Privacy policy
3H Linen — 3hlinen.co.uk
Last updated: 21.08.2026
1. About this policy
This Privacy Policy explains how 3HLINEN LTD collects, uses, shares and protects personal data when you visit 3hlinen.co.uk, place an order with us, contact us, or otherwise interact with our business.
We have written this policy to be as specific as possible. Rather than referring vaguely to "third parties" or "our partners", we name the services we actually use, explain what each one does with your data, and tell you which legal basis we rely on for each purpose.
1.1 Who we are
The data controller responsible for your personal data is:
| Company | 3HLINEN LTD |
| Registered in | England and Wales |
| Company number | 15491582 |
| Registered office | Palliser House, Second Floor, Palliser Road, London, W14 9EB, United Kingdom |
| VAT number | GB463539570 |
| Privacy contact | info@3hlinen.co.uk |
In this policy, "we", "us", "our" and "3H Linen" mean 3HLINEN LTD. "You" and "your" mean the individual whose personal data we process.
We have not appointed a Data Protection Officer. UK and EU law does not require us to do so, because our core activities do not consist of large-scale systematic monitoring of individuals or large-scale processing of special category data. Privacy matters are handled by our management team, which you can reach at the address above.
1.2 Which laws apply to us
3HLINEN LTD operates from two establishments: our registered office and commercial operations in London, and our own manufacturing facility in Poland, where our textiles are made and orders are prepared.
Because of this, both of the following apply to us at the same time:
- The UK GDPR and the Data Protection Act 2018, as supplemented by the Data (Use and Access) Act 2025, through our UK establishment. Our supervisory authority in the UK is the Information Commissioner's Office (ICO).
- The EU GDPR (Regulation 2016/679), through our Polish establishment, where processing is carried out in the context of that establishment's activities.
We also comply with:
- The Privacy and Electronic Communications Regulations 2003 (PECR) in the UK and the ePrivacy Directive as implemented in EU Member States, which govern cookies, similar technologies, and electronic marketing.
- Polish data protection law, including the Act of 10 May 2018 on the Protection of Personal Data, in relation to processing carried out through our Polish establishment.
If you are in the European Economic Area, you may contact the supervisory authority of the Member State where you live, work, or where you believe an infringement occurred. Our Polish establishment is supervised by the Urząd Ochrony Danych Osobowych (UODO).
Because our central administration is in the United Kingdom, we do not claim the benefit of the GDPR "one-stop-shop" mechanism, and we do not designate a single lead supervisory authority for the EU. You can raise concerns with any competent authority.
2. Personal data we collect
2.1 Data you give us directly
| Category | Examples | When we collect it |
|---|---|---|
| Identity data | First name, last name, business name (for trade customers) | When you create an account, place an order, or contact us |
| Contact data | Email address, telephone number, billing address, delivery address, country | Account creation, checkout, enquiries, newsletter signup |
| Account data | Username, password (stored in hashed form by Shopify), account preferences, saved addresses | When you register an account |
| Order data | Products ordered, quantities, made-to-measure specifications (width, drop, heading type, lining, colour), order value, currency, discount codes used, order history | When you place an order |
| Payment data | Payment method type, last four digits of card, cardholder name, billing address, transaction reference, payment status | At checkout. We do not receive or store your full card number, expiry date or security code — these go directly to our payment providers |
| Communications data | The content of emails, contact form submissions, live chat transcripts, WhatsApp or social media messages, and telephone call recordings | Whenever you contact us |
| Marketing preferences | Whether you have opted in to email or SMS marketing, and your subsequent choices | Signup, checkout, preference centre, unsubscribe actions |
| Review and feedback data | Product reviews, ratings, review photographs, survey responses | When you submit a review or respond to a request for feedback |
| Trade account data | Company name, VAT number, trading address, contact person, credit or account terms | When you apply for a trade or wholesale account |
2.2 Data we collect automatically
| Category | Examples |
|---|---|
| Device and technical data | IP address, browser type and version, operating system, device type, screen resolution, language and locale settings, time zone |
| Usage data | Pages viewed, products viewed, search terms entered on our site, time spent on pages, scroll depth, clicks, referring URL, exit pages |
| Session recording data | Anonymised recordings of mouse movements, clicks and scrolling, and aggregated heatmaps (via Microsoft Clarity) |
| Cart data | Items added to and removed from your basket, including abandoned baskets |
| Advertising identifiers | Cookie IDs, advertising IDs, click identifiers such as Google's GCLID and Meta's FBCLID, and pseudonymous identifiers created by our server-side tracking |
We collect this data through cookies, pixels, tags, software development kits, and server-side tracking. Section 6 explains this in detail, and our Cookie Policy lists individual cookies.
