GDPR Compliant Β· UK & EU Law Β· Effective January 2025

Privacy Policy

Filmswear collects only what we need, uses it only as stated, protects it with industry-standard security, and never sells it β€” to anyone, ever. Your data belongs to you.

πŸ”’ GDPR Compliant
🚫 Data Never Sold
βœ… 8 Legal Rights
πŸ“… January 2025
⚑ Policy at a Glance
Effective DateJanuary 2025
Data ControllerFilmswear.com
Governing LawUK GDPR & EU GDPR
Data SoldNever β€” Absolute
Max Retention7 Years (Legal Min.)
Contactsupport@filmswear.com
0
Data Sold to Third Parties
8
Your GDPR Rights
7yr
Maximum Data Retention
24h
Privacy Query Response
Section 01

🎬Introduction & Who We Are

Filmswear.com ("Filmswear", "we", "us", "our") is a premium global e-commerce brand specialising in Hollywood-inspired, handcrafted genuine leather jackets β€” shipped worldwide to customers in the USA, UK, Canada, and the European Union.

We are the Data Controller responsible for all personal information collected through this website. This Privacy Policy explains how we collect, use, store, protect, and share your personal data when you visit Filmswear.com, place an order, or contact our support team.

This policy complies fully with the UK General Data Protection Regulation (UK GDPR), the EU GDPR (2016/679), the UK Data Protection Act 2018, and the UK Privacy and Electronic Communications Regulations (PECR).

πŸ“Œ Our Core Privacy Commitment

We collect only what we need. We use it only for the purpose it was given. We protect it with best-in-class security. We never sell it, rent it, or share it beyond the purposes listed in this policy. Your personal data belongs to you β€” we are only ever temporary, responsible custodians of it.

Section 02

πŸ“–Key Definitions

The following terms are used throughout this policy. Understanding them ensures complete clarity about how your information is handled at Filmswear.

"Personal Data"
Any information that identifies or could identify you β€” name, email, postal address, IP address, order history, or any combination of data that singles you out as an individual.
"Data Controller"
Filmswear.com is the Data Controller for all data collected via this website β€” meaning we decide how and why it is processed.
"Data Processor"
A third party processing data on our behalf β€” such as Stripe for payments. They act strictly under our written instructions and cannot use your data independently.
"Processing"
Any operation on personal data β€” collecting, storing, using, sharing, archiving, or deleting. All processing by Filmswear is governed entirely by this policy.
"Consent"
A freely given, specific, informed, and unambiguous agreement β€” such as ticking a marketing opt-in box. Consent may be withdrawn at any time, without penalty.
"Legitimate Interest"
A lawful processing basis where Filmswear has a genuine, proportionate business need β€” such as fraud prevention β€” that does not override your fundamental rights and freedoms.
Section 03

πŸ“‹What Personal Data We Collect

We collect personal data through three channels: directly from you during your visit, automatically through your browser, and indirectly through third-party services integral to order fulfilment.

Data You Provide to Us Directly
  • Full name β€” required for order fulfilment and courier delivery label generation
  • Email address β€” for order confirmation, dispatch notifications, and support correspondence
  • Delivery address β€” complete postal address including country, required for international shipping
  • Phone number β€” optional; requested by some courier partners for delivery coordination only
  • Body measurements β€” only if you voluntarily submit custom sizing specifications with your order
  • Order details β€” jacket selected, size, leather tier, quantity, and any notes you include at checkout
  • Payment confirmation data β€” order total and masked card last 4 digits only; full card numbers never reach Filmswear systems
  • Support messages β€” content of emails or enquiries you send to our customer team
Data Collected Automatically When You Browse
  • IP address β€” used for fraud detection, approximate geographic analytics, and security logging
  • Browser type and version β€” used to ensure website compatibility and optimise your experience
  • Device type β€” desktop, mobile, or tablet β€” used for responsive layout and design decisions
  • Pages visited and session duration β€” anonymised data processed by Google Analytics with your consent
  • Referring URL β€” which site, search engine, or ad campaign directed you to Filmswear.com
  • Cookie identifiers β€” see our Cookie Policy for full details of every cookie we set
Data We Never Collect β€” Without Exception
  • Full payment card numbers β€” processed exclusively by Stripe and never transmitted to Filmswear servers
  • Government ID, passport numbers, or national insurance / social security numbers of any kind
  • Sensitive special-category data β€” health information, ethnicity, political opinions, religious beliefs, or biometrics
  • Children's personal data β€” Filmswear.com is strictly for users aged 18 and over
Section 04

βš™οΈHow We Use Your Personal Data

Every use of your personal data is tied to a documented purpose and a corresponding lawful basis under UK/EU GDPR. We never use your data for purposes beyond those listed here without seeking fresh, specific consent.

