Free standard delivery over £150 Returns within 14 days

This policy explains what personal data Laced Global collects when you browse this site or buy from us, why we collect it, how long we keep it, and the rights you have over it. It is written to meet our obligations under the UK GDPR and the Data Protection Act 2018.

01 — Who controls your data

Laced Global is the data controller for the personal data described in this policy. That means we decide what is collected and what it is used for, and we are accountable for it. We do not publish a company name, a company number or a registered office address, and nothing on this site should be read as a claim to be an incorporated company. Those details will be published in this section and in the site footer before online orders open.

The way to reach us about anything in this policy — including a request to exercise your rights — is support@lacedglobal.shop. Please put “Data request” in the subject line so it is routed correctly.

02 — What we collect

We try to collect as little as we can and nothing we have no use for. In practice that is:

  • Identity and contact data — your name, email address, delivery address, billing address and, if you give it to us, a phone number for the courier.
  • Order data — what you bought, the size, the price, your order number, dispatch and tracking references, and the history of that order including any return or refund.
  • Payment confirmation data — nothing at present. Online payment is not live on this site, so no card or payment data is collected here at all. Orders are reserved by email and payment is arranged directly. If online payment goes live, this will become the payment method type, the last four digits of the card and the authorisation outcome. We will never receive or store full card numbers or security codes.
  • Correspondence — emails you send us and our replies, including photographs you send in support of a return or a fault report.
  • Technical and usage data — IP address, approximate location derived from it, device and browser type, referring page, and the pages you viewed. This is collected through our hosting and, where you consent, analytics.
  • Marketing preferences — whether you have asked to receive emails from us, and when you last changed that.

We do not collect special category data (such as health or biometric data), and we ask you not to send it to us. We do not buy personal data from third parties, and we do not build profiles to make automated decisions about you other than the fraud screening described below.

03 — Why we use it, and our lawful basis

Every use of your data has a lawful basis under data protection law:

  • To take and fulfil your order — agreeing the total and arranging payment with you, packing and dispatching the pair, arranging delivery, handling returns and refunds, and answering your questions. Basis: performance of a contract with you.
  • To prevent fraud and misuse — screening orders, verifying that the order and delivery address are consistent, and investigating disputes. Basis: legitimate interests (protecting our business and legitimate customers from fraud).
  • To keep accounting and tax records — retaining transaction records for the period required by HMRC and company law. Basis: legal obligation.
  • To run and improve the site — keeping it secure and available, diagnosing faults, and understanding in aggregate which pages and products are viewed. Basis: legitimate interests, and consent where analytics cookies are involved.
  • To send marketing email — only if you have asked us to. Basis: consent, which you can withdraw at any time using the unsubscribe link or by emailing us.
  • To handle disputes and legal claims — establishing, exercising or defending legal claims. Basis: legitimate interests.

Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights and freedoms, and you can object at any time — see Your rights.

04 — Payment data

Pre-launch notice — 11 August 2026: we are not taking online payments through this site yet. There is no checkout, no card form and no payment processor connected to this website, so no payment data of any kind is collected here at present. Orders are reserved by email at support@lacedglobal.shop, the total is agreed in writing, and payment is arranged with us directly. The rest of this section describes how card data will be handled once online payment goes live, and we will update it and remove this notice on that day.

Card payments will then be processed by a third-party payment processor. Your card details will be collected by that processor in its own secure environment and transmitted directly to it. They will not pass through, and will not be stored on, Laced Global systems. We will never see a full card number and we will never store a card security code.

The processor will act as a data controller in its own right for the payment data it holds and will process it under its own privacy notice, which you should read before paying. It will use that data to authorise the payment, to meet its own legal obligations including anti-money-laundering and payment-services rules, and to screen transactions for fraud. It will return to us only what we need to run the order: the outcome, the payment method type, the last four digits and any fraud indicator. We will name the processor here before online payment goes live.

05 — Cookies and browser storage

We use browser storage in two ways:

  • Strictly necessary storage. Your bag is held in your own browser’s local storage so that it survives a page refresh. Necessary storage also supports security and fraud prevention, and will support checkout when online payment goes live. These do not require consent because the site cannot work without them, and they are not used to track you across other websites.
  • Optional cookies. Analytics or advertising cookies are set only if you agree to them. Where we use them, we will ask you first and you will be able to change your answer later. Declining them does not affect your ability to browse or buy.