2.3 Data we receive from other sources
- Payment providers confirm whether a payment succeeded, was declined, or was flagged as potentially fraudulent, and provide chargeback and dispute information.
- Advertising platforms (Google, Meta, Microsoft, Pinterest) provide aggregated campaign reporting and, where you have consented, matched-audience information.
- Carriers and fulfilment partners provide delivery status, tracking events, delivery confirmations and failed-delivery reports.
- Review platforms (Judge.me, Trustpilot) pass on reviews you submit and associated display names.
- Social media platforms provide the content of public posts or direct messages you send us.
- Referrals — if another person places an order for delivery to you, we receive your name, address and contact details from them.
2.4 Special category data
We do not deliberately collect data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation.
However, you may volunteer such information — for example, if you explain during a recorded telephone call that you need blackout curtains because of a medical condition affecting sleep, or because of a religious observance. Where this happens incidentally, we rely on Article 9(2)(a) — your explicit consent, given by volunteering the information in the context of your enquiry. We do not use it for any purpose beyond answering your enquiry, and we do not use it for marketing or profiling.
If you would prefer us not to retain such information, contact us at info@3hlinen.co.uk and we will remove it.
2.5 Children
3hlinen.co.uk is intended for adults and we do not knowingly sell to, or collect personal data from, anyone under 18. We do not direct marketing at children.
If we learn that we have collected personal data from a child under 18 without appropriate authorisation, we will delete it. If you believe a child has provided us with personal data, contact info@3hlinen.co.uk.
3. How and why we use your personal data
For each purpose below we state the legal basis we rely on. Where we rely on legitimate interests, we have carried out a Legitimate Interests Assessment balancing our interests against your rights, and we can summarise that assessment on request.
3.1 Fulfilling your order
What we do: Process your order, take payment, manufacture your made-to-measure items, arrange delivery, handle returns, refunds and exchanges, and communicate with you about your order.
Data used: Identity, contact, order, payment, communications data.
Legal basis: Article 6(1)(b) — performance of a contract with you.
Order confirmations, dispatch notifications, delivery updates, delay notices, and messages about your specific order are service communications, not marketing. You will receive them whether or not you have opted in to marketing, because they are necessary to perform our contract with you. You cannot unsubscribe from these while your order is being fulfilled.
3.2 Made-to-measure manufacturing
What we do: Transmit your measurements, fabric and finishing choices to our manufacturing facility in Poland, where your items are cut and sewn to order.
Data used: Order data including specifications, your name and an order reference. Delivery addresses are transmitted where the item is dispatched directly.
Legal basis: Article 6(1)(b) — performance of a contract.
Because our Polish facility is part of the same legal entity as our UK operation, this is an internal transfer within 3HLINEN LTD, not a disclosure to a third party.
3.3 Customer service and communications
What we do: Respond to enquiries by email, contact form, live chat and telephone; verify your identity; investigate complaints; and maintain records of our correspondence.
Data used: Identity, contact, order, communications data, call recordings.
Legal basis: Article 6(1)(b) where your enquiry relates to an existing or prospective order; Article 6(1)(f) — legitimate interests in operating a responsive customer service function and keeping accurate records of what was agreed — for general enquiries and record-keeping.
3.4 Telephone call recording
What we do: We record inbound and outbound telephone calls handled through our telephony provider, Aircall.
Why we do it:
- To confirm the specifications you have given us for made-to-measure items, where an error would result in an unusable product
- To resolve disputes about what was agreed
- To train our staff and monitor service quality
Legal basis: Article 6(1)(f) — legitimate interests. We consider recording proportionate because made-to-measure orders cannot be resold if made to incorrect specifications, and an accurate record protects both parties. We have assessed the impact on your privacy and mitigated it through limited retention, restricted access, and clear notification.
Your notification and choices:
- You will hear an announcement at the start of every recorded call.
- If you would prefer not to be recorded, tell us at the start of the call and we will either continue without recording or ask you to contact us by email instead.
- You may request a copy of a recording of a call you took part in (see Section 9).
Retention: 6 months, unless the recording relates to an ongoing dispute, complaint or legal claim, in which case we keep it until the matter is resolved.
