Privacy Policy
How PlainChains collects, uses, and protects your personal data.
Last updated: 18 June 2026
PlainChains ("we", "us", "our") is committed to protecting your privacy. This policy explains what personal data we collect when you use plain-chains.com, why we collect it, how we use it, and what rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
PlainChains is a sole trader business trading as "PlainChains",
operating from:
Office 348, Unit 5
399-405 Oxford Street, Mayfair, London
W1C 2BU, United Kingdom
For any privacy-related question or to exercise your data protection rights, contact us at
[email protected]. We are the data
controller for the personal data described in this policy.
2. Personal Data We Collect
We collect the following categories of personal data:
- Account & contact details: first name, last name, email address, phone number, and password (stored as a secure hash) when you register an account.
- Order & delivery data: billing and shipping addresses, order history, items purchased, and shipping/tracking details for orders placed with us.
- Payment information: we never see or store your full card details. All payments (card, PayPal, and Klarna) are processed securely by Stripe, our payment processor.
- Marketing preferences: whether you have opted in to receive marketing emails from us.
- Contact form submissions: your name, email address, subject, and message when you contact us via our website.
- Reviews: your name, star rating, and feedback text if you submit a product review.
- Technical data: session identifiers and basic technical information needed to operate the website securely (see our Cookies section below).
3. Why We Use Your Data & Our Legal Basis
- To fulfil your orders — processing payments, arranging delivery, and providing customer service. Legal basis: performance of a contract.
- To manage your account — letting you view order history and manage your details. Legal basis: performance of a contract.
- To respond to enquiries submitted via our contact form. Legal basis: legitimate interest in responding to customer queries.
- To send marketing emails, only if you have opted in. Legal basis: consent. You can withdraw this consent at any time.
- To prevent fraud and keep our website secure. Legal basis: legitimate interest.
- To comply with our legal obligations, such as keeping financial records for tax purposes. Legal basis: legal obligation.
4. Who We Share Your Data With
We share personal data with trusted third parties who help us run our business. We do not sell your personal data.
- Stripe — processes all payments (card, PayPal, and Klarna).
- Royal Mail — delivers your order and provides tracking information.
- getAddress.io — provides address lookup/autocomplete at checkout based on your postcode.
- Mailtrap — our transactional email provider, used to send order confirmations, shipping notifications, and account emails.
Some of these providers may process data on servers located outside the UK. Where this happens, they are required to provide an adequate level of protection for your data, for example through UK-approved Standard Contractual Clauses.
5. How Long We Keep Your Data
- Order and financial records are kept for 6 years to comply with UK tax law.
- Account data is kept for as long as your account remains active, or until you ask us to delete it.
- Marketing consent is kept until you withdraw it.
- Contact form messages are kept only as long as needed to resolve your enquiry.
6. Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request erasure of your data, where applicable.
- Restrict or object to certain processing.
- Request a copy of your data in a portable format.
- Withdraw consent at any time, for example to marketing emails.
To exercise any of these rights, email us at [email protected]. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
7. Cookies
We use a small number of cookies, all of which are strictly necessary for the website to function. We do not currently use any analytics, advertising, or tracking cookies. You can review or withdraw your acknowledgement of this at any time using the "Cookie Settings" link in our website footer.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| Session cookie | Keeps you logged in and remembers your cart/checkout progress. | Strictly necessary | Session |
| XSRF-TOKEN | Protects against cross-site request forgery attacks. | Strictly necessary | Session |
| Cookie notice acknowledgement | Remembers that you have seen our cookie notice (stored in your browser's local storage, not as a cookie). | Strictly necessary | Until cleared by you |
8. Children's Privacy
Our website is not directed at children, and we do not knowingly collect personal data from children.
9. Changes to This Policy
We may update this policy from time to time. Any changes will be posted on this page with an updated "Last updated" date.
Contact Us