Privacy policy

Last updated: 1 April 2026

This policy explains what personal data BashFashion collects, how we use it, and what rights you have over it. We are committed to handling your information responsibly and in accordance with the UK GDPR and the Data Protection Act 2018.

What We Collect

When you place an order or create an account, we collect your name, email address, delivery address, phone number, and payment details. Payment information is processed securely and we do not store card data on our systems. We also collect your IP address, browsing behaviour on our site, and data from cookies and tracking technologies.

How We Use Your Data

We use your information to process and fulfil orders, send order confirmations and shipping updates, handle customer service enquiries, improve our website and product range, send marketing communications where you have given consent, and detect and prevent fraud.

Who We Share It With

Shopify — our store is built on Shopify's platform, which processes customer data to provide core commerce services including checkout, Shop Pay, and fraud prevention. View Shopify's Privacy Policy.

Analytics and advertising — we use Google Analytics to understand how visitors use our site, and Meta Pixel, TikTok Pixel, and Pinterest Pixel to measure and optimise our advertising. Each of these providers operates under its own privacy policy.

Payment processors — payments are handled securely via Shopify Payments and other authorised providers. We do not have access to your full card details.

International transfers — some of the above providers process data outside the UK. Where this occurs, appropriate safeguards are in place in accordance with UK GDPR requirements.

Cookies & Tracking

We use cookies to keep your shopping cart active, analyse site traffic, serve relevant advertising, and protect against fraud. You can manage cookie preferences through your browser settings.

Data Retention

We retain your data only for as long as necessary. Account information is held until you request deletion. Order records are kept for 7 years to meet tax and legal obligations. Marketing data is held until you unsubscribe. Analytics data is retained for 26 months.

Your Rights

Under UK GDPR, you have the right to access, correct, or delete your personal data, to object to or restrict how we process it, and to request a portable copy of your data. To exercise any of these rights, contact us at sales@bashfashion.co.uk.

Opt-Out Options

You can opt out of Shopify's data processing at privacy.shopify.com, disable Google Analytics tracking via the Google opt-out add-on, and unsubscribe from marketing emails using the link in any email we send. Meta and TikTok ad preferences can be managed within your respective account settings on those platforms.

Age Requirement

This site is intended for users aged 18 and over. If you are under 18, you must have the permission of a parent or guardian to make a purchase.

Changes to This Policy

We may update this policy from time to time. Where changes are material, we will notify you by email or via a notice on this site.

Contact

For privacy-related questions or to exercise your rights:
Email: sales@bashfashion.co.uk
Hours: Monday to Friday, 9:00 AM – 5:00 PM (London time)
Customer account: account.bashfashion.co.uk

Governing Law

This policy is governed by the laws of England and Wales and complies with the UK GDPR and Data Protection Act 2018.