PRIVACY POLICY
roosma.com
Last updated: 28 March 2026
1. Introduction
Welcome to roosma.com. We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you visit or make a purchase from our website.
Please read this policy carefully. By using our website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please do not use our website.
2. Who We Are (Data Controller)
Roosma.com is the data controller responsible for your personal data. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller is:
Company: Roosma Ltd
Company number: 16149621 (registered in England and Wales)
Address: 220 Legrams Lane, Bradford, BD7 2EH, United Kingdom
Website: roosma.com
Email: hello@roosma.com
If you have any questions about this Privacy Policy or our data practices, please contact us using the details above or those provided in Section 17 of this policy.
3. What Personal Data We Collect
We collect and process the following categories of personal data:
3.1 Information You Provide to Us
- Full name
- Email address
- Billing address and delivery/shipping address
- Phone number
- Account login credentials (username and encrypted password)
- Order history and preferences
- Communications you send to us (e.g. enquiries, support requests)
3.2 Payment Information
All payment transactions on our website are processed securely by WooPayments, with Stripe, Inc. as the underlying payment processor. We do not store your full card details on our servers. Stripe may collect and process payment card data, billing addresses, and fraud-prevention data directly. Please refer to Stripe’s Privacy Policy for details of their data practices.
3.3 Technical & Usage Data
When you visit our website, we may automatically collect certain technical data, including:
- IP address
- Browser type and version
- Device type and operating system
- Pages visited and time spent on each page
- Referring website (where you came from)
- Date and time of your visit
3.4 Cookie Data
We use cookies and similar tracking technologies to enhance your experience on our website. Please see Section 11 (Cookies) for full details.
4. How We Collect Your Data
We collect personal data through the following means:
- Directly from you when you create an account, place an order, complete a checkout form, or contact us
- Automatically through cookies and tracking technologies when you browse our website
- Through third-party services such as Stripe (payment processing) and WordPress/WooCommerce analytics
5. How We Use Your Personal Data
We use your personal data for the following purposes:
- Order Fulfilment: Processing and fulfilling your orders, including sending confirmation and dispatch notifications
- Account Management: Managing your customer account and login credentials
- Payment Processing: Processing payments and refunds securely via Stripe
- Customer Support: Responding to your enquiries, complaints, or support requests
- Transactional Communications: Sending transactional emails (e.g. order confirmations, shipping updates)
- Marketing: Sending marketing emails and promotional offers where you have given consent or we have a legitimate interest (you can opt out at any time)
- Website Improvement: Improving our website performance, product offerings, and user experience
- Fraud Prevention & Security: Detecting and preventing fraud, abuse, and security incidents
- Legal Compliance: Complying with our legal and regulatory obligations
6. Legal Basis for Processing (UK GDPR)
Under the UK GDPR, we rely on the following legal bases to process your personal data:
- Contract (Article 6(1)(b)): Processing your orders and managing your customer account. We need your data to fulfil the contract with you
- Legitimate Interests (Article 6(1)(f)): Improving our services, fraud prevention, and sending marketing to existing customers. We have a legitimate business interest in doing so, balanced against your rights
- Consent (Article 6(1)(a)): Sending marketing communications to new contacts or using non-essential cookies. We will ask for your explicit consent, which you can withdraw at any time
- Legal Obligation (Article 6(1)(c)): Retaining financial records and complying with applicable UK law
7. Who We Share Your Data With
We do not sell your personal data to third parties. We may share your data with trusted third parties only as necessary and in accordance with this policy:
- WooPayments & Stripe (Payment Processing): Automattic, Inc. (WooPayments) and Stripe, Inc., to process your payments securely. Stripe operates as an independent data controller for payment data. Please review Stripe’s Privacy Policy at stripe.com/gb/privacy
- WooCommerce / WordPress: WooCommerce / Automattic, Inc., our ecommerce platform, which powers order management, product listings, and customer accounts
- Hosting Providers: Hosting and infrastructure providers, who host and operate our website on our behalf
- Email Providers: Email service providers, used to send you order confirmations and communications
- Shipping Couriers: Delivery and logistics partners, who fulfil and ship your orders (your name and address will be shared as necessary)
- Legal & Regulatory Bodies: Regulatory authorities, law enforcement, or courts, where we are legally required to disclose your data
All third-party service providers are required to process your data only on our instructions and in compliance with applicable data protection laws.
8. Payment Processing (WooPayments & Stripe)
All card payments on roosma.com are processed by WooPayments (provided by Automattic, Inc.) using Stripe, Inc., a PCI-DSS compliant payment processor, as the underlying payments infrastructure. When you make a purchase, you will enter your payment details directly into Stripe’s secure payment form. We never receive or store your full card number, CVV, or expiry date on our systems.
