Version 2.2
June 2024
We take the safety and security of our customers’ personal information seriously and have prepared this Privacy Notice to explain to you, our customers, how we use that personal information.
We keep this Notice under regular review, and this version was last updated on 20 June 2024.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
This Notice tells you about your privacy rights and how the law protects you, and sets out the basis on which we use the personal information you share with us.
To make sure you have a full picture of how we collect and use your personal information, this Notice describes:
In this Notice we use the words personal information to describe information that is about you and which identifies you.
You have the right to object to our use of your personal information in certain circumstances. A summary of your right to object (along with your other legal rights relating to that personal information) and the details of who to contact if you want to exercise them can be found in the 'Your rights in relation to your personal information' section below.
It is important that you read this Notice together with any other privacy notice we may provide on specific occasions when we are collecting or processing personal information about you so that you are fully aware of how and why we are using your personal information. This Notice supplements other notices and privacy policies and is not intended to override them.
Our websites and products are not intended for people who are under the age of 18, and we do not knowingly collect data relating to children.
Knickerbox.com is a trading name of Ann Summers Ltd, a company registered at Gold Group House, Godstone Road, Whyteleafe, CR3 0GG, United Kingdom with company number 01034349.
If you shop online at Knickerbox.com, Ann Summers Limited dictates the purpose for which your personal information is used and how it is used and is the controller of your personal information.
We have appointed a Data Privacy Manager who is contactable by email to support@knickerbox.com or by post at Gold Group House, Godstone Road, Whyteleafe, CR3 0GG.
The personal information that we collect, use and store about you may include the following:
Category | Examples | Collected from |
Identity | name, social media handle, title and date of birth | You, when you sign up for an account, place an order. |
Contact | billing address, delivery address, email address and telephone numbers | You, when you sign up for an account or place an order. |
Financial | bank account and payment card details | You, when you make payment for a purchase. |
Transaction | details about payments to and from you and other details of products and services you have purchased from us | You, when you purchase products from us. |
Technical | internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website | You, when you browse our website. |
Profile | your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses | You, when you place an order, complete a survey or browse our website. |
Usage | information about how you use our website, products and services | You, when you browse our website. |
Marketing | your preferences in receiving marketing from us and our third parties and your communication preferences | You, when you make a purchase, subscribe to our mailing list. |
We use your personal information in various ways, for a variety of different purposes, and we will only ever use if we have a legal reason to do so. Sometimes we might ask for your explicit consent to process your data in a certain way, but mostly we will rely on other legal reasons, which include the following:
We have set out in the table below the main purposes for which we use your personal information, together with the applicable legal basis that we rely on for doing so. Where we rely on our legitimate interests as a legal basis, we have also set out those interests.
Purpose | Type of Data | Legal Reason |
To register you as a new customer |
|
To perform the contract we have with you |
To process and deliver your order including: (i) to select your products and pack your order; (ii) to provide updates on your delivery status; (iii) to manage payments, refunds and (iv) to collect money owed to us. |
|
|
To manage our relationship with you, which will include: (i) notifying you about changes to our terms or privacy policy; (ii) managing any complaints or enquiries; (iii) notifying you about any product recalls. |
|
|
To enable you to partake in a prize draw, competition or complete a survey. |
|
|
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data). |
|
|
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you. |
|
Legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy) |
To ask you to leave a review for a product you have purchased. |
|
Legitimate interests (to study how customers use our products/services, to develop them, to grow our business) |
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences. |
|
Legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy) |
To make suggestions and recommendations to you about goods or services that may be of interest to you. |
|
Legitimate interests (to develop our products/services and grow our business) |
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. We have established the following personal data control mechanisms to help ensure that you only receive the marketing, advertising and offers that may be relevant to you.
We may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you (we call this marketing).
You will receive marketing communications from us if you have requested information from us or purchased products from us and you have not opted out of receiving that marketing.
We will get your express consent before we share your personal data with any third party for marketing purposes.
You can ask us or third parties to stop sending you marketing messages at any time by following the opt out links on any marketing message sent to you.
Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a product purchase.
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. For more information about the cookies we use, please see our Cookie Policy.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law
We may transfer personal information to third parties as follows:
For a full list of the categories of third parties that we may share your personal information with, please contact us.
We require all third parties to whom we disclose your personal information to treat it securely and in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
Our head office is located and registered in the UK. Some of the recipients we may share your personal information with may be in countries outside of the UK, so their processing of your personal information will involve a transfer outside of the UK.
Whenever we transfer your personal information out of the UK, we are committed to taking all necessary measures to ensure that transfers of your personal information are adequately protected as required by applicable data protection law. This includes ensuring at least one of the following safeguards is implemented:
Please contact us if you want further information on the specific mechanism used by us when transferring your personal information out of the UK.
Our policy is to not keep personal information for longer than is necessary. By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they cease being customers for tax purposes.
In some circumstances you can ask us to delete your data: see your legal rights below for further information.
In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have also put in place procedures to deal with any suspected personal information breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
You have several legal rights in relation to your personal information.
You also have the right to lodge a complaint with the supervisory authority in the UK, which is the Information Commissioner's Office (the 'ICO'). More information can be found here: https://ico.org.uk/.
If you require our assistance to exercise any of these rights, please contact us.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Stay in the loop on all things Knickerbox:
Updates on new arrivals, inspiration and offers!
By inputting your information, you agree that we can use it in accordance with our Privacy Policy. You are able to unsubscribe from marketing at any time. By proceeding you agree to our Terms and Conditions.
By inputting your information, you agree that we can use it in accordance with our Privacy Policy. You are able to unsubscribe from marketing at any time. By proceeding you agree to our Terms and Conditions.