PRIVACY POLICY

Last updated: May 28, 2026

This Privacy Notice for Raflex Ltd ('we', 'us', or 'our') describes how and why we might access, collect, store, use, and/or share ('process') your personal information when you use our services ('Services'), including when you:

  • Visit our website at https://www.raflex.co or any website of ours that links to this Privacy Notice

  • Engage with us in other related ways, including any marketing or events

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services.

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Notice. You can find more details by using our table of contents below.

What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.

Do we process any sensitive personal information? Some information may be considered 'special' or 'sensitive' in certain jurisdictions (e.g. financial data). We may process sensitive personal information when necessary with your consent or as otherwise permitted by applicable law.

Do we collect any information from third parties? We do not collect any information from third parties.

How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.

How do we keep your information safe? We have adequate organisational and technical processes in place to protect your personal information. However, no electronic transmission over the internet can be guaranteed to be 100% secure.

What are your rights? Depending on where you are located, the applicable privacy law may mean you have certain rights regarding your personal information.

TABLE OF CONTENTS

  1. WHAT INFORMATION DO WE COLLECT?

  2. HOW DO WE PROCESS YOUR INFORMATION?

  3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?

  4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

  5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

  6. EMAIL AND MARKETING COMMUNICATIONS

  7. FORMS, ACCOUNTS, AND CHECKOUT

  8. WEBSITE ANALYTICS

  9. HOW LONG DO WE KEEP YOUR INFORMATION?

  10. HOW DO WE KEEP YOUR INFORMATION SAFE?

  11. DO WE COLLECT INFORMATION FROM MINORS?

  12. WHAT ARE YOUR PRIVACY RIGHTS?

  13. CONTROLS FOR DO-NOT-TRACK FEATURES

  14. DO WE MAKE UPDATES TO THIS NOTICE?

  15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

  16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In Short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us. This includes when you:

  • Make a purchase

  • Fill in a form

  • Create a customer account

  • Contact us

  • Subscribe to emails

The personal information we collect may include:

  • Name

  • Email address

  • Phone number

  • Billing and shipping address

  • Passwords and account details

  • Order and purchase information

  • Details relating to your purchase (for example, product specifications, sizes, or weights)

  • Contact or authentication data

  • Communication preferences

Sensitive Information. When necessary, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information:

  • Financial data

Payment Data. We may collect data necessary to process your payment, such as your payment instrument number and security code. All payment data is handled and stored by Squarespace Payments (powered by Stripe). We do not store full payment card details. You may find their privacy notice here: https://stripe.com/gb/privacy

We may also use fraud prevention services including Sift. Their privacy policy is available at: https://sift.com/service-privacy

All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes.

Information automatically collected

In Short: Some information — such as your IP address and browser and device characteristics — is collected automatically when you visit our Services.

We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity but may include device and usage information. It is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes. The information we collect includes:

Log and Usage Data: IP address, browser type, device information, operating system, pages viewed, time spent on pages, clicks, scrolling, searches, navigation activity, date/time stamps, and crash reports.

Device Data: Computer, phone, tablet or other device information including hardware model, internet service provider, mobile carrier, and system configuration.

Location Data: General location based on IP address. You may opt out by disabling your Location settings on your device, though this may affect certain features of the Services.

Squarespace Platform Data. This website is hosted by Squarespace. As our hosting platform, Squarespace also independently collects certain personal data when you visit this website — including information about your browser, network, and device, web pages you visited prior to arriving here, web pages you view on this site, and your IP address — for the purposes of running, protecting, and improving its own platform and services. This processing is governed by Squarespace's own privacy policy, available at https://www.squarespace.com/privacy.

