Privacy Policy

LAST UPDATED 18/03/2021

This privacy policy sets out how Extras Limited trading under the brand name Smith & Canova uses and protects any information that you give Extras Ltd when you use this website.

Extras Ltd is committed to ensuring that your privacy is protected. Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this privacy statement.

Extras Ltd may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes. This policy is effective from date specified in the ‘LAST UPDATED’ statement above.

Contents

  • Data Controller
  • What Data we Collect
  • How We Use Your Data & Why
  • Marketing Messages
  • Sharing Data - Third Parties & External Websites
    • Payment Processors
    • Delivery Companies
    • Marketing Emails
    • Analytics
    • Social
    • Your Information To Countries Outside Europe
    • Links To Other Websites
  • Security
    • Passwords
    • Payment Details
    • Encryption
  • Keeping Your Data
  • Your rights
  • How We Use Cookies

Data Controller

Extras Ltd is the "Data Controller" of personal data collected by Smith & Canova. Any queries you may have regarding accessing your data, its correction, retention or removal can be made to privacy@smithandcanova.co.uk, you can also contact us by post or phone number using the details on our contact page.

What Data we Collect

We may collect the following personal data while you browse our website:

Contact Data:
Names, email addresses, phone numbers, billing and delivery addresses, delivery preferences and instructions
Transaction Data:
We do NOT collect payment data directly from you. The only access to your financial information is the transaction history we have though our payment processor.
Purchase / Basket Data:
Details about the specific products or services you selected and or have purchased from us.
Communication Data:
A history of contact you have had with us, usually in relation to your order, or feedback from social media
Technical Data:
Internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this web site, as well as how and when you interact with the site while you are visiting it.
Profile Data:
Interests, preferences, likes, follows, feedback and surveys, user names and passwords (although no password is stored in plain text)
Marketing Data:
You preference to receive marketing data and Any data you choose to provide in relation to competition or promotion.

How We Use Your Data & Why

How we use your Contact DataWhy we use it
To send or provide you with you goods or servicesWe have to perform our contract to know who you are and where to deliver your goods to you
To send you updates regarding your order for example that it has been sentWe have to perform our contract to inform you of the details of your order and any updates to it
To send you information relevant to our company and its products, services and policies.To keep you updated. We only send this to you with your consent, you can opt out at any point.
Fraud prevention and detectionTo prevent fraud to you or ourselves. Our payment processor does this on our behalf.
Showing you adverts when you browse the webTo allow you to take advantage of offers on products and services we offer
To understand what you and other customers like the mostTo ensure the products and services we offer are what people want and we are competitive at what we do
How we use your Transaction DataWhy we use it
To view payments and send refundsWe have to perform our contract with you to get payment and refund you. This is done via our payment processor
Fraud PreventionTo prevent fraud to you or ourselves. Our payment processor does this on our behalf.
Internal record keepingWe are required to keep records of our finances
How we use your Purchase / Basket DataWhy we use it
To know what to send youWe have to perform our contract to know what send to you
Provide customer service and supportWe have to perform our contract to be able to help or update you with anything related to your order
Finding out what products and services you and other customers likeWe want to ensure you are getting what you want and we want to stay competitive at what we do
How we use your Communication DataWhy we use it
To provide customer service and supportWe have to perform our contract to help you with your order and keep you updated
Train our staffWe need to make sure we all our staff can give you the best support possible
How we use your Technical DataWhy we use it
Improve our website, understand problemsTo make sure your experience on our site is as smooth and easy for you as possible
Display our site in the most relevant way possible (e.g. language or currency)To make sure your experience on our site is as smooth and easy for you as possible
Protect our siteTo detect and block any malicious intent to our site that may harm future or past visitors
How we use your Profile DataWhy we use it
To create an account for youTo create an account for you If you want to view details about your orders or selections on our site you need to an account
To verify you are who you say you are.If you want to login to the site we need to know it is really you
Finding out what products and services you and other users likeWe want to ensure you are getting what you want and we want to stay competitive at what we do
To run the competition or promotionWe have to perform our contract, if you win we need to be able to know who you are
How we use your Marketing and Communication DataWhy we use it
To know if you want to receive marketing information or notTo send you marketing data when you’re happy to have it and when you are not. You can change this option at any time
To run the competition or promotionWe have to perform our contract, if you win we need to be able to know who you are

Marketing Messages

If you say we can, we will send you marketing messages from time to time to keep you aware of us and the products and services we are offering.

You can request us to stop sending you them at any time. To do this you can:

  • If you have an account, update your setting in the my account area of the site
  • Clicking the un-subscribe link in any marketing email sent to you
  • Contacting us directly either by email / phone or post. Please see our contact details page to do this.

Sharing Data - Third Parties & External Websites

We do not, have not and will not sell any of your personal data to any third party.

However we do share information with some third parties in order to provide services to you. We try to minimize the number of companies we deal with and in so doing keep the number of third parties with access to your data as small as possible. However we are not a bank or a delivery companies and as such we must share your details with some other parties. These can be broken down into the following categories:

  • Companies that are involved in some way to do with your order. These include, Payment Processors and delivery companies.
  • Companies that provide professional services such marketing agencies and advertising partners, website hosts.
  • Credit reference agencies, law enforcement and fraud prevention agencies so we can tackle fraud.

Below are a list of some of the companies we work with that you might wish to know about in regards to your details.

