privacy policy
Last updated: 21 April 2026
Who We Are
Firkin World (“we”, “us”, “our”) is an online retailer selling Firkin World bags, based in the United Kingdom. We are the data controller for the personal data described below, and we are committed to protecting your personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
What Data We Collect
We collect different personal data depending on how you interact with us:
- When you place an order: name, email address, delivery address, phone number (if provided), and payment information (processed securely by Stripe — we do not store card details).
- When you subscribe to our mailing list: email address.
- When you join a product waitlist: email address and the product you are waitlisted for.
- When you browse the site: IP address, browser type, and basic usage data (via standard website analytics).
How We Use Your Data and Our Legal Basis
We use your data for the purposes below, under the following lawful bases:
- Fulfilling your order — to process payments, ship your bag, and handle returns (contract).
- Order updates and customer service — to send order confirmations, shipping notifications, and reply to questions (contract).
- Marketing emails — if you have subscribed via our mailing list popup, we will send you occasional emails about new releases, restocks, and promotions (consent).
- Waitlist notifications — if you have joined a product waitlist, we will email you when that specific item is back in stock (consent). We do not send general marketing emails to waitlist-only subscribers.
- Legal obligations — to keep tax and transaction records as required by UK law (legal obligation).
You can withdraw consent for marketing or waitlist emails at any time by clicking the unsubscribe link in any email, or by contacting us.
Who We Share Data With
We only share your data with third-party processors where necessary, under contractual data-processing agreements:
- Stripe — for secure payment processing.
- Resend — to send transactional emails (order confirmations, shipping updates) and marketing emails to subscribers. Resend stores subscriber email addresses on our behalf.
- Royal Mail and other couriers — for delivery.
- Vercel — our hosting provider.
We do not sell your data to third parties. Some of these processors may transfer data outside the UK; where this happens we rely on the UK’s adequacy regulations or standard contractual clauses.
How Long We Keep Your Data
We retain order and invoice data for up to 6 years for tax and legal purposes. Mailing list and waitlist email addresses are kept until you unsubscribe. You may request deletion of your data at any time, subject to legal retention requirements.
Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to processing or withdraw consent
- Receive a copy of your data in a portable format
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk
Cookies
Our website uses a small number of cookies and similar technologies. See our cookie policy for details.
Contact
To exercise any of your rights, or for any privacy-related questions, email us at firkinworld@gmail.com or reach us at @firkin.world on Instagram.