Data Protection Policy - Privacy Policy
Last updated: 16th August 2026
Titan Jewellery Ltd is committed to handling personal data lawfully, fairly and securely. This policy explains what personal information we collect, why we collect it, how long we keep it and your rights under UK GDPR and the Data Protection Act 2018.
1. Who we are
Titan Jewellery Ltd
Data Controller: Titan Jewellery Ltd
Data protection contact: Jason Beer
Our address is shown on the “About Us” page and on all invoices.
Website: https://www.titanjewellery.co.uk
2. What this policy covers
This policy applies to:
• Customers placing orders
• People contacting us
• People booking consultations
• Suppliers
• Anyone interacting with our website
It explains:
• What personal data we collect
• How we use it
• Our lawful bases for processing
• How long we keep it
• Who we share it with
3. What data we collect
We collect the information needed to process and deliver your order:
• Name
• Billing address
• Delivery address
• Email address
• Telephone number
• Items ordered
• Payment method or reference, but not full card details
We may also store optional details you give us, such as engraving instructions, personalisation details or delivery notes.
If you contact us, we may store your name, email address and any information included in your message.
We do not require customers to create an online account. Accounts are optional and, if created, allow customers to view their own order history on the website.
Engraving and personalisation
If you request engraving or personalisation, we store the text, symbols, design instructions and other information you choose to provide so that we can produce and fulfil your order.
Engraving fields allow free-text entry and you are free to choose the content you wish to have engraved. This may include names, dates, personal messages, health or medical information, or other personal or sensitive information chosen and supplied by you.
We process engraving and personalisation information only for producing, administering and keeping a record of the personalised order. We do not use the content of your engraving for marketing, profiling or other unrelated purposes.
Consultation bookings
If you book a consultation, we may collect and store your name, email address, telephone number, optional address, the service requested, consultant, preferred contact method, appointment date and time, interests or requirements selected on the booking form, any message you provide, booking status and any cancellation reason.
We may also keep notes relating to the consultation, including questions discussed, advice provided and any follow-up information.
This information is used to arrange and provide the consultation, send appointment communications and reminders, provide the advice or service requested and keep an appropriate record of the consultation.
Free-text booking fields may contain additional information that you choose to provide.
Consultation call recordings
With your permission, we may record a consultation call. We will always ask before recording.
Where a consultation is recorded, the recording may be used to produce a written summary of the topics discussed, questions asked and advice provided, and to help us identify common customer questions and improve our consultation service.
The original recording is deleted within 7 working days. The written summary may remain as part of the consultation booking record for the retention period described in Section 8.
Other telephone calls
Telephone calls are not routinely recorded, other than in the exceptional circumstances described below.
We may record a call where reasonably necessary for security, to protect our staff or business, or to retain evidence relating to a serious complaint, threat or dispute.
4. Online payments
Payments are processed securely by our payment service providers:
• PayPal
• Bank of Scotland
• WooPayments, powered by Stripe
These providers use appropriate payment-security measures. You enter your card details directly with the relevant payment provider. We never see your full card number or CVC.
We may receive limited payment information such as:
• The last 4 digits of the card and expiry date
• A payment or transaction reference
5. Why we process personal data
We process personal data under the following lawful bases:
• Contract – to take your order, produce personalised or engraved goods using the information you provide, arrange and provide requested consultations, send appointment communications and reminders, supply goods and contact you about delivery or queries.
• Legal obligation – to keep appropriate accounting and invoice records for tax and other legal requirements.
• Legitimate interests – to operate and protect our website, provide customer support, maintain appropriate records of consultations and advice, prevent fraud, spam or misuse, improve our services, protect our staff and business, deal with serious complaints or disputes, and carry out limited analytics where consent is not required.
• Consent – where you agree to an optional consultation call being recorded, and where consent is required for analytics or advertising technologies.
Where you choose to include health, medical or other sensitive information in engraving or personalisation instructions, we process that information only as part of your specific instruction to produce and administer the personalised item you have requested.
6. Cookies, analytics and advertising
Our website uses essential cookies so the shopping basket, checkout and other necessary website functions can work.
If you consent, we use Google Analytics 4 (GA4) to understand how visitors use our website. Analytics cookies are non-essential under PECR and only load where the relevant consent has been given.
We also use Google Ads conversion tracking to understand whether our advertising results in visits, enquiries or purchases. Google advertising technologies may use cookies or other identifiers where the relevant consent has been given.
Google Consent Mode is used so that Google services adjust their behaviour according to your cookie and advertising choices.
Form security
Some forms on our website use Google reCAPTCHA to help prevent spam and automated abuse. reCAPTCHA may process technical information about your browser and device and may use cookies or similar technologies for security and risk analysis. reCAPTCHA is provided by Google and is subject to Google’s privacy policy and terms.
Engraving preview tool
Our website offers a 3D engraving preview tool that lets you design and share an engraving on a ring.
When someone opens a shared design link, we record the design content, including the text and font selected, metal and ring orientation, together with the device type, operating system and browser used to view it, for example iOS Safari on mobile.