PurposeData UsedLegal Basis
Processing and fulfilling your orderName, address, email, order detailsContract
Order confirmation & dispatch notificationsEmail address, order reference numberContract
Arranging international courier deliveryName, full address, phone if providedContract
Secure payment processing via Stripe / PayPalEmail, billing address, payment confirmationContract
Responding to customer support enquiriesEmail, name, order number, message contentContract
Fraud prevention and transaction securityIP address, payment patterns, order dataLegitimate Interest
Website analytics and performance improvementAnonymised session data, IP addressConsent
Marketing emails β€” new collections and offersEmail address, purchase history (opted-in only)Consent
Legal compliance and tax record-keepingOrder data, billing informationLegal Obligation
Retargeted advertising on Meta and Google AdsCookie identifiers, browsing signals β€” consentedConsent
πŸ’‘ Marketing Emails β€” Strictly Opt-In Only

We only send marketing emails if you have explicitly opted in at checkout or via our newsletter sign-up form. We never auto-enrol customers after a purchase. Unsubscribe at any time via the link in any email, or by contacting support@filmswear.com. Opting out of marketing has no effect on your transactional order notifications.

Section 05

πŸ”—When and With Whom We Share Your Data

Filmswear does not sell, rent, or trade personal data. We share data only with carefully selected third-party service providers that are operationally essential β€” and only the minimum data required for each specific function.

All third parties processing data on our behalf are bound by Data Processing Agreements (DPAs) that obligate them to handle your data securely, use it only for the stated purpose, and comply with GDPR in full.

πŸ’³
Stripe
Payment Processing
Processes all card payments via PCI-DSS Level 1 infrastructure β€” the highest card security standard. Full card numbers never reach Filmswear servers at any stage.
πŸ…ΏοΈ
PayPal
Alternative Payment
Processes PayPal transactions under their own privacy policy. We receive only order confirmation data β€” no card or account credentials are shared with Filmswear.
🚚
Courier Partners
International Delivery
Your name, full delivery address, and optional phone number are shared with courier partners (DHL, FedEx, or equivalent) solely to fulfil your shipment.
πŸ“Š
Google Analytics
Analytics β€” Consent Only
Anonymised, aggregated session data shared only if you consent to analytics cookies. IP anonymisation is fully enabled. No personally identifiable data is sent to Google.
πŸ“£
Meta (Facebook)
Marketing β€” Consent Only
Meta Pixel data shared only if you consent to marketing cookies. Used for ad conversion tracking only. Manage your preferences via Meta Ad Settings at any time.
πŸͺ
WooCommerce
Store Platform
Our e-commerce platform processes order and account data on our GDPR-compliant, access-controlled hosting infrastructure. Data is not shared externally by the platform itself.
We Absolutely Never Share Your Data With
  • Data brokers, list resellers, or advertising aggregators of any kind
  • Other e-commerce retailers, brands, fashion companies, or direct competitors
  • Social platforms beyond what you explicitly consent to via cookie preferences
  • Any third party for their own independent commercial or marketing activities
  • Government or law enforcement β€” except where legally compelled by a valid court order or statutory requirement
Section 06

🌍International Data Transfers

Filmswear operates globally, meaning your personal data may be transferred to and processed in countries outside your own. Every international transfer is governed by appropriate GDPR-compliant legal safeguards.

  • UK to EU transfers: Covered by UK Adequacy Regulations β€” no additional safeguards required for transfers to EU member states.
  • Transfers to the USA (Stripe, Google, Meta): Protected by Standard Contractual Clauses (SCCs) incorporated into each provider's Data Processing Agreement, providing GDPR-equivalent protections.
  • Production workshop transfers: Our workshop team receives only the minimum data required to craft your jacket β€” size and design specifications only. Contact details such as email or address are never shared with production staff. These limited transfers follow strict internal data handling protocols.
  • Courier transfers: Delivery address data is shared under the Contract legal basis β€” necessary to deliver your order. All major international courier partners maintain their own GDPR-compliant privacy policies.
πŸ’‘ Request Transfer Safeguards at Any Time

Under UK and EU GDPR you may request a copy of the specific safeguards we rely upon for any international data transfer. Email support@filmswear.com and we will respond within 30 calendar days.

Section 07

πŸ—“οΈHow Long We Keep Your Data

We retain personal data only as long as necessary to fulfil the original collection purpose or satisfy a legal obligation. The schedule below sets out our specific retention periods by data category.

Data CategoryRetention PeriodJustification
Order records (name, address, items, value)7 YearsUK tax law and financial audit compliance requirement
Email address (transactional)7 YearsRetained alongside order record for legal purposes
Customer support correspondence3 YearsTo resolve future disputes or post-sale warranty queries
Marketing consent recordsUntil withdrawn + 3 YearsProof of consent record required under GDPR
Google Analytics session data14 MonthsMaximum duration configured in our Analytics account
Cookie consent preference12 MonthsDuration of consent cookie β€” refreshed annually
Payment confirmation records7 YearsFinancial audit trail required by HMRC
Fraud investigation logs5 YearsRequired for insurance and legal defence purposes
Deleted account data90 Days, then purgedRecovery window before permanent anonymisation

After the relevant retention period, data is securely and permanently deleted or irreversibly anonymised so it can no longer be attributed to any individual. Anonymised aggregate statistics may be retained indefinitely as they contain no personal identifiers.

