Skip to content

The small print, in plain words

Privacy notice

What we collect when you buy from us or read this website, why, who else sees it, how long it is kept, and what you can ask us to do about it.

Version
2.4
First published
Last changed
Next review

Flower & Glory is the florist studio at 12 Blacks Yard, Blighs Meadow, Sevenoaks, Kent TN13 1DS, and is responsible for the personal data described here (the “data controller”, in the law’s words). Write to us about anything on this page at enquiries@flowerandglory.co.uk, or call the shop on 01732 743419. Registration with the Information Commissioner's Office is being confirmed.

What we collect, and why

Almost all of it is what you type in yourself. Nothing here is bought from anybody, and nothing here is sold to anybody.

  • When you order — your name, email address, phone number, the name and address of the person the flowers go to (and their phone number, if you give it, so the driver can reach them), the day you want them, what you bought and the words you asked us to write on the card. We need these to make and deliver the order; the lawful basis is performing our contract with you.
  • The photograph of your flowers — before your flowers leave the studio we photograph them, and we email that photograph to you and keep it with the order (in your account, if you have one). It is kept for as long as the order’s other details, so that a question about how they looked when they left can be answered, and a member of the team may look at it to check our work. It can show the card with your words on it, so it goes when those details go, or when you ask us to erase your record.
  • When you pay — we never see or hold your card number. Online, the payment is taken by Stripe: the card field on our checkout page is Stripe’s own, loaded from them, and what you type into it goes to them, not to us. In the shop, it is taken by the card machine, which tells us only the last four digits and the authorisation code so a refund can be found later.
  • When you make an account — your email address and a password, which is stored only as a one-way hash: nobody here can read it, and neither could anybody who stole the database. Anything else on your account is there because you put it there: your address, your birthday, the people you send flowers to, the dates you want reminding of, and what you like and would rather avoid.
  • When you get in touch — your name, email, phone number if you give one, and what you wrote, whether through the contact form, a subscription or letterbox enquiry, or a course booking. We keep it so we can answer, and so the next person who picks it up knows what was said.
  • If you tick the box — your email address is used to tell you what is in season and what the studio is doing. Only if you tick it, and you can untick it on your account or from any message we send. We record when you said yes or no, and where, because the law asks us to be able to show it.
  • If you ask for texts — your mobile number is used to tell you the flowers are on the van, ready to collect, or delivered, and for nothing else. Only if you ask, and STOP in reply switches it off. We never market by text.
  • If you join The Bunch or set a date to send itself — the stems you earn and spend, your tier, your referral code, and the people and dates you asked us to remember; where you ask for a card to be kept for a standing order, it is kept by Stripe, never by us, and we hold only a reference to it.
  • When you read this website — which pages you looked at, in what order, how long each was in front of you and how far down you got; the size of your window, the kind of browser and operating system, the region and town our host reports (and the town’s position on a map, to the nearest ten kilometres or so), where you arrived from and any campaign tag on the link. It tells us which pages are worth writing and which ones lose people.

Why we are allowed to

The law asks us to say which of its reasons covers each thing we do with your data. Here they are, in the law’s own categories:

  • Performing our contract with you — making and delivering an order, running a subscription or a standing order, taking a payment or issuing a refund, answering an enquiry about an order, running your account.
  • A legal obligation — keeping the invoices and the books for the years tax law requires, and being able to show that you agreed to hear from us.
  • Our legitimate interests — counting visitors without identifying them, keeping the site and the shop secure, preventing fraud, and reminding a customer of an occasion they told us about. We have weighed each of these against your interests and none of them overrides them; you can object to any of them below.
  • Your consent — marketing emails, texts, being measured across visits, the recording of how you use the site, and a business-visitor lookup. Consent can be withdrawn as easily as it was given, and withdrawing it does not affect anything done before.

How the website counts visitors

What is described here is our own measurement, written by us and run on our own servers. The advertising networks' tags (Google) are separate: they load only if you say yes to advertising, as "Who else sees it" describes.

