Privacy policy
Sam Mackulin/ Sam Mackulin Art Privacy Policy
Date Completed: 12/08/2022
Last Updated: 22/05/2026
Our contact details
Name: Samantha Mackulin
E-mail: sammackulinart@gmail.com
This Privacy Policy describes how your personal information is collected, used, and shared when you visit or make a purchase from www.sammackulin.com.
We currently collect and process the following information:
Order Information – including your name, billing address, shipping address, payment information (including credit card numbers, relevant Paypal information) email address, and phone number.
Names and Email Addresses (in isolation to an order.)
PLEASE NOTE - Shopify may still collect this data if you input all your details, even if you do not place an order, meaning when you abandon the checkout. However I do not use abandoned checkout information and will erase it as soon as possible if it ever does get collected.
When you visit our website (may be referred to in this document as ‘the site’) we automatically collect certain information about your device, including: information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the site, we collect information about the individual web pages or products that you view, what websites or search terms referred you to the site, and information about how you interact with the site. We refer to this automatically-collected information as “Device Information.”
You may also consent to additional cookies (via the cookie banner) these cookies and other tracking data help to enable store analytics and marketing.
Applications within shopify also access certain store data in order to function and perform their relevant purpose, all apps are checked to be meeting relevant data protection standards by shopify.
Please Note: if you are browsing from California, under the California Consumer Privacy Act (CCPA), customers in California have the right to opt out of the sale of their data. Please see: https://sammackulin.com/pages/ccpa-opt-out
Please Note: our website is hosted on Shopify, Shopify have their own privacy policy that contains more in depth information on what data Shopify itself may collect/hold. https://www.shopify.com/legal/privacy/customers
Shopify now uses a system called 'Shopify network intelligence,' Shopify states, 'customer data is securely used with other Shopify data to improve products, ad targeting, and personalization for your store as described in the Additional Services Terms. No other merchant can see your data.' Please note I cannot disable this for my shop without loosing significant tools such as tools for my mailing list.
Please Note: If you contact customer support through Shopify, Shopify may take various personal information as given by the customer through the support channels, this should again be referred to the Shopify privacy policy above as the merchant does not hold or take responsibility for this information.
Please Note: If you choose to use Paypal to pay then you are allowing Paypal to process personal information which will be transferred between Shopify and Paypal. Please view Paypal's privacy policy for more information.
Please note: MINORS
The Site is not intended for individuals under the age of 16 and those under the age of 16 should not place an order to this site.
Please note: CHANGES
We may update this privacy policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons.
How we get the personal information and why we have it:
Most of the personal information we process is provided to us directly by you for one of the following reasons:
Your ‘Order Information’ will be collected when you make or attempt to make an order on our website.
You have contacted us and given us your information to contact you/reply.
You have signed up to a mailing list and consented to receiving email marketing, updates, offers and more.
We collect Device Information using the following technologies:
- “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. For more information about cookies, and how to disable cookies, visit http://www.allaboutcookies.org. Additional Cookies can be consented to or rejected via the Cookie banner displayed on or website.
- “Log files” track actions occurring on the Site, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
- “Web beacons,” “tags,” and “pixels” are electronic files used to record information about how you browse the Site.
We also receive personal information indirectly, from the following sources in the following scenarios: Not Currently Applicable
We use the information that you have given us in order to:
We use the Order Information that we collect generally to fulfill any orders placed through the site (including processing your payment information, arranging for shipping, and providing you with invoices and/or order confirmations). Additionally, we use this Order Information to:
- Communicate with you;
- Screen our orders for potential risk or fraud; and when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.
We use the Device Information that we collect to help us screen for potential risk and fraud (in particular, your IP address), and more generally to improve and optimize our Site (for example, by generating analytics about how our customers browse and interact with the Site, and to assess the success of our marketing and advertising campaigns).
Reply to a contact request we received from you.
Send email offers, marketing, updates, blog posts and more, (only as consented to when signing up to email mailing list.)
Your address (usually only your postcode) may also appear on my post office receipts and proof of postage which I store with my receipts. This is usually with tracked orders only. I do not share or show this information when inputting my self assessment tax return.
Please note: particularly for international orders such as U.S. orders, your email address and phone number needs to be given when sending your order through royal mail, this is to ensure customs can contact you if there is a problem with your order. It is difficult to send orders to the U.S. without this information as it is a requirement.
