Privacy policy
We only use personal data to run the business you see in front of you: taking orders, delivering and fitting work, keeping accounts (including online customer accounts), answering enquiries (including live chat on this website), and staying in touch where the law allows or you have opted in. This policy describes that in plain language. If you have questions, we are happy to talk them through at enquiries@crestwoodcontract.com or on 01590 670370.
1. Who holds your information
For UK data protection law, the data controller is CRESTWOOD (SOUTHERN) LIMITED (company number 04189679; trading as Crestwood of Lymington), a company registered in England and Wales. We operate Crestwood Interiors (this website and online store) and the Crestwood of Lymington showroom.
We act as a credit broker, not the lender, and are authorised and regulated by the Financial Conduct Authority (FRN: 1037496). Credit is provided by third-party lenders; see section 5 for how finance data is handled.
You can write to us at 150 Wellworthy Road, Ampress Park, Lymington, Hampshire, SO41 8JY, United Kingdom, or use the email and telephone above for anything to do with this policy or your personal data.
2. What we collect
Depending on how we work together, we may hold:
- Contact and identity details: name, delivery and billing addresses, phone number, email.
- Order and project information: quotations, orders, payments, delivery notes, emails or notes that help us deliver your job.
- Online customer account information: if you register on this website, we store the details you provide (name, email, optional phone number, saved delivery addresses) and a record of your online orders. We do not store your password in readable form; it is handled securely by our authentication provider.
- Trade account information: business name, role, invoicing details, and occasionally references or credit information where we have agreed a trade facility. If we obtain credit information from a credit reference agency or a referee, we will tell you at the time and explain the source.
- Finance and credit information: if you apply for finance through us, we process the information you provide in the finance application and share relevant details with our lender partner for eligibility and credit assessment. Our initial eligibility check runs a soft search which does not impact your credit score; a hard search is carried out if you proceed with a full finance application. The lender makes its own underwriting decisions as an independent controller.
- Payment information: when you pay online, card and bank details are entered directly with our regulated payment service provider. We receive confirmation that payment succeeded and limited billing context (such as the last four digits of a card) for order records, but we do not store full card numbers or security codes.
- Project briefs: when you send a kitchen, bathroom, blinds or similar project brief, we collect the contact details and preferences you provide. You may also optionally share approximate room or window measurements and room photographs to help us prepare for a call or visit.
- Live chat: the Tidio chat widget on this website and the messages you send, plus any name, email, phone number, or other details you provide in the conversation. If you are signed in to an online account, we may also pass your name, email and phone to Tidio so the conversation can be handled. You do not need to re-type those details.
- Technical information: such as IP address, browser type, and pages viewed, when you use our website (including through cookies and similar browser storage; see section 6).
- CCTV: at our premises we may record images for the security of visitors, colleagues and stock, in line with notices on site.
We do not set out to collect sensitive categories of data (such as health information). If you voluntarily tell us about accessibility or health-related needs so we can help you (for example during a visit or installation), we use that information only for that purpose, treat it carefully, and rely on your explicit consent under UK GDPR Article 9(2)(a) where required.
What you must provide. To place an online order we need at least your name, delivery address, email and a way to pay (via our payment provider). Without these we cannot complete the contract. For finance applications, the lender requires additional information; if you do not provide it, we cannot submit an application on your behalf.
3. Why we use it
UK law requires a lawful basis for processing. The summary below maps what we do to the usual legal bases under UK GDPR Article 6. Where we rely on legitimate interests, we only do so when the processing is fair, necessary and proportionate, and we name that interest on the relevant item.
| Process orders, deliver goods, operate online accounts, respond to enquiries (including optional project-brief sizes and room photos) | |
| Introduce you to a finance lender and pass application details | |
| Keep finance and tax records | |
| Service messages (delivery updates, password resets, order confirmations) | |
| Security, fraud prevention, IT monitoring | |
| CCTV at our premises | |
| Marketing to existing retail customers about similar goods (soft opt-in) | |
| Promotional email or post where you have opted in | |
| Google Analytics 4 (only if you allow Analytics cookies) | |
| Google Ads purchase conversion measurement, including hashed order contact details (only if you allow Advertising cookies) | |
| Live chat on this website |
4. Marketing
We do not send promotional email or post unless you have signed up, or the law allows us to write to existing retail customers about similar goods and services (with a clear opt-out each time). Every marketing message includes a simple way to unsubscribe; you can also email us anytime to update your preferences.
