Legal
Privacy Policy
Last updated: June 2026
TIMZ CO ("we", "us", "our") is the data controller for personal data collected through timzco.store. This policy explains what we collect, why, how we use it, how long we keep it, and the rights available to you under the EU GDPR, UK GDPR, the California Consumer Privacy Act (CCPA/CPRA) and other applicable laws.
1. Data we collect
- Identity & contact: name, email, phone, shipping and billing address.
- Order data: products purchased, order value, currency, returns history.
- Payment data: processed by Stripe, Shopify Payments and PayPal; we receive a tokenised reference and the last four digits of the card only.
- Technical: IP address, browser, device, language, referring URL, pages viewed.
- Communications: messages you send to our concierge (email, chat, WhatsApp).
- Marketing preferences: consent status for newsletters and analytics.
2. How we use your data and our lawful basis
- Contract: processing orders, payment, delivery, returns and customer service.
- Legal obligation: tax, accounting and consumer-protection records.
- Legitimate interests: fraud prevention, securing the Site, improving our products, sending service emails about orders you have placed.
- Consent: marketing emails, optional analytics cookies, WhatsApp concierge messaging.
3. Sharing your data
We share data only with processors needed to run our business: payment providers (Stripe, Shopify Payments, PayPal), shipping carriers (DHL, FedEx, UPS), email and messaging providers (Resend, Twilio/WhatsApp), our e-commerce platform (Shopify), our backend infrastructure provider, and professional advisors. All processors are bound by written agreements and process data only on our instructions.
4. International transfers
Some of our processors are located outside the UK / EEA. Where this is the case we rely on European Commission adequacy decisions or the Standard Contractual Clauses, combined with supplementary safeguards where required.
5. How long we keep your data
Order, tax and accounting records are retained for the period required by law (typically 6–10 years). Marketing data is retained until you unsubscribe. Concierge conversations are retained for 24 months to improve service quality. Analytics data is retained for 14 months. Account data is deleted on request, subject to legal-retention obligations.
6. Your rights
You have the right to access, rectify, erase, restrict or port your personal data, and to object to processing based on legitimate interests or direct marketing. EU/UK residents may lodge a complaint with their local supervisory authority. California residents have the right to know, delete, correct and limit use of sensitive information, and to opt out of "sale" or "sharing" — TIMZ CO does not sell personal information. To exercise any right, email atelier@timzco.com; we respond within 30 days.
7. Cookies
We use strictly-necessary cookies to operate the cart and authentication, and (with your consent) analytics cookies to understand traffic. You can manage your choices at any time via the cookie banner.
8. Security
The Site is served over HTTPS. Passwords are hashed and payment data is tokenised. We apply role-based access controls, row-level security on our database and regular security reviews. No system is 100% secure; please use a strong, unique password.
9. Children
The Site is not directed at children under 16 and we do not knowingly collect data from them. Contact us if you believe a child has provided personal data.
10. Changes to this policy
We may update this policy from time to time. The "last updated" date above will reflect the latest revision. Material changes will be highlighted on the Site.
11. Contact
For privacy questions or to exercise your rights: atelier@timzco.com.