Privacy Policy
Privacy Policy
This policy describes how COXCOTA LIMITED ("we," "us," "our") collects, uses, discloses, and protects your personal data. We operate in compliance with multiple global privacy frameworks.
1. COMPREHENSIVE LEGAL FRAMEWORK COMPLIANCE
We process your data in accordance with the following regulations, as applicable to your location:
- European Union / European Economic Area: Regulation (EU) 2016/679 (General Data Protection Regulation - "GDPR")
- United Kingdom: UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018
- Switzerland: Revised Federal Act on Data Protection ("revDSG", effective from 01.09.2023)
- United States - California: California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA")
- United States - Nevada: Nevada Privacy Law (NRS Chapter 603A)
- United States - Virginia, Colorado, Utah, Connecticut: Respective state privacy laws (VCDPA, CPA, UCPA, CTDPA)
2. INFORMATION WE COLLECT
2.1. Categories of Personal Data
- Identity & Contact Data: Name, billing/delivery address, email, phone number, age/date of birth (for verification).
- Financial & Transaction Data: Payment method (PayPal, card type), transaction history, order details. We do not store full payment card numbers.
- Technical & Usage Data: IP address, browser type, device information, pages visited, time spent (collected via cookies and similar technologies).
- Marketing & Communications Data: Your preferences for receiving marketing, communication history.
2.2. Legal Basis for Processing (GDPR/UK GDPR/revDSG)
We process your personal data on the following legal grounds:
- Performance of a Contract: To process and deliver your order, manage your account.
- Legal Obligation: For tax, accounting, AML/KYC compliance, and age verification.
- Legitimate Interest: To prevent fraud, ensure network security, improve our website, and conduct direct marketing (you have the right to object).
- Consent: For non-essential cookies and direct marketing communications (you can withdraw consent anytime).
3. HOW WE USE YOUR DATA
- To fulfill and manage your orders, process payments, and arrange shipping.
- To screen for fraud, sanctions, and money laundering (see our AML Policy).
- To comply with legal and regulatory obligations (tax, consumer law).
- To send you service messages (order confirmations, updates).
- With your consent, to send you marketing communications about products, offers, and news.
- To improve our website, products, and customer service.
4. DATA SHARING AND DISCLOSURES
We share your data only with trusted third parties for specific, limited purposes:
- Payment Processors: (e.g., PayPal) to complete transactions.
- Logistics Partners: (e.g., DPD, Royal Mail, DHL, DPD) to deliver your order.
- Professional Advisors: Accountants, lawyers for legal and financial compliance.
- IT and Analytics Providers: For website hosting, maintenance, and analytics (under strict data processing agreements).
- Legal Authorities: When required by law (e.g., tax authorities, law enforcement, regulatory bodies).
We do not and will not sell your personal data to third parties for their own marketing purposes. For CCPA/CPRA purposes, sharing data with advertising partners may constitute a "sale" or "sharing"; you can opt-out via our Do Not Sell My Data page.
5. INTERNATIONAL DATA TRANSFERS
As an international retailer, your data may be transferred and processed outside the EU/UK/Switzerland (e.g., to our US-based payment processor or analytics provider). We ensure such transfers are protected by appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- The UK International Data Transfer Agreement (IDTA).
- Adequacy decisions for Switzerland under the revDSG.
6. YOUR RIGHTS BY REGION
6.1. Rights under GDPR, UK GDPR, and Swiss revDSG
You have the right to: Access, Rectify, Erase, Restrict processing, Object to processing, Data portability, and not to be subject to automated decision-making. To exercise these rights, contact our DPO.
6.2. Rights under US State Laws
Depending on your state of residence, you may have the right to: Know, Delete, Correct, Opt-out of sale/sharing, Limit use of sensitive information, and Non-discrimination.
California Residents: Visit our Do Not Sell My Data page to opt-out of the "sale" or "sharing" of personal information.
Nevada Residents: You may submit a verified request to opt out of the sale of certain personal information by emailing privacy@sforne.com with "Nevada Opt-Out" in the subject line.
7. DATA SECURITY AND RETENTION
We implement appropriate technical and organizational measures (encryption, access controls, secure protocols) to protect your data. We retain your personal data only as long as necessary for the purposes we collected it, including to satisfy any legal, accounting, or reporting requirements (typically 6-7 years for tax and transaction records).
8. COOKIES AND TRACKING TECHNOLOGIES
We use essential, functional, analytics, and advertising cookies. You can manage your preferences via our cookie banner or browser settings. Full details are in our Cookies Policy.
CONTACT DETAILS & SUPERVISORY AUTHORITIES
Data Controller:
COXCOTA LIMITED
Company Number: NI725210
Registered Office: Suite 100, 92 Castle Street, Area 1/1, Belfast, Northern Ireland, BT1 1HE, UK.
Data Protection Officer (DPO) / Privacy Enquiries:
Email: dpo@sforne.com
To Exercise Your Rights (CCPA/General):
Email: privacy@sforne.com
Phone: +44 7477 205445
Supervisory Authorities:
- UK: Information Commissioner's Office (ICO) - https://ico.org.uk
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC)
- EU: The data protection authority in your EU member state of residence
Main Page