This is used to understand how the tool is being used and to help us support customers who contact us about a specific design.
The engraving preview tool does not store your IP address, name, location, email address or any other identifying information as part of the design record. The lawful basis is legitimate interests for analytics and customer support.
Engraving preview analytics records are deleted automatically after 90 days without a further view of the shared design.
If your design contains personal information you have entered into the engraving text, that information will form part of the preview record for that period. To request earlier deletion of a specific design record, contact us with the share link and we will delete it within 30 days.
This retention period relates to the engraving preview analytics record only. Engraving instructions submitted as part of an actual order form part of the order record and are retained as described in Section 8.
For full details, see our Cookie Policy on our website.
You can change or withdraw your cookie consent at any time using the cookie settings on our website.
7. How your data is stored
Personal data is stored securely:
• Electronic records are protected using appropriate technical and organisational security measures, including encryption where appropriate.
• Printed invoices are kept in secure storage with restricted access.
• Old computer hard drives are removed and destroyed before disposal.
8. How long we keep your data
We keep order and invoice records for 7 years for accounting, tax and legal purposes. After that they are securely deleted or destroyed.
Engraving and personalisation instructions form part of the relevant order record and may therefore also be retained for up to 7 years. This includes any personal or sensitive information that you have chosen to include in the engraving instructions.
For consultation bookings, direct contact details stored in the booking system are removed after 6 months. The remaining booking record is deleted after 30 months, unless information needs to be retained for longer because of an unresolved complaint, dispute or legal requirement.
Where a consultation call is recorded with your permission, the original recording is deleted within 7 working days. Any written consultation summary is retained as part of the booking record and follows the consultation retention period above.
Any exceptional recording of another telephone call is retained only for as long as reasonably necessary for the security, complaint, threat or dispute for which it was made, and is then deleted.
Engraving preview analytics records are subject to the separate retention period described in Section 6.
If you join a mailing list, currently not active, you can unsubscribe at any time.
9. Your rights
Under the UK GDPR, you have the right to:
• Access your personal data
• Correct inaccurate or incomplete data
• Request deletion when data is no longer needed
• Request restriction of processing in certain circumstances
• Object to processing based on legitimate interests
• Request data portability where applicable
• Withdraw consent where processing is based on consent
• Complain to the Information Commissioner’s Office (ICO)
These rights may be subject to legal limitations. For example, we may need to retain certain information where we have a legal obligation to keep it.
To exercise any rights, contact us using the details on our website.
10. Accessing your data
We can provide a copy of the personal data we hold. We may ask for proof of identity to ensure data is sent to the correct person.
Data protection enquiries should be made using the contact details shown on our website.
11. Who we share your data with
We only share personal data where necessary to operate our website, provide our services, process and deliver orders, meet legal obligations, prevent fraud or protect our systems.
Payment processors:
PayPal, Bank of Scotland and WooPayments, powered by Stripe.
Delivery services:
Royal Mail, Post Office Counters and Parcelforce.
Review platform:
Codepath Ltd / CusRev.
Only limited information required for the review service is shared, such as the reviewer name, or an anonymised name, and reviewer location, or an anonymised location.
Website security and delivery:
Cloudflare.
Cloudflare provides website security, traffic filtering, content delivery and performance services. In providing these services, Cloudflare may process technical information about website visitors, including IP addresses and information about requests made to our website.
Website hosting and infrastructure:
Kinsta Inc.
Kinsta provides our website hosting, security, performance monitoring, analytics, technical support and related infrastructure. In providing these services, Kinsta may process website and customer data on our behalf and may use approved subprocessors for services including hosting, security, analytics and AI-powered technical tools.
Analytics, advertising and form security:
Google.
Google provides services including Google Analytics 4, Google Ads conversion tracking and Google reCAPTCHA. Depending on your consent choices and the service being used, Google may process technical, browser, device and website usage information.
Consultation communications:
WhatsApp, a Meta service.
If you choose WhatsApp for a voice or video consultation, the call is normally live only and Titan Jewellery does not retain the audio or video. Basic call history, such as the date and time of the call, may remain visible within WhatsApp and is also subject to WhatsApp’s own privacy terms.
Some of our service providers, including Cloudflare, Kinsta, Google and Meta/WhatsApp, may process personal data outside the United Kingdom. Where required, appropriate safeguards or applicable UK data-transfer arrangements are used in accordance with UK data protection law.
Accountants and professional advisers:
We may share order and invoice records with our accountant or other professional advisers where necessary for accounting, tax, legal or regulatory purposes.
We may share information with law enforcement or other authorities where required by law, or where necessary in connection with fraud prevention or a payment investigation such as a chargeback.
We do not sell or trade personal data.
12. CCTV
CCTV is used at our premises for security purposes. Footage is retained for approximately 30 days before being overwritten, unless there is a reason to retain it for longer. Access is restricted to directors only.
13. Data breaches
If a data breach occurs that risks your rights or freedoms, we will notify the Information Commissioner’s Office (ICO) and contact affected individuals where required.