Payment Processors

In order to make your payment as easy and secure as possible we partner with financial company who specialise in card payments. Stripe. They handle all payment transactions from cards data you enter onto the checkout page loaded. None of your card details, number, expiry, CCV detail etc. ever comes into our possession when you make a purchase though our site. Instead they are sent directly and securely to stripe. When they directly receive your card details we also share some of your contact details with them. This allows us to identify your payment in their system and also for them to provide fraud protection to both you and ourselves. Stripe have their own privacy policy which you can review here:
Stripe Privacy Policy

Delivery Companies

We work with Royal Mail, FedEx and DPD to deliver the majority of customer orders. We share with them your contact details to allow them to know where to send goods. We may work with other delivery companies on occasion if our usual companies cannot provide delivery to your location or if there is an exceptional circumstance.

Marketing Emails

If you consent to receiving marketing information from us we use a third party to send emails contacting this marking material. To do so we must share some of your contact details such as your email address, name to allow them to be able to send email to you effectively. We also share some of you Purchase Data if you make a purchase as a result of clicking though from on any email sent. We do this to judge your opinion of each email and improve them in the future. Mailchimp have their own privacy policy which you can review here:
Mailchimp Privacy Policy

Analytics

As with over 50% of all websites we use Google Analytics to gather information on customer browsing habits and user behaviour while on our website. This information is collected to allow us to optimise our website in order to provide the best customer experience possible. It also guides us in produce products that best fit our customer’s needs.

Google collects information on User Behaviour as well as Demographics and Interest Reports. You may opt out of being included in these statistics using Google Analytics Opt Out Tools

Social

When you interact with us, or use any of our pages on social media sites, such as Facebook, Twitter, Instagram etc., we may collect information about you which could include personal data. For example, when you "Like" a post on our Facebook page, or "Follow" us on Twitter. Those social media sites will also have their own privacy policies explaining how they use and share your personal data. You should carefully review these privacy policies before you use those social media sites, to make sure that you are happy with them.

Your Information To Countries Outside Europe

We work to reduce the sharing of data to companies outside of Europe to a minimum. Where they are shared we check to see if they have comparable privacy policies in place or are subscribed to compatible standards such as Privacy Shield

Links To Other Websites

Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.

Security

We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.

Passwords

All passwords you provide to us are stored in encrypted form. This means that we are unable to view them in plain text even if we wished to do so. In the event that a user wishes access their account and cannot remember their password we are only able to offer the ability to reset the password to a new value. This can be done automatically at the users request using the password reset link on any login form or by contacting us directly. At no point should you need to provide us with your password ever!

Payment Details

Payment Details as Debit or Credit Card numbers, Start and Expiry Dates, Issue numbers and Security codes entered into the indicated boxes on our site’s checkout page are never sent to any of our staff or pass through any servers we control. Instead they are sent encrypted directly to our payment processor Stripe. You can read more about them in our third party section

Encryption

All areas of our site implement and force the use of encrypted communication between our servers and the customer’s computer. The form of encryption used is an SHA-256 bit key signed by Gandi. Please consult your web browser’s vendor on details of how to identify that a certificate is in place.

Keeping Your Data

We’ll only hold on to your information for as long as you are a customer. If you haven’t logged onto our website for five years we will delete your information from our systems. If you no longer wish to be a customer, you can also contact our Customer Care team and request to delete all the information we have on you.

If reasonably necessary or required to meet legal or regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our Terms & Conditions, we may also keep hold of some of your information as required, even after you have closed your account or it is no longer needed to provide the services to you.

Your rights

You have many rights in relation to the data we may hold about you they are:

The right to be informed about how your personal information is being used The right to access the personal information we hold about you The right to request the correction of inaccurate personal information we hold about you. If you have an account you can do this though the My Account section The right to request that we delete your data, or stop processing it or collecting it, in some circumstances The right to stop direct marketing messages, which you can do through My Account, and to withdraw consent for other consent-based processing at any time The right to request that we transfer or port elements of your data either to you or another service provider The right to complain to your data protection regulator - in the UK, the Information Commissioner’s Office

If you want to exercise your rights, have a complaint, or just have questions, please contact us.

How We Use Cookies

A cookie is a small file that our servers place on your computer's hard drive. The cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. They allow our website to keep state as you move from page to page within our site. Without them it would be very difficult to persist information unique to yourselves, such as the contents of your basket.

We use traffic log cookies to identify which and how pages are being used. This helps us analyse data about web page traffic and improve our website in order to tailor it to customer needs. Some of these Cookies may involve our 3rd party analytics provider. More information on this can be found in the Analytics section.

The types of cookies we use fall into a number of categories

  • Site functionality cookies – these cookies allow you to navigate the site and use our features, such as “Add to Bag” and “Save for Later”
  • Site analytics cookies – these cookies allow us to measure and analyse how our customers use the site, to improve both its functionality and your shopping experience.
  • Customer preference cookies – when you are browsing or shopping, these cookies will remember your preferences (like your language or location), so we can make your shopping experience as seamless as possible, and more personal to you.
  • Targeting or advertising cookies – these cookies are used to deliver ads relevant to you. They also limit the number of times that you see an ad and help us measure the effectiveness of our marketing campaigns

Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data share with us while using our site.

You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.

There are also a number of tools that can be used to block cookies especially those in relation to advertising data such as Google analytics opt out, uBlock Origin and Privacy Badger. If you wish to install check the add-ons centre for the browser you are using.

Contact Us

If you have any queries or wish to exercise any of your rights explained on this page please contact us either using the details found on the contact us page or directly at privacy@smithandcanova.co.uk