Privacy Policy

Last updated: 10 January 2026

1. Introduction

SecretPrints Ltd. ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website and services. We comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data Controller

SecretPrints Ltd.
Registered in Ireland
Email: privacy@secretprints.com
Website: www.secretprints.com

3. Information We Collect

3.1 Personal Information

We collect the following types of personal information:

  • Contact Information: Name, email address, shipping address, phone number
  • Payment Information: Processed securely through Stripe (we do not store full payment card details)
  • Order Information: Product selections, order history, preferences
  • Images: Photographs and images you upload for printing
  • Communication Data: Correspondence with our customer service team

3.2 Automatically Collected Information

When you visit our website, we automatically collect:

  • IP address and location data
  • Browser type and version
  • Device information
  • Pages visited and time spent on pages
  • Referring website addresses
  • Cookies and similar tracking technologies (see our Cookie Policy)

4. How We Use Your Information

We use your personal information for the following purposes:

  • Order Processing: To process and fulfill your orders, including printing and shipping
  • Payment Processing: To process payments and prevent fraud
  • Customer Service: To respond to your inquiries and provide support
  • Communication: To send order confirmations, shipping updates, and service-related communications
  • Legal Compliance: To comply with legal obligations and protect our rights
  • Website Improvement: To analyze usage patterns and improve our website and services
  • Marketing: With your consent, to send promotional communications (you can opt-out at any time)

5. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance: To fulfill our contract with you (processing orders)
  • Legal Obligation: To comply with legal requirements (tax, accounting, etc.)
  • Legitimate Interests: To improve our services and prevent fraud
  • Consent: For marketing communications and non-essential cookies

6. Data Sharing and Disclosure

We may share your personal information with:

  • Service Providers: Third-party companies that help us operate our business (payment processors, shipping carriers, cloud storage providers)
  • Legal Requirements: When required by law, court order, or government regulation
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • Protection of Rights: To protect our rights, property, or safety, or that of our users

We do not sell your personal information to third parties. All service providers are contractually obligated to protect your data and use it only for the purposes we specify.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • SSL encryption for data transmission
  • Secure cloud storage with access controls
  • Regular security assessments and updates
  • Limited access to personal data on a need-to-know basis
  • Secure payment processing through Stripe

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

8. Data Retention

We retain your personal information for as long as necessary to:

  • Fulfill the purposes for which it was collected
  • Comply with legal obligations (e.g., tax records for 7 years)
  • Resolve disputes and enforce our agreements

Images uploaded for printing are automatically deleted after order fulfillment, unless you request otherwise or we are required to retain them for legal purposes.

9. Your Rights Under GDPR

As a data subject, you have the following rights:

  • Right of Access: Request a copy of your personal data we hold
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restrict Processing: Request limitation of how we process your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent for processing where consent is the legal basis

To exercise these rights, please contact us at privacy@secretprints.com. We will respond within one month.

10. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Other appropriate safeguards as required by GDPR

11. Children's Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

12. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience. For detailed information about our use of cookies, please see our Cookie Policy.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on our website with a new "Last updated" date. We encourage you to review this policy periodically.

14. Supervisory Authority

If you are located in the EEA and believe we have not addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority. In Ireland, this is:

Data Protection Commission
Canal House, Station Road, Portarlington, Co. Laois, R32 AP23, Ireland
Website: www.dataprotection.ie

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

SecretPrints Ltd.
Email: privacy@secretprints.com
Website: www.secretprints.com