Two layers, and the banner decides which one you are in. Whether or not you answer it, one thing happens on every page: we record which page it was, which link brought you, and the part of the country or the country the address is in (one of the UK’s twelve regions at the finest, never a town), against a short code made by folding together your address, your browser, the date and a secret only we hold. That code cannot be turned back into you, it changes at midnight, and nothing whatever is written to your device to produce it. It is how we know that four hundred people read the wedding page last month, and that most of them were in the South East, and it identifies none of them.

If you say yes, we also keep the order you moved through the pages, how long each was in front of you, how far down you read, the size of your window, the town our host reports and which advert or link brought you, and we put a random id in a cookie (fg_v) so that a second visit is recognised as the same one rather than as a stranger. That is the difference between “four hundred visits” and “two hundred people, half of whom came back”. Your address is never stored in a form anybody can read.

If you tell us who you are (by signing in, making an account, going to pay, sending an enquiry or booking a course), the visits made from that browser are attached to your customer record, so the studio can see what you were reading before you got in touch. This only ever happens for someone who agreed to the paragraph above, and only from something you did yourself. We do not match people by address, we do not buy data about you, and we do not guess that two visitors are the same person because they look alike.

Nothing under the shop’s admin, your account pages or our own interfaces is counted, whatever you have agreed to. Campaign tags on a link (the utm_ ones) are held in your browser’s tab and are gone when you close it.

Watching how the site is used, if you say yes

The site can ask whether it may record how you move through it. It is switched off at the moment, so it is not asking anybody. If you say yes, we keep where you clicked, how far you scrolled, roughly where the pointer went and which pages you moved between. We do not record anything typed into a field, whether a search box, a card message or a password. There is no video and no copy of the page; the replay we watch is a schematic of boxes and dots. Your answer is kept in the fg_c cookie in your own browser, and the footer of every page offers to change it. Recordings are deleted after 30 days.

What is stored on your device

This is the complete list. Everything in the second group is there because you said yes, and goes when you say no.

  • Always, because the site cannot work otherwise — fg_customer keeps you signed in to your account for thirty days; fg_admin and fg_finance do the same for the studio’s own staff; your basket lives in your browser until you check out. And fg_c keeps the answer you gave the banner, for 365 days. A cookie that records a refusal is the one cookie we may set without asking, because otherwise the refusal could not be remembered and the banner would come back for ever.
  • Only if you agree to be measured — fg_v is a random id, kept for 365 days, so a return visit is recognised as the same one. It is ours alone: it means nothing to any other website and is never sent to one. Alongside it, a per-tab id and any campaign tag live in storage that empties when you close the tab.
  • Only if you say yes to advertising — the cookies of Google, which those networks set themselves and which the cookies page lists by name. Say no and none of them is loaded. Beyond those: no cross-site identifier of ours, no tag manager, no fingerprinting, and no “partner” you have never heard of.

You can change any of it whenever you like, from Change what you allow at the foot of every page. Saying no later removes the id and cuts the thread between your visits; it does not un-count the visits you already made, which were counted the way the first group above describes and carry nothing that says who you are.

Who else sees it

A short list, and each one is here because it does a job for us. Every one of them is bound to use the data only for that job.

