Privacy Policy
Last updated: February 2026
Introduction
Fill My Garden Ltd ("Fill My Garden", "we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the Fill My Garden platform.
This policy applies to:
- Visitors to our website at fillmygarden.co.uk
- Garden centres and nurseries ("Business Users") who use the platform to manage their online stores
- Customers ("Customers") who browse and purchase from stores hosted on our platform
Fill My Garden Ltd is the data controller for personal data collected through the platform. For personal data processed on behalf of Business Users (e.g. their customer order data), we act as a data processor.
Information We Collect
We collect the following categories of personal data:
Account Data
When you create an account, we collect your name, email address, and password (stored securely as a hash). If you sign in via Google or Apple, we receive your name and email from those providers.
Transaction Data
When you place an order, we collect your delivery address, billing details, and order history. Payment card details are collected and processed directly by Stripe — we do not store your full card number on our servers.
Usage and Analytics Data
We collect information about how you use the platform, including pages visited, features used, device type, browser, IP address, and referring URLs. This helps us improve the platform and diagnose technical issues.
Store Data (Business Users)
Business Users provide product listings, images, pricing, store settings, and branding information. This data is used to operate their online storefronts.
Customer Data Processed on Behalf of Business Users
When Customers place orders through a garden centre's store, we process that data on behalf of the Business User. This includes customer names, email addresses, delivery addresses, and order details. The garden centre is the data controller for this data, and we act as their data processor.
Legal Basis for Processing
Under the UK General Data Protection Regulation (UK GDPR), we process your personal data on the following legal bases:
- Performance of a contract (Article 6(1)(b)) — To provide the platform services, process orders, and manage your account.
- Legitimate interests (Article 6(1)(f)) — To improve the platform, ensure security, prevent fraud, and communicate service updates. We balance these interests against your rights and freedoms.
- Consent (Article 6(1)(a)) — For optional marketing communications and non-essential cookies. You may withdraw consent at any time.
- Legal obligation (Article 6(1)(c)) — To comply with tax, accounting, and other legal requirements.
How We Use Your Information
We use the personal data we collect for the following purposes:
- Platform operation — Running and maintaining the Fill My Garden platform, including user accounts, storefronts, and dashboards.
- Order processing — Processing orders, managing delivery, and handling returns and refunds.
- Payments — Facilitating secure payments through Stripe Connect, including payouts to Business Users.
- Communications — Sending transactional emails (order confirmations, shipping updates), account notifications, and, with your consent, marketing emails.
- Customer support — Responding to enquiries, troubleshooting issues, and providing assistance.
- Analytics and improvement — Understanding how the platform is used so we can improve features, performance, and user experience.
- Fraud prevention and security — Detecting and preventing fraudulent activity, abuse, and security threats.
Who We Share Your Data With
We share personal data only where necessary to operate the platform. We work with the following categories of service providers:
- Stripe — Payment processing and Business User payouts.
- Vercel — Website hosting and content delivery.
- Neon — Database hosting (PostgreSQL).
- Upstash — Session and cache management (Redis).
- Google — Authentication (Google Sign-In) and analytics.
- Email service providers — Transactional and marketing email delivery.
When Customers place orders through a Business User's store, the relevant order information is shared with that Business User so they can fulfil the order.
We never sell your personal data to third parties.
Data Retention
We retain your personal data only for as long as necessary for the purposes set out in this policy:
- Account data — Retained while your account is active, plus 6 years after closure to comply with legal obligations.
- Order and transaction data — Retained for 6 years after the transaction date, as required by HMRC for tax and accounting purposes.
- Usage and analytics data — Retained in aggregated or anonymised form. Identifiable usage data is retained for up to 26 months.
- Marketing consent records — Retained for as long as the consent is valid, plus a reasonable period for record-keeping.
You have the right to request deletion of your personal data at any time (see "Your Rights" below). Where deletion conflicts with a legal obligation (e.g. HMRC requirements), we will explain which data must be retained and for how long.
Your Rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of access — You can request a copy of the personal data we hold about you.
- Right to rectification — You can ask us to correct inaccurate or incomplete data.
- Right to erasure — You can ask us to delete your personal data (subject to legal retention requirements).
- Right to restriction — You can ask us to restrict the processing of your data in certain circumstances.
- Right to data portability — You can request your data in a structured, commonly used, machine-readable format.
- Right to object — You can object to processing based on legitimate interests or for direct marketing purposes.
To exercise any of these rights, please contact us at privacy@fillmygarden.co.uk. We will respond to your request within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Cookies and Tracking
We use cookies and similar technologies to operate and improve the platform:
Essential Cookies
These are necessary for the platform to function, including authentication, shopping cart, and security cookies. They cannot be disabled.
Analytics Cookies
We use analytics tools to understand how visitors use the platform. This data is aggregated and does not personally identify you. You can opt out of analytics cookies via your browser settings or our cookie preferences.
Third-Party Cookies
Some of our service providers (e.g. Stripe for payments) may set their own cookies. These are governed by their respective privacy policies.
You can manage your cookie preferences through your browser settings. Please note that disabling essential cookies may affect the functionality of the platform.
International Data Transfers
Some of our service providers process data outside the United Kingdom. Where personal data is transferred internationally, we ensure appropriate safeguards are in place:
- UK-US Data Bridge — For transfers to US-based providers certified under the UK Extension to the EU-US Data Privacy Framework.
- Standard Contractual Clauses (SCCs) — Where the Data Bridge does not apply, we rely on UK International Data Transfer Agreements or Addendums to the EU SCCs, as approved by the ICO.
We only transfer data to countries or organisations that provide an adequate level of protection for your personal data.
Children's Privacy
The Fill My Garden platform is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe that a child under 16 has provided us with personal data, please contact us at privacy@fillmygarden.co.uk and we will take steps to delete that information promptly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify Business Users via email or through the platform dashboard
- Where required by law, seek your consent to the updated terms
We encourage you to review this policy periodically.
Contact Us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:
- Email: privacy@fillmygarden.co.uk
- Address: Fill My Garden Ltd, [Registered Address], United Kingdom
- Companies House: [Company Registration Number]