What we collect and why
Privacy policy
Last updated: 9 August 2026
This policy explains what personal information WardaNasir collects when you visit our shop or place an order, what we do with it, and the rights you have over it. It applies to wardanasir.online and any order placed through it.
The data controller is WardaNasir, 73 Holburn Street, Aberdeen, AB10 6BR, United Kingdom. You can reach us at mustafabusiness2001@hotmail.com.
What we collect
When you place an order
- Name, delivery address, billing address
- Email address and phone number
- Order contents and order history
- Payment confirmation — we never see or store your full card number. Card details go directly to our payment processor.
When you browse the shop
- Device type, browser, operating system
- IP address and rough location (country/city level)
- Pages viewed, time on site, and how you arrived
- Cookie identifiers (see the cookies section below)
When you sign up to emails
- Email address, and whether you opened or clicked our emails
Why we use it, and our legal basis
| What for | Legal basis |
|---|---|
| Processing and delivering your order | Performance of a contract |
| Order confirmations and delivery updates | Performance of a contract |
| Handling returns, refunds and complaints | Performance of a contract / legal obligation |
| Fraud screening and chargeback defence | Legitimate interests |
| Keeping accounting and tax records | Legal obligation |
| Marketing emails | Consent (you can withdraw any time) |
| Analytics and improving the shop | Consent (via cookie banner) |
Who we share it with
We don't sell your data. We share it only with the companies that make the shop work:
- Shopify — hosts the shop and processes orders
- Payment processors — take payment securely (Shopify Payments)
- Royal Mail — needs your name, address and phone number to deliver your parcel
- Shopify notifications and Shopify Email — send your order confirmations, delivery updates and newsletters, from mustafabusiness2001@hotmail.com
- Shopify analytics — built into the shop platform, showing us which pages and bundles people use. We do not currently use Google Analytics or any other third-party analytics provider.
- Our accountant and HMRC — for tax records
Some of these are based outside the UK/EEA. Where data is transferred abroad, it's protected by UK adequacy regulations or Standard Contractual Clauses.
Cookies
Cookies are small files stored on your device. We use:
- Essential cookies — keep your basket working and let you log in. These can't be switched off.
- Analytics cookies — tell us which pages people actually use. Optional.
- Marketing cookies — let us show relevant ads and measure whether they worked. Optional.
You can accept or reject the optional ones from the cookie banner, change your mind later in your browser settings, or clear them at any time. Blocking essential cookies will break checkout.
How long we keep it
- Order and invoice records — 6 years, as required for UK tax purposes
- Marketing subscribers — until you unsubscribe, then 30 days
- Shop analytics — held by Shopify for as long as the shop is active
- Support emails — 2 years after the issue is closed
Your rights
Under UK GDPR you can ask us to:
- Give you a copy of the data we hold about you
- Correct anything that's wrong
- Delete your data, where we're not legally required to keep it
- Stop using it for marketing — instantly, via the unsubscribe link
- Restrict or object to how we use it
- Send your data to another provider
Email mustafabusiness2001@hotmail.com and we'll respond within 30 days. There's no charge.
If you're not happy with our response, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
Children
Our products are made for children, but our shop is not. We don't knowingly collect data from anyone under 16. Orders should be placed by a parent, carer or school. If you believe a child has given us their details, email us and we'll delete them.
Security
The shop runs over HTTPS, payments are handled by PCI-DSS compliant processors, and access to customer data is limited to people who need it to fulfil orders. No system is perfectly secure, but if a breach affects your data we'll tell you and the ICO within 72 hours.
Changes to this policy
If we change anything significant we'll update the date at the top of this page and, where the change affects you materially, email subscribers directly.
Keep this current: if you later connect Google Analytics, Klaviyo, Meta Pixel or a second courier, add them to the sharing list on this page the same day you connect them. A processor that is running but undeclared is the most common privacy-policy failure for small shops.