Stripe may process your data in the United States and other countries. Stripe implements appropriate safeguards, including Standard Contractual Clauses, to protect transfers of personal data outside the UK. For more information, please visit:
9. International Data Transfers
Some of our third-party service providers (including Stripe and Automattic/WooCommerce) are based outside the United Kingdom. When we transfer your personal data internationally, we ensure that appropriate safeguards are in place, such as:
- UK adequacy decisions
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner’s Office (ICO)
- Other lawful transfer mechanisms under the UK GDPR
10. How Long We Keep Your Data
We retain your personal data only for as long as necessary to fulfil the purposes set out in this policy, or as required by law. Our general retention periods are:
- Order and financial records: Retained for 6 years after the end of the tax year in which the transaction occurred, in accordance with HMRC requirements
- Customer account data: Retained while your account remains active, and for up to 2 years after your last login or purchase
- Marketing preferences and communications: Retained for up to 2 years from the date of your last communication
- Technical and usage data: Retained for up to 12 months
When your data is no longer required, we will securely delete or anonymise it.
11. Cookies
Our website uses cookies (small text files stored on your device) to provide core functionality and improve your experience. We use the following types of cookies:
- Strictly Necessary Cookies: Essential for the website to function (e.g. shopping cart, login session). These cannot be disabled.
- Analytics Cookies: Help us understand how visitors interact with our website (e.g. pages visited, time on site). We use this data in aggregate to improve our website.
- Functional Cookies: Used by WooCommerce to remember items in your cart, your login status, and your preferences.
- Payment & Security Cookies: Used by Stripe to detect fraudulent activity and ensure secure payment processing.
You can manage or disable non-essential cookies through your browser settings or our cookie consent banner. Please note that disabling certain cookies may affect the functionality of our website.
12. Your Rights Under UK GDPR
As a UK resident, you have the following rights regarding your personal data:
- Right of Access: To obtain a copy of the personal data we hold about you
- Right to Rectification: To correct any inaccurate or incomplete personal data
- Right to Erasure (‘Right to be Forgotten’): To request that we delete your personal data in certain circumstances
- Right to Restriction of Processing: To request that we restrict the processing of your data in certain circumstances
- Right to Data Portability: To receive your personal data in a structured, machine-readable format and transmit it to another controller
- Right to Object: To object to processing based on legitimate interests or for direct marketing purposes
- Right to Withdraw Consent: To withdraw your consent at any time where processing is based on consent (this will not affect the lawfulness of processing before withdrawal)
- Right to Lodge a Complaint: To lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk
To exercise any of these rights, please contact us at hello@roosma.com. We will respond within one calendar month of receiving your request. We may need to verify your identity before fulfilling your request.
13. Data Security
We take the security of your personal data seriously. We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, alteration, or disclosure. These measures include:
- SSL/TLS encryption for all data transmitted through our website (HTTPS)
- Secure, encrypted storage of passwords (your password is never stored in plain text)
- Restricted access to personal data: only authorised personnel can access your data
- Use of PCI-DSS compliant payment processing via Stripe
- Regular software updates and security patches to our WordPress and WooCommerce installation
While we take all reasonable steps to protect your data, no transmission over the internet is entirely secure. You use our website at your own risk in this respect.
14. Children’s Privacy
Our website is not directed at children under the age of 13, and we do not knowingly collect personal data from children. If you believe that a child has provided us with personal data without parental consent, please contact us and we will take steps to delete such data promptly.
15. Third-Party Links
Our website may contain links to third-party websites. This Privacy Policy applies solely to roosma.com. We are not responsible for the privacy practices of any third-party sites. We encourage you to read the privacy policy of any website you visit.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the ‘Last updated’ date at the top of this page. We encourage you to review this policy periodically.
Your continued use of our website after any changes constitutes your acceptance of the updated policy.
17. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:
Company: Roosma Ltd
Company number: 16149621 (registered in England and Wales)
Address: 220 Legrams Lane, Bradford, BD7 2EH, United Kingdom
Website: roosma.com
Email: hello@roosma.com
You also have the right to make a complaint to the UK’s data protection supervisory authority:
Information Commissioner’s Office (ICO)
ICO Helpline: 0303 123 1113
This Privacy Policy was last reviewed and updated on 28 March 2026.
roosma.com is committed to protecting your privacy in accordance with UK GDPR and the Data Protection Act 2018.