Privacy policy
Last Updated: August 21, 2025
This Privacy Policy describes how Mini Cuddles ("we", "our", "us") collects, uses, and discloses your personal information when you visit or make a purchase from our website b2b.minicuddles.uk (the “Site”), or otherwise interact with our services (collectively, the “Services”). Mini Cuddles is owned and operated by FIRST STEPS BABYWEAR UK LTD, a company registered in the United Kingdom.
We use Shopify Inc. to host our e-commerce platform and process transactions. This Privacy Policy outlines how both we and Shopify handle your personal data.
Personal Information We Collect
We collect various categories of personal information including, but not limited to:
- Contact Details: Name, address, phone number, email
- Order & Transaction Details: Products purchased, order value, payment method, shipping info
- Payment Information: Card details or payment platform info (handled securely via Shopify)
- Account Info: Login credentials, saved preferences
- Device and Usage Info: IP address, browser type, cookies, session data
- Customer Support Communications: Any messages or inquiries you send us
How We Collect Personal Information
We collect data:
- Directly from you (e.g. order placement, form submission)
- Automatically through the Site (e.g. cookies, analytics)
- From third-party service providers (e.g. payment processors, advertising platforms)
Our Lawful Basis for Processing Your Information
We process your personal information only when we have a valid lawful basis to do so under the UK General Data Protection Regulation (UK GDPR). The purposes for which we process your data and the lawful basis we rely on for each are detailed below:
For Order Processing and Fulfilment: Contract
When you make a purchase from our site, we process your personal information (including your name, address, and payment details) because it's necessary for the performance of a contract we have with you. Without this data, we cannot process your payment, ship your order, or fulfil our obligations to you as a customer.
For Marketing and Personalisation: Consent
We will only send you marketing communications, such as newsletters or promotional emails, if you have given us your explicit consent to do so. You can withdraw your consent at any time by clicking the "unsubscribe" link in any marketing email or by contacting us directly.
For Business Operations and Fraud Prevention: Legitimate Interests
We may process your personal information for our legitimate interests as a business, provided that your fundamental rights and freedoms do not override those interests. Our legitimate interests include:
- Detecting and preventing fraud and security threats: We process certain data (like IP addresses and browsing behaviour) to protect our business and customers from fraudulent activity. This is necessary to maintain a safe and secure online environment.
- Improving our products and services: We use data about how you use our site to understand customer preferences and enhance our website functionality and product offerings.
- Internal operational purposes: We process data for activities such as accounting, record-keeping, and general business management.
For Compliance with Legal Obligations: Legal Obligation
In some cases, we are legally required to process your personal data to comply with our statutory obligations. For example, we must retain certain transactional data for tax and financial auditing purposes as required by UK law.
How We Use Your Information
We use your data to:
- Provide and personalise the Services
- Process and fulfil orders
- Communicate with you (order confirmations, support, updates)
- Send marketing (if you’ve opted in)
- Detect and prevent fraud or security threats
- Comply with legal obligations (e.g. tax, consumer rights)
How We Share Your Information
We may share your information with:
- Shopify – for e-commerce hosting and order processing
- Payment Gateways – for secure transactions
- Delivery Partners – for shipping your orders
- Marketing Partners – for campaigns if consented
- Legal Authorities – if required under law
- Corporate Affiliates – for internal operational purposes
We do not sell your data.
Cookies & Tracking Technologies
We use cookies and similar technologies for functionality, analytics, and marketing purposes. You may manage your cookie preferences through your browser settings.
Your Rights (UK & GDPR)
You may have the right to:
- Access the personal data we hold about you
- Rectify incorrect or incomplete data
- Erase your data (right to be forgotten)
- Restrict or object to data processing
- Withdraw consent at any time (e.g. unsubscribe from emails)
- Request data portability, where applicable
To exercise these rights, email us at: info@minicuddles.co.uk. We may ask for verification before fulfilling your request.
Data Retention
We retain personal data only as long as needed to fulfil the purposes above, including legal, tax, and compliance obligations.
Children’s Privacy
We do not knowingly collect personal data from children under the age of 16. If you are a parent or guardian and believe your child has provided us information, please contact us.
International Transfers
Your data may be processed outside the UK, including by Shopify in Canada and the US. When we transfer data internationally, we ensure appropriate safeguards under UK GDPR (e.g. standard contractual clauses).
Security
We implement appropriate technical and organisational measures to protect your personal data. However, no system is fully secure. Please do not share your login credentials.
Shopify as Processor & Independent Controller
Shopify helps operate our Site and may process your data as an independent controller.
Shopify as a Processor
For the vast majority of activities, Shopify acts as a Data Processor for Mini Cuddles. When a customer places an order, Shopify stores and processes that customer's name, address, and order history on behalf of Mini Cuddles to run the online store. Shopify is acting on Mini Cuddles' instructions as the platform provider.
Shopify as an Independent Controller
Shopify also acts as an "independent controller." This is because Shopify has its own business interests and purposes for processing the data that goes through its platform, which are distinct from Mini Cuddles'. For example:
- For Analytics and Risk Detection: Shopify uses data from across all its stores to monitor traffic, detect fraudulent transactions, and analyse trends. It does this to improve its own platform and services, not just on behalf of Mini Cuddles.
- For Its Own Business Operations: Shopify processes data to manage its billing relationships with merchants, to provide customer support, and to comply with its own legal obligations.
For more about Shopify’s data handling, refer to Shopify's Privacy Policy.
Third-Party Links
Our Site may contain links to third-party sites. This Privacy Policy does not apply to them. We recommend reviewing their privacy notices before engaging with those sites.
Updates to This Policy
We may update this Privacy Policy periodically. Any changes will be posted on this page with the updated “Last Updated” date. Continued use of our Services indicates acceptance of the updated policy.
Should you have any Enquiries / Issues / Complaints
If you have questions, concerns, or complaints regarding your personal data or this Privacy Policy, contact us: Email: care@minicuddles.uk By post: First Steps Babywear UK LTD, Lewis Building, Bull Street, Birmingham, United Kingdom B4 6EQ