1. Who we are (the data controller)
7TCommerce Ltd (trading as “ThatBuddyBrummie”, “we”, “us”, “our”) is the controller of your personal data. We are a company registered in England and Wales, Company number 17214174.
- Contact for data matters: hello@thatbuddybrummie.shop
- ICO registration number: ZC161242
This policy explains how we handle your personal data under the UK GDPR and the Data Protection Act 2018.
2. The data we collect
- Identity and contact data: name, billing/delivery address, email, phone number.
- Age-verification data: confirmation that you are 18+, and, where required by our provider Didit, identity documents and/or a facial/liveness check used to confirm your age. This may include special category or biometric data and is treated with extra care.
- Order and transaction data: items purchased, order value, delivery details, and a payment confirmation (we do not store full card numbers).
- Technical and usage data: IP address, device/browser information, and how you use the Site, collected via cookies and similar technologies.
- Communications: messages you send us and our replies.
3. How we collect it
Directly from you (when you create an account, place an order or contact us); from Didit during age verification; from our payment provider; and automatically via cookies when you use the Site.
4. Why we use it, and our legal basis
Purpose | Legal basis |
|---|---|
Verifying you are 18+ before selling age-restricted products | Legal obligation (preventing unlawful underage sales) and, for any ID/biometric data, the substantial-public-interest / legal-obligation conditions in the DPA 2018 |
Processing and delivering your order | Performance of a contract |
Taking payment and preventing fraud | Contract and legitimate interests |
Customer service and handling returns/complaints | Contract and legitimate interests |
Marketing emails (if you opt in) | Consent — you can withdraw at any time |
Keeping records for tax, accounting and regulatory compliance | Legal obligation |
Improving and securing the Site | Legitimate interests |
5. Age-verification data (Didit)
We use Didit as a processor to verify your age. Depending on the check, Didit may process identity documents and a facial scan. We receive a verification result (and only the limited data needed to evidence the check). Didit processes this data under our instructions and its own privacy terms — see https://didit.me/terms/privacy-policy/. We keep age-verification records only as long as needed to demonstrate compliance (see section 8).
6. Who we share data with
We share data only as necessary with:
- Didit — age verification
- VivaPayments — payment processing
- Royal Mail or DPD or DHL — delivery
- Namecheap — running the Site
We never sell your personal data.
7. International transfers
Where a provider processes data outside the UK, we ensure appropriate safeguards are in place (UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses).
8. How long we keep it
- Order, transaction and tax records: 6 years to meet HMRC/accounting requirements.
- Age-verification records: until your account is permanently deleted. Didit retention policy is set to “forever”.
- Marketing data: until you unsubscribe.
- Account data: while your account is active, then deleted/anonymised.
9. Your rights
Under UK data protection law you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and withdraw consent for anything based on consent (such as marketing). To exercise any right, email help@thatbuddybrummie.shop. We respond within one month.
You can also complain to the Information Commissioner’s Office (ICO) — ico.org.uk, helpline 0303 123 1113 — though we’d appreciate the chance to put things right first.
5. Age-verification data (Didit)
We use Didit as a processor to verify your age. Depending on the check, Didit may process identity documents and a facial scan. We receive a verification result (and only the limited data needed to evidence the check). Didit processes this data under our instructions and its own privacy terms — see https://didit.me/terms/privacy-policy/. We keep age-verification records only as long as needed to demonstrate compliance (see section 8).
6. Who we share data with
We share data only as necessary with:
- Didit — age verification
- VivaPayments — payment processing
- Royal Mail or DPD or DHL — delivery
- Namecheap — running the Site
We never sell your personal data.
7. International transfers
Where a provider processes data outside the UK, we ensure appropriate safeguards are in place (UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses).
8. How long we keep it
- Order, transaction and tax records: 6 years to meet HMRC/accounting requirements.
- Age-verification records: until your account is permanently deleted. Didit retention policy is set to “forever”.
- Marketing data: until you unsubscribe.
- Account data: while your account is active, then deleted/anonymised.
9. Your rights
Under UK data protection law you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and withdraw consent for anything based on consent (such as marketing). To exercise any right, email help@thatbuddybrummie.shop. We respond within one month.
You can also complain to the Information Commissioner’s Office (ICO) — ico.org.uk, helpline 0303 123 1113 — though we’d appreciate the chance to put things right first.
10. Cookies
We use cookies for essential Site functions, and (with your consent) for analytics and marketing. You can manage your preferences via our cookie banner or your browser settings.
11. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit and restricted access. No system is completely secure, but we take protecting your information seriously.
12. Under-18s
Our Site and products are strictly for adults aged 18+. We do not knowingly collect data from anyone under 18, and our age-verification process is designed to prevent underage purchases.
13. Changes to this policy
We may update this policy from time to time. The current version is always on this page, with the “last updated” date above.
14. Contact
Data protection queries: help@thatbuddybrummie.shop
7TCommerce Ltd [17214174] T/A ThatBuddyBrummie