You can clear or block cookies and local storage in your browser settings at any time. Blocking necessary storage will stop the bag from working properly.

06 — Who we share data with

We do not sell your personal data, and we do not share it for anyone else’s marketing. We share it only with organisations that help us run the business, and only with what they need:

  • a payment processor, to take payment and issue refunds — not yet, because online payment is not live; we will name it here before it is;
  • delivery carriers, to deliver your parcel and provide tracking — this means your name, address and, where you gave one, your phone number;
  • hosting and IT providers, who store the site and our order records;
  • our email and helpdesk provider, which carries our correspondence with you;
  • our accountants and professional advisers, where they need it to do their work;
  • law enforcement, regulators or courts, where we are legally required to disclose, or where disclosure is necessary to establish or defend legal claims.

Everyone we use as a processor is bound by a written contract requiring them to act only on our instructions, to keep the data secure, and to delete or return it when the work ends. If our business is ever sold or reorganised, customer records may transfer to the acquiring business, which would remain bound by this policy.

07 — International transfers

Some of our providers process data in other countries. Where that happens, we make sure the transfer is covered by one of the safeguards data protection law allows: an adequacy regulation for the destination country, or the International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. You can ask us which safeguard applies to a particular provider.

08 — How long we keep it

  • Order and transaction records — six years from the end of the financial year the order falls in, because tax and company law require it.
  • Support correspondence — up to 24 months after the matter is closed, so we can pick up a history if you come back to us.
  • Fraud and chargeback records — up to six years, to defend claims and to prevent repeat fraud.
  • Marketing consent records — until you unsubscribe, plus a minimal record of the withdrawal so we do not email you again.
  • Analytics data — no longer than 14 months, in aggregated form where possible.

When a retention period ends we delete the data or anonymise it so it can no longer identify you.

09 — Security

We use encrypted connections (HTTPS) across the site, restrict access to order data to the people who need it, and require a second factor to sign in to the systems that hold it. We hold no card data at all: online payment is not live here, and if it goes live card data will stay with the payment processor rather than enter our environment. No system is perfectly secure, but if a breach ever occurs that is likely to result in a risk to your rights, we will notify the Information Commissioner’s Office within 72 hours and tell you where the risk to you is high.

10 — Your rights

You have the right to:

  • Access — ask for a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — ask us to delete data where we no longer need it for the purpose we collected it. This does not extend to records we must keep by law, such as transaction records.
  • Restriction — ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
  • Portability — receive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller.
  • Objection — object to processing based on legitimate interests, and object at any time to direct marketing, which we will always stop.
  • Withdraw consent — where we rely on consent, withdraw it at any time. This does not affect processing carried out before you withdrew it.
  • Not be subject to solely automated decisions with legal or similarly significant effects. If an order is ever declined by an automated fraud check, you can ask a person to review it.

To use any of these rights, email support@lacedglobal.shop. We do not charge for this. We will respond within one month, and we will tell you if we need to extend that by up to two further months because the request is complex. We may ask you for information to confirm your identity before we release data.

11 — Complaints to the ICO

If you are unhappy with how we have handled your data, please tell us first at support@lacedglobal.shop so we can put it right. You also have the right to complain to the supervisory authority, the Information Commissioner’s Office, at ico.org.uk/make-a-complaint. Complaining to the ICO does not affect any other legal remedy you have.

12 — Children

This site is intended for people aged 18 and over, and we do not knowingly collect data from children. If you believe a child has given us personal data, email us and we will delete it.

13 — Changes to this policy

We update this policy when what we do with data changes, or when the law does. The date at the top of this page shows the last revision. Where a change materially affects you, we will tell you by email if we hold your address.

14 — Contact us

Email support@lacedglobal.shop with any question about this policy, about the data we hold on you, or about how a specific order was handled.

See also our Terms & Conditions, Returns & Refunds and Delivery policies, or get in touch.

No payments are taken here yet

There is no checkout on this site, so no card data is collected and no payment processor is connected to it. Orders are reserved by email at support@lacedglobal.shop and payment is arranged directly. If online payment goes live it will be handled end-to-end by a third-party payment processor, which we will name here first: Laced Global would store your order, delivery and contact details — never a full card number and never a security code.