Information We Collect
Name, address and postcode.
Email address – this is only taken if you request that we contact you this way.
Telephone numbers – this is our primary method of communication with you and is vital for us to contact you to advise when your order is complete and ready for collection or if we encounter problems during the execution of your order to enable us to contact you quickly to discuss.
Payment card number, expiry date, issue no. and name of card holder – We may collect but will not hold payment card information. Dependant on the ordering method, payment card information is either:
Telephone – taken verbally and entered onto a secure online payment provider (WorldPay) by the salesperson.
In person – taken via a chip and pin terminal.
Where you heard about us - we may ask you this to help make our marketing more efficient.
Correspondence - if you contact us we may keep a record of that correspondence.
IP addresses - when you visit our site, we will automatically receive your IP address, a unique identifier for your computer or other access device.
Cookies - As with the majority of websites, we collect cookies to enhance user experience and to enable our site to properly function. You can read more information on Cookies and how we use them in the Cookies Policy section
How We Use the Information We Collect
Our main uses of your information are explained above which in general is to process your orders, as well as to help us understand your needs and provide you with a better service.
Your account may be used to store information about your previous purchases and personal preferences. But you should also be aware of the following uses –
Marketing - we may use the information we collect to inform you, by SMS, email or equivalent, about offers, products and services that we offer that we think may be of interest to you.
WE NEVER HAVE AND NEVER WILL SUPPLY THIS INFORMATION TO THIRD PARTIES FOR ANY MARKETING PURPOSES WHATSOEVER.
We will tell you about this when we collect your information and if you do not wish to receive these communications, please let us know. You can change your mind at any time by emailing in with your request.
Customer care and correspondence - as part of our customer care procedures, we may follow-up, either by phone, SMS or email, customers who have purchased goods or services from our shop or who have posted comments about Abingdon Picture Framing on the internet, for example to resolve a complaint or to ask for a testimonial.
Market research - from time to time, we may also use your information to contact you for market research purposes. We may contact you by phone or email.
Website improvement - to help us design our website and improve your experience, we may collect information about the way you use and access our website. We collect information about each visitor, including IP address, the length of time spent on the website and the order in which pages are visited. This is explained in more detail in our Cookies Policy.
Fraud Prevention - in order to protect our customers and us from fraud and theft, we may look at the information that we get from making identity checks and other information in our customer records and may pass this to other group companies, and to financial and other organisations (including law enforcement agencies) involved in fraud prevention and detection, to use in the same way.
Delivery Fulfilment – we will share address and contact information with third party carriers and postal fulfilment providers to enable deliveries to be completed.
You have a right to access the personal information that is held about you. To obtain a copy of the personal information Abingdon Picture Framing holds about you, please email us at enclosing your name, postal details and the details of your request.
Security - we have taken many steps to make sure your trading experience with us is secure. Information about you will be kept safe and secure. In order to prevent unauthorised access or disclosure of your information, we have put in place suitable physical, electronic and managerial procedures to protect and secure information that is collected instore and online.
Keeping your information secure;
Security on our premises - access to your information is restricted in our premises. Only employees who need the information to perform a specific job are granted access to personally identifiable information. The servers that store this information are kept in a secure environment.
Notification of Changes to This Policy
Payment Card Security - The Website has numerous security measures in place to protect the loss, misuse and alteration of information under our control, such as passwords and firewalls.
We stringently follow WorldPays card payment security protocols and comply fully with the Payment Card Industry Data Security Standard (PCI DSS)
We cannot, however, guarantee that these measures are, or will remain, adequate. We do, however, take data security very seriously and will use all reasonable endeavours to protect the integrity of the information you provide.
Who we share your personal information with and why?
We share your personal information with third party service providers that we use to complete services and to manage our infrastructure. We do not sell or disclose your personal information to governments, marketing or advertising services, other clients or anyone else except as outlined in this statement or as may be required by law.
Why do we collect personal information?
We collect personal information in the course of our business activities. Our primary function is as a retailer to consumer service supplier. We assume that the personal information you supply relates to you. Holding and processing the data is necessary for the purposes of the legitimate interest we pursue in providing our products and services to you.
When we provide our services to you as our client, you are generally responsible for the following aspects of the collection and processing of personal information:
Determining what personal information, we collect and how we use it;
Establishing a legitimate basis to collect and process personal information and ensuring that the collection and processing complies with the applicable law;
If appropriate, you are notified of, or provide consent for, the collection and processing of your personal information in accordance with applicable law;
Complying with any legal obligation you may have as the entity that controls or owns the personal data.
