- Who we are
1.1. We are Mister Men Limited (“us”, “we” or “our”).
1.2. We are the sellers of the products on the Sanrio webshop for UK, Europe, Australia and New Zealand www.shopsanrio.com (the “Website”).
1.3. If you are using our Website from the UK or Europe, we are also the “Data controller” - as defined under section 4, No. 7 of the GDPR - that processes your personal data pursuant to the GDPR. You can find all our contact details in Section 10 below.
1.4. Our partners for this service are:
- Sanrio GmbH, who is the principal licensee of the intellectual property rights embedded in our products;
- Star Editions Limited (a company registered in England with company number 06628133) who are our fulfilment partner and who print (where applicable) and arrange for delivery of all orders;
- Shopify, who provides the e-commerce platform;
- Shopify Payments, who processes payments paid via credit / debit card;
- PayPal, who processes payments paid via Paypal;
- Royal Mail, who handles shipping and delivery; and
- UK Mail, who handles shipping and delivery if you choose the couriered option at checkout.
1.5. If you are using our Website from the UK or Europe, please note that Star Editions Limited and Shopify have been appointed as Data Processor pursuant to Section 28 of the GDPR. The other partners listed under section 1.4 operate either as autonomous data controllers (in which case you can find a link to their privacy policies below) or as one of our partner's other processors, pursuant to Section 28, par. 4 of the GDPR.
- What personal information do we collect and process?
The information collected about you differs depending on how you use the website. For example, we may collect information directly from you when you provide it to us, or when you browse or make purchases on the Website.
2.1. When you make a product purchase we collect and process:
- Contact number
- Email address
- Payment information
- Browsing data
We will process your personal data for the sole purpose of performing the order you have placed. If you are making a product purchase from the UK or EU, the legal basis for the data processing is the performance of the purchase agreement you have entered with us. The provision of your personal data is optional. However, if you refuse to provide us with the personal data listed above when you make a product purchase through our Website you will not be able to place the order and thus enjoy our products.
2.2. In relation to user web activity / browsing the site we collect and process:
- Browsing data such as the pages you visit, the time you spend on each page and which country you are located in.
- IP Address which are numbers that can uniquely identify a specific computer or other network device on the internet.
Please note that we shall process the data listed above for (i) marketing communications purposes concerning our and/or our partners’ products, offers and competitions; and (ii) profiling purposes. If you are browsing our Website from the UK or Europe, the legal basis for this data processing will be your explicit prior consent. If you refuse to provide us with your consent there shall be no consequences. However, you will not be able to receive information regarding our and/or our partners’ marketing and promo-advertising initiatives, offers, as well commercial communications that might be of interest to you. In case you provide us with your consent for carrying out profiling activities this will entail an automated activity in order to allocate your personal data into a category of subjects with homogeneous characteristics (in terms of purchase preferences) on the basis of the products and/or services you have previously purchased, any market surveys that you may have completed, your demographic class and your web activities when browsing and using our Website.
2.3. If you enter a competition we collect and process:
- Contact number
- Email address
Please note that we shall process the data listed above for the sole purpose to perform the competition. If you are a UK or EU citizen entering the competition, the legal basis for the latter data processing will be the performance of the competition agreement to which you have agreed. Please note that the provision of your personal data is optional. However, if you refuse to provide us with the personal data listed above when you are entering the competition through our Website, you will not be able to participate to the competition.
- Information collected automatically during your use of our services:
Some information is automatically collected whilst you browse the Website, we use this information to improve our Website and service to you.
3.1. When you use our services we record information about your usage of those services, your interaction with our promotions and our emails as well as information about the device you are using and your internet connection.
We do this in two ways:
3.2. Log data: When you use our services, certain information gets recorded in our log files such as your device's Internet Protocol (IP) Address, its unique ID, its operating system and location, and your browser type, the pages you viewed, cookie information and referral links (the link that sent you to a particular page).
3.3. Tracking technologies (cookies): In conjunction with our log data we may use tracking technologies such as tags on our web pages and small data files which we store on your device (known as "cookies"). These technologies enable us to recognise your device and to track your interaction with our services
3.4. See our Cookies Policy for more information.
- What do we do with your data?
Your data will be used differently depending on whether you’re just browsing the Website, making a purchase or entering a competition. If you purchase something on our site, then you’ll be using our service.
4.1. We need to take personal information from you when you place an order, to pass on to our fulfilment partner and their third-party shipping service.
If you are making a product purchase on our Website from the UK or EU, see Section 2.1. above.
Marketing data and competition
4.2. If you opt-in, you will receive marketing information from us and/or from Sanrio GmbH including latest offers and competitions.
If you are an UK or EU user, see Sections 2.2. and 2.3. above.
