Privacy Policy

Last updated: 30 November 2025

This Privacy Policy explains how Cozee London (“Cozee London”, “we”, “us”, “our”) collects and uses your personal data when you visit or make a purchase from cozeelondon.com (the “Site”), or otherwise interact with us online or by email.

We are committed to protecting your privacy and complying with our obligations under:

  • The UK General Data Protection Regulation (“UK GDPR”);
  • The Data Protection Act 2018; and
  • The Privacy and Electronic Communications Regulations 2003 (“PECR”).

1. Who we are and how to contact us

For the purposes of UK data protection law, Cozee London is the data controller of your personal data.

  • Business name: Cozee London
  • Postal address: Cozee London (C/o Beige Plus Fashions Ltd) St. Albans House, St. Albans Lane, NW11 7QE, London, England
  • Email: support@cozeelondon.com

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at support@cozeelondon.com.

You have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection (see ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us first.


2. The personal data we collect

The exact data we collect will depend on how you interact with us (for example, browsing, placing an order, creating an account, or contacting customer support). Similar online jewellery retailers collect comparable categories of data for these purposes. 

2.1 Information you provide directly

When you use the Site or communicate with us, you may provide:

  • Identity and contact details – name, title, billing and delivery address, email address, telephone number.
  • Order and transaction information – products ordered, purchase date and time, order value, payment confirmation, delivery method and tracking information.
  • Account information – if you create an account, we may process your login details (email and password) and your saved preferences.
  • Marketing preferences – whether you wish to receive marketing emails, your newsletter subscription status, competition entries and survey responses.
  • Customer service information – information you provide when you contact us for support, complaints or enquiries (including email content and any attachments).
  • User-generated content – product reviews, ratings, comments, or photos you choose to submit or post on our channels.

You are not obliged to provide personal data, but if you choose not to, some services (such as processing an order or responding to a query) may not be available.

2.2 Information we collect automatically

When you visit the Site, we automatically collect certain technical and usage data using cookies and similar technologies, as is standard for modern e-commerce sites. 

This may include:

  • Device information (IP address, browser type and version, operating system, device identifiers).
  • Log data (pages viewed, time and date of access, referring website, time spent on pages, click-throughs).
  • Approximate location data derived from your IP address.
  • Cookie identifiers and similar tracking IDs.

For more information, see Section 5 – Cookies and similar technologies.

2.3 Information we receive from third parties

We may receive personal data about you from third parties, for example: 

  • E-commerce platform provider (for example, Shopify) – which powers our store and helps us manage orders, payments, analytics and customer communications.
  • Payment service providers – who process card and other payments on our behalf and may provide information to help us prevent fraud and verify transactions.
  • Delivery and logistics partners – who share delivery updates and confirmation or issues relating to shipment.
  • Analytics and advertising partners – who help us understand how people use our Site and measure the effectiveness of our marketing and adverts.
  • Social media platforms – if you interact with us via social media tools, we may receive profile information and engagement data in line with your platform settings.

We treat any such data in accordance with this Privacy Policy and applicable law.


3. Purposes and legal bases for processing

We only process your personal data where we have a valid legal basis under UK GDPR. The main purposes and legal bases are:

3.1 To set up and manage your account

  • Data: identity data, contact details, login details, preferences.
  • Legal basis: performance of a contract (Article 6(1)(b) UK GDPR) – to provide an account at your request.

3.2 To process and deliver your orders

  • Data: identity and contact details, order details, payment confirmation, delivery details, communications about the order.
  • Legal bases:
    • Performance of a contract (to process payment, fulfil your order and manage returns/exchanges).
    • Legal obligation (for tax and accounting purposes).

3.3 To provide customer service

  • Data: identity and contact details, account and order details, communications, complaints and query history.
  • Legal bases:
    • Performance of a contract (to respond to your queries regarding an order).
    • Legitimate interests (Article 6(1)(f) UK GDPR) – to provide good customer service and improve our business.

3.4 To send you marketing communications

  • Data: identity and contact details, marketing preferences, purchase and browsing history where relevant.
  • Legal bases:
    • Consent (Article 6(1)(a) UK GDPR) where required by PECR, for example when you sign up to our newsletter.
    • Legitimate interests, in limited cases where PECR allows a “soft opt-in” (for example, where you are an existing customer and we contact you about similar products, and you have been given a clear opportunity to opt out).

You can opt out of marketing at any time (see Section 8).

3.5 To personalise your experience and improve our Site

  • Data: technical data, usage data, purchase history, cookie data.
  • Legal basis: legitimate interests – to understand how customers use our Site, improve usability, and develop new products and services. Comparable retailers use analytics and personalisation for the same reasons.

Where required under PECR (for non-essential cookies or certain analytics/advertising cookies), we will obtain your consent before placing such cookies.

3.6 To prevent fraud and keep our Site secure

  • Data: identity data, order and payment data, technical and usage data.
  • Legal bases:
    • Legitimate interests – to prevent fraud and misuse of our Site and services.
    • Legal obligation – where we are required to cooperate with law enforcement or regulatory bodies.

3.7 To comply with legal and regulatory obligations

  • Data: order records, payment data, communications, identification data.
  • Legal basis: compliance with our legal obligations (for example, tax, accounting, and consumer protection laws).

3.8 To manage our business, including potential corporate transactions

  • Data: any relevant categories as reasonably required.
  • Legal basis: legitimate interests – to run and protect our business, maintain appropriate records, and consider corporate transactions such as a restructuring, sale of assets or business.

