Privacy Policy
This privacy policy explains what personal data we collect, how it is used, and how it is protected across the UNBOUND website, orders and customer support channels.
This privacy policy applies to information collected when you visit the website, place an order, contact support or otherwise interact with UNBOUND.
Who We Are
UNBOUND is the controller of personal data collected through the website and related services. Final company details, business address, and support email should match the legal business information published in Shopify admin.
Personal Data We Collect
- Contact details such as name, email address, phone number and shipping address
- Order and transaction details including products ordered, payment status and delivery information
- Account and device information such as browser type, IP address and session activity
- Messages sent to support and any follow-up communication
- Marketing preferences where consent has been given
Purpose And Legal Basis Of Processing
| Purpose | Legal basis |
|---|---|
| Fulfilling orders, processing payments and customer support | Contract performance |
| Sending marketing communications | Consent |
| Website analytics and service improvement | Legitimate interest |
| Fraud prevention and security monitoring | Legitimate interest and legal obligations |
Marketing Communications
Marketing emails should only be sent where the customer has opted in or where another valid legal basis exists. Customers must be able to unsubscribe at any time.
Cookies
The website may use cookies and similar technologies for site functionality, analytics and performance measurement. A separate cookie policy or cookie settings tool can be linked here.
How We Share Your Data
- Service providers involved in hosting, analytics, email or customer support
- Payment and logistics partners required to process and deliver orders
- Authorities or advisers where disclosure is legally required
International Data Transfers
If personal data is transferred outside the primary operating region, appropriate safeguards should be put in place, such as standard contractual clauses or equivalent protection mechanisms.
Data Security
- Secure systems and access controls
- Authentication and restricted admin access
- Regular monitoring and security review processes
Data Retention
Personal data should only be kept as long as necessary for order fulfilment, legal record-keeping, fraud prevention and customer support obligations.
Your Rights Under GDPR
- Right of access
- Right to rectification
- Right to erasure where applicable
- Right to restrict or object to processing
- Right to data portability
- Right to withdraw consent where processing depends on consent
Changes To This Policy
This page should be reviewed and updated whenever the privacy handling of the store changes. Add the final updated date once the legal wording is approved.

