Privacy policy

Last updated: April 2026

At Andrew Gardner, we respect your privacy and are committed to protecting your personal data. This policy explains what information we collect, how we use it, and your rights in relation to it.

This website is operated by Fashion by Design Ltd, trading as Andrew Gardner, of 1–4 The Tanyard, Tring Road, Wendover, HP22 6ND, United Kingdom. We are the data controller for the personal information collected through this site.

For any privacy-related questions, please contact us at shop@andrewgardner.co.uk.


1. Information We Collect

Device & browsing information When you visit our site, we automatically collect certain technical information, including your browser version, IP address, time zone, cookie data, pages viewed, search terms, and how you navigate the site. This helps us ensure the site loads correctly and allows us to understand how it is being used.

Order information When you place an order, we collect your name, billing and shipping address, email address, phone number, and payment details (processed securely via Shopify's payment systems). This information is necessary to fulfil your order, process payment, arrange delivery, and send order confirmations.

Customer support communications If you contact us by email or phone, we may retain records of that correspondence to help resolve your query and improve our service. Please note that all phone calls are recorded for training and monitoring purposes.

Email marketing If you opt in to our mailing list, we will use your email address to send you information about new products, promotions, and offers. You can unsubscribe at any time using the link in any of our emails.


2. How We Use Your Information

We use your personal information to:

  • Process and fulfil your orders
  • Communicate with you about your purchases
  • Screen orders for potential fraud or risk
  • Improve and optimise our website
  • Send marketing communications where you have consented
  • Comply with our legal obligations

3. Lawful Basis for Processing (UK & EU GDPR)

As a UK-based business, we process your data in accordance with the UK GDPR and the Data Protection Act 2018. Where we also serve customers in the European Economic Area, the EU GDPR applies. We rely on the following lawful bases:

  • Contract performance — processing your order and arranging delivery
  • Legal obligation — complying with applicable laws and regulations
  • Legitimate interests — fraud prevention, site analytics, and improving our services, where these do not override your rights
  • Consent — for marketing emails and non-essential cookies

4. Sharing Your Information

We do not sell your personal information. We share it only where necessary with trusted third parties who help us operate our business:

  • Shopify — our e-commerce platform processes and stores order and customer data. See their privacy policy at shopify.com/legal/privacy
  • Google Analytics — helps us understand site usage. You can opt out at tools.google.com/dlpage/gaoptout. See Google's privacy policy at policies.google.com/privacy
  • Advertising partners — we may use data for targeted advertising via Facebook/Meta and Google. See opt-out options in Section 6 below
  • Legal authorities — we may disclose information where required by law, court order, or to protect our legal rights

5. Cookies

Cookies are small files downloaded to your device when you visit our site. We use them to keep the site functioning correctly, remember your preferences, and understand how visitors use the site.

Essential cookies — required for the site to work (shopping cart, checkout, login):

Cookie Purpose
cart Shopping cart contents
checkout_token Checkout process
secure_customer_sig Customer login
_secure_session_id Storefront navigation
_shopify_u Customer account updates

Analytics & performance cookies — help us improve the site:

Cookie Purpose
_s, _shopify_s, _shopify_y Shopify analytics
_shopify_sa_p / _sa_t Marketing & referral analytics
_landing_page, _orig_referrer Track how visitors arrive
_tracking_consent Records your cookie preferences

Most cookies persist between 30 minutes and two years. You can manage or block cookies through your browser settings (usually found under Tools or Preferences). Be aware that blocking certain cookies may affect how the site functions. For more information, visit allaboutcookies.org.


6. Targeted Advertising

We may use your data to show you relevant advertising on other platforms. You can opt out of personalised advertising using the links below:

  • Facebook/Meta: facebook.com/settings/?tab=ads
  • Google: google.com/settings/ads/anonymous
  • Microsoft/Bing: about.ads.microsoft.com/en-gb/resources/policies/personalized-ads

You can also opt out of multiple services via the Digital Advertising Alliance portal at optout.aboutads.info.


7. Data Retention

We retain your personal information for as long as necessary to fulfil the purposes described in this policy, including for legal and accounting obligations. If you would like us to delete your data, please see your rights below.


8. Automated Decision-Making

We do not use fully automated decision-making that has a legal or significant effect on you. Shopify uses limited automation to help prevent fraud, including temporary blocks on IP addresses or payment cards associated with repeated failed transactions. These measures are temporary and do not have a lasting legal effect.


9. Your Rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct any inaccurate or incomplete information
  • Erase your data ("right to be forgotten") in certain circumstances
  • Restrict how we process your data
  • Object to processing based on legitimate interests or for direct marketing
  • Data portability — receive your data in a structured, machine-readable format
  • Withdraw consent at any time where processing is based on consent (such as marketing emails)

To exercise any of these rights, please contact us at shop@andrewgardner.co.uk. We will respond within 30 days.


10. Complaints

If you are unhappy with how we have handled your data, please contact us in the first instance and we will do our best to resolve your concern.

If you remain unsatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection authority: 🌐 ico.org.uk | 📞 0303 123 1113

If you are based in the EEA, you may also contact your local data protection authority.


11. International Data Transfers

Your data may be transferred to and stored in countries outside the UK and EEA, including Canada and the United States, where Shopify operates its infrastructure. These transfers are carried out in accordance with UK GDPR requirements. For more information, see Shopify's GDPR Whitepaper at help.shopify.com/en/manual/your-account/privacy/GDPR.


12. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices or legal requirements. When we do, we will update the date at the top of this page. We encourage you to review it periodically.


13. Contact Us

Fashion by Design Ltd (Andrew Gardner) 1–4 The Tanyard, Tring Road, Wendover, HP22 6ND

📧 shop@andrewgardner.co.uk 📞 01296 625488