Privacy policy

Last updated: 10 August 2026

John's Ceylon Tea respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain and protect personal information when you visit johnsceylontea.co.uk (the "Site"), create an account, place or receive an order, join our rewards programme, request a stock notification, subscribe to marketing, contact us or otherwise use our products and services (together, the "Services").

This notice is written principally for customers and visitors in the United Kingdom and is intended to meet the transparency requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where relevant, the Privacy and Electronic Communications Regulations 2003 (PECR), as amended.

Please read this Privacy Policy carefully. Where a separate notice is shown at the point we collect information, that notice supplements this policy.

Who we are and how to contact us

For UK data-protection purposes, the controller responsible for the personal information described in this policy is:

  • Legal owner/controller: John's Ceylon Tea
  • Trading name: John's Ceylon Tea
  • Postal address: 9A First Unit, 4 Raven Road, South Woodford, London E18 1HB, United Kingdom
  • Email: info@johnsceylontea.co.uk
  • Telephone: +44 20 8281 1898

Please mark privacy-related correspondence for the attention of the Privacy Lead. We have not named a Data Protection Officer in this notice; if one is appointed, we will update these contact details.

Personal information we collect

The information we collect depends on how you interact with the Services. It may include:

  • Identity and contact information: such as your name, title, email address, telephone number, billing address, delivery address and, where you buy a gift, the recipient's name and delivery details.
  • Order and transaction information: such as products purchased, basket contents, order number, discounts, delivery method, delivery status, returns, refunds, complaints, payment status and limited payment-related information. We do not normally receive or store your full payment-card number or security code; payment providers process those details.
  • Account and loyalty information: such as your customer-account identifier, login details handled by our commerce platform, saved addresses, wish-list items, reward points, reward activity and account preferences.
  • Communications and customer-service information: including enquiries, chat or email messages, call notes, return requests, feedback and any information you choose to provide when contacting us.
  • Marketing and preference information: including newsletter subscriptions, consent records, unsubscribe choices, product interests, back-in-stock requests and communication preferences.
  • Technical and usage information: such as IP address, device identifiers, browser type, operating system, time zone, pages and products viewed, search terms, referring pages, clicks, session activity, approximate location derived from IP address, cookie identifiers and similar technology data.
  • Security and fraud-prevention information: such as login events, transaction risk signals, suspected misuse, failed payment information and records needed to protect customers and the Services.
  • Feedback and public-content information: such as a review, testimonial, social-media interaction or other content you submit or authorise us to publish.
  • Inferences and personalisation information: such as likely interests or shopping preferences derived from your activity, but only where the relevant processing is lawful and any required cookie consent has been obtained.

Information we do not ask you to provide

We do not intentionally collect special-category information, such as information about health, race or ethnicity, religious or philosophical beliefs, political opinions, trade-union membership, genetic or biometric data, or information about sex life or sexual orientation. Please do not send this type of information unless we specifically request it for a lawful reason and explain how it will be handled.

How we collect personal information

  • Directly from you: when you browse or search the Site, create an account, place an order, join rewards, save a wish list, request a stock alert, subscribe to emails, submit a form, contact us, make a return or otherwise communicate with us.
  • Automatically from your device: through essential cookies, server logs and, where required, technologies activated only after your consent or under a documented legal exemption.
  • From service providers: including Shopify, payment providers, fraud-prevention providers, delivery carriers, email and customer-support providers, rewards and stock-notification providers, and analytics or advertising providers where enabled.
  • From third-party platforms: for example if you contact or interact with us through Instagram or another social-media service. The platform will also process information under its own privacy notice.
  • From another person: for example where a customer sends a gift to you or asks us to communicate with you. The person providing your details should have authority to do so.

Why we use personal information and our lawful bases

UK data-protection law requires us to have a lawful basis for each use of personal information. Depending on the circumstances, we rely on the following bases:

To process, fulfil and deliver orders

We use identity, contact, order and transaction information to take payment, confirm orders, arrange delivery, provide tracking, manage returns and refunds, and communicate about the purchase. The lawful basis is performance of a contract with you or taking steps at your request before entering a contract. We may also use relevant records to meet legal obligations.

To provide accounts, wish lists and rewards

We use account, preference and loyalty information to create and administer requested features. The lawful basis is performance of our contract with you where the feature forms part of the requested service, and our legitimate interests in providing useful customer features and administering our customer relationship.

To answer enquiries and provide customer support

We use contact, order and communication information to respond to questions, complaints, returns and other requests. The lawful basis is performance of a contract where the request relates to an order, or our legitimate interests in providing support and maintaining customer relationships.

To operate, secure and improve the Services

We use technical, usage and security information to keep the Site working, diagnose faults, prevent misuse, protect accounts, improve navigation and evaluate service performance. We rely on our legitimate interests in operating a safe and effective retail business. Where storage or access technologies require consent under PECR, we will seek consent before activating them unless a specific exemption applies.