Access: Recordings are accessible only to customer service staff and management. They are not used for automated analysis or profiling.
3.5 Account management
What we do: Create and maintain your account, authenticate you when you log in, store your saved addresses and order history, and let you track orders.
Data used: Identity, contact, account, order data.
Legal basis: Article 6(1)(b) — performance of a contract.
3.6 Email and SMS marketing
What we do: Send you newsletters, information about new products and collections, seasonal offers, and discount codes by email (via Klaviyo) and, where you have given a mobile number and opted in, by SMS (via Sakari).
Legal basis: Article 6(1)(a) — consent, or Article 6(1)(f) — legitimate interests where the "soft opt-in" applies.
The soft opt-in explained. Under PECR regulation 22(3) and the equivalent provisions in EU Member States, we may send you marketing about our own similar products where:
- We obtained your contact details in the course of a sale or negotiations for a sale, and
- We are marketing our own similar goods, and
- We gave you a simple opportunity to refuse marketing when we collected your details, and in every message since.
Where you have not purchased from us — for example, if you subscribed to our newsletter or left an abandoned basket — we rely on your consent instead, and we will only market to you if you have actively opted in.
How to opt out:
- Click "unsubscribe" at the foot of any marketing email
- Reply STOP to any marketing SMS
- Change your preferences in your account
- Email info@3hlinen.co.uk
Opting out of marketing does not affect service communications about orders you have placed.
Separate consents. Email and SMS consent are managed separately. Opting in to one does not opt you in to the other. We only use your telephone number for SMS marketing if you have specifically agreed to SMS marketing — providing a phone number for delivery purposes does not constitute consent to marketing.
3.7 Business-to-business marketing
What we do: Market our products to businesses, including interior designers, hospitality buyers and trade customers.
Legal basis: Article 6(1)(f) — legitimate interests in promoting our products to businesses that may need them.
Under PECR, marketing emails to corporate subscribers (limited companies, LLPs and public bodies) do not require prior consent. However, sole traders and unincorporated partnerships are treated as individual subscribers and receive the same protections as consumers — we will only email them with consent or under the soft opt-in.
Every B2B marketing message includes an opt-out. To be removed from B2B marketing, email info@3hlinen.co.uk.
3.8 Abandoned basket reminders
What we do: If you enter your email address and add items to your basket but do not complete your order, we may send you a reminder.
Legal basis: Article 6(1)(f) — legitimate interests, where you are an existing customer and the soft opt-in applies; Article 6(1)(a) — consent, where you have opted in to marketing but not previously purchased.
We do not send abandoned basket reminders to people who have neither purchased from us nor opted in to marketing.
3.9 Personalisation and profiling for marketing
What we do: Analyse your browsing and purchase history to segment our audiences and tailor the content of our marketing and the advertisements you see. For example, we may group customers by product category interest, order frequency, or average order value, and show different content accordingly.
Data used: Usage, order, cart, advertising identifier data.
Legal basis: Article 6(1)(a) — consent, given through our cookie banner for tracking-based personalisation; Article 6(1)(f) — legitimate interests, for segmentation based on your own purchase history within our own systems.
This does not produce legal or similarly significant effects. Profiling affects which marketing you see. It does not affect pricing, whether we accept your order, or the terms we offer you. We do not carry out automated decision-making within the meaning of Article 22.
Your right to object. You can object to profiling for direct marketing at any time, and we will stop. Withdraw cookie consent through the cookie preferences link in our website footer, or email info@3hlinen.co.uk.
3.10 Advertising and audience matching
What we do: Advertise on Google, Meta (Facebook and Instagram), Microsoft (Bing) and Pinterest. This includes:
- Retargeting — showing you advertisements for products you viewed
- Conversion tracking — measuring which advertisements led to sales
- Customer Match / Custom Audiences — uploading hashed (irreversibly scrambled) versions of your email address or phone number to Google and Meta so they can show you our advertisements if you have an account with them
- Lookalike / similar audiences — asking those platforms to find new potential customers who resemble our existing customers
Legal basis: Article 6(1)(a) — consent, obtained through our cookie banner before any advertising technology is activated.
About hashed uploads. Before uploading, your email address or phone number is converted using a one-way SHA-256 hash. The platform compares this hash against hashes of its own users. We do not send your email address or phone number in readable form. However, this is still processing of your personal data, and we only do it where you have consented.
Withdrawing consent. Use the cookie preferences link in our footer. To be excluded from audience uploads specifically, email info@3hlinen.co.uk and we will suppress your details from future uploads.
