Privacy policy
Held Dear ("we", "us", "our") is operated by Mondaylabs Ltd, a company registered in England and Wales (company no. [COMPANY NUMBER]). We are the data controller for the personal information described below. This policy explains what we collect, why, and the rights you have.
What we collect
- Order & contact details: name, email, shipping address, and order history.
- Payment information: processed securely by our payment providers (e.g. Shopify Payments). We do not store full card numbers.
- Your images: the drawing or photo you send us so we can make your pendant, plus the digital proofs and finished-piece photos we create from it.
- Site usage data: basic analytics and cookies (see "Cookies" below).
Why we use it & our legal basis
- To fulfil your order and provide customer support — performance of a contract.
- To send order and proof emails — performance of a contract.
- To send marketing emails, only if you opt in — consent.
- To show before/after marketing images (the drawing alongside the finished piece), only where you have given consent at checkout — consent.
- To meet legal and accounting obligations — legal obligation.
Children's drawings (COPPA & safeguarding)
The drawings we receive are submitted by an adult customer as artwork/source material for a commissioned product. We do not knowingly collect personal information directly from children, and we never publish a child's face or identifying details. Marketing images only ever show the artwork and the finished piece, never a child's photograph.
Sharing your information
We share data only with the service providers who help us run the shop (e.g. our e-commerce platform, payment processors, and shipping carriers), and only as needed to fulfil your order or comply with the law. We never sell your personal information.
Withdrawing marketing consent
You can withdraw consent to marketing — including consent to share your drawings/finished pieces — at any time by emailing helddear.life@proton.me. When you withdraw consent, we will stop using those images for marketing and take down any such images we control within 30 days.
Your rights
Depending on where you live, you have rights to access, correct, delete, restrict, or port your data, and to object to certain processing:
- UK / EU residents — under the UK GDPR, the Data Protection Act 2018, and the EU GDPR. You may also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
- California residents — under the CCPA/CPRA, including the right to know, delete, and opt out of "sale/sharing" of personal information. We do not sell personal information.
To exercise any right, email helddear.life@proton.me.
Data retention
We keep order records for as long as required for accounting and legal purposes, and keep your images only as long as needed to fulfil your order and any agreed marketing use.
Cookies
We use essential cookies to run the store (cart, checkout) and, with your consent where required, analytics cookies to understand how the site is used. You can manage non-essential cookies through the cookie banner shown in regions with privacy laws.
Contact
Data questions or requests: helddear.life@proton.me.