top of page

Privacy Policy

​Last updated: 31/01/2026

​​

Runecraft Collectables ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you interact with our business, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR / ePrivacy Directive).

This policy applies to our website, online store, social media pages, events, and any other interactions you may have with Runecraft Collectables.

1. Who We Are

Legal name: Robert Tallent T/A Runecraft Collectables
Trading name: Runecraft Collectables
Business type: Sole trader
Email: RunecraftCollectables@Gmail.com
Location: United Kingdom

For the purposes of data protection law, Runecraft Collectables is the data controller.

2. Personal Data We Collect

We may collect and process the following types of personal data:

a) Information You Provide Directly
  • Name

  • Email address

  • Postal address

  • Telephone number

  • Payment and billing details (note: payment details are processed securely by third‑party payment providers; we do not store full card details)

  • Account information (if you create an account)

  • Order history and preferences

  • Communications with us (emails, messages, enquiries, reviews)

b) Information Collected Automatically
  • IP address

  • Browser type and version

  • Device information

  • Pages visited and actions taken on our website

  • Cookies and similar tracking technologies (see Section 9)

c) Information from Third Parties
  • Payment confirmation from payment providers

  • Delivery updates from courier services

  • Platform data from services such as Shopify, Etsy, eBay, or social media platforms (where applicable)

3. How We Use Your Personal Data

We use your personal data for the following purposes:

  • To process and fulfil orders

  • To manage payments, refunds, and returns

  • To communicate with you about your orders or enquiries

  • To provide customer support

  • To improve our website, services, and product offerings

  • To comply with legal and accounting obligations

  • To prevent fraud and ensure site security

  • To send marketing communications only where you have given consent or where permitted under PECR

4. Lawful Bases for Processing (UK GDPR)

We process personal data under the following lawful bases:

  • Contract: Where processing is necessary to fulfil an order or provide a service

  • Legal obligation: Where we are required to comply with UK law (e.g. tax and accounting records)

  • Legitimate interests: To operate and improve our business, prevent fraud, and ensure security (balanced against your rights)

  • Consent: For marketing communications and non‑essential cookies

You may withdraw your consent at any time (see Section 8).

5. Sharing Your Personal Data

We only share personal data where necessary and with trusted third parties, including:

  • Payment processors (e.g. PayPal, Stripe)

  • E‑commerce and website hosting platforms

  • Delivery and courier services

  • Accounting and bookkeeping services

  • IT and security providers

All third parties are required to respect the security of your data and to process it in accordance with UK data protection law.

We do not sell your personal data to third parties.

6. International Data Transfers

Some of our service providers may be located outside the UK. Where personal data is transferred internationally, we ensure appropriate safeguards are in place, such as:

  • UK adequacy regulations

  • Standard contractual clauses

  • Platform‑level compliance measures

7. Data Retention

We retain personal data only for as long as necessary:

  • Order and transaction data: up to 6 years (for HMRC and legal compliance)

  • Customer account data: until account deletion or inactivity

  • Marketing data: until consent is withdrawn

  • Enquiry communications: up to 24 months

Data is securely deleted or anonymised when no longer required.

8. Your Rights Under UK GDPR

You have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request erasure of your data ("right to be forgotten")

  • Restrict processing of your data

  • Object to processing

  • Data portability

  • Withdraw consent at any time

To exercise your rights, please contact us using the details in Section 1.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO): - www.ico.org.uk

9. Cookies and ePrivacy (PECR)

Our website uses cookies and similar technologies.

a) Essential Cookies

Required for the operation of the website (e.g. shopping basket, checkout, security).

b) Non‑Essential Cookies

Used for analytics and performance improvement. These cookies will only be used with your consent, in accordance with PECR.

You can manage or withdraw your cookie consent at any time through your browser settings or our cookie banner.

A separate Cookie Policy may apply.

10. Marketing Communications

We may send marketing emails only where:

  • You have explicitly opted in, or

  • You are an existing customer and the communication relates to similar products or services (soft opt‑in under PECR)

You can unsubscribe at any time using the link in our emails or by contacting us directly.

11. Data Security

We take appropriate technical and organisational measures to protect your personal data, including:

  • Secure hosting and encrypted connections (SSL)

  • Limited access to personal data

  • Regular software and security updates

While no system is completely secure, we work hard to protect your data from unauthorised access, loss, or misuse.

12. Children’s Data

Our products and services are not directed at children under the age of 13. We do not knowingly collect personal data from children.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.

We encourage you to review this policy periodically.

14. Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact:

Runecraft Collectables
Email: RunecraftCollectables@Gmail.com

bottom of page