Privacy Policy
Your privacy matters to us. This policy explains how we collect, use and protect your personal information when you shop with Croft & Cleo.
Last updated: June 2025
Who we are
Croft & Cleo is a trading name of An Larach Holdings, a Partnership registered in Scotland. Our registered address is An Larach House, Fassach, IV4 7HT. When we refer to “we”, “us” or “our” in this policy, we mean An Larach Holdings (trading as Croft & Cleo), the data controller responsible for your personal information.
If you have any questions about how we handle your data, please contact us.
What information we collect
Information you give us
When you place an order or create an account, we collect information such as your name, delivery address, email address, telephone number and payment details. Payment information is processed securely by our payment provider and is not stored by us.
Information collected automatically
When you visit our website, we may automatically collect certain information about your device and browsing behaviour, including your IP address, browser type, pages visited and how you found us. This is collected using cookies and similar technologies. Please see our Cookie Policy for further details.
How we use your information
We use your personal information to:
- Process and fulfil your orders, including arranging delivery and handling returns
- Communicate with you about your order or any queries you have raised
- Send you marketing communications, where you have given your consent
- Improve our website and the products we offer
- Meet our legal and regulatory obligations
Legal basis for processing
- Contract: to fulfil orders and provide the services you have requested
- Legitimate interests: to improve our services and communicate relevant information
- Legal obligation: to comply with applicable laws and regulations
- Consent: for marketing communications, which you may withdraw at any time
Who we share your information with
We do not sell your personal data. We may share it with third parties only where necessary, including:
- Delivery carriers, to fulfil and track your orders
- Payment processors, to handle transactions securely
- Our e-commerce platform provider (Shopify), which hosts our store
- Analytics services, where you have given consent
All third parties we work with are required to handle your data securely and in accordance with applicable data protection law.
How long we keep your data
We retain your personal information for as long as is necessary to fulfil the purposes described in this policy and to meet our legal obligations. Order records are generally retained for six years in accordance with UK accounting and tax requirements. You may request deletion of your data at any time, subject to any overriding legal obligations.
Your rights
Under UK data protection law, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request erasure of your data, subject to legal retention requirements
- Object to or restrict how we process your data
- Request that we transfer your data to another organisation
- Withdraw consent for marketing at any time
To exercise any of these rights, please contact us. We will respond within one calendar month.
If you are not satisfied with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
Security
We take the security of your personal information seriously. Our website uses SSL encryption to protect data in transit, and we implement appropriate technical and organisational measures to prevent unauthorised access, loss or disclosure.
Changes to this policy
We may update this Privacy Policy from time to time. Any changes will be published on this page with a revised date. If you have any questions, please contact us.