Your privacy is very important to us and we want to assure you that we take the confidentiality and security of your personal data very seriously. “Petal Plan”, “we”, “us” refers to Petal Plan Limited, a company registered in England and Wales.
- What personal data do we collect?
We collect personal data from you whenever you interact with our Website, including when you make purchases, when you browse our Website, when you use our services or when you sign up to receive any of our services. When providing personal data to us through a form, we indicate which personal data is optional. Please note that, when collection of personal data is required or necessary either as needed for us to fulfil your order or based on legal obligation and you elect not to provide the personal data, we may not be able to accept or fulfil your order.
We collect Device Information using the following technologies:
- “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. For more information about cookies, and how to disable cookies, visit http://www.allaboutcookies.org.
- “Log files” track actions occurring on the Website, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
- “Web beacons,” “tags,” and “pixels” are electronic files used to record information about how you browse the Website.
The types of personal data that we will collect, store, maintain or process includes the following.
Personal data you provide when you purchase from us:
- Your contact details you provide when placing your order, including name, title, billing address, telephone numbers and e-mail address
- Recipient and delivery details you provide when placing your order, including name, address, contact telephone numbers, delivery instructions and email address
- Any personal data contained within the card message (e.g., names and birthdays)
- Details associated with the products you order
- Details of the services you purchase
- When you make a purchase, your payment card details (in accordance with payment card industry standards)
- Your communication and marketing preferences including delivery updates and notifications
- Additional Personal Data provided through the “My Account” feature
- Any stored payment card details (in accordance with payment card industry standards)
- Additional Personal Data obtained when you use our Website:
- Details of your online browsing activities on our Website such as the pages visited and the parts of the Website used
- Details of the type of device used to access our Website, your device IP address, and your device location
- Additional Personal Data obtained through contact with us
- Details of your interaction with emails that we send you including links that you click and emails that you open
- If contact occurs between us, we may keep a record of that correspondence, including your name and contact data, and details of your customer care issues or other concerns and our responses
Our Website is not intended for use by persons under the age of 16 and our terms and conditions require that a person be 16 or older when placing an order with us. If you believe we have collected personal data from a person under the age of 16, please notify us at the information provided in this policy.
- How we use the personal data we collect from you?
We will use your personal data for the following purposes:
To fulfil your order:
- To process your order
- To process payment including payment authorisation via payment card or other third party payment processor
- To carry out identity verification and fraud prevention checks when purchasing with a payment card and validating personal data you provide via a third party payment processor
- To provide data to any third party supplier or vendor who may fulfil your order on our behalf
- To provide order confirmation, status notifications on any order placed with us
For customer care purposes:
- To address any customer care issues that occur either with respect to a product or service, delivery, or a complaint or enquiry that you or your recipient raise with us
- To contact you with any changes, cancellation or other issues with your order
- To manage any registered accounts you have through the Website
- To obtain customer feedback with respect to an order either from you or your recipient (to the extent permitted under the applicable law)
- Please note that you will receive communications with respect to fulfilling your order or for customer care purposes even if you opt out of receiving marketing communications
For marketing purposes:
- To keep you up-to-date with new products and services that we think will be of interest to you
- To provide you with promotional offers
- Notify you of competitions and prize draw offers to enable you to enter and to notify you of any wins
For marketing through third parties:
- If you use our Website, then you may receive personalised advertisements of our products and services when browsing other Website using the same computer or device you used to view our Website. This marketing is enabled through the cookies collecting data of your online browsing behaviour.
For internal business purposes:
- We will use any of the personal data collected to help us to understand how many people visit our Website, how well the Website is working and to consider any improvements we may need to make to the Website to improve your online experience. It also helps us determine what products and services you are interested in and what you or other customers might wish to purchase from us in future.
More specifically, we may use your personal data for the following internal business purposes:
- To analyse your browsing and purchasing activity on our Website
- To analyse the demographic data we collect when you place your order or otherwise use our Website including your title, address, IP address, browser type, and occasions for which you purchase flowers in order to offer you better products and services and improve our business
- To analyse customers shopping with us to understand our target audience for the purposes of selecting similar customers for advertising purposes
- To analyse delivery location data you provide when placing your order to understand the delivery logistics required to fulfil the order
- To analyse your responses to our marketing communications
- To ensure our online content is presented in the most effective manner for you and your electronic device(s) i.e. tailored for a desktop computer, tablet, iPhone or Android
- To obtain customer feedback with respect to an order either from you or your recipient (to the extent permitted under the applicable law) to determine the quality of the customer or recipient experience and to improve customer care experiences
- To develop and provide new or improved products or services
- For crime and fraud prevention, detection and related matters, including cooperation with the police and similar authorities with their lawful queries and investigations
- To confirm your identity, as necessary
- To comply with any legal obligation for the purposes of good governance or regulatory guidance with respect to applicable law
- With respect to any legal claims or related guidance by our advisors
- When may you opt out of marketing communications?
You have the right to opt out of receiving direct marketing communications at any time. Your opt out request will be automatically implemented.
You may opt out of marketing communications or change your preferences with respect to marketing communications by:
- Unsubscribing from emails using the unsubscribe link which can be found in all marketing emails
- Updating your preferences within your “My Account”
- Contacting us via the contact information provided in this policy
- How do we protect your personal data?
