Privacy Policy

1. Who we are

The Cosy Canvas Co. (“we”, “us”, “our”) is the controller of your personal data.

Contact:

2. What this policy covers

This policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and your rights.

3. What data we collect

Depending on how you interact with us, we may collect:

  • Contact details: name, email address, phone number

  • Booking/enquiry details: dates, location/postcode, package choice, notes you provide

  • Payment-related information: payment status and transaction references (payments are processed by our payment provider; we do not store full card details)

  • Website usage data: pages visited and basic device/browser information (via cookies/analytics)

  • Marketing preferences: whether you opt in/out of emails

4. How we collect your data

We collect data when you:

  • Submit an enquiry or booking request (e.g., via Typeform)

  • Join our waitlist/newsletter (via Kit)

  • Contact us by email, phone, or social media

  • Use our website (via cookies/analytics)

5. Why we use your data (and our legal basis)

We use your personal data to:

  • Respond to enquiries and provide quotes (legitimate interests; and steps prior to entering a contract)

  • Provide the hire service and manage bookings (contract)

  • Take payments and manage deposits/security deposits (contract; legal obligation for records)

  • Customer support and issue resolution (contract; legitimate interests)

  • Improve our website and services (legitimate interests)

  • Send marketing emails (consent  you can unsubscribe any time)

6. Who we share your data with

We only share data where needed to run the business, for example:

  • Kit (ConvertKit): to manage our waitlist/newsletter

  • Typeform: to collect enquiries/booking requests

  • Stripe: to process payments

  • Website hosting / website tools: to run and secure our website

  • Analytics providers (e.g., Google Analytics): to understand website performance

These providers process data on our behalf and are expected to protect it.

7. International transfers

Some of our service providers may process data outside the UK. Where this happens, we rely on appropriate safeguards (such as contractual protections) to help keep your data protected.

8. How long we keep your data

We keep personal data only as long as necessary:

  • Enquiries: typically up to 12 months

  • Bookings and payment records: typically up to 6 years (for accounting/tax and record-keeping)

  • Marketing list data: until you unsubscribe or ask us to delete it

9. Your rights

You have rights under UK data protection law, including:

  • Access to your personal data

  • Correction of inaccurate data

  • Deletion of your data (in certain situations)

  • Restriction or objection to processing (in certain situations)

  • Data portability (in certain situations)

  • Withdraw consent at any time (for marketing)

To exercise your rights, contact us at [email protected].

10. Cookies

We use cookies and similar technologies to help our website work and to understand how its used. You can control cookies through your browser settings and (where available) our cookie banner.

11. Security

We take reasonable steps to protect your personal data. No method of transmission or storage is 100% secure, but we work to protect your information.

12. Complaints

If you have concerns, please contact us first and well do our best to resolve them.

You also have the right to complain to the UK supervisory authority:

13. Changes to this policy

We may update this policy from time to time. The latest version will be posted on our website.