  • Stripe — takes payments made on the website and issues refunds. They see your name, email and the amount; the card details go to them and never to us. Their card field is loaded from them on our checkout page and nowhere else on the site, and sets their own fraud-prevention cookies there. A card you choose to save for next time is kept by Stripe; we hold only a reference to it.
  • Dojo — runs the card machines in the shop.
  • Resend — sends the emails: your order confirmation, an invoice, a photograph of your bouquet, the answer to an enquiry. It reports back whether a message bounced or was opened.
  • Twilio — sends the texts, only to somebody who asked for them, and receives a STOP.
  • DPD — carries anything we send that is not a fresh bunch on our own van: letterbox flowers, the everlasting stems and the Home & Glory pieces. For each parcel they are given the name and address it is going to, a phone number and an email, the order number and what the parcel weighs, so they can deliver it and tell the person it is on its way. They send those delivery messages themselves, as their own privacy notice describes.
  • Spotify — plays the record a bunch is named after, and only once you press the speaker on that product page. Until you press it, nothing of Spotify’s is fetched at all: the song’s title and artist on the page are our own words, and no Spotify script, frame or cookie is loaded. Press it and their player loads, which means Spotify sees the request and may set their own cookies, as their privacy notice describes. Nothing about you is sent to them by us, and nothing is remembered on our side about which songs you played.
  • Vercel and Neon — host the website and its database, and store the documents and photographs attached to an order. The database and the code that answers a page run in London; Vercel’s network delivers the static parts of the site from wherever you are.
  • Xero — is the studio’s accounting system. Invoices and the contact they are addressed to go there, because an accountant has to be able to see what was sold to whom.
  • postcodes.io — is asked which town a postcode is in when you check whether we deliver to you. It is sent the postcode and nothing else.
  • Photoroom — is sent a product photograph taken in the studio’s lightbox, to cut the flowers out of it: a photograph of flowers, taken with nobody in shot. Never the photograph of your order, and nothing of the camera’s: the picture goes without its location, the phone’s name or the time it was taken.
  • OpenAI — is sent a product photograph taken in the studio’s lightbox, with the flowers already cut out, to draw the room and the light around them: a photograph of flowers, taken with nobody in shot. Never the photograph of your order, and nothing of the camera’s. A photograph Photoroom finds a person in is never sent to it. The flowers you see on a product page are always the real ones: what it draws of them is thrown away.
  • Google Ads and Microsoft Advertising — are told about a sale only when the visitor came from one of the studio’s adverts and agreed to be measured: the advert’s own click id, the date and the amount are uploaded by the studio as a file, so the network learns which click became a sale. No name, address or basket is sent that way.
  • Google — run their advertising tags on this website, and only for a visitor who said yes to “Advertising and social media” on the banner. With that yes they are told which pages you visit, which products you look at, what goes in your basket and whether you buy (the product, the price and the order number), and they set their own cookies to recognise your browser. When you buy, the email address you gave is sent to them as a scrambled code (a SHA-256 hash, which cannot be read back into the address) so they can match the sale to an advert you clicked. Each uses what it learns under its own privacy notice, which may include connecting it with an account you hold with them. Say no, or change your answer later, and none of this happens.
  • Google, Bing and the map — know about our own listing and how our pages rank, not about you. The one time your data touches a map is the address a driver opens on their own phone to find your door, and the delivery postcodes the van visits that day being put in order.
  • The weather — is read for the shop’s own postcode from Open-Meteo, so the bench knows a frost is coming. Nothing about you is involved.

Where it goes

Our own records stay in the United Kingdom. Some of the companies above are based, or keep copies, in the United States or elsewhere outside the UK, among them Stripe, Resend, Twilio, Vercel, Photoroom and OpenAI. Where your data leaves the UK it goes under the protections UK data protection law provides for a transfer: to a country the UK has found adequate, or under the International Data Transfer Agreement or the UK addendum to the EU’s standard contractual clauses, which each of those companies offers as part of its terms. Ask us and we will tell you which applies to which.

The website's pages are served from London (Vercel) and its database is in London too (Neon). Some of the companies listed above are based outside the UK; where they are, the transfer is made under the safeguards UK data protection law provides for.

How long we keep it

  • Orders: 7 years — at least, with who it was for and from. We do not yet take your details off old orders automatically after that; ask and we will, keeping only what the books need.
  • Invoices and the books: 6 years — HMRC requires it, so this is the one thing we cannot shorten and cannot delete on request. It is the figures and the document, not you.
  • Session recordings: 30 days — deleted automatically, whether or not anybody watched them.
  • What you allowed: 365 days — the answer itself, and a record of when you gave it and from where. The law asks us to be able to show that you agreed, which we cannot do without keeping the fact that you did. After that we ask again.
  • Visitor addresses: 30 days — and only in the one mode where they are kept at all, described above. Otherwise there is nothing to delete because nothing readable was ever stored.
  • Your account: while you have one — close it whenever you like; see below.

What you can ask us to do

These are your rights under UK data protection law, and none of them costs anything. Where the website can do it for you, it does.

