1. Introduction

Welcome to Folk & Thread’s Privacy Policy. This document outlines how we collect, use, and protect your personal information.

Folk & Thread Ltd is committed to protecting your privacy. This policy explains what data we collect, why we collect it, how we use it, and your rights.

By using our website, you confirm that you have read and understood this policy.

Who We Are

Folk & Thread Ltd is the data controller for the personal information we hold about you.

Address:
Folk & Thread Ltd,Bowling Green House,
2 Summer Hill, Kendal, LA9 4JU

Email:  hello@folkandthread.co.uk

2. What do we do with your information?

When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us such as your name, address and email address.

When you browse our store, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system.

Email marketing (if applicable):
With your permission, we may send you emails about our store, new products, baby sleep tips and other updates.

We use Klaviyo as our email and marketing automation platform. Your data will be transferred to Klaviyo for processing in accordance with their Privacy Policy.

3. Our lawful basis for processing your data

Under UK GDPR, we must have a lawful basis to process your personal data. We rely on the following:

Contract:  To process your order, arrange delivery, and manage returns.

Legitimate interests:  To improve our website, prevent fraud, and keep records of transactions. We have assessed that these interests do not override your rights.

Consent:  To send you marketing emails. You can withdraw this consent at any time (see Consent section below).

Legal Obligation:  To comply with UK
law, including tax and financial record-keeping requirements.

4. Consent

How Do You Get My Consent?

When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we rely on contract as our lawful basis for processing.

If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent or provide you with an opportunity to say no.

How do I withdraw my consent?

If after you opt-in you change your mind, you may withdraw your consent for us to contact you for marketing at any time by clicking the unsubscribe link in any email, or by contacting us at hello@folkandthread.co.uk or mailing us at: Folk & Thread Ltd, Folk & Thread
Ltd,Bowling Green House, 2 Summer Hill, Kendal, LA9 4JU

5. Disclosure

We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service.

We do not sell your personal data to third parties.

6. Shopify

Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.

Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.

For more information, you may also want to read Shopify’s Privacy
Statement
.

7. Payment

If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase
transaction information is deleted.

All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards
Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover.

PCI-DSS requirements help ensure
the secure handling of credit card information by our store and its service
providers.

8. Third-party services

The third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us. These include:

Shopify Inc  — our e-commerce platform

Klaviyo  — our email marketing platform

Payment processors  — who handle card transactions securely in line with PCI DSS standards.

Delivery and logistics providers  - to fulfil and ship your orders

Google Analytics  — to help us understand how visitors use our website using anonymised data

Certain third-party service providers may be located in or have facilities in a different jurisdiction than either you or us. Where your data is transferred internationally, we ensure it is protected to a standard that is not materially lower than UK data protection law, in line with the Data (Use and Access) Act 2025.

Once you leave our store’s website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website’s Terms of Service.

9. Children’s data

Folk & Thread sells baby and infant sleep products. Our website is intended for adults only. We do not knowingly collect personal data from anyone under the age of 18.

In line with the Data (Use and Access) Act 2025, we take children’s higher protection matters seriously:

We do not use children’s data for profiling or targeted advertising

—    
We do not share data relating to children with third parties for marketing purposes.

—    
If you believe we have inadvertently collected data relating to a child, please contact us at hello@folkandthread.co.uk and we will delete it promptly

By using this site, you confirm that you are at least 18 years of age.

10. Personal data

Personal data collected for the following purposes and using the following services:

Analytics  — Google Analytics. Personal Data: Cookies and anonymised usage data.

11. Links

When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.

12. Security

To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.

If you provide us with your credit card information, the information is encrypted using secure socket layer
technology (SSL) and stored with AES-256 encryption. Although no method of
transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.

13. Cookies

Here is a list of cookies that
we use. We have listed them here so that you can choose if you want to opt-out of cookies or not.

_session_id  — unique token, sessional. Allows Shopify to store information about your session (referrer, landing page, etc).

_shopify_visit  — no data held, persistent for 30 minutes from the last visit. Used by our website provider’s internal stats tracker to record the number of visits.

_shopify_uniq  — no data held, expires midnight of the next day. Counts the number of visits to a store by a single customer.

cart  — unique token, persistent for 2
weeks. Stores information about the contents of your cart.

_secure_session_id  — unique token, sessional.

storefront_digest  — unique token, indefinite. If the shop has a password, this is used to determine if the current visitor has access.

You have the right to opt out of non-essential cookies at any time by adjusting your browser settings or by
contacting us at hello@folkandthread.co.uk.

14. Your rights

Under UK GDPR and the Data (Use
and Access) Act 2025, you have the following rights:

Right of access  — you can request a
copy of the personal data we hold about you.

Right to rectification  — you can ask us to correct inaccurate or incomplete data.

Right to erasure  — you can ask us to delete your data in certain circumstances.

Right to restrict processing  — you can ask us to limit how we use your data.

Right to data portability  — you can request your data in a machine-readable format.

Right to object  — you can object to
us processing your data for marketing purposes.

Right to contest automated decisions  - you have the right to be informed of, and to contest, any significant decisions
made about you solely by automated means

To exercise any of these rights,
please contact us at hello@folkandthread.co.uk. We will respond within one month. We may need to verify your identity before processing your request.

15. How to make a complaint

If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve the matter: hello@folkandthread.co.uk

If you remain dissatisfied, you have the right to complain to the UK’s data protection regulator:

Information Commissioner’s Office (ICO)

Website:  https://ico.org.uk/make-a-complaint

Telephone:  0303 123 1113

Post:  Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

16. How long we keep your data

We only keep your personal data for as long as necessary for the purpose it was collected, or as required by law:

Order and transaction data:  kept for 7 years for legal and tax purposes

Marketing data:  kept until you unsubscribe or withdraw consent

Website analytics data:  retained in
anonymised form

After the relevant retention period, your data is securely deleted or anonymised.

17. Changes to this privacy policy

We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and
clarifications will take effect immediately upon their posting on the website.
If we make material changes to this policy, we will notify you here that it has
been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.

If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.

Questions and Contact Information

If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at hello@folkandthread.co.uk or by mail at:

Folk & Thread Ltd,

Bowling Green House,

2 Summer Hill,

Kendal,

LA9 4JU