3.11 Analytics and site improvement
What we do: Measure how our website is used, identify pages that perform poorly, diagnose technical faults, and test changes.
Tools: Google Analytics 4, Microsoft Clarity, Shopify's built-in analytics, HubSpot analytics.
Legal basis: Article 6(1)(a) — consent, for all non-essential analytics; Article 6(1)(f) — legitimate interests, for aggregated Shopify reporting that is strictly necessary to operate the store.
Microsoft Clarity records anonymised session replays. It is configured to mask text you type into form fields, including payment and address details. Recordings show interaction patterns, not the content of what you enter.
3.12 Reviews and feedback
What we do: Invite you to review products you have purchased, and publish those reviews.
Tools: Judge.me, Trustpilot.
Legal basis: Article 6(1)(f) — legitimate interests in gathering feedback and providing prospective customers with genuine reviews.
Review invitations are service-related rather than promotional, so you may receive them even if you have opted out of marketing. If you do not want to receive them, use the opt-out in the invitation or email info@3hlinen.co.uk.
Reviews are published with the display name you choose. Please do not include personal details in review text — once published, reviews are visible to anyone.
3.13 Fraud prevention and payment security
What we do: Screen orders for indicators of fraud, verify identity where an order is unusual, and investigate chargebacks.
Data used: Order, payment, device, technical data, including IP address and device fingerprint indicators supplied by our payment providers.
Legal basis: Article 6(1)(f) — legitimate interests in preventing fraud and protecting our business and customers; Article 6(1)(c) — legal obligation, in relation to anti-money-laundering and payment regulation requirements.
Shopify and our payment providers apply automated fraud scoring. Where an order is flagged, a human reviews it before any decision is taken. If we decline an order, you may contact us for an explanation and to provide further information.
3.14 Legal compliance, accounting and business records
What we do: Keep accounting records, file VAT returns, respond to regulators and law enforcement, establish and defend legal claims, and maintain records required by law.
Legal basis: Article 6(1)(c) — legal obligation; Article 6(1)(f) — legitimate interests, in relation to establishing, exercising or defending legal claims.
3.15 Business transfers
If we sell or reorganise our business, customer data may be transferred to the acquiring entity as part of the transaction.
Legal basis: Article 6(1)(f) — legitimate interests in the effective conduct of corporate transactions.
We would notify you of any such transfer and of any change to how your data is handled.
4. Automated decision-making
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing.
Automated systems assist us with fraud screening (Section 3.13) and marketing segmentation (Section 3.9), but fraud decisions involve human review, and marketing segmentation does not have a significant effect on you.
5. Who we share your personal data with
We do not sell your personal data. We do not share your contact details with other companies so they can market their own unrelated products to you.
Everything below is either a service provider acting on our instructions, an independent controller with its own responsibilities, or a disclosure required by law. All processors are bound by written contracts meeting Article 28 requirements.
5.1 E-commerce platform
| Provider | Role | What they process |
|---|---|---|
| Shopify Inc. / Shopify International Ltd | Processor | Our entire store: accounts, orders, checkout, customer records, built-in analytics |
Shopify hosts our store and processes personal data on our instructions. Shopify's own privacy policy: https://www.shopify.com/legal/privacy
5.2 Payment providers
These are independent controllers for the payment data they handle. Each has its own privacy policy governing that processing.
| Provider | What they process |
|---|---|
| Shopify Payments (Stripe Payments Europe Ltd as underlying processor) | Card details, transaction data, fraud signals |
| Stripe | Card details, transaction data, fraud signals |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Account identifier, transaction data, address |
| Klarna Bank AB | Identity, contact, order and payment data; Klarna carries out its own affordability and credit assessment for its pay-later products |
| Apple Pay (Apple Inc.) | Device payment token, transaction confirmation |
| Google Pay (Google LLC / Google Ireland Ltd) | Device payment token, transaction confirmation |
Note on Klarna. If you choose a Klarna pay-later or instalment option, Klarna acts as your credit provider. It carries out its own checks and processes your data as an independent controller under its own privacy policy: https://www.klarna.com/uk/privacy/. We do not carry out credit checks and we do not receive credit reference information about you.
We do not receive or store your full card number, expiry date, or CVV. Card data is transmitted directly to the payment provider.