Only when opted-in, will you receive marketing updates and the latest offers from our store and/or concerning the Sanrio brands. You can unsubscribe from these at any time by following the ‘unsubscribe’ link on any of our emails. Once you have unsubscribed, you will be removed from our marketing list as soon as reasonably practicable.
If you are a UK or EU user of our Website, see Section 2.2 above.
- Where do we store your data?
- Who do we share your data with?
6.1. Within our organisation, your personal data may be processed by the relevant offices entrusted with the execution of certain processing activities (i.e. Administration, Sales, Marketing, IT, Finance, Legal). We will only share your information with third parties (other than Star Editions Limited and Sanrio GmbH) if we have your consent to do so or when they are providing a service for us. Such third parties will only use that information in accordance with our instructions and not for their own purposes. Otherwise, we will keep your information confidential except where disclosure is required or permitted by law (for example to government bodies and law enforcement agencies).
6.4. Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
6.5. Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
6.6. If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS).
6.7. All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
For more information you may also want to read Shopify’s Terms of Services (https://www.shopify.com/legal/terms) or Privacy Statement (https://www.shopify.com/legal/privacy).
Royal Mail and UK Mail
6.8. Your name, address, email and contact number will be passed by Star Editions to Royal Mail (for standard shipping) or UK Mail (if you choose the couriered option at checkout) in order for them to deliver your goods. We or Star Editions will send email updates to let you know when your order is being processed and when it has been shipped. If using the couriered option, UK Mail may contact you by email or phone with further delivery instructions.
6.9. Some of the third parties referred to in this clause 6 are located in the same country as you. However, others may be located overseas, including in the UK, countries in the EU and the USA.
- Tracking Technologies
7.1. We use different types of cookies for different things, such as:
- Analyse how you use the Website
- Calculate currency based on your location
- Process your order
7.2. We use Google Analytics to monitor website usage and provide us with anonymised analytics data concerning visits to the website.
7.3. We use Facebook Pixel to monitor traffic from Facebook adverts and for the tailoring of advertising content across Facebook. All the data collected and processed through Facebook Pixel is anonymous.
- Links to other websites
- Your rights
Retention of your personal data
9.1. If you are under 18, please get your parent/guardian’s permission before providing us with any personal information.
9.2. In accordance with industry standards, we reserve the right to retain your record for a reasonable amount of time so we can ensure that we do not contact you in the future. Please note that we may be required to retain certain information by law and/or for own legitimate business purposes.
9.3. If you are an UK or EU user of our Website, any personal data collected for the purposes indicated under sections 2.1 and 2.3 above shall be retained for as long as necessary to deliver you the product purchased or make you participate to the competition, and subsequently for a period not exceeding the statutory limitation period. Any personal data collected for the purposes indicated under section 2.2. shall be retained until you withdraw your consent to receiving marketing information from us and/or from our partners, except for cases where we need to retain such personal data to defend our rights in relation to any disputes that are on-going at the time of your request, or upon formal request from public authorities.
Updating and Deleting Your Data
9.4. Unless you are a UK or a EU user of our Website, some requests may be subject to a small fee.
9.5. To protect your privacy, we will require you to prove your identity before granting access to your personal information.
9.6. If you would like us to delete your information from our records then please contact us using the details below in Section 11 and we will respond within a reasonable time.
9.7. If you are an UK or EU user of our Website you have also the right to:a) obtain the termination of the processing for direct marketing purposes, also in relation to products and services identical to those we have already provided to you;
9.8. Moreover, if you are an UK or EU user you have the right to contact the competent Data Protection Authority of your Member State. You can find the relevant contact details here: https://ec.europa.eu/digital-single-market/en/news/list-personal-data-protection-competent-authorities
9.9. If you are an Australian or New Zealand user of the Website, you can contact us (using the details set out in clause 11) to:
a) request access to, or the correction of your personal information; and
b) make a complaint about the use of your information. When contacting us for this purpose, we ask you to provide us with as much detail as possible about your complaint. We will take any privacy complaint seriously and will try to resolve it in a timely and efficient manner. We ask that you co-operate with us during this process and provide us with any relevant information that we may need. If you are not satisfied with the outcome of our assessment of your complaint, you may wish to contact the Office of the Australian Information Commissioner or the Office of the New Zealand Privacy Commissioner.
- Get in touch
You hereby acknowledge that your personal data shall be processed for the purposes referred to under sections 2.1. and 2.3. of this Privacy Notice, namely for purposes associated with the provision of the products you have purchased through our Website and with your participation to competitions. You also agree to:
- the processing of your personal data for delivering you newsletters on our activities and marketing communications concerning our products, offers and competitions (referred to under section 2.2. above);
- the processing of your personal data for profiling activities, such as analysing your preferences through automated means in order to improve our commercial offer (referred to under section 2.2., above);
- the processing of your personal data for delivering commercial and promotional communications concerning products and/or services of our partners, including Sanrio GmbH (referred to under section 2.2.above).