Legal
Privacy Policy
Your privacy matters. This policy explains what we collect, why, who we share it with, and the rights you have.
Last updated: 22 June 2026
1. Data controller
The data controller is JAMES PATERSON & SONS (PLUMBING & HEATING) LIMITED, registered in Scotland (SC104349), Fire Station, Glebe Street, Denny, Scotland, FK6 6AA. For any privacy matter, contact privacy@jpatersonsons.shop.
2. What we collect
- Identity & contact details: name, email, shipping address, phone.
- Order information: items purchased, order value, history.
- Technical data: IP address, device and browser information, cookie identifiers.
- Communications: messages you send us via forms or email.
We do not collect or store your full payment card number. Card details are entered directly with our payment processor, Stripe.
3. Why we use your data and our legal basis
- To fulfil your order (performance of a contract): processing, shipping, support.
- Legitimate interests: fraud prevention, securing and improving our store.
- Consent: optional marketing emails and non-essential cookies.
- Legal obligation: keeping tax and transaction records.
4. Processors we share data with
We share data only with service providers who process it on our behalf:
- Stripe — payment processing.
- PayPal — payment processing, where offered.
- Supabase — database, authentication and storage.
- Resend — transactional and (with consent) marketing email.
- Shipping carriers — to deliver your order.
- Analytics — only with your consent, to understand site usage.
5. International transfers
Some processors are located outside the UK/EU (for example, in the United States). Where data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses.
6. How long we keep data
We keep order and transaction records for as long as required by law (typically six years for tax purposes). Marketing data is kept until you withdraw consent. Other data is kept only as long as needed for the purpose it was collected.
7. Your rights (GDPR)
If you are in the UK or EU, you have the right to:
- access a copy of your data;
- correct inaccurate data;
- erase your data (“right to be forgotten”);
- restrict or object to processing;
- data portability;
- withdraw consent at any time.
To exercise any right, email privacy@jpatersonsons.shop. We respond within 30 days. You may also complain to the UK Information Commissioner's Office (ICO).
8. Your rights (CCPA — California residents)
California residents have the right to know what personal information we collect, to request deletion, to opt out of the “sale” or “sharing” of personal information, and not to be discriminated against for exercising these rights. We do not sell your personal information for money. To opt out of any sharing for advertising purposes, use our Do Not Sell or Share My Personal Information page.
9. Cookies
We use essential cookies to operate the store and, with your consent, optional analytics cookies. See our Cookie Policy and manage your choice via the cookie banner.
10. Security
We use industry-standard measures to protect your data, including HTTPS across the site and PCI-DSS-compliant payment handling via Stripe.
11. Changes
We may update this policy from time to time. The “last updated” date above shows the latest version.
12. Contact
Privacy enquiries: privacy@jpatersonsons.shop. General enquiries: support@jpatersonsons.shop · +44 7936 134078.