Privacy policy

NEUROLINK LABS LTD respects customer privacy and processes personal information in accordance with applicable UK data protection law, including the UK GDPR and the Data Protection Act 2018.

Data controller

The data controller for the online store is NEUROLINK LABS LTD, company number 16685144, with registered office at L220, Beaconside Business Village, Stafford Enterprise Park, Weston Road, Stafford, United Kingdom, ST18 0BF.

Privacy contact: support@neurolinklabs.com

Information we collect

· Identity and contact data, such as name, billing address, delivery address, email address and any telephone number voluntarily supplied at checkout.

· Order and transaction data, such as products purchased, order value, returns, refunds and correspondence.

· Payment-related information processed by payment providers. We generally receive transaction status and limited payment details rather than complete card credentials.

· Technical and usage data, such as IP address, browser, device information, cookie identifiers, pages viewed and interactions with the store.

· Customer service information contained in messages, product reviews, return requests or complaints.

· Marketing preferences and consent records.

How and why we use information

Purpose

Typical information

Legal basis

Process and deliver orders

Contact, order, transaction and delivery data

Contract

Handle returns, refunds and support

Order details and communications

Contract and legal obligation

Prevent fraud and secure the store

Transaction and technical signals

Legitimate interests and legal obligation

Maintain records and comply with law

Orders, invoices, refunds and correspondence

Legal obligation

Improve the store and understand use

Cookie and usage data

Consent where required; otherwise legitimate interests

Send marketing communications

Contact details and preferences

Consent or another lawful basis permitted by law

Sharing personal information

We share personal information only where reasonably necessary with service providers such as:

· Shopify and related ecommerce infrastructure providers;

· payment processors and fraud-prevention providers;

· warehousing, fulfilment and delivery providers;

· IT, hosting, analytics and customer-support providers;

· professional advisers, insurers, auditors and accountants; and

· public authorities, regulators or law-enforcement bodies where disclosure is required or permitted by law.

Service providers are expected to protect personal information and use it only for authorised purposes. Some third parties, such as payment providers, may also act as independent data controllers under their own privacy notices.

International transfers

Some technology or service providers may process information outside the United Kingdom. Where UK data protection law requires safeguards, we use an approved transfer mechanism, such as adequacy regulations or contractual safeguards, together with appropriate technical and organisational measures.

Retention

We retain personal information only for as long as needed for the purposes described in this policy, including customer service, dispute resolution and legal, accounting or tax obligations. Order and transaction records may normally be retained for at least six years where required for company and tax records. Marketing data is retained until consent is withdrawn or it is no longer needed, subject to a limited suppression record where necessary to respect an opt-out.

Customer rights

Depending on the circumstances, individuals may have the right to request access, correction, deletion, restriction, objection, data portability and withdrawal of consent. A request can be sent to the privacy contact. We may ask for proportionate information to verify identity before responding.

Individuals also have the right to complain to the UK Information Commissioner's Office. We encourage customers to contact us first so that we can try to resolve the concern.

Information Commissioner's Office: https://ico.org.uk/make-a-complaint/

Marketing

Marketing messages are sent only where permitted by law. Every marketing email will provide an unsubscribe method. Transactional messages about orders, delivery, security or policy changes are not marketing and may still be sent when necessary.

Cookies

The store uses cookies and similar technologies as explained in the Cookie Policy. Non-essential cookies should be used only after the required consent has been obtained through the store's cookie preference controls.

Security and children

We use reasonable administrative, technical and organisational measures to protect personal information. No internet transmission or storage system is completely secure. The store is not directed to children, and we do not knowingly collect personal information from children who cannot lawfully provide it.

Policy changes

We may update this policy to reflect changes in the store, service providers or legal requirements. The current version and effective date will be published on the website.