We are committed to protecting and respecting your privacy rights, and to ensuring that your personal data is safe and secure.
Petal Plan uses Shopify to handle payment card data in a manner consistent with the Payment Card Industry Data Security Standard (PCI-DSS).
- What can you do to protect your personal data?
We will never ask you to confirm any bank account or credit card details in writing or via email. If you receive an email or any other written communication claiming to be from us, asking you to provide this data, please ignore it and do not respond.
If you are using a computing device in a public location, you should always log out and close the website browser when you have finished your online session.
If you create an account with us, you must keep your password private and avoid using the same password for multiple online accounts.
- When might we share your personal data with third parties?
We will share your personal data with certain third parties in order to fulfil and process your order, enable us to perform our contract to provide your purchase to you, provide our Websites and to provide you with marketing. The following is a list of types of third parties that may receive your personal data. Our third party providers are required to handle your personal data in accordance with appropriate data protection and security controls.
Florists/Partners: Petal Plan shares data with our florists who are independently owned and operated businesses. Our florists are our distributors for the purposes of fulfilling and delivering your purchases. Our florists and fulfilment partners may contact the recipient to assist in fulfilling your order. More specifically, on some occasions, you or the recipient may be contacted to schedule delivery or verify delivery information and availability. To maintain our high quality standards, we may contact recipients to ensure satisfaction with their flowers
Market Research Providers: In order to continually improve our customer experience, Petal Plan contracts with third parties who provide market research services which include collating and reporting of customer feedback, and collate and provide customer feedback via customer surveys.
Website Improvement: In order to improve our online customer experience, Petal Plan contracts with third parties who help us identify and make improvements to our website, provide website traffic data and website performance analysis information, and provide analysis on website performance focused on customer experience.
Other third parties: Petal Plan uses Shopify to power our online store. You can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy.
Petal Plan uses Google Analytics to help us understand how our customers use our website -you can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
In addition to the reasons identified above, we may provide your personal data to third parties in the following circumstances:
Law Enforcement/Government Requests: We may be required by law to provide personal data to law enforcement, a government agency or in response to a search warrant, subpoena or other legally valid enquiry or order, or to an investigative body or civil litigant including emergency situations. We may also disclose personal data when we believe in good faith that disclosure is necessary to comply with relevant laws, for the establishment, exercise or defence of legal claims, to prevent and address fraud and other illegal activity, to prevent death or imminent bodily harm, or to protect or defend the rights, property or safety of our users, others and ourselves.
Business and Legal Purposes/Mergers and Acquisitions: There may be business or legal reasons to disclose personal data. As an example, we may transfer data we have about you to third parties in connection with an actual or potential merger, consolidation, acquisition, reincorporation, sale/divestiture, acquisition or other similar transaction involving all or part of our company or any affiliate, or as part of a corporate reorganisation or stock sale or other change in corporate control. If we undergo such a business transition, personal data may be one of the assets that may be shared or transferred as part of the business transition and used by such third party as though such third party were Petal Plan.
- How long do we keep your personal data?
We will only retain your personal data for the purposes set out in this policy and for as long as we have a legal or business requirement to do so. Different retention periods apply for different types of personal data, however, the longest we will normally hold any personal data is 7 years after the last contact with such person or purchase by such person. The time period for retention will depend on applicable laws, rules or regulations that we are required to follow, whether there is an ongoing request or query or other type of legal claim or dispute, the type of information we are holding and whether we are asked by you or a regulatory authority to keep the personal data.
- When might we transfer your personal data abroad?
Your personal data may be sent outside the European Economic Area (EEA), as we use Shopify to process payment and order information.
Consequently, personal data may be processed in what are considered “third countries”. It is important to understand that “third countries” are not automatically deemed by the European Commission to have adequate legal protections for personal data or individual data subject rights.
- Your rights to access your data and rectify any inaccuracies in your personal data
Under certain circumstances, you have rights under data protection laws in relation to your personal data. Please see the appendix to find out more about these rights:
- Request access to your personal data.
- Request correction of your personal data.
- Request erasure of your personal data.
- Object to processing of your personal data.
- Request restriction of processing your personal data.
- Request transfer of your personal data.
- Right to withdraw consent.
If you wish to exercise any of the rights set out above, please contact us.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. We try to respond to all legitimate requests within one month.
- Contact details
Petal Plan can be contacted at:
- Updates to this policy
We may use technology to track the patterns of behaviour of registered and non-registered visitors to our site. This can include using a "cookie" which is a small file stored on your browser. The information collected in this way can be used to identify you unless you modify your browser to prevent this happening - guidance for which is set out below. We also aggregate this data to perform statistical analyses of the characteristics and behaviour of visitors to our Websites. Cookies are also used as a further means of ensuring private and secure purchase sessions are operated within the Website.
We may use third party advertising companies to serve advertisements on our behalf. These companies may employ cookies and action tags (also known as single pixel gifs or web beacons) to measure advertising effectiveness. Any information that these third parties collect via cookies and action tags is completely anonymous. Your browser can be modified to not accept cookies - guidance for which is provided in the paragraph below.
You have the ability to accept or decline cookies by modifying the settings in your browser. However, you may not be able to use all the interactive features of our Website if cookies are disabled. For more information about cookies, including how to set your internet browser to reject cookies, please go to www.allaboutcookies.org.