Privacy Policy
Welcome to Ceylon Teabox. We are deeply committed to protecting your privacy and safeguarding your personal data. This notice explains how we care for your information when you visit our website, purchase our teas, or interact with us. It also outlines your privacy rights and how the law protects you.
Please take a moment to read this policy. By using our site and providing your information, you are agreeing to the practices described here.
1. IMPORTANT INFORMATION & WHO WE ARE
1.1 The Purpose of This Notice
This privacy notice aims to give you a clear understanding of how Ceylon Teabox collects and processes your personal data through your use of this website and our services.
We may provide additional, specific privacy notices on certain occasions, and we encourage you to read those alongside this one so you are fully informed.
1.2 Who is Collecting Your Data?
Ceylon Teabox, Webtastic Ltd (company number: 12854444) is the data controller responsible for your personal data (referred to as "Ceylon Teabox", "we", "us" or "our" in this notice).
1.3 How to Contact Us
We have appointed a Data Protection Officer (DPO) to oversee questions about this privacy notice.
Full company name: Webtastic Ltd T/A Ceylon Teabox
Email: info@ceylonteabox.com
You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK's data protection authority (www.ico.org.uk). However, we would appreciate the opportunity to address your concerns first, so please do contact us in the initial instance.
1.4 Updates to This Notice & Your Information
We may update this policy periodically. If we make significant changes, we will notify you via email or a notice on our website. This version was last updated on 6th October 2025.
The personal data we hold must be accurate. Please help us by keeping us informed of any changes to your details.
1.5 Links to Other Websites
Our website may contain links to other third-party sites, plug-ins, and applications. Clicking on these may allow third parties to collect or share data about you. We do not control these sites and are not responsible for their privacy practices.
2. THE DATA WE COLLECT ABOUT YOU
Personal data is any information that can be used to identify you. It does not include anonymised data, which we use to help us improve our service.
We may collect, use, store, and transfer the following kinds of personal data:
Identity and Contact Data: Such as your name, billing/delivery address, email address, and telephone number.
Transaction Data: Details about payments and your purchases of our teas and products.
Technical and Usage Data: Information about how you use our website, gathered through cookies.
Marketing and Communications Data: Your preferences for receiving marketing from us and your communication preferences.
Profile Data: Your interests, preferences, feedback, and survey responses.
We also create Aggregated Data (like statistical or demographic information) from your personal data, which is not considered personal in law as it does not reveal your identity.
3. HOW WE COLLECT YOUR PERSONAL DATA
We use different methods to collect data from and about you, including:
Direct Interactions: You may give us your data by filling in forms on our site, creating an account, purchasing our teas, subscribing to our newsletter, or by corresponding with us by post, phone, email, or otherwise.
Automated Technologies: As you interact with our website, we may automatically collect Technical and Usage Data through cookies and similar technologies.
Third Parties: We may receive personal data about you from technical, payment, and delivery service providers.
4. HOW WE USE YOUR PERSONAL DATA
We will only use your personal data when the law allows us to. Most commonly, we will use your data in the following circumstances:
To perform the contract we are about to enter into or have entered into with you (e.g., processing and delivering your order).
Where it is necessary for our legitimate interests and your interests and fundamental rights do not override those interests (e.g., improving our website and services).
Where we need to comply with a legal or regulatory obligation.
Where you have given us your consent for a specific purpose (e.g., sending you our tea newsletter).
5. PURPOSES FOR USING YOUR DATA
We will use your personal data for the following core purposes:
To process and deliver your order, including managing payments and arranging shipping.
To manage our relationship with you, which will include notifying you about changes to our terms or privacy policy, or asking you to leave a review.
To administer and protect our business and this website (including troubleshooting, data analysis, and system testing).
To deliver relevant website content and advertisements to you and measure the effectiveness of that advertising.
To use data analytics to improve our website, products/services, marketing, and your experience.
Where you have given us your express consent, we may also process your data for:
Sending you marketing communications about new teas, tasting events, and promotions we think you will love.
Inviting you to take part in a market research survey or customer review.
6. MARKETING
We love sharing news about our latest tea collections and offers with you. You will receive marketing communications from us if you have requested information from us or purchased teas from us and you have not opted out of receiving that marketing.
Opting Out
You can ask us to stop sending you marketing messages at any time by:
Clicking the 'unsubscribe' link in any marketing email.
Contact us at any time using the details in section 1.3.
Where you opt out of marketing, this will not apply to personal data provided to us as a result of a product purchase, warranty registration, or other transaction.
7. COOKIES
Our website uses cookies (small text files stored on your device) to distinguish you from other users. This helps us provide you with a smooth browsing experience and allows us to improve our site.
You can set your browser to refuse all or some browser cookies. However, if you disable or refuse cookies, please note that some parts of the website may become inaccessible or not function properly. For detailed information on the cookies we use, please see our Cookie Policy.
8. DATA SHARING
We may share your personal data with the following parties for the purposes set out above:
Service Providers: Such as payment processors, delivery companies, and IT support, who are based in the UK and EU.
Professional Advisers: Including lawyers, bankers, auditors, and insurers.
Authorities: HM Revenue & Customs, regulators, and other authorities who require reporting of processing activities.
Business Transfers: Third parties to whom we may sell, transfer, or merge parts of our business or our assets.
We require all third parties to respect the security of your data and to treat it in accordance with the law.
9. INTERNATIONAL TRANSFERS
We do not transfer your personal data outside the European Economic Area (EEA).
10. DATA SECURITY
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way. We limit access to your personal data to those who have a genuine business need to know it.
11. DATA RETENTION
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
When determining the retention period, we consider the amount, nature, and sensitivity of the data. In some circumstances, you can ask us to delete your data (see below).
12. YOUR LEGAL RIGHTS
Under certain circumstances, you have rights under data protection laws in relation to your personal data. You have the right to:
Request access to your personal data.
Request correction of any inaccurate or incomplete data.
Request erasure of your personal data.
Object to the processing of your personal data.
Request the restriction of processing your data.
Request the transfer of your data to you or a third party.
Withdraw consent at any time where we are relying on consent to process your data.
If you wish to exercise any of these rights, please contact us using the details in section 1.3. We may need to request specific information from you to help us confirm your identity. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
We will respond to all legitimate requests on time. If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO).