Privacy Policy

Your privacy matters to us. Kiva Confections UK collects only the personal data necessary to process your order and improve your experience. We do not sell your data to third parties under any circumstances.

1. Who We Are

Kiva Confections UK operates the website kivaconfections.co.uk. For all privacy-related enquiries, contact us at [email protected].

Our business address is: [Add your business address here], United Kingdom.

2. Data We Collect

We collect the following categories of personal data when you use our website or place an order:

CategoryExamplesPurpose
Identity dataName, date of birth (age verification)Order processing, legal compliance
Contact dataEmail address, phone numberOrder confirmation, delivery updates, support
Delivery dataShipping addressOrder fulfilment
Payment dataTransaction reference only (we do not store card details)Payment processing via third-party gateway
Technical dataIP address, browser type, device, cookiesSite performance, analytics, fraud prevention
Usage dataPages visited, time on site, referral sourceImproving user experience

3. How We Collect Your Data

  • Directly from you — when you place an order, create an account, or contact us
  • Automatically — via cookies and analytics tools as you browse the site
  • From third parties — payment processors and delivery partners share transactional and fulfilment data with us

4. How We Use Your Data

  • Processing and fulfilling your orders
  • Sending order confirmations and delivery tracking updates
  • Responding to customer support queries
  • Verifying customer age in compliance with legal requirements
  • Improving website performance via anonymized analytics
  • Detecting and preventing fraud

We do not use your data for unsolicited marketing unless you have explicitly opted in to receive communications from us.

  • Contract performance — processing your order requires handling your personal data
  • Legal obligation — age verification and regulatory compliance
  • Legitimate interests — fraud prevention, site analytics, customer support
  • Consent — marketing emails and non-essential cookies (where you have opted in)

6. Cookies

We use the following categories of cookies:

  • Essential cookies — required for the site and checkout to function (cart, session)
  • Analytics cookies — Google Analytics to understand how visitors use the site (anonymized)
  • Marketing cookies — only set with your explicit consent via our cookie banner

You can manage or withdraw cookie consent at any time via your browser settings.

7. Who We Share Your Data With

We share your personal data only with trusted third parties where necessary:

  • Payment processors — to securely handle transactions
  • Delivery carriers — Royal Mail and other carriers to fulfil and track your order
  • Analytics providers — Google Analytics (anonymized and aggregated data only)
  • IT and hosting providers — to operate website infrastructure

All third parties are contractually required to handle your data securely and in accordance with UK GDPR.

8. Data Retention

  • Order records — 7 years (legal and tax compliance)
  • Customer account data — until account deletion is requested
  • Analytics data — 26 months (Google Analytics default)
  • Support correspondence — 2 years

9. Your Rights Under UK GDPR

  • Right of access — request a copy of the data we hold about you
  • Right to rectification — ask us to correct inaccurate data
  • Right to erasure — request deletion of your data (subject to legal obligations)
  • Right to restrict processing — limit how we use your data
  • Right to data portability — receive your data in a machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to withdraw consent — for any consent-based processing at any time

To exercise any of these rights, email [email protected]. We will respond within 30 days.

10. Data Security

We use SSL/TLS encryption across the entire site. Card payments are handled by PCI-DSS compliant payment processors — we never store full card details. We implement appropriate technical and organizational measures to protect your data against unauthorized access or loss.

Our website may contain links to external sites. We are not responsible for the privacy practices of those sites and recommend reviewing their policies independently.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects any changes. Continued use of the site after changes constitutes acceptance of the updated policy.

13. Complaints

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the UK’s data protection regulator:

Information Commissioner’s Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113

Privacy Contact

Email: [email protected]

Address: [167c Stroud Green Rd, Finsbury Park, London N4 3PZ], United Kingdom

Response time: within 30 days