Privacy Policy

Last Updated: 3 February 2026

This Privacy Policy describes how Gitmalu Ltd (the "Site", "we", "us", or "our") collects, uses, and discloses your personal information when you visit, use our services, or make a purchase from www.gitmalu.co.uk (the "Site") or otherwise communicate with us (collectively, the "Services").

For purposes of this Privacy Policy, "you" and "your" means you as the user of the Services, whether you are a customer, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy.

Please read this Privacy Policy carefully. By using and accessing any of the Services, you agree to the collection, use, and disclosure of your information as described here. If you do not agree to this Privacy Policy, please do not use or access any of the Services.

CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our business practices or for legal and regulatory reasons. When updates are made, we will revise the "Last Updated" date at the top of this page and take any other steps required by applicable law. We encourage you to review this policy periodically to stay informed about how we are protecting your information.

HOW WE COLLECT AND USE YOUR PERSONAL INFORMATION

To provide the Services, we collect and have collected over the past 12 months personal information about you from a variety of sources, as set out below. The information that we collect and use varies depending on how you interact with us. In addition to the specific uses set out below, we may use information we collect about you to communicate with you, provide the Services, comply with any applicable legal obligations, enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.

WHAT PERSONAL INFORMATION WE COLLECT

The types of personal information we obtain about you depends on how you interact with our Site and use our Services. When we use the term "personal information", we are referring to information that identifies, relates to, describes or can be associated with you. The following sections describe the categories and specific types of personal information we collect.

1. INFORMATION WE COLLECT DIRECTLY FROM YOU Information that you directly submit to us through our Services may include:

  • Basic contact details: including your name, address, phone number, email.
  • Order information: including your name, billing address, shipping address, payment confirmation, email address, phone number.
  • Account information: including your username, password, security questions.
  • Shopping information: including the items you view, put in your cart or add to your wishlist.
  • Customer support information: including the information you choose to include in communications with us, for example, when sending a message through the Services.

Some features of the Services may require you to directly provide us with certain information about yourself. You may elect not to provide this information, but doing so may prevent you from using or accessing these features.

2. INFORMATION WE COLLECT THROUGH COOKIES

 We also automatically collect certain information about your interaction with the Services ("Usage Data"). To do this, we may use cookies, pixels and similar technologies ("Cookies"). Usage Data may include information about how you access and use our Site and your account, including device information, browser information, information about your network connection, your IP address and other information regarding your interaction with the Services.

3. INFORMATION WE OBTAIN FROM THIRD PARTIES

 Finally, we may obtain information about you from third parties, including from vendors and service providers who may collect information on our behalf, such as:

  • Companies who support our Site and Services, such as Shopify.
  • Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders and provide you with products or services you have requested, in order to perform our contract with you.
  • When you visit our Site, open or click on emails we send you, or interact with our Services or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.

Any information we obtain from third parties will be treated in accordance with this Privacy Policy. We are not responsible or liable for the accuracy of the information provided to us by third parties and are not responsible for any third party's policies or practices.

 

HOW WE USE YOUR PERSONAL INFORMATION

1. Providing Products and Services We use your personal information to provide you with our Services and fulfill our contract with you. This includes:

  • Transactions: Processing payments and fulfilling your orders.
  • Communications: Sending notifications regarding your account, purchases, returns, exchanges, or other transactions.
  • Account Management: Creating, maintaining, and managing your user account.
  • Logistics: Arranging for shipping and facilitating returns or exchanges.
  • Engagement: Enabling you to post product reviews.

2. Marketing and Advertising We use your personal information for marketing and promotional purposes to grow our relationship with you. This includes:

  • Direct Outreach: Sending promotional communications via email, text message, or postal mail.
  • Targeted Ads: Showing you advertisements for products or services that may interest you.
  • Personalization: Using your data to better tailor our Services and advertising on both our Site and external websites.