5.3 Manufacturing and fulfilment
| Provider | Role | What they process |
|---|---|---|
| Our Polish manufacturing facility | Internal (same legal entity) | Order specifications, name, order reference, delivery address where dispatched directly |
| ShipBob, Inc. | Processor | Name, delivery address, contact details, order contents |
| SkladUSA | Processor | Name, delivery address, contact details, order contents |
| Fulfillment Network | Processor | Name, delivery address, contact details, order contents |
5.4 Carriers and shipping
| Provider | Role | What they process |
|---|---|---|
| Royal Mail (via Click & Drop) | Independent controller | Name, delivery address, contact details for delivery notifications |
| FedEx | Independent controller | Name, delivery address, contact details, customs data for international shipments |
| Packlink PRO | Processor / broker | Name, delivery address, contact details, passed to the selected carrier |
For international deliveries, carriers pass your name, address and shipment contents to customs authorities as required by law.
5.5 Marketing and communications
| Provider | Purpose |
|---|---|
| Klaviyo, Inc. | Email marketing, segmentation, campaign analytics, abandoned basket flows |
| Sakari | SMS marketing and transactional SMS |
| HubSpot, Inc. | CRM, contact records, forms, marketing analytics, visitor identification |
5.6 Advertising and analytics platforms
These platforms act as independent or joint controllers for the data they receive. Section 6 gives full detail on each.
| Provider | Purpose |
|---|---|
| Google Ireland Ltd / Google LLC | Google Ads, Google Analytics 4, Google Tag Manager, Merchant Center, Customer Match |
| Meta Platforms Ireland Ltd | Meta Pixel, Conversions API, Custom Audiences, Lookalike Audiences |
| Microsoft Ireland Operations Ltd | Microsoft Advertising (Bing) UET, Microsoft Clarity |
| Pinterest Europe Ltd | Pinterest Tag, conversion tracking, retargeting |
| Stape | Server-side tag management infrastructure (see Section 6.4) |
Joint controllership note. For the Meta Pixel and for Google Analytics audience features, we and the platform each determine certain purposes and means of processing. Where the platform's terms establish joint controllership, we operate under those arrangements. Meta's controller addendum: https://www.facebook.com/legal/controller_addendum
5.7 Customer service and operations
| Provider | Purpose |
|---|---|
| Aircall | Telephony and call recording |
| Intercom (including Fin AI) | Customer service messaging and AI-assisted response drafting |
| Tidio | Live chat |
| Shopify Inbox | Live chat integrated with our store |
| Zapier, Inc. | Automated transfer of data between the systems listed in this policy |
| Make (Celonis SE) | Automated workflows between the systems listed in this policy |
About AI-assisted customer service. Intercom's Fin feature uses AI to draft or suggest responses to customer enquiries based on the content of your message and our help content. Your message content is processed to generate the response. Our staff review responses before substantive decisions are made about your order, refund or complaint. We do not use your enquiries to train third-party AI models.
About Zapier and Make. These are automation tools that move data between our systems — for example, copying an order into a spreadsheet, or adding a customer to a marketing list. They process whatever data the specific automation requires. They do not use your data for their own purposes.
5.8 Reviews
| Provider | Purpose |
|---|---|
| Judge.me | Product review collection and display |
| Trustpilot A/S | Business review collection and display |
Trustpilot is an independent controller for reviews published on its own platform: https://uk.legal.trustpilot.com/end-user-privacy-terms
5.9 Store functionality applications
We use applications installed on our Shopify store to provide specific features. These process personal data as processors, only as needed for the feature concerned and only on our instructions. They fall into the following categories:
- Product configuration — capturing your made-to-measure specifications (dimensions, heading type, lining, colour) as part of your order
- Checkout and order management — customising the checkout, applying order rules, and generating invoices and packing slips
- Regional routing — directing you to the appropriate store for your country, based on your IP address
- Product recommendations — suggesting related items based on the contents of your basket
- Consent management — our cookie banner and consent records are provided by Consentmo
We also use catalogue management tools that access product information only and do not process customer personal data.
A current list of the applications with access to personal data is available on request from info@3hlinen.co.uk.
5.10 Professional advisers and authorities
We may disclose personal data to:
- Accountants, auditors, lawyers and insurers, where necessary for professional advice or to establish or defend legal claims
- HM Revenue & Customs, and Polish tax authorities, as required by tax and VAT law
- Courts, tribunals, regulators and law enforcement, where we are legally required to disclose or where disclosure is necessary to protect our rights or the safety of others
- The ICO or another supervisory authority, in connection with a complaint or investigation
6. Cookies, tracking and similar technologies
6.1 Your control
Before any non-essential cookie or tracking technology is set, we ask for your consent through our cookie banner, provided by Consentmo.