Generally speaking, we will be responsible for the following aspects of the collection and processing of personal information:
Carrying out the services requested by you in accordance with your instructions;
Storing and protecting personal information in our custody in accordance with your instructions; and
Comply with any legal obligation we may have as a data processor, custodian, service provider or similar under applicable law
We will not reuse personal information for a new purpose other than the original one(s) for which it was collected, unless:
the new use is compatible with the original one, meaning you should reasonably expect it;
we have notified you of the new use and given you an opportunity to object to it; or
the new use is otherwise permitted or required by law.
When, why and how do we communicate personal information outside of
Abingdon Picture Framing?
To complete services
When we provide our services to you, we may transmit personal information back and forth. This is done through our secure web platforms, phone and email and occasionally by mail.
Engage services providers
Whilst most of our work is carried out by our employees or authorised personnel who access personal information directly from our systems and whose activities are under our direct control, we use third party service providers for certain specialised tasks, information technology support and some services we perform for our clients.
It would be impractical to list all the service providers, however, should you wish to understand which service providers may receive your personal information, please contact us.
When we provide services to a client it is done so in accordance with your instructions.
In exceptional circumstances, we may be asked to communicate personal information to law enforcement agencies, national security agencies, courts or other public bodies in any jurisdiction where we are subject to the law, regardless of where personal information is stored. If we receive a production order, warrant, subpoena or other enforceable demand, we will comply as required by law. If we receive a request to provide information voluntarily, we will consider your interests, our business interests, the interests of our clients, public safety implications and our legal obligations prior to deciding whether to communicate personal information. In any case where the information in question was collected from or on behalf of a client, we will consult with you before proceeding unless prohibited by law.
We may proactively communicate personal information to law enforcement or other third parties if necessary to investigate or report a violation of the law or a contractual agreement or if otherwise appropriate and permitted by law.
How do we ensure your personal information is accurate?
Much of the personal information we collect comes directly from you, in which case you are in control of its accuracy. Our processes for collecting and transcribing personal information are automated to the greatest extent possible and are subject to rigorous quality controls. Information that is found to be inaccurate, either through our own audits or following your request for correction, is updated.
Do we engage in automated decision-making or profiling using personal information?
We do not make decisions about you, automated or otherwise, and do not attempt to analyse or predict your behaviour preferences, interests, health or other personal characteristics.
Do we conduct research using personal information?
We do not use your personal information to conduct any research.
How long do we keep personal information?
We keep personal information as long as you are a customer of ours or as long as we need to keep it to comply with our legal obligations. For information on how long your personal information may be retained, please contact us.
Do we transfer personal information between countries?
We do not transfer personal information between countries. Your personal information is collected and stored in the United Kingdom.
How do we protect personal information?
We have advanced security measures in place to secure and protect your personal information, such as internal and external firewalls, monitoring and alert systems to prevent and detect intrusion attempts. Our servers are located within a securely managed infrastructure. Our employees access data through secure desktop interfaces and our online interfaces are encrypted, password protected and monitored.
We employ equally rigorous physical security policies to prevent physical access to our premises. Our servers and offices, including personal information in hard copy form, are kept in access-controlled and monitored environments.
We restrict access to your personal information to individuals who need it to perform their work functions. Our staff and account management personnel may have regular access to your information as necessary and to fulfil our legal obligations.
We also enter into contractual agreements with service providers (such as WorldPay for example) with which we may need to share your personal information, which require them to protect your personal information to the same level as we do.
How can you choose how and whether we collect and use your personal information?
Providing your information to us is voluntary. The purpose for collecting personal information is to enable us to provide our products and services to you.
Whenever our legitimate basis for collecting and using personal information is your consent, you can withdraw or modify your consent for future collection or use of your personal information at any time, and we will explain the consequences of doing so.
If we use your personal information for sales or marketing purposes, you can ask us to stop at any time and we will do so.
How can you access or correct your personal information, request that it be deleted, or ask for it to be transferred to another organisation?
At any time, you can request access to your personal information, request that any inaccuracies will be corrected, and request that comments or explanations be added to records about you.
You can also ask about:
whether and why we have your personal information;
how we got your personal information;
what we have done with your personal information;
to whom we have communicated your personal information;
where your personal information has been stored, processed or transferred;
how long we will retain your personal information, or how that retention period will be determined; and
the safeguards in place to protect your information when it is transferred to third parties or third countries.
Finally, you can ask us not to collect or use your personal information for certain purposes, you can ask us to delete your personal information, or you can ask us to provide your personal information to a third party.
Depending on which laws apply to your personal information, we may only be able to do some of these things for you. If you request one of these things and we refuse to do it, we will explain your legal rights, the reason for our refusal and any recourse you may have.
How can you make a complaint about how we have handled your personal information or responded to a request to exercise your rights?
We commit to investigating and resolving complaints about our collection or use of your personal information. To make a complaint, contact us at