Privacy and Cookie Policy

Effective date: 1 August 2025

This Privacy Policy explains how we collect, use, and protect your personal data when you use the Books by Mary Oakley website.

This policy applies to all users of our website and customers who place orders through it. By using our website, you agree to the terms of this Privacy Policy.

1. Who We Are

Books by Mary Oakley is operated by Elizabeth Oakley, a sole trader based in the United Kingdom. For the purposes of the UK General Data Protection Regulation (UK-GDPR), Elizabeth Oakley is the data controller.

If you have any questions about this policy or how your data is used, please contact us using the contact information on our website.

2. Personal Data We Collect

We collect the following personal information when you place an order or contact us:

  • Full name
  • Delivery and billing address
  • Email address
  • Phone number

We may also collect information automatically via cookies when you browse the website (see section 6).

3. How We Use Your Data

We use your personal data for the following purposes:

  • To process and fulfil your orders
  • To contact you about your order, including despatch and delivery updates
  • To respond to customer enquiries or complaints
  • To comply with legal obligations

We do not use your personal information for marketing purposes unless you have explicitly opted in.

4. Lawful Basis for Processing

Under the UK-GDPR, we rely on the following lawful bases for processing your data:

  • Contractual necessity – to process and deliver your orders.
  • Legal obligation – to comply with tax and accounting laws.
  • Legitimate interests – to respond to your enquiries and ensure the security and functionality of our website.

5. How Your Data Is Stored and Protected

Your personal data is stored on a dedicated server using industry-standard security measures, including firewalls and secure access protocols.

Regular backups of data are made and stored in an encrypted format using private key encryption. Only authorised personnel have access to this data.

We retain your data only as long as necessary to fulfil our obligations, including legal and accounting requirements.

6. Cookies

Our website uses essential cookies required for its basic functionality. A full list of the cookies we use will be provided below:

Cookie Name Cookie Description
FORM_KEY Stores randomly generated key used to prevent forged requests.
PHPSESSID Your session ID on the server.
GUEST-VIEW Allows guests to view and edit their orders.
PERSISTENT_SHOPPING_CART A link to information about your shopping basket and viewing history, if you have asked for this.
STF Information on products you have emailed to friends.
STORE The store view or language you have selected.
USER_ALLOWED_SAVE_COOKIE Indicates whether a customer is allowed to use cookies.
MAGE-CACHE-SESSID Facilitates caching of content on the browser to make pages load faster.
MAGE-CACHE-STORAGE Facilitates caching of content on the browser to make pages load faster.
MAGE-CACHE-STORAGE-SECTION-INVALIDATION Facilitates caching of content on the browser to make pages load faster.
MAGE-CACHE-TIMEOUT Facilitates caching of content on the browser to make pages load faster.
SECTION-DATA-IDS Facilitates caching of content on the browser to make pages load faster.
PRIVATE_CONTENT_VERSION Facilitates caching of content on the browser to make pages load faster.
X-MAGENTO-VARY Facilitates caching of content on the server to make pages load faster.
MAGE-TRANSLATION-FILE-VERSION Facilitates translation of content to other languages.
MAGE-TRANSLATION-STORAGE Facilitates translation of content to other languages.

You can manage cookie preferences through your browser settings.

7. Sharing Your Information

We do not sell, rent, or trade your personal data. We may share your information with trusted third parties only when necessary to:

  • Fulfil your order (e.g. postal or courier services)
  • Comply with legal obligations

All third-party providers are required to handle your data securely and in compliance with UK-GDPR.

8. Your Rights Under UK-GDPR

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate or incomplete data
  • Request deletion of your data where appropriate
  • Object to or restrict certain types of processing
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with the Information Commissioner's Office (ICO)

To exercise any of these rights, please contact us using the details on our website.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised effective date.