Section 08

πŸ›‘οΈHow We Protect Your Data

We have implemented layered technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, alteration, or disclosure at every stage of processing.

Technical Security Measures in Place
  • 256-bit SSL/TLS encryption on all pages β€” your entire connection to Filmswear.com is encrypted in transit at all times
  • PCI-DSS Level 1 compliance via Stripe β€” the highest internationally recognised payment card security standard
  • Stripe-hosted payment environment β€” card data is entered directly into Stripe's secure system and never passes through our servers
  • Two-factor authentication required for all team members accessing order management and customer data systems
  • Encrypted, access-controlled database backups with strict geographic and personnel access restrictions
  • Regular security patching and active monitoring of all website and hosting infrastructure
⚠️ In the Event of a Data Breach

Should a personal data breach occur that poses a risk to your rights and freedoms, Filmswear will notify the UK ICO within 72 hours and will inform affected individuals directly without undue delay β€” as required under UK GDPR Articles 33 and 34. We will clearly communicate what occurred, what data was affected, and every step taken to mitigate the harm.

Section 09

βœ…Your Eight Data Protection Rights

Under UK and EU GDPR you hold eight legally enforceable rights over your personal data. Filmswear is obligated to facilitate each one at no charge. Exercise any right by emailing support@filmswear.com at any time.

πŸ‘οΈ
Right of Access
Request a complete copy of all personal data we hold about you. We will provide a full Subject Access Report within 30 calendar days β€” free of charge.
✏️
Right to Rectification
Request correction of any inaccurate or incomplete data we hold about you. Verified records are updated within 5 business days of a confirmed request.
πŸ—‘οΈ
Right to Erasure
Request deletion of your personal data β€” the "right to be forgotten." All non-legally-required data will be erased within 30 days of a verified request.
⏸️
Right to Restriction
Request that we pause active processing β€” storing data but not using it β€” while a dispute or correction request is being resolved.
πŸ“€
Right to Portability
Receive your personal data in a structured, machine-readable format (CSV or JSON) to transfer to another provider. Applies to data processed by consent or contract.
🚫
Right to Object
Object to processing based on legitimate interest β€” including direct marketing and analytics. Objection to marketing takes effect immediately upon receipt of your request.
πŸ€–
Automated Decision Rights
Request human review of any automated decision affecting you. Filmswear does not operate fully automated decision-making systems without human oversight for any customer function.
πŸ›οΈ
Right to Complain
Lodge a complaint with the UK ICO (ico.org.uk) or your local EU supervisory authority at any time. We always welcome the opportunity to resolve concerns directly first.
How to Exercise Any Right β€” Step by Step
  • Email support@filmswear.com with subject line "Data Rights Request β€” [Right Name]"
  • Include your full name and the email address associated with your Filmswear order or account
  • Clearly state which right you wish to exercise and any relevant context or supporting details
  • We acknowledge your request within 5 business days and respond in full within 30 calendar days
  • We may verify your identity using the minimum necessary information before processing sensitive requests
  • All rights requests are processed completely free of charge β€” no exceptions
Section 10

πŸ”žChildren's Privacy

Filmswear.com is strictly for users aged 18 and over. Our products are premium adult consumer goods and our website, marketing, and all communications are directed exclusively at adult audiences. We do not knowingly collect personal data from anyone under 18.

If We Discover a Minor Has Submitted Data
  • All personal data associated with the submission will be immediately and permanently deleted
  • Any associated order will be cancelled and fully refunded to the original payment method without delay
  • If you are a parent or guardian and believe your child has submitted data to Filmswear.com, contact us immediately at support@filmswear.com
Section 12

πŸ“¬Policy Updates & Contact Details

Filmswear reserves the right to update this Privacy Policy at any time to reflect changes in applicable law, our business practices, or the services we use. Material updates will be communicated by revising the effective date at the top of this page. For changes significantly affecting your rights, existing customers will be notified by email.

  • Governing Law: This policy is governed by the laws of England and Wales under the UK GDPR and UK Data Protection Act 2018.
  • UK Supervisory Authority: Information Commissioner's Office (ICO) β€” ico.org.uk. EU customers may also contact their local national Data Protection Authority.
  • Last Reviewed: January 2025 β€” reviewed at minimum annually, or whenever our data practices change materially.

Filmswear β€” Privacy & Data Protection Contact

Subject LinePrivacy / Data Rights Request
AcknowledgementWithin 5 Business Days
Full ResponseWithin 30 Calendar Days
Support HoursMon – Sat, 9 AM – 6 PM GMT
Supervisory BodyICO β€” ico.org.uk