DUE TO A TEMPORARY SUPPLY ISSUE, ALL DELUXE BRIDLES WILL BE FITTED WITH PLAIN RING BITS RATHER THAN FULMER BITS. SORRY FOR ANY Inconvenience. 

The Rocking Horse Shop

Designers, Makers & Restorers of Beautiful Rocking Horses Since 1976

Privacy and Cookies Policy

 

CUSTOMER PRIVACY POLICY

'The Rocking Horse Shop Ltd.' is a company registered (No.3733336) in England and Wales (collectively referred to as "The Rocking Horse Shop Ltd.", “TRHS”, "we" or "us" in this policy).

 

OVERVIEW

Maintaining the security of your data is a priority at TRHS, and we are committed to respecting your privacy rights. We pledge to handle your data fairly and legally at all times. TRHS is also dedicated to being transparent about what data we collect about you and how we use it.

This policy, which applies whether you visit our store(s), use your mobile device or go on line, provides you with information about:

  • how we use your data;
  • what personal data we collect;
  • how we ensure your privacy is maintained; and
  • your legal rights relating to your personal data

WHY THIS POLICY EXISISTS

This data protection policy ensures The Rocking Horse Shop

  • Complies with data protection law and follow good practice
  • Protects the rights of staff, students and partners
  • Is open about how it stores and processes individuals’ data
  • Protects itself from the risks of a data breach

This policy helps to protect The Rocking Horse Shop from some very real data security risks, including:

  • Breaches of confidentiality. For instance, information being given out inappropriately.
  • Failing to offer choice. For instance, all individuals should be free to choose how the society uses data relating to them.
  • Reputational damage. For instance, the society could suffer if hackers successfully gained access to sensitive data.

HOW WE USE YOUR DATA

General

TRHS uses your personal data:

  • to provide goods and services to you;
  • to make a tailored website available to you;
  • to manage any registered account(s) that you hold with us
  • to verify your identity;
  • for crime and fraud prevention, detection and related purposes;
  • with your agreement, to contact you electronically about promotional offers and products and services which we think may interest you;
  • for market research purposes – for us to be able to understand your needs better;
  • to enable TRHS to manage customer service interactions with you; and
  • where we have a legal right or duty to use or disclose your information (for example in relation to an investigation by a public authority or in a legal dispute).

 

Marketing

Promotional communications

TRHS uses your personal data for electronic marketing purposes (with your consent) and may send you postal mail to update you on the latest TRHS offers.

TRHS aims to update you with regards to information about products & services that are of interest and relevance to you as an individual.

You have the right to opt out of receiving promotional communications at any time.

Sharing data with third parties

Our service providers and suppliers

In order to deliver your order we need to share your personal data with our delivery service providers.

TRHS only allows its service providers to handle your personal data when we have confirmed that they apply appropriate data protection and security controls. We also impose contractual obligations on service providers relating to data protection and security, which mean that they can only use your data to provide services to TRHS and to you, and for no other purposes.

Other third parties

Aside from our service providers, TRHS will not disclose your personal data to any third party, except as set out below. We will never sell or rent our customer data to other organisations for marketing purposes.

We may share your data with:

  • credit reference agencies where it is necessary for card payments;
  • governmental bodies, regulators, law enforcement agencies, courts/tribunals and insurers where we are required to do so: -
  • to comply with our legal obligations;
  • to exercise our legal rights (for example in the event of court cases);
  • for the prevention, detection, investigation of a crime or the prosecution of offenders; and
  • for the protection of our employees and customers.

International transfers

To deliver products and services to you, it is sometimes necessary for TRHS to share your data outside of the European Economic Area.

This will typically occur when service providers are located outside the EEA or if you are based outside the EEA. These transfers are subject to specific rules under data protection laws.

If this happens, we will ensure that the transfer will be compliant with data protection law and all personal data will be secure. Our standard practice is to use ‘standard data protection clauses’ which have been approved by the European Commission for such transfers.

How long do we keep your data?

We will not retain your data for longer than necessary for the purposes set out in this Policy. Different retention periods apply for different types of data, however the longest we will normally hold any personal data is 7 years.


