1. Who we are
MarketWayMobile (marketwaymobiles.co.uk) is the controller of your personal data. This privacy policy explains how we collect, use, disclose, protect, and retain your information when you use our website, make a purchase, contact us, or otherwise interact with us.
We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
2. Personal data we collect
We collect information in the following categories:
- Identification and contact details: name, email address, telephone number, billing and delivery addresses.
- Account information: username, password (stored securely using industry-standard hashing), preferences, and communication settings.
- Order and payment details: items purchased, order history, transaction identifiers, and limited payment details processed by payment providers (we do not store full card numbers).
- Delivery information: recipient name, address, and contact details provided for fulfilment and courier services.
- Communications: messages sent to our customer service, feedback, reviews, and correspondence records.
- Marketing preferences: your choices regarding newsletters, promotions, and cookies.
- Technical and usage data: IP address, device and browser details, pages viewed, referring pages, time on site, approximate location derived from IP, and cookie identifiers.
- Cookies and similar technologies: data stored on or read from your device as described in Section 5.
- Fraud prevention data: signals from our payment and security providers to help prevent fraud and abuse.
We do not intentionally collect special categories of personal data (such as health, biometric, or religious information) or information about criminal convictions through the website.
3. How we collect personal data
- Directly from you: when you browse the site, create an account, place an order, contact us, or subscribe to marketing.
- Automatically: via cookies, pixels, and similar technologies when you use the website.
- From third parties: payment processors, analytics providers, advertising partners (with your consent where required), fraud prevention services, and delivery/courier partners.
4. Purposes of processing and legal bases
We use your personal data for the following purposes and under these legal bases:
- To provide and deliver products, manage orders, process payments, and provide customer service
– Legal basis: performance of a contract; legitimate interests (efficient operation and customer support). - To create and manage your account, authenticate access, and maintain preferences
– Legal basis: performance of a contract; legitimate interests (account security and user experience). - To communicate with you about orders, service updates, and changes to our terms or policies
– Legal basis: performance of a contract; legal obligation; legitimate interests (informing users). - To send marketing communications and personalise offers (email, SMS, online ads)
– Legal basis: consent (for electronic marketing to individuals and cookies); legitimate interests (for soft opt-in where permitted under PECR and for non-cookie-based personalisation); you can opt out at any time. - To perform analytics, measure performance, improve our website and services, and develop new features
– Legal basis: consent (for non-essential cookies/analytics under PECR); legitimate interests (service improvement using aggregated or necessary data). - To prevent and detect fraud, abusive behaviour, and security incidents; and to protect our rights
– Legal basis: legitimate interests (fraud prevention and network security); legal obligation. - To comply with legal and regulatory obligations (including tax and accounting)
– Legal basis: legal obligation.
5. Cookies and similar technologies
We use cookies, pixels, and similar technologies to operate the website, remember your choices, analyse traffic, and, with your consent, tailor marketing. Non-essential cookies are used only with your consent in accordance with PECR. You can manage your cookie preferences via the cookie banner on our site and through your browser settings. You can withdraw consent at any time; this will not affect the lawfulness of processing before withdrawal.
Types of cookies we use:
- Strictly necessary cookies: required for core site functions such as page navigation, shopping cart, checkout, and security. These are set to provide the service you request and do not require consent.
- Preference cookies: remember settings and choices (e.g., language, region). Typical lifetime: up to 12 months.
- Analytics cookies: help us understand how visitors use the site to improve performance (e.g., pages visited, time on page). Typical lifetime: 13 to 26 months. Set only with consent.
- Advertising and social media cookies: used to show relevant ads and measure campaign effectiveness, and to enable social sharing features. Typical lifetime: 6 to 13 months. Set only with consent.
You can also delete cookies via your browser settings. If you block or delete cookies, some features of the website may not function properly.
6. Sharing your personal data
We do not sell your personal data. We share personal data only as necessary for the purposes described above, with the following categories of recipients:
- Service providers (processors) who host our website, provide IT, security, analytics, customer support tools, email/SMS distribution, and marketing services.
- Payment processors and financial institutions to process transactions and prevent fraud.
- Delivery and logistics partners to fulfil and deliver your orders and handle returns.
- Professional advisers (lawyers, accountants, auditors) and insurers where necessary.
- Public authorities, regulators, law enforcement, and courts when required by law or to protect our rights or the rights of others.
- Successors in the event of a business reorganisation, merger, or sale, in which case we will ensure appropriate protections are in place.
Where we engage processors, they are bound by contractual obligations to protect your data and process it only on our documented instructions.
7. International data transfers
Your personal data may be transferred outside the United Kingdom when we use service providers or partners located abroad. We only transfer data internationally where appropriate safeguards are in place to protect your information, such as:
- UK adequacy regulations for certain countries or territories.
- The International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, including additional measures where appropriate.
- The UK Extension to the EU–US Data Privacy Framework (UK–US Data Bridge) where the recipient is certified.
You can request more information about our transfer safeguards by contacting us (see Section 12).
8. Data retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including to meet legal, accounting, or reporting requirements. Typical retention periods are:
- Account data: for the life of your account and for up to 24 months after closure, unless we need to retain it longer for legal claims or fraud prevention.
- Order and transaction records: 6 years from the end of the financial year in which the transaction occurred (to comply with tax and accounting obligations).
- Customer service correspondence: up to 3 years after resolution, depending on the nature of the query.
- Marketing preferences and consent records: for as long as you are subscribed and for up to 24 months after you opt out, to demonstrate compliance.
- Analytics data: typically 13 to 26 months, depending on the tool and your cookie choices.
- Fraud prevention and security logs: up to 24 months, unless a longer period is required for investigation.
We will securely delete or anonymise data when it is no longer needed.
9. Your rights
Under the UK GDPR, you have the following rights, subject to conditions and exemptions:
- Right of access: obtain a copy of your personal data and information about how we process it.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure: request deletion of your data in certain circumstances.
- Right to restriction: ask us to limit processing in certain cases.
- Right to data portability: receive your data in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible.
- Right to object: object to processing based on legitimate interests, including profiling, and to direct marketing at any time.
- Right to withdraw consent: where we rely on consent, you can withdraw it at any time.
- Rights related to automated decision-making: not to be subject to a decision based solely on automated processing that has legal or similarly significant effects on you.
To exercise your rights, contact us using the details in Section 12. We may need to verify your identity before responding. We will respond within one month, or within the additional time permitted by law for complex requests.
10. Direct marketing
We will only send you electronic direct marketing (such as email or SMS) with your consent, or under the “soft opt-in” where you have purchased or negotiated to purchase goods or services from us and we are marketing similar products, and you have not opted out. You can opt out at any time by using the unsubscribe option in our messages or by contacting us.
11. Data security
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, authentication, secure configuration, vulnerability management, and staff training. While we work to protect your information, no system is completely secure. If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority where required by law.
12. Children’s privacy
Our services are not directed to children and we do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete such information.
13. Data Protection Officer and contact
We have appointed a Data Protection Officer (DPO). You can contact our DPO or our privacy team regarding this policy, your rights, or our data protection practices at:
Email: privacy@marketwaymobiles.co.uk
14. Complaints
If you have concerns about how we process your personal data, please contact us first so we can try to resolve your concern. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Telephone: 0303 123 1113.
If you are located outside the UK, you may also have the right to complain to your local data protection authority.
15. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices, legal requirements, or technology. Significant changes will be highlighted on our website. The date below indicates the most recent update.
Last updated: 28 December 2025