To prevent fraud and protect legal rights

We use order, payment-status, technical and security information to screen transactions, investigate suspected fraud, enforce terms, establish or defend legal claims and protect customers, our business and others. We rely on legitimate interests and, where applicable, compliance with legal obligations.

To meet legal, accounting and regulatory duties

We use order, transaction, identity and communication records for tax, accounting, product-safety, consumer-law, data-protection and other legal requirements. The lawful basis is compliance with a legal obligation. We may also rely on legitimate interests in managing legal claims.

To send requested notifications

We use your email address and product preference to send a back-in-stock alert or another notification you request. We rely on your request and consent, and our legitimate interests in responding to it. You may cancel the request at any time.

To send direct marketing

We use contact details and marketing preferences to send product news, offers and newsletters. We rely on consent or, for our own similar products offered to qualifying existing customers, the PECR soft opt-in together with our legitimate interests. We provide an opt-out when details are collected and in every marketing message. We do not rely on the soft opt-in for bought-in lists.

To measure marketing and personalise content

Subject to your cookie choices, we may use usage, cookie and preference information to understand campaign performance, limit repeated advertising, create audiences, personalise Site content and show relevant advertising. Where PECR requires consent for the technology, consent is the relevant basis for storing or accessing information on your device. Our subsequent use of personal information will rely on consent or legitimate interests, as applicable and explained in the cookie preference centre.

To manage business changes

If we consider a sale, merger, financing, restructuring or transfer of all or part of the business, we may use and disclose relevant information where necessary for our legitimate interests in managing the transaction, subject to confidentiality and legal safeguards.

Our legitimate interests

Where we rely on legitimate interests, we consider whether the processing is necessary and balance our interests against your rights, interests and reasonable expectations. You may object to processing based on legitimate interests; see Your rights below.

If we want to use personal information for a materially different purpose, we will assess whether the new purpose is compatible, update this notice where required and seek consent if the law requires it.

When information is required

Some information is required to enter into or perform a contract with you. For example, we need your name, contact details, delivery address and payment confirmation to process an order. If you do not provide required information, we may be unable to accept or fulfil the order or provide the requested feature. Optional fields will be identified where practical.

Cookies and similar technologies

We use cookies and similar technologies, including pixels, tags, scripts, local storage and device identifiers. These may be set by us or by service providers.

  • Strictly necessary technologies: enable core functions such as security, checkout, basket contents, network management, account access and remembering privacy choices. Where the law permits, these may operate without consent.
  • Functional technologies: remember optional choices and enhance features. We request consent where PECR requires it.
  • Analytics technologies: help us understand Site use and performance. We request consent before using them unless we have documented that a specific PECR exemption applies and have met all conditions, including any required information and simple means of objecting.
  • Advertising technologies: help measure campaigns, create audiences, personalise advertising and control frequency. We obtain consent before activating advertising technologies where PECR requires it.

You can accept, reject or manage non-essential technologies through the Site's cookie controls and change your choices at any time. You can also use browser settings, although blocking strictly necessary technologies may prevent parts of the Site from working. Our Cookie Policy or preference centre should identify active providers, purposes and durations and forms part of this Privacy Policy.

Direct marketing

We may send email marketing where you have consented or where the PECR soft opt-in lawfully applies to our own similar products. We will tell you at the point of collection if we intend to use your details for marketing.

You can stop marketing at any time by using the unsubscribe link in an email, changing available account preferences or contacting info@johnsceylontea.co.uk. Opting out of marketing does not stop essential service communications, such as order, delivery, security, return or recall messages.

We may keep the minimum information needed on a suppression list so that we honour your choice and do not accidentally contact you again. We do not sell or rent personal information for third parties' own direct marketing.

Who we share personal information with

We disclose personal information only where reasonably necessary for the purposes described in this policy, including to:

  • Shopify and its group companies, which provide the online store, hosting, checkout, customer-account and order-management infrastructure.
  • Payment and wallet providers selected at checkout, including PayPal and providers supporting card payments or digital wallets. These providers may act as independent controllers for parts of their payment, fraud-prevention and legal-compliance processing.
  • Royal Mail and other delivery, fulfilment, warehouse and tracking providers that need information to deliver and manage orders.
  • Providers of email delivery, customer support, rewards, wish lists, back-in-stock notifications, website development, cloud hosting, security, fraud prevention and other operational services.
  • Analytics, search, social-media and advertising providers, but only where enabled and subject to applicable consent requirements and your cookie choices.
  • Professional advisers, including accountants, auditors, insurers, banks, lawyers and tax advisers, where necessary and subject to duties of confidentiality.
  • Government departments, regulators, courts, law-enforcement bodies and other authorities where disclosure is required or permitted by law or necessary to protect legal rights.
  • A potential or actual buyer, investor, lender, seller or successor in connection with a business transaction, subject to appropriate confidentiality and data-protection safeguards.
  • Other parties where you direct us to disclose information or give valid consent.

Service providers acting as our processors may use personal information only on our documented instructions, for agreed purposes and subject to contractual confidentiality and security duties. Some recipients, such as payment providers or social-media platforms, may act as separate controllers under their own privacy notices.