4. Sharing your personal data

We do not sell your personal data. We may share it with:

  • Service providers and processors – including our e-commerce platform provider (for example, Shopify), payment providers, IT and hosting providers, email and marketing platforms, and analytics providers, who act on our instructions and are bound by appropriate contractual safeguards.
  • Delivery and logistics partners – to deliver your order and manage returns.
  • Professional advisers – such as lawyers, accountants and auditors, where necessary.
  • Regulators and authorities – where required by law, court order or to protect our rights or the rights of others.
  • Potential buyers or investors – in connection with a merger, acquisition, or other corporate transaction, subject to confidentiality.

Where another entity acquires us or our assets, personal data may be transferred to that entity as part of the transaction, subject to applicable law.


5. Cookies and similar technologies

Like many online stores, we use cookies and similar technologies to:

  • Enable core Site functionality (for example, your shopping basket, checkout, account login).
  • Remember your preferences (such as currency and language).
  • Understand how visitors use the Site and improve performance.
  • Support marketing and advertising, including showing you relevant products and offers.

Our store is powered by Shopify, an e-commerce platform that uses cookies as part of its service; further details of those platform cookies can be found in that provider’s own cookie information. 

Where required by PECR, we will obtain your consent before setting non-essential cookies (for example, for certain analytics and advertising purposes). You can manage cookies by:

  • Using the cookie banner or settings tool on our Site (where available); and/or
  • Adjusting your browser settings to block or delete cookies.

Please note that disabling certain cookies may affect how the Site functions.


6. International transfers

Some of our service providers may be located, or may store data, outside the UK and European Economic Area (EEA) (for example, cloud hosting or support services). Similar e-commerce brands rely on such providers for global operations. 

Where personal data is transferred outside the UK/EEA, we will ensure that one of the following applies:

  • The destination country has been deemed to provide an adequate level of protection by the UK Government or European Commission; or
  • We have implemented appropriate safeguards, such as standard contractual clauses approved by the relevant authority; or
  • Another appropriate safeguard under UK data protection law is in place.

You can contact us at support@cozeelondon.com for more information about the safeguards used for international transfers.


7. Data retention

We will only keep your personal data for as long as reasonably necessary for the purposes set out in this Privacy Policy, including:

  • Orders and purchase records: typically up to 7 years after the end of the relevant financial year, to comply with tax and accounting obligations.
  • Customer service records: usually up to 6 years after resolution of your query or complaint, to respond to potential disputes.
  • Marketing data: until you withdraw your consent or opt out, or we conclude you are no longer engaged.
  • Technical and analytics data: for shorter periods that are necessary for analysis and site security (commonly 12–24 months), unless a longer period is required for security or legal reasons.

In all cases, we will retain data only for as long as necessary, after which it will be securely deleted or anonymised.


8. Marketing communications

We may send you marketing communications by email about our products, offers and news where:

  • You have actively consented (for example, by ticking a box to join our mailing list); or
  • You purchased from us previously and we rely on the “soft opt-in” permitted under PECR for similar products, and you have not opted out.

You can opt out of marketing at any time by:

  • Clicking the “unsubscribe” link in any marketing email; or
  • Contacting us at support@cozeelondon.com.

If you opt out, we will stop sending marketing communications, but we may still send service messages relating to orders, account changes or legal notices.


9. Your rights

Under UK data protection law, you have the following rights (subject to certain conditions and exceptions):

  1. Right of access – to obtain confirmation of whether we process your personal data and to receive a copy.
  2. Right to rectification – to have inaccurate or incomplete personal data corrected.
  3. Right to erasure – to request deletion of your personal data in certain circumstances (the “right to be forgotten”).
  4. Right to restriction – to have the use of your data restricted in certain circumstances.
  5. Right to data portability – to receive certain data in a structured, commonly used and machine-readable format, and to transmit it to another controller.
  6. Right to object – to processing based on legitimate interests (including profiling) and to direct marketing at any time.
  7. Right not to be subject to automated decision-making, including profiling, which produces legal or similarly significant effects on you, in certain circumstances.
  8. Right to withdraw consent – where we rely on consent, you can withdraw it at any time (this will not affect the lawfulness of processing based on consent before its withdrawal).

You can exercise any of these rights by contacting us at support@cozeelondon.com. We may need to request specific information from you to help us confirm your identity and ensure your rights are exercised securely.

We aim to respond to all legitimate requests within one month, or within any extended period permitted by law for complex requests.

You also have the right to lodge a complaint with the ICO (see ico.org.uk) if you are unhappy with how we process your personal data. 


10. Third-party links and social media

Our Site may contain links to third-party websites, plug-ins and applications (such as Instagram or TikTok). Clicking on those links or enabling those connections may allow third parties to collect or share data about you. 

We do not control these third-party sites and are not responsible for their privacy statements. We encourage you to read the privacy policy of every website and service you visit.


11. Children

Our Site and products are not intended for children under 13, and we do not knowingly collect personal data relating to children under this age.

If you believe that a child under 13 has provided personal data to us, please contact support@cozeelondon.com. We will take steps to delete such data in accordance with applicable law.


12. Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction or damage. These measures are aligned with industry practice among reputable online retailers. 

However, no website, internet transmission, or data storage system can be guaranteed to be 100% secure. You are responsible for keeping any account credentials confidential and for using a secure connection when accessing our Site.


13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example to reflect changes in our practices, the services we offer, or legal requirements. 

When we do so, we will:

  • Post the updated version on this page; and
  • Update the “Last updated” date at the top of the policy.

We encourage you to review this Privacy Policy periodically to stay informed about how we collect and use personal data.


14. How to contact us

If you have any questions about this Privacy Policy, your personal data, or wish to exercise any of your rights, please contact us:

  • Email: support@cozeelondon.com

Post: Cozee London, (℅ Beige Plus Fashions Ltd) FAO Eva Stefanidou St. Albans House, St. Albans Lane, NW11 7QE, London, England