Privacy policy

Last updated: 19th January 2026

This Privacy Policy explains how we collect, use, share, and protect your personal data when you visit or shop on themagicbazaar.com (the “Site”), and when you contact us or interact with our services.

If you have any questions, contact us at:
Email: info@themagicbazaar.com
Address: Elsie Whiteley Innovation Centre, Hopwood Lane, Halifax, HX1 5ER

1) Who we are (Data Controller)

For the purposes of UK data protection law, we are the data controller of your personal data.

 

2) The personal data we collect

We may collect and process the following categories of personal data:

a) Information you give us

  • Account details: name, email, password (encrypted)
  • Order details: billing/shipping address, phone number, items purchased, order notes
  • Payment information: we do not store full card details; payments are processed by our payment provider (see Section 7)
  • Customer support: messages you send us, complaint details, returns information
  • Marketing preferences: whether you opt in/out

b) Information collected automatically

  • Device and usage data: IP address, browser type, pages visited, time spent, referral source
  • Cookies/analytics identifiers: see Section 10

c) Information from third parties

  • Payment providers (confirmation of payment status)
  • Delivery partners (delivery status)
  • Fraud prevention providers (risk scoring and verification)

3) How we use your personal data

We use your personal data to:

  • Provide the Site and fulfil orders (process orders, deliver products, manage returns/refunds)
  • Manage your account (create/login, store addresses, view order history)
  • Customer service (respond to enquiries, resolve issues)
  • Improve our Site (analytics, testing, performance)
  • Security and fraud prevention (detect suspicious activity, protect accounts)
  • Legal compliance (tax, accounting, consumer law requirements)
  • Marketing (only where permitted and in line with your preferences)

 

4) Lawful bases for processing (UK GDPR)

We rely on the following lawful bases:

  • Contract: to process and deliver your order, manage returns/refunds
  • Legal obligation: for tax, accounting, and consumer law requirements
  • Legitimate interests: to improve our Site, prevent fraud, secure our services (balanced against your rights)
  • Consent: for certain marketing and non-essential cookies (where required)

5) Marketing communications

If you opt in (or where permitted under “soft opt-in” for existing customers), we may send you marketing emails about products, offers, or updates.

You can unsubscribe at any time by using the link in our emails or contacting us at info@themagicbazaar.com.

We will not sell your personal data to third parties for their marketing.

6) Orders, payments and security

Payments are handled securely by third-party payment processors. We do not store full payment card details on our servers.

We take reasonable technical and organisational measures to protect personal data, including access controls, encryption where appropriate, and secure hosting.

 

7) Who we share your personal data with

We only share personal data where necessary, including with:

  • Payment providers: e.g. Stripe / PayPal / Square (as applicable)
  • Ecommerce/website platform: e.g. Shopify / WooCommerce / Squarespace (as applicable)
  • Delivery/courier providers: e.g. Royal Mail / DPD (as applicable)
  • IT and hosting providers: website hosting, email services, support tools
  • Analytics providers: e.g. Google Analytics (see cookies)
  • Professional advisers: accountants, insurers, solicitors (where required)
  • Authorities/regulators: where required by law

All service providers are required to protect your data and only use it for specified services.

8) International transfers

Some service providers may store or process personal data outside the UK. Where this happens, we ensure appropriate safeguards are in place (such as UK Addendum/Standard Contractual Clauses) to protect your personal data.

 

9) How long we keep your personal data

We keep personal data only as long as necessary:

  • Orders and invoices: typically 6 years for tax and accounting records
  • Customer service enquiries: typically up to 24 months after resolution
  • Marketing records: until you unsubscribe or we determine they are no longer relevant
  • Analytics data: per provider settings and retention policies

We may retain certain data longer if required by law or to resolve disputes.

10) Cookies and similar technologies

We use cookies and similar technologies to:

  • make the Site work (essential cookies)
  • remember preferences
  • analyse Site traffic and performance
  • support marketing (only where enabled)

You can manage cookie preferences via [Cookie Banner/Settings Link] and browser settings.

If you use Google Analytics, you can also use Google’s opt-out tools where available.

11) Your data protection rights (UK)

Depending on your circumstances, you may have the right to:

  • access your personal data
  • correct inaccurate data
  • request deletion
  • restrict processing
  • object to processing (including marketing)
  • data portability
  • withdraw consent (where processing is based on consent)

To exercise your rights, contact us at info@themagicbazaar.com.

You also have the right to complain to the Information Commissioner’s Office (ICO):
ico.org.uk

12) Children’s privacy

Our Site is not intended for children under 13 (or the relevant age in your jurisdiction). We do not knowingly collect personal data from children.

13) Third-party links

Our Site may include links to third-party websites. We are not responsible for their privacy practices. Please review their policies before providing personal data.

14) Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post changes on this page and update the “Last updated” date.