  • See it, and take it with you — Your account has a Download everything button that gives you the lot as one machine-readable file, at once. If you would rather ask a person, write to us and we will answer within a month.
  • Correct it — your details are yours to edit on your account. Anything you cannot reach, we will change if you tell us.
  • Be forgotten — ask on your account, or write to us. We remove your name, contact details, addresses and preferences. Your past orders stay as trading history with nothing on them that says who you were, and the invoices behind them are kept for 6 years because the law requires it. We will tell you when it is done.
  • Stop the marketing — untick the box on your account or use the link in any message. It takes effect at once and needs no reason. A newsletter sign-up keeps, as its evidence, the address it was made from, the browser, the page and the moment you said yes; unsubscribing clears the address and the browser.
  • Change your mind about any of it — Change what you allow at the foot of every page. It takes effect at once: the id is deleted, the thread between your visits is cut, and nothing further is recorded.
  • Object, or ask us to restrict what we do — tell us what you object to and we will stop while we look at it.
  • Take it somewhere else — the Download everything file is machine-readable, which is what the right to portability asks for.

We aim to answer any of these within a month. If a request is complicated we may take up to two months more, and we will tell you within the first month if so. We may ask you to prove who you are first, because the worst thing we could do with your data is give it to somebody pretending to be you.

Decisions made by software

Nothing here makes a decision about you with a legal or similarly serious effect without a person. Two things are worked out automatically: your tier in The Bunch is worked out from the stems you have earned in the last twelve months, and only changes what you are offered; and Stripe runs its own fraud checks on a card payment, which may decline one. That is their decision, made under their own notice, and a declined payment can always be tried another way with us.

Children

This website is not written for children and we do not knowingly collect a child’s data. In the UK a child under thirteen cannot themselves consent to an online service; if you believe a child has given us their details, tell us and we will remove them.

How it is kept safe

The site is served over an encrypted connection; passwords are stored only as one-way hashes; the studio’s own screens need a sign-in and, for anything financial, a second code or a passkey; every file the shop keeps is private and read back through a door that checks who is asking; and every change to an order or a customer record is written to a tamper-evident log. If we ever learn of a breach that is likely to put you at risk we will tell you, and the regulator, without undue delay; the law gives us seventy-two hours for the regulator.

If we get it wrong

Tell us first, at enquiries@flowerandglory.co.uk, and we will put it right. If you are still unhappy you can complain to the Information Commissioner’s Office, the UK’s data protection regulator, at ico.org.uk, or on 0303 123 1113. You do not have to come to us first, but we would rather you did. When you complain to us about how we have handled your data we will acknowledge it within thirty days and tell you what we have done about it without undue delay. That is now a duty on us in law, and it is what we would do anyway.

Last read through: 10 September 2026. This notice describes the website and the shop as they work today; when the software changes, this changes with it, and the history below says when.

History of this document

Every version, with the day it took effect (and, where we published a change, the minute). The version in force is the one on this page.

  1. Version 2.4The photo studio's services named among the processors while the studio uses them: Photoroom and fal, which cut a bouquet out of its photograph, and OpenAI, which draws the room around it. Each is sent a product photograph and nothing else, with nothing of the camera's left in it.
  2. Version 2.3Read against the site as it runs: the advertising networks' cookies are named while a network is on, the banner's answer is the fg_c cookie, the pages and the database run in London, a Bunch tier comes from the stems earned, and orders are kept at least the window, with details taken off automatically only once the studio switches that on.
  3. Version 2.2DPD, the courier for everything that is not a fresh bunch on our van, named among the processors, with what each parcel's booking tells them.
  4. Version 2.1The checkout does not offer a marketing box. Stripe's "email me with news and offers" is offered only to US businesses, so it never appeared for this shop; the paragraph that described it is removed.
  5. Version 2.0Moved to /legal/privacy. Reviewed against the UK GDPR notice checklist: the lawful basis for each purpose, every processor and where it sits, children, automated decisions, the complaints route and the dated history on this page.
  6. Version 1.1The two-layer consent model: what is counted for everybody and what only after a yes.
  7. Version 1.0First published, written from the code that collects the data.

This document is written by the studio in plain words and is not legal advice. Questions about it go to the shop: get in touch.