Privacy Policy

This privacy policy explains what personal data we collect, how it is used, and how it is protected across the UNBOUND website, orders and customer support channels.

This privacy policy applies to information collected when you visit the website, place an order, contact support or otherwise interact with UNBOUND.

Who We Are

UNBOUND is the controller of personal data collected through the website and related services. Final company details, business address, and support email should match the legal business information published in Shopify admin.

Personal Data We Collect

  • Contact details such as name, email address, phone number and shipping address
  • Order and transaction details including products ordered, payment status and delivery information
  • Account and device information such as browser type, IP address and session activity
  • Messages sent to support and any follow-up communication
  • Marketing preferences where consent has been given

Purpose And Legal Basis Of Processing

Purpose Legal basis
Fulfilling orders, processing payments and customer support Contract performance
Sending marketing communications Consent
Website analytics and service improvement Legitimate interest
Fraud prevention and security monitoring Legitimate interest and legal obligations

Marketing Communications

Marketing emails should only be sent where the customer has opted in or where another valid legal basis exists. Customers must be able to unsubscribe at any time.

Cookies

The website may use cookies and similar technologies for site functionality, analytics and performance measurement. A separate cookie policy or cookie settings tool can be linked here.

How We Share Your Data

  • Service providers involved in hosting, analytics, email or customer support
  • Payment and logistics partners required to process and deliver orders
  • Authorities or advisers where disclosure is legally required

International Data Transfers

If personal data is transferred outside the primary operating region, appropriate safeguards should be put in place, such as standard contractual clauses or equivalent protection mechanisms.

Data Security

  • Secure systems and access controls
  • Authentication and restricted admin access
  • Regular monitoring and security review processes

Data Retention

Personal data should only be kept as long as necessary for order fulfilment, legal record-keeping, fraud prevention and customer support obligations.

Your Rights Under GDPR

  • Right of access
  • Right to rectification
  • Right to erasure where applicable
  • Right to restrict or object to processing
  • Right to data portability
  • Right to withdraw consent where processing depends on consent

Changes To This Policy

This page should be reviewed and updated whenever the privacy handling of the store changes. Add the final updated date once the legal wording is approved.