Google API. Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

2. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

  • To facilitate account creation and authentication and otherwise manage user accounts

  • To deliver and facilitate delivery of services to the user

  • To respond to user enquiries and offer support to users

  • To send administrative information to you, including details about products, services, and policy changes

  • To fulfil and manage your orders, payments, returns, and exchanges

  • To send transactional emails such as order confirmations, shipping updates, account notifications, and password resets (these cannot be unsubscribed from as they are necessary for service delivery)

  • To send marketing emails and promotional content (if you opt in — you can unsubscribe at any time)

  • To send abandoned cart reminders if you begin checkout but do not complete a purchase and have provided your email address

  • To request feedback and to contact you about your use of our Services

  • To protect our Services through fraud monitoring and prevention

  • To identify usage trends and improve our Services

  • To comply with legal obligations such as tax, accounting, and regulatory requirements

  • To save or protect an individual's vital interest, such as to prevent harm

3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?

In Short: We only process your personal information when we have a valid legal reason to do so under applicable law.

The UK GDPR and the Data (Use and Access) Act 2025 require us to explain the valid legal bases we rely on to process your personal information:

Contract. We may process your personal information to fulfil our contractual obligations to you, including providing our Services or at your request prior to entering into a contract.

Consent. We may process your information if you have given us permission for a specific purpose, such as marketing emails and non-essential cookies. You can withdraw your consent at any time by contacting us, though this will not affect the lawfulness of processing before its withdrawal.

Legitimate Interests. We may process your information when it is reasonably necessary to achieve our legitimate business interests, including: analysing how our Services are used to improve them; diagnosing problems and preventing fraudulent activities; understanding how users use our products and services to improve user experience.

Legal Obligation. We may process your information where necessary for compliance with our legal obligations, such as tax, accounting, cooperating with law enforcement, or disclosing your information as evidence in litigation.

Vital Interests. We may process your information where necessary to protect your vital interests or those of a third party, such as situations involving potential threats to the safety of any person.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: We may share information in specific situations and with specific third parties.

We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf. We have contracts in place with our third parties which are designed to safeguard your personal information. They cannot do anything with your personal information unless we have instructed them to do so, and they commit to protect the data they hold on our behalf.

The third parties we may share personal information with are:

  • Website hosting and infrastructure: Squarespace

  • Payments and billing: Stripe and Squarespace Payments

  • Fraud prevention: Sift

  • Analytics: Google Analytics and Squarespace Analytics

  • Email and communications: Squarespace Email Campaigns

  • Fonts and content delivery: Google Fonts, Adobe Fonts

  • Shipping and fulfilment: delivery partners (as required)

  • Address autocomplete: Google Places API (if enabled)

  • User account registration and authentication: Squarespace

We may also share your personal information in the following situations:

Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

Google Maps Platform APIs. We may share your information with Google Maps Platform APIs (e.g. Google Maps API, Places API) for address autocomplete functionality.

5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

In Short: We may use cookies and other tracking technologies to collect and store your information.

We may use cookies and similar tracking technologies (like web beacons and pixels) to gather information when you interact with our Services. We use them for:

  • Essential website functionality and security

  • Analytics and performance tracking

  • User experience improvements, including saving your preferences

  • Abandoned cart reminders (depending on your communication preferences)

  • Marketing and advertising (if enabled and consented to)

Non-essential cookies are only used with your consent via our cookie banner. Most web browsers accept cookies by default. You can set your browser to remove or reject cookies, though this may affect certain features or services.

Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Notice.

Note: The ICO published updated guidance on storage and access technologies in April 2026 reflecting changes introduced by the Data (Use and Access) Act 2025. We keep our cookie practices under review in line with this guidance.

6. EMAIL AND MARKETING COMMUNICATIONS

In Short: We send transactional emails as part of service delivery and marketing emails only with your consent.

Transactional Emails

We may send transactional communications that are necessary for the administration and use of your account. These include:

  • Order confirmations

  • Shipping and delivery updates

  • Account notifications

  • Password resets

  • Changes to our terms and policies

These communications cannot be unsubscribed from as they are necessary for service delivery.

Marketing Emails

If you have opted in, we may send promotional content, offers, and updates. You can unsubscribe from marketing emails at any time by clicking the unsubscribe link in any email we send, or by contacting us using the details in Section 15.

Abandoned Cart Emails

If you begin checkout but do not complete a purchase, we may send you an automated reminder email within 24 hours. This occurs when all of the following conditions are met:

  • You enter your email address at checkout, or are logged into your customer account

  • You add an in-stock product to your cart

  • You close your browser or leave the website without completing your purchase

The email will link back to this website so you can complete your purchase. You can unsubscribe from abandoned cart emails at the bottom of the email. This processing is carried out on the basis of our legitimate interests in recovering potential sales and improving customer experience.

7. FORMS, ACCOUNTS, AND CHECKOUT

Forms

We collect information submitted via website forms to respond to enquiries and provide our services.

Customer Accounts

If you create a customer account, we may store:

  • Login details

  • Order history

  • Address information

  • Checkout and invoice data

Checkout and Payments

During checkout, we may use your data to:

  • Process payments

  • Issue invoices

  • Calculate applicable taxes (via Stripe and Squarespace)

  • Auto-complete addresses via the Google Places API (if enabled)

8. WEBSITE ANALYTICS

We use analytics tools such as Squarespace Analytics and Google Analytics (if enabled) to understand website performance and usage. This may include data on:

  • Pages visited and files viewed

  • User interactions and navigation activity

  • Device and browser information

  • IP address and general location

Where Google Analytics is used, data may be transferred to Google's servers. You can opt out of Google Analytics tracking by using the Google Analytics Opt-out Browser Add-on.

9. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: We keep your information for as long as necessary to fulfil the purposes outlined in this Privacy Notice unless otherwise required by law.

We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). In general, we do not retain personal data for longer than the period during which you hold an account with us, except where a legal obligation requires otherwise.

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it. If deletion is not immediately possible (for example, because data is stored in backup archives), we will securely store the data and isolate it from further processing until deletion is possible.

10. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We aim to protect your personal information through a system of organisational and technical security measures.

We have implemented appropriate and reasonable technical and organisational security measures designed to protect the security of any personal information we process. However, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.

11. DO WE COLLECT INFORMATION FROM MINORS?

In Short: We do not knowingly collect data from or market to children under 18 years of age.

We do not knowingly collect, solicit data from, or market to children under 18 years of age, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of a minor and consent to such minor dependent's use of the Services.

If we learn that personal information from users under 18 has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us using the details in Section 15.

12. WHAT ARE YOUR PRIVACY RIGHTS?

In Short: In some regions, such as the UK, EEA, and Switzerland, you have rights that allow you greater access to and control over your personal information.

In some regions (like the UK, EEA, and Switzerland), you have certain rights under applicable data protection laws. These may include the right:

  • To request access and obtain a copy of your personal information

  • To request rectification or erasure of your personal data

  • To restrict or object to the processing of your personal information

  • To data portability (where applicable)

  • Not to be subject to automated decision-making

  • To withdraw consent at any time (where processing is based on consent)

  • To lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk

If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.

Account Information

If you would at any time like to review or change the information in your account or terminate your account, you can log in to your account settings and update your user account. Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with investigations, enforce our legal terms, and/or comply with applicable legal requirements.

Opting Out of Marketing Communications

You can unsubscribe from our marketing and promotional communications at any time by clicking on the unsubscribe link in the emails that we send, or by contacting us using the details in Section 15. You will then be removed from the marketing lists. However, we may still communicate with you to send service-related messages that are necessary for the administration and use of your account.

Withdrawing Consent

If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time by contacting us using the details in Section 15. Please note that this will not affect the lawfulness of the processing before its withdrawal.

13. CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers and some mobile operating systems include a Do-Not-Track ('DNT') feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognising and implementing DNT signals has been finalised. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.

14. DO WE MAKE UPDATES TO THIS NOTICE?

In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to stay informed of how we are protecting your information.

15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this notice, or wish to exercise any of your privacy rights, you may contact us by post or email:

Raflex Ltd
182–184 High Street North
Office 18990
East Ham, England E6 2JA
United Kingdom

Email: hello@raflex.co

16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law.

To request to review, update, or delete your personal information, please contact us using the details provided in Section 15, or submit a data subject access request. We will consider and act upon any request in accordance with applicable data protection laws.

Raflex Ltd • Registered in England and Wales • https://www.raflex.co