Privacy Policy
Last updated:
1. Introduction
We respect your privacy and are committed to protecting your personal data. This notice describes what we collect, how we use it, who we share it with, and your choices.
2. Scope & who we are
This policy applies to websites, apps, and in‑store services operated by GMCosta. Registered office: [Address Line 1], [City], [Postcode], [Country]. If you interact with our social channels, their privacy practices also apply.
3. Personal data we collect
- Identifiers (e.g., name, email, phone, order ID).
- Order & payment details (processed via trusted payment providers).
- Device & usage data (e.g., IP address, browser type, pages viewed).
- Location data (approximate, from IP or if you share it for store directions).
- Preferences (e.g., newsletter opt‑ins, cookie choices).
- Communications you send to us (support requests, feedback).
We collect information directly from you, automatically via cookies and similar technologies, and from third parties (e.g., delivery partners or analytics providers) where permitted.
4. How we use your data
- Provide and improve our services and products.
- Process orders, payments, pickups, and deliveries.
- Respond to inquiries and provide customer support.
- Send service messages (e.g., order updates); with consent or where permitted, send marketing.
- Monitor performance, debug issues, and enhance security.
- Comply with legal obligations and enforce our terms.
5. Legal bases (where applicable)
Where laws like the EU/UK GDPR apply, we rely on one or more of the following legal bases: performance of a contract, legitimate interests, consent, legal obligation, or vital interests.
8. International transfers
If we transfer your data outside of [Jurisdiction/Region], we implement appropriate safeguards, such as standard contractual clauses or equivalent mechanisms, as required by applicable law.
9. Data retention
We keep personal data only as long as necessary for the purposes described here, to meet legal and accounting requirements, or to resolve disputes. Retention periods vary by data type and context.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, or port your data; object to or restrict certain processing; and withdraw consent where processing is based on consent.
EU/UK (GDPR)
- Access, rectification, erasure.
- Restriction, objection, portability.
- Right to withdraw consent.
- Lodge a complaint with your data protection authority.
California (CCPA/CPRA)
- Know, access, correct, delete personal information.
- Opt out of sale/share of personal information.
- Limit use/disclosure of sensitive personal information.
- No discrimination for exercising your rights.
To exercise rights, email privacy@gmcosta.co.uk or visit Do Not Sell or Share My Personal Information.
11. Security
We use technical and organizational measures to safeguard personal data. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
12. Children’s privacy
Our services are not directed to children under the age of 13. If you believe we have collected personal data from a child, please contact us so we can take appropriate action.
13. Changes to this notice
We may update this Privacy Policy from time to time. If we make material changes, we will post a notice on our website and update the "Last updated" date above.
14. Contact us
To ask questions or exercise your privacy rights, contact us at privacy@gmcosta.co.uk or write to: GMCosta, [Address Line 1], [City], [Postcode], [Country].