You can:
- Accept all, reject all, or choose by category
- Change your mind at any time via the cookie preferences link in our website footer
- Withdraw consent as easily as you gave it
Rejecting non-essential cookies does not prevent you from browsing or purchasing. Only strictly necessary cookies remain active.
We record your consent choice, the date, and the version of the banner shown, so we can demonstrate compliance. These records are kept for 12 months.
6.2 Categories
Strictly necessary — Required for the site to function. Set without consent under PECR regulation 6(4) and Article 5(3) of the ePrivacy Directive.
Includes: session management, shopping basket contents, checkout state, security and bot protection (Cloudflare __cf_bm), load balancing, language and region preference, and your cookie consent choice itself.
Analytics — Measuring site usage. Requires consent.
Includes: Google Analytics 4, Microsoft Clarity, HubSpot analytics (hubspotutk, __hstc, __hssc, __hssrc), Shopify analytics (_shopify_y, _shopify_s, _shopify_analytics).
Advertising — Retargeting and conversion measurement. Requires consent.
Includes: Google Ads conversion and remarketing tags, Meta Pixel (_fbp, fbc), Microsoft UET, Pinterest Tag, and Shopify marketing attribution (_shopify_marketing).
Functional — Enhanced features such as live chat and review widgets. Requires consent.
6.3 Named tracking technologies
Google Analytics 4 — Measures traffic, page views, conversions and user journeys. Sets _ga and related cookies. We use Google Consent Mode v2, which adjusts Google's data collection according to your consent choice. Retention of event-level data: 14 months. https://policies.google.com/privacy
Google Ads — Conversion tracking and remarketing. Records which advertisement brought you to our site and whether you purchased. Uses Google's _gcl_* cookies and the GCLID parameter.
Google Tag Manager — Container that loads and controls the tags listed here. Does not itself collect personal data, but governs what other tags do.
Google Merchant Center — Receives our product catalogue for Shopping listings. Does not receive customer personal data.
Google Customer Match — Where you have consented, we upload hashed email addresses so Google can show our advertisements to existing customers and build similar audiences.
Meta Pixel — Tracks page views, product views, add-to-basket events and purchases for advertising measurement and retargetting on Facebook and Instagram. Sets _fbp. https://www.facebook.com/privacy/policy
Meta Conversions API — Sends the same event data from our server directly to Meta, rather than from your browser. This produces more complete measurement where browsers block pixels. It is subject to the same consent requirement as the browser pixel — we do not send events for visitors who have declined advertising cookies.
Meta Custom Audiences and Lookalike Audiences — Where you have consented, hashed contact details are matched against Meta accounts so we can advertise to existing customers and find new audiences resembling them.
Microsoft Advertising UET — Conversion tracking and remarketing for Bing search advertising.
Microsoft Clarity — Session recordings and heatmaps, with form field content masked. https://privacy.microsoft.com/privacystatement
Pinterest Tag — Conversion tracking and retargeting for Pinterest advertising.
HubSpot — Identifies returning visitors, associates form submissions with browsing history, and maintains our CRM contact records. Sets hubspotutk and related cookies across our domain and HubSpot's domains. https://legal.hubspot.com/privacy-policy
Klaviyo — Tracks email opens, clicks, and on-site behaviour linked to your subscriber profile where you have subscribed.
Judge.me and Trustpilot — Load review widgets and record which reviews are displayed.
Tidio, Shopify Inbox, Intercom — Maintain chat session state and message history.
6.4 Server-side tracking — important disclosure
We use Stape to operate a server-side tag management container on the subdomain load.server.3hlinen.co.uk.
What this means in practice. Instead of your browser sending tracking data directly to Google, Meta and other platforms, it sends data to our own server subdomain first. Our server then forwards that data to the advertising platforms.
Why we tell you this. Server-side tracking is less visible than conventional cookies. Because the requests go to a subdomain of our own site, they may not appear in browser privacy tools or third-party cookie scanners as advertising activity, and cookies set this way are first-party cookies with longer lifespans that browsers do not automatically restrict.
What we want to be clear about:
- Server-side tracking does not exempt us from the consent requirement. The data still reaches Google, Meta, Microsoft and Pinterest, and it is still your personal data. We apply your consent choice to server-side tracking exactly as we apply it to browser-based tracking.
