Skip to content

Cart

Your cart is empty

Privacy policy

Last updated: 23 November 2025

This Privacy Policy explains how we collect, use and share personal data when you visit or shop with Chai Patti. It is drafted for a UK controller with UK/EU customers and GCC audiences (Qatar, UAE). Obtain local counsel review before publishing.

  1. Who we are (Controller) Chai Patti Ltd is the controller. Contact: info@chaipatti.uk; postal: 2nd Floor, Grove House, 55 Lowlands Road, Harrow, Middlesex, HA1 3AW, United Kingdom.
  2. What data we collect Identification & contact (name, email, phone, addresses) Account & order data (cart, purchases, payments, subscription selections) Marketing preferences and consents (email/SMS) Technical data (device, IP, cookies) for functionality, analytics and marketing Ambassador data (social handles, performance metrics, payout details)
  3. How we use data & lawful bases Contract: to process orders, deliver subscriptions, handle returns, and pay ambassadors Legitimate interests: fraud prevention, programme analytics, attribution (link/code), service improvement Consent: email/SMS marketing; non essential cookies/trackers Legal obligation: tax/accounting record keeping
  4. Marketing (PECR / ePrivacy) We send electronic marketing only with valid consent or soft opt-in to existing customers for similar products. You can opt out at any time via unsubscribe links or by contacting us.
  5. Cookies & similar technologies We use categories: Strictly Necessary, Performance/Analytics, Marketing/Advertising, and Affiliate Attribution. Non essential cookies load only after consent; manage preferences via our banner. See our Cookies Policy for details.
  6. Sharing & international transfers We share necessary data with processors: Shopify; payments; couriers; analytics/advertising; Klaviyo; subscription and affiliate platforms. Where data is transferred outside the UK/EEA, we use appropriate safeguards (e.g., UK/EU Standard Contractual Clauses).
  7. Retention Orders: 6 years (tax/accounting) Ambassadors: while active and for 6 years after last payment Marketing consents: until withdrawal or inactivity Cookie logs: per consent platform limits
  8. Your rights UK/EU: access, rectification, erasure, restriction, portability modif, objection; withdraw consent at any time. GCC: we aim to honour applicable rights under Qatar PDPL and UAE PDPL. Contact us to exercise rights.
  9. Children Our services are not directed to under 18s. Do not provide data for minors without parental/guardian consent when permitted by law.
  10. Security We implement administrative, technical and physical measures appropriate to risk. No system is 100% secure.
  11. Complaints UK: you can complain to the ICO (ico.org.uk). EU: your local DPA. GCC: contact the competent local authority where applicable. We encourage contacting us first so we can resolve concerns quickly.
  12. Changes We will post updates to this Policy with a new Last updated date.