Privacy policy
Last updated: 23 November 2025
This Privacy Policy explains how we collect, use and share personal data when you visit or shop with Chai Patti. It is drafted for a UK controller with UK/EU customers and GCC audiences (Qatar, UAE). Obtain local counsel review before publishing.
- Who we are (Controller) Chai Patti Ltd is the controller. Contact: info@chaipatti.uk; postal: 2nd Floor, Grove House, 55 Lowlands Road, Harrow, Middlesex, HA1 3AW, United Kingdom.
- What data we collect Identification & contact (name, email, phone, addresses) Account & order data (cart, purchases, payments, subscription selections) Marketing preferences and consents (email/SMS) Technical data (device, IP, cookies) for functionality, analytics and marketing Ambassador data (social handles, performance metrics, payout details)
- How we use data & lawful bases Contract: to process orders, deliver subscriptions, handle returns, and pay ambassadors Legitimate interests: fraud prevention, programme analytics, attribution (link/code), service improvement Consent: email/SMS marketing; non essential cookies/trackers Legal obligation: tax/accounting record keeping
- Marketing (PECR / ePrivacy) We send electronic marketing only with valid consent or soft opt-in to existing customers for similar products. You can opt out at any time via unsubscribe links or by contacting us.
- Cookies & similar technologies We use categories: Strictly Necessary, Performance/Analytics, Marketing/Advertising, and Affiliate Attribution. Non essential cookies load only after consent; manage preferences via our banner. See our Cookies Policy for details.
- Sharing & international transfers We share necessary data with processors: Shopify; payments; couriers; analytics/advertising; Klaviyo; subscription and affiliate platforms. Where data is transferred outside the UK/EEA, we use appropriate safeguards (e.g., UK/EU Standard Contractual Clauses).
- Retention Orders: 6 years (tax/accounting) Ambassadors: while active and for 6 years after last payment Marketing consents: until withdrawal or inactivity Cookie logs: per consent platform limits
- Your rights UK/EU: access, rectification, erasure, restriction, portability modif, objection; withdraw consent at any time. GCC: we aim to honour applicable rights under Qatar PDPL and UAE PDPL. Contact us to exercise rights.
- Children Our services are not directed to under 18s. Do not provide data for minors without parental/guardian consent when permitted by law.
- Security We implement administrative, technical and physical measures appropriate to risk. No system is 100% secure.
- Complaints UK: you can complain to the ICO (ico.org.uk). EU: your local DPA. GCC: contact the competent local authority where applicable. We encourage contacting us first so we can resolve concerns quickly.
- Changes We will post updates to this Policy with a new Last updated date.