International transfers

Some providers, including global commerce, cloud, payment, support, analytics and advertising providers, may store or process personal information outside the United Kingdom. The destination country's laws may not provide the same level of protection as UK law.

When UK transfer rules apply, we use a lawful transfer mechanism. Depending on the destination and provider, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, binding corporate rules or another mechanism permitted by UK law. We also assess and use supplementary measures where required. A limited statutory exception may be used only where legally available.

You may contact us to request further information about the safeguards relevant to a particular transfer, subject to appropriate redactions for confidentiality and security.

How long we keep personal information

We keep personal information only for as long as reasonably necessary for the purpose collected, including to meet legal, accounting, tax and reporting requirements; resolve disputes; prevent fraud; and enforce agreements. Our usual retention approach is:

  • Orders, invoices, payments, returns and accounting records: normally six years after the end of the relevant financial year, or longer if required by law, tax enquiries or a legal claim.
  • Customer accounts, wish lists and rewards profiles: while the account remains active and normally for up to two years after closure or sustained inactivity. Transaction records may be retained separately for the longer period above.
  • Customer-service messages and complaints: normally three years after the matter closes, or up to six years where linked to a contract, dispute, safety issue or legal claim.
  • Marketing subscriptions and preferences: until you unsubscribe, withdraw consent or remain inactive for a period we determine is no longer reasonable, normally no more than 24 months without engagement. A minimal suppression record may be retained as long as needed to honour an opt-out.
  • Back-in-stock requests: until the alert is sent or you cancel the request, then normally deleted or anonymised within 90 days unless needed to resolve an issue.
  • Cookie and analytics information: for the period stated in the cookie preference centre or Cookie Policy. Durations vary by technology and provider.
  • Security logs and fraud-risk records: normally up to 24 months, but longer where needed to investigate an incident, prevent repeat fraud, comply with law or manage a claim.
  • Privacy-rights requests and related correspondence: normally three years after closure, or longer where necessary to demonstrate compliance or manage a dispute.

We may retain information for longer if a law, regulatory request, litigation hold or active dispute requires it. When information is no longer needed, we delete it, anonymise it so it no longer identifies anyone, or securely isolate it until deletion is possible. Residual copies may remain in protected backups until they are overwritten under normal backup cycles.

How we protect personal information

We use appropriate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access. Measures may include access controls, secure connections, account authentication, payment-provider security, service-provider reviews, backups, staff confidentiality and incident-management procedures.

No internet transmission or storage system can be guaranteed completely secure. You are responsible for keeping account credentials confidential and should contact us promptly if you believe your account or personal information has been compromised.

Your UK data-protection rights

Depending on the circumstances and lawful basis, you may have the right to:

  • Access personal information we hold about you and receive information about how we use it.
  • Ask us to correct inaccurate information or complete incomplete information.
  • Ask us to erase personal information in circumstances where the law requires or permits deletion.
  • Ask us to restrict processing in certain circumstances.
  • Object to processing based on legitimate interests, including related profiling, based on your particular situation.
  • Object at any time to the use of personal information for direct marketing, including related profiling. This right is absolute.
  • Receive personal information you provided to us in a structured, commonly used and machine-readable format, and ask us to transfer it where the right to data portability applies.
  • Withdraw consent at any time where processing relies on consent. Withdrawal does not affect processing that was lawful before withdrawal.
  • Ask for safeguards relating to certain international transfers.
  • Complain to the Information Commissioner's Office.

RIGHT TO OBJECT

You have an absolute right to object to direct marketing. You may also object to processing based on legitimate interests for reasons relating to your situation. Email info@johnsceylontea.co.uk to exercise this right.

To exercise a right, email info@johnsceylontea.co.uk or write to the postal address above. Please describe your request clearly. We may request information reasonably necessary to verify your identity and protect your information. You may use an authorised representative, but we may ask for proof of authority and may still need to verify your identity.

We normally respond without charge and within one month, although UK law permits an extension in certain complex cases. We will tell you if an extension or lawful exemption applies.

Automated decision-making and profiling

We may use automated tools and risk signals to help detect fraud, secure the Site, recommend products or measure advertising. We do not intend to make decisions based solely on automated processing that produce legal effects or similarly significant effects for you. If that changes, we will provide the information and safeguards required by law, including information about the logic involved and the likely consequences.

Children's information

The Site is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information without appropriate authorisation, contact us and we will investigate and delete it where required. A person under 18 should use the Services with the involvement of a parent or guardian where appropriate.

Third-party websites and social media

The Site may link to third-party websites, apps or social-media services. We do not control their privacy practices. If you follow a link or interact with a third party, review that party's privacy information before providing personal information.

Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to our Services, providers, practices or legal obligations. We will post the revised version on the Site and change the "Last updated" date. Where a change materially affects how we use personal information, we will take additional steps required by law, which may include giving a prominent notice or seeking consent.

Contact and complaints

If you have a question, concern or complaint about this Privacy Policy or our handling of personal information, please contact us first:

You also have the right to complain to the UK supervisory authority: