1. Who we are
Kendall Group Ltd is the data controller responsible for personal information handled through The Cookie Project website and store. “The Cookie Project”, “we”, “us” and “our” in this policy mean Kendall Group Ltd.
We handle personal information in accordance with applicable UK data protection law, including the UK GDPR, the Data Protection Act 2018 and relevant rules on electronic communications.
2. Scope of this policy
This policy applies when you visit thecookieproject.co.uk, create an account, place or discuss an order, request a custom cookie cutter, join our mailing list, contact us or otherwise deal with The Cookie Project. It does not cover websites operated by other organisations, even where we link to them.
3. Information we collect
Depending on how you interact with us, we may collect:
- Identity and contact details: name, email address, postal address, delivery address and any telephone number you choose to provide.
- Account details: username, encrypted password information, account preferences and saved wishlist items.
- Order and transaction details: products, sizes and options ordered, order value, payment status, refunds, delivery tracking and purchase history.
- Custom design information: artwork, measurements, instructions, approvals and messages supplied for a custom cookie cutter.
- Payment and fraud information: payment method, limited payment references, billing checks, device or risk signals and transaction identifiers. We do not receive or store your complete payment-card number.
- Communications: enquiries, complaints, reviews submitted to us and records of customer support.
- Marketing preferences: whether you have asked to receive or stop receiving email marketing.
- Technical and usage information: IP address, browser and device information, pages viewed, referring page, timestamps, security logs, cookie identifiers and consent choices.
Please do not send special category information, payment-card details by email, or more personal information than is needed for your request.
4. How we collect information
We collect information directly from you when you complete a form, create an account, place an order, send us a design, contact us or choose cookie and marketing preferences. We also collect limited technical information automatically through cookies, server logs and similar technologies.
Contact enquiries, optional reference files and newsletter sign-ups are recorded in our protected WordPress administration area so we can respond, evidence marketing consent and export the records when needed. An email notification may also be sent to our business mailbox, but a notification failure does not remove the stored form entry.
We may receive information from payment providers, fraud-prevention services, Royal Mail or another delivery provider, our website and email providers, and marketplaces through which you buy our products.
5. Why we use information and our lawful bases
| Purpose | Information normally used | Lawful basis |
|---|---|---|
| Answer enquiries, provide quotes and take steps requested before an order | Identity, contact, communications and custom design details | Contract or steps before a contract |
| Accept, make, dispatch and manage orders, returns and refunds | Identity, contact, account, order, payment status and delivery details | Contract |
| Process payments and prevent fraudulent or abusive transactions | Transaction, device, billing and risk information | Contract and our legitimate interests in protecting customers and the business |
| Keep accounting, tax, consumer-law and corporate records | Orders, invoices, refunds and relevant communications | Legal obligation |
| Operate accounts, wishlists, website security, backups and technical support | Account, technical, usage and security information | Contract and our legitimate interests in running a secure and reliable store |
| Respond to complaints, enforce terms and establish or defend legal claims | Orders, communications, technical and account information | Legal obligation and legitimate interests |
| Improve products, navigation and customer service using proportionate statistics | Orders, enquiries and appropriately limited usage information | Our legitimate interests in improving the store, or consent where required for cookies |
| Send optional email marketing | Name, email and marketing preferences | Consent, or the limited “soft opt-in” where PECR permits it; you can opt out at any time |
| Set non-essential cookies or similar technologies | Cookie identifiers, device and usage information | Consent |
Where we rely on legitimate interests, those interests are operating and improving the store, protecting customers and the business, preventing fraud, keeping appropriate records and dealing with disputes. We consider whether those interests are necessary and balanced against your rights.
Where information is required to enter into or perform a contract, we may be unable to accept or fulfil an order if it is not provided.
6. Who we share information with
We do not sell personal information. We share only what is reasonably necessary with:
- WordPress, WooCommerce, Everest Forms, hosting, backup, security, email and other IT providers supporting the store;
- Cloudflare, which provides the Turnstile security check used to detect automated or abusive form submissions;
- Stripe and any other payment or fraud-prevention provider used at checkout;
- Royal Mail and any other carrier used to deliver or return an order;
- professional advisers, insurers, auditors and accountants where necessary;
- government bodies, regulators, courts, law enforcement or other parties where disclosure is required or permitted by law; and
- a buyer, investor or adviser involved in a genuine sale, restructure or transfer of all or part of the business, subject to appropriate confidentiality and data-protection safeguards.
These recipients may act as our processor or as a separate controller depending on the service and their legal responsibilities.
7. Payments and Stripe
Card payments are intended to be processed securely by Stripe. Payment details are entered into Stripe-controlled payment components and are handled under Stripe’s own privacy information as well as our instructions where Stripe acts for us. We receive transaction references, status and limited payment information needed to administer the order, but not your complete card number or security code.
Stripe may use device and transaction information to authenticate payments, prevent fraud and meet legal obligations. You can read Stripe’s privacy policy.
8. International transfers
Some service providers may process information outside the UK. Where a restricted international transfer occurs, we require an available lawful safeguard, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another safeguard permitted by UK data protection law. You may contact us for more information about the safeguards relevant to your information.
9. How long we keep information
We keep personal information only for as long as reasonably needed for the purpose collected, including legal, accounting, security and dispute requirements. Our usual periods are:
- Orders, invoices and associated financial records: six years from the end of the company financial year to which they relate, and longer where law, a tax enquiry or a live dispute requires it.
- Customer accounts: while active, then normally deleted or anonymised within two years after closure or last activity, except for order records we must retain.
- General enquiries and support records: contact-form entries, messages and optional reference files are normally kept for up to two years after the matter closes, or longer if connected to an order, complaint or legal claim.
- Custom design files: normally up to two years after fulfilment so we can deal with remakes or queries, unless a longer or shorter period is agreed.
- Marketing records: newsletter sign-up entries, the consent wording, submission date and source are kept while you remain subscribed. After you unsubscribe, we may retain a minimal suppression and consent record so we honour and can evidence your choice.
- Routine security and server logs: normally up to 12 months unless needed to investigate an incident.
- Cookies: for the periods described in our Cookie Policy.
We may anonymise information so it can no longer identify you and use that anonymous information for statistics.
10. Security
We use proportionate organisational and technical measures designed to protect information against accidental loss, unauthorised access, alteration or disclosure. Measures include access controls, encrypted connections, security monitoring, backups and limiting access to people and providers who need it. No online system is completely risk free, so please use a unique password and contact us promptly if you believe your account or information has been compromised.
11. Your data-protection rights
Depending on the circumstances, you may have the right to:
- ask for access to your personal information and a copy of it;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information where there is no lawful reason to keep it;
- ask us to restrict how information is used;
- object to processing based on legitimate interests or to direct marketing;
- receive certain information you provided in a portable format;
- withdraw consent at any time, without affecting earlier lawful use; and
- complain to the Information Commissioner’s Office.
Some rights are subject to legal conditions and exemptions. We may ask for information to verify your identity. We normally respond within one month and do not charge unless a request is manifestly unfounded or excessive.
12. Children and automated decisions
Our store is intended for adults making purchases. We do not knowingly collect information directly from children under 13. If you believe a child has provided information without appropriate permission, please contact us.
We do not currently make decisions ourselves based solely on automated processing that produce legal or similarly significant effects. Payment and fraud-prevention providers may use automated tools under their own policies.
13. Contact, complaints and changes
For questions or to exercise a right, email [email protected] or write to Kendall Group Ltd, 51 Birch Grove, Mansfield, England, NG18 4JH. Please mark postal correspondence “Data Protection”.
We would appreciate the opportunity to resolve a concern first. You may also complain to the Information Commissioner’s Office, the UK data-protection regulator.
We may update this policy when our services, providers or legal obligations change. Material changes will be highlighted where appropriate.
Last updated: 27 August 2026