Sunny's Workshop

Privacy Policy

Privacy Policy

This policy explains what personal information Sunny's Workshop uses, why we use it, who we share it with and the choices available to you.

Effective date: 16 July 2026 Last updated: 18 August 2026 Data controller: Sunny's Workshop

Privacy at a glance

1. Who we are and how to contact us

Sunny's Workshop is an independent UK business and is the data controller for the personal information described in this policy, except where another organisation acts as an independent controller for its own service.

Data controller: Sunny's Workshop

Email: support@sunnysworkshop.co.uk

Website: sunnysworkshop.co.uk

Correspondence address: shown on order or repair documentation and available by contacting us.

2. Personal information we collect

Depending on how you use our website and services, we may collect:

Payment providers may collect payment-card, bank or digital-wallet information. We do not store full payment-card details on our own website.

3. Where we obtain personal information

Most information is provided directly by you when you register, place an order, submit a repair or return, subscribe to email updates, contact us or provide custom content.

We may also receive information from:

4. Why we use personal information and our lawful bases

The main ways we use information and the lawful bases we normally rely on are summarised below. More than one basis may apply where the purposes are genuinely different.

Information needed to process payment, deliver an order or carry out a repair is normally required so that we can enter into or perform the contract. If required information is not provided, we may be unable to accept or fulfil the order, deliver the goods, provide the repair or complete a return.

Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing that took place before consent was withdrawn.

5. Who we share information with

We share only the information reasonably required for the relevant purpose. Recipients may include:

Some providers, such as payment companies and marketplaces, may act as independent data controllers and process information under their own privacy notices.

We do not sell, rent or trade personal information.

6. International transfers

Some providers used for payments, website content, hosting, email, security or support may process information outside the United Kingdom, including in the United States. Providers may include Stripe and Google where their relevant services are used.

Depending on the provider and destination, a transfer may rely on UK adequacy regulations, including the UK-US data bridge where the recipient is appropriately certified, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful safeguard. You may contact us for information about the safeguard relevant to a particular provider or to request a copy where available.

7. How long we retain information

We retain information only for as long as reasonably necessary for the purpose collected, including legal, accounting, warranty, security and dispute-resolution requirements. Our usual approach is:

We may retain information longer where there is an active complaint, dispute, legal claim, regulatory requirement or law-enforcement request.

8. How we protect information

We use reasonable technical and organisational safeguards, including encrypted website connections, password hashing, access controls, restricted administrative permissions, private storage for supporting return files, security logging and reputable payment providers.

Where a device passcode is needed, we ask customers to use a temporary code or dedicated test account where practical. Access is limited to what is reasonably necessary for diagnosis and testing, and customers should change any temporary credential after the device is returned.

No internet or storage system is completely secure. If a personal-data breach creates a legal reporting or notification duty, we will take the steps required by applicable law.

9. Your data protection rights

Depending on the circumstances and lawful basis, you may have the right to:

Your right to object

You have the right to object at any time to processing of your personal information for direct marketing. You may also object to processing based on legitimate interests, although we may continue where we have compelling legitimate grounds or need the information for legal claims.

To exercise a right, contact support@sunnysworkshop.co.uk. We may need to verify your identity. Rights are not absolute, and we will explain if an exemption or limitation applies. We normally respond without undue delay and within one month, although the law allows an extension for particularly complex or numerous requests.

10. Cookies, sessions and local storage

Our website uses first-party cookies and browser storage for functions such as customer and admin sessions, security, cart contents, sidebar preferences and dark/light mode. Session and authentication information normally expires when the session ends, the user signs out or the configured security period expires. Cart information may remain until checkout, removal by the user or the configured cart expiry. Appearance and sidebar preferences may remain until the user clears browser storage or changes the preference.

These technologies are used only for the purpose described. Where we use analytics, advertising or another technology that is not covered by a legal exception, we request consent before it is stored or accessed. Where an exception permits use without consent, we provide the required information and any required means of objection. Refusing or clearing essential storage may prevent sessions, accounts, carts or preferences from operating correctly.

Third-party content may also receive technical information needed to supply that content. For example, the current page requests the Outfit font from Google, which receives information such as the requesting IP address and browser information. We do not use that request to obtain payment-card information.

11. Email marketing and newsletter subscriptions

Marketing communications are separate from service messages about orders, accounts, payments, repairs, returns and security.

12. Children's information

Orders and repair contracts must be placed by an adult aged 18 or over. Our website and account services are not directed at children under 13, and we do not knowingly invite children to create accounts or place orders.

An adult may provide a child's name, photograph or other content for a personalised product. We use that content only for the order and related support, retain it as described in section 7 and do not use it for unrelated marketing without an appropriate permission. If you believe a child has provided personal information without appropriate authority, contact us so that we can investigate and take suitable action.

13. Automated decision-making

We do not currently use personal information to make decisions that produce legal or similarly significant effects solely by automated means. We may use automated checks to support fraud prevention, security and email delivery, but significant decisions are reviewed where appropriate.

14. Questions and complaints

Please contact us first if you have a privacy concern so that we can try to resolve it.

You may also complain to the Information Commissioner's Office at ico.org.uk.

15. Changes to this policy

We may update this policy when our services, suppliers, systems or legal obligations change. The latest version will be published here with a revised effective date.