- If you decline advertising or analytics cookies, we do not forward corresponding events through our server-side container.
- Data forwarded may include: pseudonymous identifiers, page URLs, product identifiers, order values, click identifiers, IP address and user agent, and — for conversions, where you have consented — hashed contact details.
Retention: Server-side event data is retained in transit only and is not stored on our servers beyond what is necessary to forward it, other than logs kept for up to 30 days for technical troubleshooting.
6.5 Browser controls
Independently of our banner, you can control cookies through your browser settings, use browser tracking protection, or enable Global Privacy Control. We honour Global Privacy Control signals where your browser sends them.
Blocking strictly necessary cookies will prevent our checkout from working.
7. International transfers
7.1 Transfers within 3HLINEN LTD
Data moves between our UK operations and our Polish manufacturing facility. Both are part of the same legal entity.
- UK to Poland (EEA): The UK recognises the EEA as providing adequate protection. No additional safeguards required.
- Poland (EEA) to UK: The European Commission renewed its adequacy decision for the United Kingdom on 19 December 2025, valid until 27 December 2031. No additional safeguards required.
7.2 Transfers outside the UK and EEA
Several of our providers are established in, or transfer data to, the United States. These transfers are protected by:
- The EU-US Data Privacy Framework and its UK Extension, where the provider is certified. Certification can be verified at https://www.dataprivacyframework.gov
- EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) together with the UK International Data Transfer Addendum, or the UK IDTA, where the provider is not certified
- Transfer Risk Assessments carried out by us, with supplementary technical and organisational measures where the assessment identifies a residual risk
Providers involving transfers outside the UK and EEA include: Shopify, Google, Meta, Microsoft, Klaviyo, Sakari, HubSpot, Stripe, PayPal, Intercom, Tidio, Judge.me, Zapier, Make, ShipBob, SkladUSA, Fulfillment Network, FedEx, Stape, and Consentmo.
To request a copy of the safeguards applying to a specific transfer, email info@3hlinen.co.uk. We may redact commercially confidential terms.
8. How long we keep your personal data
We keep personal data only as long as necessary. Where a retention period is driven by law, we state which law.
| Data | Retention | Reason |
|---|---|---|
| Order and transaction records | 6 years from the end of the accounting period | Companies Act 2006 s.388; VAT Act 1994 Sch.11 |
| VAT records | 6 years | HMRC requirement |
| Customer account data | Until you close your account, then 30 days, except where order records must be kept | Account closure |
| Made-to-measure specifications | 6 years | Retained with order records; also needed for warranty and repeat orders |
| Payment records (excluding card numbers, which we never hold) | 6 years | Accounting and chargeback windows |
| Marketing consent records | Duration of consent plus 3 years after withdrawal | Evidence of lawful marketing under PECR |
| Marketing contact data | Until you unsubscribe, or 24 months of inactivity, whichever is sooner | Data minimisation |
| Telephone call recordings | 6 months, or until resolution of any related dispute | Section 3.4 |
| Live chat and email correspondence | 3 years from last contact | Complaint and claim limitation periods |
| Cookie consent records | 12 months | Demonstrating consent |
| Website analytics data | 14 months (Google Analytics 4 event data) | Platform configuration |
| Server-side tracking logs | 30 days | Technical troubleshooting |
| Reviews | Indefinitely while published, unless you request removal | Ongoing publication |
| Data subject request records | 3 years from completion | Demonstrating compliance |
| Complaint records | 6 years from closure | Legal claim limitation periods |
| CCTV / premises footage | Not applicable — we operate no public premises | — |
Where we no longer need data but cannot delete it immediately (for example, in backups), we isolate it from active use and delete it when the backup cycle completes.
9. Your rights
Under the UK GDPR and EU GDPR you have the following rights. They are free to exercise, and we respond within one month. Where a request is complex, we may extend by up to two further months and will tell you why within the first month.
Right of access (Article 15) — Obtain confirmation that we process your data, a copy of it, and information about how we use it. This includes copies of recordings of calls you took part in.
Right to rectification (Article 16) — Have inaccurate data corrected and incomplete data completed. You can update most account details yourself.
Right to erasure (Article 17) — Have your data deleted where it is no longer necessary, where you withdraw consent and there is no other basis, or where you object and no overriding grounds apply. This right is not absolute — we cannot delete records we are legally required to keep, such as order records within the 6-year accounting period. We will tell you what we have deleted and what we must retain, and why.
Right to restriction (Article 18) — Require us to stop processing your data, while retaining it, in certain circumstances such as while we verify a rectification request.
Right to data portability (Article 20) — Receive data you provided to us, in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible. Applies to data processed by automated means on the basis of consent or contract.
Right to object (Article 21) —
- To direct marketing: absolute. Object and we stop, with no balancing test.
- To processing based on legitimate interests: we stop unless we demonstrate compelling legitimate grounds that override your interests, or the processing relates to legal claims.
Right to withdraw consent (Article 7(3)) — Withdraw at any time, as easily as you gave it. This does not affect the lawfulness of processing before withdrawal.
Rights in relation to automated decision-making (Article 22) — We do not carry out solely automated decision-making with legal or similarly significant effects. Where automated fraud screening flags an order, a person reviews it, and you may contest the outcome.
How to exercise your rights
Email info@3hlinen.co.uk with the subject line "Data Protection Request", or write to us at our registered office.
Please include: your name, the email address associated with your account or orders, which right you are exercising, and any detail that helps us locate the data.
Identity verification. We may ask you to verify your identity before we act. We ask for the minimum necessary — usually confirmation from the email address on your account, or details of a recent order. We do not require identity documents for routine requests.
Requests made on your behalf. If someone acts for you, we need evidence of their authority — a signed authority, or a power of attorney. Without it we cannot proceed, and we will explain why.
10. Complaints
We take data protection complaints seriously. This section sets out our complaints procedure, which we maintain in accordance with the requirement introduced by the Data (Use and Access) Act 2025, in force from 19 June 2026.
How to complain
Email info@3hlinen.co.uk with "Data Protection Complaint" in the subject line, or write to our registered office.
To help us investigate, please include:
- Your name and contact details
- A clear description of what happened
- Relevant dates, order numbers or correspondence
- What outcome you are seeking
What happens next
- Within 5 working days — we acknowledge your complaint in writing.
- Investigation — we review what happened and may contact you for further information.
- Within 30 days — we give you a full response setting out our findings, any action we are taking, and what you can do if you remain dissatisfied. If the matter is complex, we will tell you within the 30 days and give a revised timescale.
We keep records of complaints for 6 years from closure.
If you are not satisfied
You may complain to a supervisory authority. We would appreciate the chance to resolve matters first, but you are not required to contact us before approaching a regulator.
United Kingdom — Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Helpline: 0303 123 1113 · https://ico.org.uk
Poland — Urząd Ochrony Danych Osobowych ul. Stawki 2, 00-193 Warszawa, Poland · https://uodo.gov.pl
Elsewhere in the EEA — you may complain to the supervisory authority in your country of residence or workplace. A list is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en
You also have the right to an effective judicial remedy against a supervisory authority or against us.
11. Security
We take appropriate technical and organisational measures to protect personal data, including:
- Encryption in transit — TLS across our website and administrative systems
- Encryption at rest — applied by our platform and hosting providers
- Access control — role-based access on a least-privilege basis, with individual accounts and mandatory multi-factor authentication for staff with access to customer data
- Payment security — PCI DSS compliance through our payment providers; we never handle full card numbers
- Vendor due diligence — assessment of providers before engagement, and written processing agreements
- Bot and abuse protection — Cloudflare protection across our infrastructure
- Backups — regular encrypted backups with tested restoration
- Incident response — a documented procedure for detecting, assessing and reporting breaches
Breach notification. If a personal data breach occurs, we notify the ICO and, where relevant, the UODO within 72 hours where the breach is likely to result in a risk to individuals' rights. Where it is likely to result in a high risk to you, we notify you directly without undue delay.
No system is completely secure. Please use a strong, unique password for your account and tell us immediately at info@3hlinen.co.uk if you suspect unauthorised access.
12. Third-party links
Our website links to third-party sites, including social media platforms, payment providers and review platforms. We are not responsible for their privacy practices. Please read their policies before providing personal data.
13. Changes to this policy
We review this policy at least annually and update it when our processing changes.
The "Last updated" date at the top shows when it was last revised. For material changes — new purposes, new categories of recipient, or changes affecting your rights — we notify you by email or a prominent notice on our website before the change takes effect.
Previous versions are available on request.
14. Contact us
Privacy enquiries, requests and complaints: info@3hlinen.co.uk
Post: 3HLINEN LTD Palliser House, Second Floor Palliser Road London W14 9EB United Kingdom