identifiable living person). Please read on to find out what kinds of personal data we collect, how we use and protect it, who we share it with, how long we keep it for and how you can access and rectify it.
Please do not use our website or apps unless you are completely happy with this Privacy Policy.

Can the privacy policy change?
It may change from time to time. Whenever we have updated our Privacy Policy, we will alert you via email. Please take that opportunity to re-read it. We will assume you agree to the revised Privacy Policy if you use the website or apps after the effective date shown at the top of the Privacy Policy.

The type of personal information we collect
We currently collect and process the following information:
1. Contact Data (“Contact Data”)
· Date of birth
· Full Name
· Home Address
· Email Address
· Contact number

2. Payment Data (“Payment Data”)
· Your bank or payment details

3. Consumer Behaviour Data (“Consumer Behaviour Data”)
· Purchase history
· Product reviews/feedback
· Your IP Address

4. Survey Data (“Survey Data”)
· Age bracket
· Household make up
· Sex
· Allergies/food preferences
· Product / brand preferences

How we get the personal information and why we have it
Most of the personal information we process is provided to us directly by you for one of the following reasons:

· To process and fulfil an order
· To process payment
· Marketing and communications
· Advertising and promotions
· Cross promotions
· Customer data Analytics
· Age verification for purchase of alcohol
· Product / brand preferences
· To process refunds where applicable

For Example
We also collect and store your IP address ("customer behaviour data") to improve your shopping experience by suggesting suitable products for you, based on previous purchases, or products looked at.
We collect your bank card details (payment information) in order to process payments and refunds.

We collect survey data (after each purchase.) which can include household makeup (number of children and age bracket), age (bracket not birthday), gender and food preferences/allergies in order to understand how we are serving different types of customers and what we need to do to improve their experience.

We also receive personal information indirectly, from the following sources in the following scenarios:
· Facebook Pixel
· Big Cartel
· Google analytics
· Cookies (See below Privacy Policy)
· Mail Chimp - Mail Chimp would only be used to send mass emails if our Shopify server went down.

We use the information that you have given us via the forms on our website, apps or when contacting us in some other way in order to:
· To process and fulfil an order
· To process refunds where applicable
· Marketing and communications
· Advertising and promotions
· Cross promotions
· Customer data Analytics
· Age verification for purchase of alcohol
· Product / brand preferences
· To process refunds where applicable

For Example
We collect and store your contact data to process and keep you up to date with orders.
We also collect and store customer behaviour data e.g. your Order History, to improve your shopping experience by suggesting suitable products for you, based on previous purchases.

We collect your bank card details payment data in order to process payments and refunds.
We collect survey data in order to understand how we are serving different types of customers and what we need to do to improve their experience.

We may share this information with:
Shopify.co.uk
Facebook
Google Analytics
Klaviyo
YotPo
Six By Nico
DPD

We will share data with Shopify.co.uk. Shopify is a third party vendor platform we will use to process the orders. This will be limited to Contact Data and Payment Data.
We will share some Contact Data with our delivery contractor DPD. The basis for this is contractual. DPD need to know your address so they can delivery your order. The Data will be limited to your name, address and contact number.

Six by Nico (Holdings) Limited (‘Six by Nico) are a separate company to us but we are part of the same group of companies. Six by Nico are restaurants, and you may be interested hearing about what they have to do. Their web address is https://www.sixbynico.co.uk/ if you would like more information We will only share your data with Six by Nico where you have given your consent to sharing. You can opt out anytime.

Under the General Data Protection Regulation (GDPR), the lawful bases we rely on for processing this information are:
(a) Your consent. You are able to remove your consent at any time. You can do this by contacting dpo@home-x.com
(b) We have a contractual obligation.
(c) We have a legal obligation.
(d) We have a legitimate interest.

For Example
Under GDPR, we will use the lawful basis of “contractual obligation”, where we use contact and payment data to fulfil orders.
When use ask for your date of birth to verify an alcohol sale the basis would be “legal obligation”.

When we use contact, survey, or customer behaviour data for marketing reasons, the lawful basis will be "consent", or "legitimate interest". If you would like further information, please contact us using the details within this privacy policy.

How we store your personal information
Your information is securely stored on Cloudfare.com and Shopify.co.uk.
Shopify is a third party vendor platform which we will use to process the orders. External plug ins associated with Shopify.com are as follows:
- Facebook Pixel.
- Google Analytics
- Klaviyo - all of our email marketing
- YotPo - customer reviews on site

These plugins operate as part of Shopify Pay but Shopify would store any data collected using the plugins.

DPD our delivery contractor will store contact data required to fulfil and process orders. This will be limited to your Name, Address and contact telephone number. Any Data you provide DPD yourself will be governed by their own GDPR policy.

Shopify will store data provided to process the orders. This will be limited to Contact Data and Payment Data. Any data you provide to Shopify yourself will be governed by their own GDPR Policy.

We keep your Personal Data for 3 years after your last order unless a request for deletion is received. We retain your data in order to comply with legal obligations, enforce our terms and conditions, prevent fraud, collect any fees owed, resolve disputes, troubleshoot problems, assist with any investigations and take other actions as permitted by law.

We will then dispose your information by Removing data from all platform storage and from any third party vendors and ensuring this is destroyed securely.

Your Data Rights
You have the right to request a copy of your information, to rectify your information, to opt out from marketing communications and to request the deletion of your information. Below, we describe the processes for making these requests.

Update/rectify your information: You can easily correct/change the following personal information on “My Account” page by logging in to your account on our website or apps:
1. first name and last name
2. phone number
3. email address
4. delivery address
5. billing address
6. payment details
Alternatively, you can contact us: dpo@home-x.com

Opt out of marketing communications: You can easily change your marketing permissions on "My Account" page, under "My communication preferences" section by logging in to your account on our website or apps.

Access your information: You have the right to request personal data that we hold about you, subject to us reserving the right to withhold such data to the extent permitted by law. Please contact dpo@home-x.com

Delete your information: You have the right to request to delete all the personal data that we hold about you. Contact our Data Protection Officer for this request: dpo@home-x.com

If you wish to contact us about anything to do with your data and Home-X, please contact us via dpo@home-x.com

For information about your rights under UK data protection laws, see the website of the UK Information Commissioner.

You can report any concern to the ICO, https://ico.org.uk/make-a-complaint

We are registered with the Information Commissioner’s Register of Data Controllers under number ZA797312

Cookie Policy

What are Cookies
Cookies are files stored on your computer that contain data that helps the web server identify the user’s authenticity and browsing preferences (for example language preferences etc).

This data can comprise of things like authentication data, preferences, and searches. Cookies can also be used to identify individual users and enhance or tailor their browser experience.

How we use Cookies
Our website uses cookies improve your browsing experience and online security.

For example, we would use cookies to remind us what you have in your basket and to authenticate your payment details. Without these our site simply wouldn’t work.

We also use cookies to tell us a bit about you. You need to consent to these cookies. We would use the information to learn how you are using the website. This helps us to improve our service and give you the best experience we can.

For example, we could use information like what you browse and for how long to show you products you might be interested in.

We use the following cookies
The table below sets out the cookies, where they came from, their expiry date and whether they are necessary or not. Any cookies not classed as necessary requires your consent.

Cookies that require your consent are no less important than necessary cookies to your overall browsing experience. We just need your consent so they can do their job.

Cookie

Provider

Expiry

Status

_cfduid

Shopifypreview.com

29 days

Necessary

_shopify_d

Shopifypreview.com

Session

Necessary

cart_currency

Shopifypreview.com

14 days

Necessary

cart_sig

Shopifypreview.com

14 days

Necessary

cookietest

Shopifypreview.com

Session

Necessary

I

p.yotpo.com

Session

Necessary

Secure_customer_sig

Shopifypreview.com

20 years

Necessary

_shopify_country

Shopifypreview.com

Session

Preference

KL_FORMS_MODAL

Shopifypreview.com

1 Year

Preference

_kla_id

Shopifypreview.com

2 years

Statistics

_ga

Shopifypreview.com

2 years

Statistics

_gat

Shopifypreview.com

1 day

Statistics

_gid

Shopifypreview.com

1 day

Statistics

_landing_page

Shopifypreview.com

13 days

Marketing

_orig_referrer

Shopifypreview.com

13 days

Marketing

_s

Shopifypreview.com

1 day

Marketing

_shopify_fs

Shopifypreview.com

1 day

Marketing

_shopify_s

Shopifypreview.com

1 day

Marketing

_shopify_sa_p

Shopifypreview.com

1 day

Marketing

_shopify_sa_t

Shopifypreview.com

1 day

Marketing

__shopify_y

Shopifypreview.com

1 year

Marketing

_y

Shopifypreview.com

1 year

Marketing

_sp_id.dc.42

Shopifypreview.com

 

Unclassified

_sp_ses.dc42

Shopifypreview.com

 

Unclassified

eg_settings

Shopifypreview.com

 

Unclassified

Pixel

Yotpo.com

1 year

Unclassified


Session cookies will be deleted or expire as soon as you close your browser. A persistent cookie will remain until it expires or is deleted.

Turning off cookies
If you turn off all cookies, our website might not work properly. But if you want to, you can delete your cookies and manage how cookies are used for the browser you use.

Here are the instructions for desktop browsers:
· Google Chrome
· Firefox
· Safari
· Internet Explorer

And here are the instructions for mobile browsers:
· Google Chrome on Android
· Firefox on Android
· Safari on iOS

To opt out of being tracked by Google Analytics across all websites, visit http://tools.google.com/dlpage/gaoptout.

Changes to the Cookies or Policy itself
If we make any changes to this policy, we will be required to ask you for your consent again. We will ask for this the first time you visit the website after the changes are made.