WHAT PERSONAL DATA DO WE COLLECT?

TRHS may collect the following information about you:

  • your name;
  • your contact details: postal address including billing and delivery addresses, telephone numbers (including mobile numbers) and e-mail address;
  • previous and existing purchases and orders made by you;
  • your on-line browsing activities on TRHS websites;
  • your password;
  • your payment card details, when you make a purchase or place an order with us;
  • your communication and marketing preferences;
  • your location;
  • your correspondence and communications with TRHS;

HOW WE PROTECT YOUR DATA

Our controls

TRHS is committed to keeping your personal data safe and secure. Our security measures include:

  • encryption of data;
  • data is controlled at all time, a copy of our data flow map is available upon request.
  • regular cyber security assessments of all service providers who may handle your personal data;
  • security controls which protect the entire TRHS IT infrastructure from external attack and unauthorised access; and
  • internal policies setting out our data security approach and training for employees.

 

General Staff Guidelines

  • The only people able to access data covered by this policy should be those who need it for their work.
  • Data should not be shared informally. When access to confidential information is required, employees can request it from their line managers.
  • The Rocking Horse Shop will provide training as required to all employees to help them understand their responsibilities when handling data.
  • Employees should keep all data secure, by taking sensible precautions and following the guidelines below.
  • In particular, strong passwords must be used and they should never be shared.
  • Personal data should not be disclosed to unauthorised people, either within the society or externally.
  • Data should be regularly reviewed and updated if it is found to be out of date. If no longer required, it should be deleted and disposed of.
  • Employees should request help from their line manager or the data protection officer if they are unsure about any aspect of data protection.
  • Ensuring that the same guidelines apply when working from home as required by the Society

WHAT YOU CAN DO TO HELP PROTECT YOUR DATA

TRHS will never ask you to confirm any bank account or credit card details via email. If you receive an email claiming to be from TRHS asking you to do so, please ignore it, do not respond and contact us immediately.

If you are using a computing device in a public location, we recommend that you always log out and close the website browser when you complete an online session.

In addition, we recommend that you take the following security measures to enhance your online safety both in relation to TRHS and more generally: -

  • keep your account passwords private. Remember, anybody who knows your password may access your account.
  • when creating a password, use at least 8 characters. A combination of letters and numbers is best. Do not use dictionary words, your name, email address, or  other personal data that can be easily obtained. We also recommend that you frequently change your password.
  • avoid using the same password for multiple online accounts.

YOUR RIGHTS

You have the following rights:

  • the right to ask what personal data that we hold about you at any time,
  • the right to ask us to update and correct any out-of-date or incorrect personal data that we hold about you free of charge;
  • (as set out above) the right to opt out of any marketing communications that we may send you. If you wish to exercise any of the above rights, please contact us using the contact details set out below.

Legal basis for TRHS processing customer personal data General

TRHS collects and uses customers’ personal data because is it necessary for:

  • the pursuit of our legitimate interests (as set out below);
  • the purposes of complying with our duties and exercising our rights under a contract for the sale of goods to a customer; or
  • complying with our legal obligations.

In general, we only rely on consent as a legal basis for processing in relation to sending direct marketing communications to customers via email or text message.

Customers have the right to withdraw consent at any time. Where consent is the only legal basis for processing, we will cease to process data after consent is withdrawn.


COOKIES POLICY

What are cookies?

Like most websites, TRHS websites use cookies to collect information.  Cookies are small data files which are placed on your computer or other devices (such as smart ‘phones or ‘tablets’) as you browse this website. They are used to ‘remember’ when your computer or device accesses our websites. Cookies are essential for the effective operation of our websites and to help you shop safety with us online. They are also used to tailor the products and services offered and advertised to you, both on our websites and elsewhere.


CONTACT INFORMATION

If you have any questions about how TRHS uses your personal data that are not answered here, or if you want to exercise your rights regarding your personal data, please contact us by any of the following means:

  • phone us on: 01759 368737
     
  • e-mail us at: info@rockinghorse.co.uk
  • write to us at The Rocking Horse Shop Ltd, Manor House Farm, Fangfoss, York, YO41 5JH

 

UPDATES

This policy was last updated in September 2024.