3. Security and Fraud Prevention

 We use your information to protect our community and platform by detecting, investigating, or taking action regarding possible fraudulent, illegal, or malicious activity. If you register an account, you are responsible for keeping your credentials safe. We highly recommend that you do not share your username, password, or other access details. If you believe your account has been compromised, please contact us immediately.

4. Communicating with You

 We use your personal information to provide customer support and improve our Services. It is in our legitimate interest to remain responsive to your needs, provide effective services, and maintain our ongoing business relationship with you.

COOKIES

Like many websites, we use Cookies on our Site. For specific information about the Cookies that we use related to powering our store with Shopify, see https://www.shopify.com/legal/cookies. We use Cookies to power and improve our Site and our Services (including to remember your actions and preferences), to run analytics and better understand user interaction with the Services (in our legitimate interests to administer, improve and optimize the Services).

We may also permit third parties and services providers to use Cookies on our Site to better tailor the services, products and advertising on our Site and other websites. Most browsers automatically accept Cookies by default, but you can choose to set your browser to remove or reject Cookies through your browser controls.

Please keep in mind that removing or blocking Cookies can negatively impact your user experience and may cause some of the Services, including certain features and general functionality, to work incorrectly or no longer be available.

HOW WE DISCLOSE PERSONAL INFORMATION

In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy. Such circumstances may include:

  • With vendors or other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and shipping).
  • With business and marketing partners, including Shopify, to provide services and advertise to you. Our business and marketing partners will use your information in accordance with their own privacy notices.
  • When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations, with your consent.
  • With our affiliates or otherwise within our corporate group, in our legitimate interests to run a successful business.
  • In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.

We have disclosed the following categories of personal information about users for the purposes set out above:

  • Identifiers: Basic contact details and certain order and account information.
  • Commercial information: Order information, shopping information and customer support information.
  • Internet or other similar network activity: Usage Data.

We do not use or disclose sensitive personal information for the purposes of inferring characteristics about you.

USER GENERATED CONTENT

The Services may enable you to post product reviews and other user-generated content. If you choose to submit user generated content to any public area of the Services, this content will be public and accessible by anyone. We do not control who will have access to the information that you choose to make available to others, and cannot ensure that parties who have access to such information will respect your privacy or keep it secure.

THIRD PARTY WEBSITES AND LINKS

Our Site may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites.

CHILDREN'S DATA

The Services are not intended to be used by children, and we do not knowingly collect any personal information about children. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted.

SECURITY AND RETENTION OF YOUR INFORMATION

Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee "perfect security." In addition, any information you send to us may not be secure while in transit. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.

When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information. However, please note that we are required by UK tax and company law to keep basic order details (such as your name, contact details, and transaction data) for a minimum of 6 years after the end of the financial year in which the transaction occurred. After this period, your data will be securely deleted or anonymized.

INTERNATIONAL DATA TRANSFERS

Your Personal Information may be transferred to, and processed in, countries outside of the United Kingdom (UK) and the European Economic Area (EEA). Specifically, as our store is hosted by Shopify, your data is transferred to Canada and the United States.

When we transfer your Personal Information to countries outside of the UK/EEA, we ensure that appropriate safeguards are in place to protect your data. For transfers to Canada, we rely on the UK Government's "Adequacy Decision," which recognizes Canada’s privacy laws as providing an adequate level of protection. For transfers to other countries (such as the United States), we rely on recognized legal mechanisms, such as Standard Contractual Clauses (SCCs) or the International Data Transfer Agreement (IDTA), to ensure your information remains protected to a standard equivalent to that of the UK.

YOUR RIGHTS (UK & GDPR)

If you are a resident of the UK or EEA, you have the right to access the Personal Information we hold about you, to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us through the contact information below.

If you are a UK resident, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe we have not handled your data properly.

CONTACT US

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail or by mail using the details provided below:

Gitmalu Ltd support@gitmalu.co.uk

Registered office: 21 East Street, Bromley, England, BR1 1QE