Privacy Policy
This page follows personal information through its lifecycle at Everyday Paper, in the order the events occur: what is collected when you arrive, what happens while you browse and order, how long it is kept and how you can act on it.
Information we collect
The first thing that happens when the site is opened is that technical information is recorded: the kind of device and browser in use, an approximate location derived from the IP address, and which pages are viewed.
Nothing at this stage identifies anyone by name. It is statistical information used to keep the site working and to see, in aggregate, which pages are read and which are ignored.
The second category of information appears only when something is supplied: a name, email address, delivery and billing addresses, a contact number where the carrier requires one, the items purchased and the result of the payment returned by the processor.
Correspondence sent to Everyday Paper is filed against the relevant order, so that a later question can be answered without the customer repeating the history. No special category information, such as health or biometric data, is ever requested.
Optional fields at checkout may be left blank without affecting the order, and required fields are marked as such rather than left to be discovered by rejection.
Cookies and storage
While the site is being used, a small number of cookies and browser storage entries come into play. They fall into two categories, and only one of them is essential.
The essential entries carry the basket and hold the checkout session open. Remove them and the basket clears on every page change, which is why they cannot be disabled from inside the site.
Analytics storage records page views in aggregate, using a random identifier rather than a name or email address. It cannot be joined to an order record, and it is not used to identify anyone personally.
No third-party advertising or retargeting cookies are present. Campaign visits are recorded in aggregate only, and no profile is built that follows a customer to other websites.
Cookies can be blocked in the browser. The pages will still load, but the basket will not survive a change of page and the checkout cannot be finished without essential storage.
Where a customer returns to the site, the analytics identifier may recognise the browser as a previous visitor, but that recognition is statistical rather than personal and does not affect prices or content.
How we use information
Placing an order is the point at which the information stops being statistical and becomes operational. Order details are used to take payment, dispatch the parcel, send delivery updates, handle returns and meet accounting obligations.
Technical information continues to be used in the background to run the site and to detect unusual activity that may indicate fraud rather than a genuine purchase.
Correspondence is used to answer the enquiry and, where it concerns an order, to keep a record of what was agreed so that the next person to read it has the full picture.
What does not happen is equally important: information is not used to build advertising profiles, and it is not sold. Each category is held against one of the purposes above rather than retained on the chance that it becomes useful.
Where a use rests on consent rather than on performing a contract, that consent may be withdrawn at any time, and withdrawal applies to future use rather than to anything already done lawfully.
Who we share it with
Fulfilling an order requires a small number of other companies, and information reaches only those, and only to the extent required.
The recipients are the payment processor, the delivery carrier, the hosting provider and the service that sends confirmation emails. The carrier receives the delivery address and a contact number, not payment details; the processor receives payment information, not order history beyond the amount.
Before appointing any supplier that receives order data, Everyday Paper establishes what that supplier does with the data and how long it retains it, and records the answer. A supplier that cannot meet the required standard is not appointed.
Suppliers are bound by contract to process information only on instruction and to apply appropriate security measures, and a replacement supplier inherits exactly the same restriction.
Information is not sold, is not passed to unrelated marketing lists, and is released to a public authority only where legally compelled. Where disclosure is compelled, the customer is told unless the law prohibits that notification.
Retention periods
Once an order is complete, the information does not simply sit there indefinitely. Each category has a defined period, and it is deleted when that period ends.
Order records, including the delivery address and the items purchased, are kept for seven years to satisfy tax and accounting requirements. Support correspondence is kept for two years, which allows a repeated question to be answered without retaining every message forever.
Analytics stay aggregated so that no individual can be picked out, and a basket that is never ordered disappears on its own after a short interval.
Once a retention period runs out the record is erased rather than merely concealed, and no stale copy is left behind in a system nobody revisits.
While a legal claim is running, the records it touches are kept until it finishes, and the customer is told if that has a bearing on a deletion they asked for.
The periods above are checked from time to time to confirm they still hold and that nothing is kept past the point it is needed.
Security measures
Security applies throughout the lifecycle rather than at a single point. Traffic to the site is encrypted in transit, so what a customer types cannot be read on the network.
Card details are entered on the processor's hosted page and never reach Everyday Paper systems or logs. Access to order data is restricted to the small team that packs and supports orders, each using an individual account rather than a shared credential.
Access rights are reassessed whenever someone joins or leaves that team, and the review is recorded. Patterns that look unusual, such as repeated failed payments from one address, are monitored because they usually indicate card testing rather than genuine customer activity.
No system is perfect, and Everyday Paper does not claim otherwise. Any breach affecting customer information would be investigated and the individuals concerned told what happened and what has been done about it.
The outcome of each security review informs the access rules described above, so that the arrangements stay current rather than being set once and forgotten.
Your rights
At any point a customer may exercise the rights set out here. They are free of charge, no reason needs to be given, and a request is not treated as a complaint or recorded against the customer.
Access: obtain a copy of the personal information held. Rectification: have inaccurate information corrected. Erasure: request deletion of information that is not legally required to be retained.
Objection: object to a specific use, marketing email among them. Portability: obtain the information in a structured format that is widely used.
A request is answered within 30 days, and where it is complex the customer is told why it is taking longer rather than the deadline passing in silence.
If a request cannot be met in full, the rule standing in the way is named and the remaining options are set out, instead of a flat refusal.
The team that answers order enquiries also handles data requests, so whoever replies can already see the order record in question.
Children
The site is intended for adults, and that shapes how information is handled for younger visitors.
Information is not knowingly collected from a child under 13, and no advertising is directed at children. No account, mailing list or prize draw aimed at children is operated, and the checkout does not ask anyone to state an age.
Where an item is purchased for a child, the order is placed by an adult and the contact details held are those of that adult rather than of the child.
A parent or guardian may exercise any of the rights above on a child's behalf, and requests of that kind are handled in the same way, and within the same 30-day period, as any other.
Photographs sent in connection with a sizing or fitting enquiry are used only to answer that enquiry and are never published, used in advertising or passed to another party.
An age range shown on a product page speaks to safe use of the item, not to who is entitled to buy it.
Privacy contact
The final stage is contact. Write to support@giselleoutlet.shop with the word privacy in the subject line, together with a statement of what is being requested.
No particular form of words is required. A short email setting out what the customer wants done is sufficient, and anything further that is needed will be asked for in reply.
A response is provided within one working day, and formal requests are answered within 30 days. Identity may be verified before information is released or deleted, so that it cannot be obtained by someone impersonating the customer.
A customer unhappy with the answer may ask for it to be looked at again, and will be told which member of staff dealt with it originally.
Should the handling of personal information change in substance, the new text appears on this page with the revision date at the top.
Where a request cannot be granted, the rule preventing it is identified and the available options explained, so the customer is not left without a route forward.