Liverpool Eclipse

Privacy notice

Privacy.

Controller

Jamescape Limited, Innovation Centre, 131 Mount Pleasant, Liverpool, L3 5TF. Privacy requests: hello@jamescape.net.

Information we use

We use order reference, product, batch, price, payment and fulfilment records. Stripe supplies the email needed for confirmation. For local delivery, we also collect name, phone, delivery address and optional access instructions. Do not include health details, access codes or other sensitive information in instructions.

Purposes and legal bases

Quote, payment, contract, pickup, local delivery, support and refunds are processed to perform the contract. Accounting, tax, regulator and product-safety records are kept for legal obligations. Proportionate fraud, security, audit, dispute, recall and aggregate store-usage measurement use legitimate interests. We do not create a marketing list and no advertising or session replay is enabled.

Service providers

Vercel hosts the application and provides privacy-focused web analytics; Neon stores application records; Stripe processes payment; the local courier receives only delivery-required information; Bird receives only transactional-email information; and Better Auth protects the administrator area. Vendor processing, locations, subprocessors, retention, security terms, DPAs and any UK transfer mechanism are documented in the service register.

Security and minimisation

Phone numbers, addresses and instructions are encrypted by the application. Secrets are separated by environment. Public order tokens are hashed in storage, excluded from indexing and protected by no-referrer/no-store headers. Administrator access is restricted, rate-limited and audited. We do not place personal information in payment metadata, URLs, analytics events or email subject lines beyond a short order reference.

Retention

Access instructions are deleted after fulfilment or refund and no later than seven days, unless needed for an open safety case. Operational phone and full-address fields, plus public tokens, are removed after 90 days. Payment, accounting, product-batch, safety, dispute and audit records are retained only for their confirmed legal, insurance and tax periods. Open safety incidents suspend automated deletion of relevant order data.

Analytics and cookies

The public store uses Vercel Web Analytics to measure page visits and key store actions without advertising profiles, session replay or analytics cookies. Dynamic order and marketplace tokens are removed from analytics URLs, event properties contain no contact details, addresses, payment credentials, order references or free-text information, and administrator pages are excluded. Strictly necessary secure session and security storage is used only for administrator authentication and abuse prevention.

Your rights

You may request access, correction, deletion, restriction, objection or a portable copy where applicable. You may make the request in free text by email and are not required to use an online form. We may retain information where a legal obligation or active product-safety issue requires it. You can also complain to the UK Information Commissioner's Office.

Incidents

The operator maintains a breach register and a 72-hour ICO assessment procedure covering containment, processor escalation, risk assessment, notification decisions and communications to affected people.