We may share this information with:
We share your Personal Information with third parties to help us use your Personal Information, as described above. For example, we use Shopify to power our online store--you can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy.
We share relevant personal information with Royal mail and/or the post office so we can send your order, if you choose tracked shipping we may also share your email with Royal Mail so they can send you updates on tracking your order.
We also use Google Analytics to help us understand how our customers use the Site--you can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout.
Finally, we may also share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
GDPR Compliance Centre – Application within Shopify that monitors data collected by cookies, hosts the cookie banner and helps us to better comply with GDPR rules. The Apps Privacy Policy: https://www.pandectes.io/privacy-policy/
Please Note: DO NOT TRACK:
Please note that we do not alter our Site’s data collection and use practices when we see a Do Not Track signal from your browser.
Under the UK General Data Protection Regulation (UK GDPR), the lawful bases we rely on for processing this information are:
(a) Your consent. You are able to remove your consent at any time. You can do this by contacting sammackulinart@gmail.com
(b) We have a contractual obligation.
How we store your personal information:
Your information is securely stored.
When you place an order through the site (and you have not signed up for our mailing list), we will keep any data collected as stated for no longer than necessary, our current retention period (length of time we keep your data) is 1 year and 6 months since your last order or attempted order/ anytime Shopify collected data you input into the store whether you placed an order or not. We then do an erasure of your data by requesting data erasure through Shopify. We will dispose of any information stored elsewhere by deleting the digital information and any backups, and shredding and destroying any physical documents that displayed the information. To clarify the above statement for attempted orders, Shopify also collects your data or some of it when you attempt to make an order but it is not fully completed. This data has the same retention period of 1 year and 6 months. Please note that receipts showing postcodes only will need to be kept for up to 7 years for tax purposes, this is typically only on tracked orders.
We will retain the record of your order but with annoymised data, as this is important for our records and for things like tax purposes.
In the case of an active dispute with your order the data erasure process would begin once the dispute was resolved.
Most recent customer erasure completed in September 2025 of any customer who's last order or attempted order was placed before December 2024. (A reminder this does not include customers who are signed up to the mailing list.)
You always have the right to request the erasure of your data but please note that your data cannot be erased through Shopify any sooner than 6 months, or 180 days since your last order as Shopify does not allow this incase of any issues with orders, your data will automatically be erased after this time period. Contact me at sammackulinart@gmail.com to request this.
This information would also be destroyed within 90 days of the business closing down. Shopify states it will ‘purge personal data within 90 days after a store is closed.’
If you have contacted us via email but there is no continued need or permission to remain in contact any data collected and your email address will be erased at least 2 years since our last email correspondence.
After consenting to joining our mailing list we keep your data indefinitely, you may request to remove your email from the list at any time and your data would be erased after the period explained above or as requested.
Another reason would be if/when the business closed down. We will then dispose of your information by deleting the digital information and any backups, shredding and destroying any physical documents that displayed the information.
Cookie data is kept temporarily by Shopify. Shopify automatically destroys this data after a certain time. Please view this link for all the time periods for various cookies that the information is held and a more in depth explanation of each cookie and its uses: https://www.shopify.co.uk/legal/cookies.
Read more about Shopify data erasure and erasure requests here:
Your data protection rights:
If you are a European resident, you have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted. If you would like to exercise this right, please contact us through the contact information below.
Additionally, if you are a European resident we note that we are processing your information in order to fulfill contracts we might have with you (for example if you make an order through the Site), or otherwise to pursue our legitimate business interests listed above. Additionally, please note that your information will be transferred outside of Europe, including to Canada and the United States.
Under data protection law, you have rights including:
Your right of access - You have the right to ask us for copies of your personal information.
Your right to rectification - You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
Your right to erasure - You have the right to ask us to erase your personal information in certain circumstances.
Your right to restriction of processing - You have the right to ask us to restrict the processing of your personal information in certain circumstances.
Your right to object to processing - You have the the right to object to the processing of your personal information in certain circumstances.
Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Please contact us at sammackulinart@gmail.com if you wish to make a request.
Note: If an erasure request is received and you placed an order with our shop within the last 180 days, your data will not be erased by Shopify until the 180 days have passed.
How to complain
If you have any concerns about our use of your personal information, you can make a complaint to us at sammackulinart@gmail.com.
You can also complain to the ICO if you are unhappy with how we have used your data.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk