We collect the information we need to run the shop properly, fulfil your order and support you afterwards. We do not sell your personal data.
Who we are
Mabels Munchies is a UK-based online sweet shop selling pick n mix, imported sweets, traditional favourites and gift boxes. This privacy policy explains how we collect, use and protect personal information when you use our website or place an order with us.
What information we collect
Depending on how you use the site, we may collect:
- your name
- email address
- billing and delivery address
- phone number
- order details and purchase history
- account login details
- support messages, contact form submissions and event enquiries
- technical information such as IP address, browser type and device information
- cookie and session data needed for the site to function
How we collect your data
We collect personal information when you:
- place an order on our website
- create a customer account
- contact us through a form or support request
- subscribe to updates or marketing where offered
- browse the site with cookies enabled
How we use your data
We use personal data to:
- process and fulfil your order
- take payment securely
- arrange packing, shipping and delivery updates
- respond to customer support requests
- manage your account and order history
- detect fraud or misuse of the website
- improve how our website, checkout and service work
- send marketing messages where you have chosen to receive them
Our legal basis for using your data
Under UK data protection law, we need a reason to use your personal data. The main reasons we rely on are:
Contract
If you place an order, we need your information to take payment, dispatch the parcel, contact you about the order and provide aftercare.
Legitimate interests
We may use data where it is reasonably necessary to run and improve the business, such as keeping records, investigating order issues, preventing fraud, maintaining account security and reviewing how customers use the site.
Consent
Where we rely on consent, such as certain cookies or optional marketing, you can withdraw that consent later.
Who we share data with
We only share information where it is necessary to provide our service or meet our obligations. This may include:
- payment providers, including Stripe, so payments can be processed securely
- delivery partners, such as Royal Mail, Evri and InPost, so your order can be delivered
- service providers who help us operate the website, customer support or transactional emails
- professional advisers or authorities where required for legal, tax, fraud-prevention or regulatory reasons
We do not sell your personal information to third parties.
Payment information
Card payments are handled through Stripe or other secure payment tooling used by the website. We do not store raw card numbers or full payment card details on our own servers.
How long we keep your data
We keep information only for as long as we reasonably need it for the purposes described above. For example:
- order records may be kept for up to 6 years for accounting, tax and customer service reasons
- support requests may be kept for a reasonable period to help with follow-up issues
- unused customer accounts may be reviewed and removed after a prolonged period of inactivity
- marketing preferences are kept until you unsubscribe or ask us to remove them
How we store and protect data
We take reasonable technical and organisational steps to protect personal data. That includes secure account access, password hashing, controlled admin access, payment provider security, and limiting access to customer information to those who genuinely need it to do their job.
Even so, no system can ever be guaranteed to be completely risk-free, so we encourage customers to use strong passwords and contact us if they think their account has been accessed without permission.
Your rights
You have rights under UK data protection law, including the right to:
- request access to the personal data we hold about you
- ask us to correct inaccurate information
- request deletion of data where we no longer need to keep it
- object to certain uses of your data
- ask us to restrict how we use your information in some circumstances
- withdraw consent where consent was the basis for processing
Some rights are subject to legal exceptions, particularly where we need to keep records for accounting, fraud-prevention or order-related reasons.
Cookies and website tracking
We use cookies and similar tools to keep the website functioning properly, remember your session and understand how people use the store. For more detail, please see our Cookie Policy.
Children's privacy
Our website is aimed at general consumers and is not intentionally designed to collect personal data from children without appropriate involvement from a parent or guardian.
Contacting us about privacy
If you have a privacy question or would like to make a data request, please contact us through the website contact page and clearly mark your message as a privacy request. We will aim to respond within a reasonable time.
Updates to this policy
We may update this privacy policy from time to time if the website, our services or legal obligations change. The latest version published on the site will apply.