Privacy policy
NEUROLINK LABS LTD respects customer privacy and processes personal information in accordance with applicable UK data protection law, including the UK GDPR and the Data Protection Act 2018.
Data controller
The data controller for the online store is NEUROLINK LABS LTD, company number 16685144, with registered office at L220, Beaconside Business Village, Stafford Enterprise Park, Weston Road, Stafford, United Kingdom, ST18 0BF.
Privacy contact: support@neurolinklabs.com
Information we collect
· Identity and contact data, such as name, billing address, delivery address, email address and any telephone number voluntarily supplied at checkout.
· Order and transaction data, such as products purchased, order value, returns, refunds and correspondence.
· Payment-related information processed by payment providers. We generally receive transaction status and limited payment details rather than complete card credentials.
· Technical and usage data, such as IP address, browser, device information, cookie identifiers, pages viewed and interactions with the store.
· Customer service information contained in messages, product reviews, return requests or complaints.
· Marketing preferences and consent records.
How and why we use information
|
Purpose |
Typical information |
Legal basis |
|
Process and deliver orders |
Contact, order, transaction and delivery data |
Contract |
|
Handle returns, refunds and support |
Order details and communications |
Contract and legal obligation |
|
Prevent fraud and secure the store |
Transaction and technical signals |
Legitimate interests and legal obligation |
|
Maintain records and comply with law |
Orders, invoices, refunds and correspondence |
Legal obligation |
|
Improve the store and understand use |
Cookie and usage data |
Consent where required; otherwise legitimate interests |
|
Send marketing communications |
Contact details and preferences |
Consent or another lawful basis permitted by law |
Sharing personal information
We share personal information only where reasonably necessary with service providers such as:
· Shopify and related ecommerce infrastructure providers;
· payment processors and fraud-prevention providers;
· warehousing, fulfilment and delivery providers;
· IT, hosting, analytics and customer-support providers;
· professional advisers, insurers, auditors and accountants; and
· public authorities, regulators or law-enforcement bodies where disclosure is required or permitted by law.
Service providers are expected to protect personal information and use it only for authorised purposes. Some third parties, such as payment providers, may also act as independent data controllers under their own privacy notices.
International transfers
Some technology or service providers may process information outside the United Kingdom. Where UK data protection law requires safeguards, we use an approved transfer mechanism, such as adequacy regulations or contractual safeguards, together with appropriate technical and organisational measures.
Retention
We retain personal information only for as long as needed for the purposes described in this policy, including customer service, dispute resolution and legal, accounting or tax obligations. Order and transaction records may normally be retained for at least six years where required for company and tax records. Marketing data is retained until consent is withdrawn or it is no longer needed, subject to a limited suppression record where necessary to respect an opt-out.
Customer rights
Depending on the circumstances, individuals may have the right to request access, correction, deletion, restriction, objection, data portability and withdrawal of consent. A request can be sent to the privacy contact. We may ask for proportionate information to verify identity before responding.
Individuals also have the right to complain to the UK Information Commissioner's Office. We encourage customers to contact us first so that we can try to resolve the concern.
Information Commissioner's Office: https://ico.org.uk/make-a-complaint/
Marketing
Marketing messages are sent only where permitted by law. Every marketing email will provide an unsubscribe method. Transactional messages about orders, delivery, security or policy changes are not marketing and may still be sent when necessary.
Cookies
The store uses cookies and similar technologies as explained in the Cookie Policy. Non-essential cookies should be used only after the required consent has been obtained through the store's cookie preference controls.
Security and children
We use reasonable administrative, technical and organisational measures to protect personal information. No internet transmission or storage system is completely secure. The store is not directed to children, and we do not knowingly collect personal information from children who cannot lawfully provide it.
Policy changes
We may update this policy to reflect changes in the store, service providers or legal requirements. The current version and effective date will be published on the website.