7. How long we keep things
We keep information only as long as we need it for the purposes above, including legal and tax rules. Indicatively:
- Online customer accounts: while your account is active and for up to 24 months after closure (for example to resolve disputes or honour warranties), unless we must keep specific records longer.
- Orders and invoices: typically 6 years after the end of the relevant tax year (HMRC practice).
- Finance applications and related records: for as long as required by FCA rules and applicable law (often several years).
- Marketing preferences: until you opt out, and then on a suppression list as long as needed to honour your choice.
- Project brief photographs: optional room photos are kept for up to 14 days, then deleted automatically, unless we need to keep a copy in a live job or customer file after you proceed with work.
- Live chat: typically up to 12 months after the conversation for support records, unless we must keep specific records longer.
- Website analytics: for the period configured in Google Analytics (see section 6), if you have allowed Analytics.
- Website and security logs: typically up to 90 days, unless we are investigating a security issue.
- CCTV: typically up to 30 days, unless footage is needed for an incident investigation or legal claim.
8. Security
We take the security of personal data seriously and use technical and organisational measures appropriate to an online retailer, including:
- Encrypted connections: our website and online services are served over HTTPS so data in transit is protected.
- Password protection: online account passwords are never stored in plain text. They are handled securely by our authentication provider.
- Payment separation: card details are collected by our payment service provider; we do not store full card numbers or card security codes on our own systems.
- Access controls: limited staff access on a need-to-know basis, and separation between customer-facing systems and internal administration.
- Monitoring and hardening: security headers, sensible configuration, and ongoing review of how our online services are run.
No internet transmission or storage system is perfectly secure. If you have an online account, please use a strong unique password, keep it confidential, sign out on shared devices, and tell us promptly if you think your account may have been compromised.
If we become aware of a personal data breach that is likely to pose a risk to your rights, we will notify the Information Commissioner’s Office within 72 hours where required and contact affected individuals when the law says we should.
9. Your rights
Under UK data protection law you may have the right to ask for a copy of your data, to correct mistakes, to delete data in certain cases, to restrict processing, to move data you provided (where processing is automated and based on contract or consent), and to withdraw consent where we rely on it.
Right to object. You have the right to object at any time to processing based on our legitimate interests (for example security, CCTV, or soft opt-in marketing to existing customers about similar goods). We will stop unless we have compelling grounds or the law allows us to continue. If we process your data for direct marketing, you can object at any time and we will stop that marketing.
We aim to respond to rights requests without undue delay and within one month (UK GDPR Article 12(3)). If a request is complex, we may extend by a further two months and will tell you why.
For online accounts, you can update many details yourself when signed in (name, phone, saved addresses). To request a copy of your data, account closure, or anything you cannot change online, please use the contact details in section 1. We may need to confirm your identity first; that protects you as well as us.
Data protection complaints. You can make a complaint directly to us as the controller under Data Protection Act 2018 section 164A by email or using our online contact form. We will acknowledge receipt within 30 days and respond without undue delay, including informing you of the outcome. If you remain unhappy, you may complain to the Information Commissioner’s Office (ico.org.uk). Our complaints policy explains this route alongside our other complaint procedures.
10. Children
Our services are aimed at adults. For online services, UK law treats 13 as the age from which a child may consent to information-society services in many cases; we do not knowingly collect personal data from children under 13 without appropriate parental involvement. If you believe a child has given us personal data, please contact us.
11. Automated decisions
We do not make decisions about you using solely automated processing that would have serious legal or similarly significant effects on you. Our live chat may use an automated reply assistant to help answer common questions; that is not a decision with legal or similar significance. Finance underwriting decisions are made by the lender, not by us.
12. Changes
If we change how we handle data (for example if we add new non-essential cookies or change finance processing), we will update this page and the date at the top. For important changes we will give notice on the website or by email where appropriate.
