IRONLEAF
Company policy / last updated 20 July 2026

Privacy Policy

This policy explains the information boundary around orders, worldwide physical delivery, membership, support and store security.

Responsible company: RIDDELL FABRICATION SERVICES LTD
Contact: support@riddellfabb.shop · +44 7815267425
Address: 8 Forvie Path, Bridge of Don, Aberdeen, Scotland, AB22 8TG, United Kingdom

01

Who is responsible

RIDDELL FABRICATION SERVICES LTD is the data controller for information collected through Ironleaf at riddellfabb.shop. The company is established in Scotland and applies UK GDPR and the Data Protection Act 2018. EU visitors may also exercise EU GDPR rights; California residents receive the disclosures below.

Privacy enquiries can be sent to support@riddellfabb.shop or by post to 8 Forvie Path, Bridge of Don, Aberdeen, Scotland, AB22 8TG, United Kingdom.

02

What we collect

We collect name, email, telephone, billing address, shipping address, country, basket contents, order history, delivery status, returns and exchanges, membership tier, support messages, consent records and communication preferences.

Our hosting and security systems may collect IP address, device and browser data, referral page, timestamps, cookie choices and security events. Payment providers send us transaction identifiers, payment status, billing name and limited card metadata such as brand and last four digits. We do not receive or store the complete card number or security code.

03

Collection sources

Most information comes directly from you when you complete checkout, create or manage a membership, contact support, request a return or exchange, submit a trade order enquiry, choose cookies or communicate with us.

We also receive order and payment status from Stripe or PayPal; delivery scans, customs events and address updates from fulfilment and shipping carriers; technical and security events from our hosting and fraud-prevention systems; and support-delivery status from our email provider. We may infer limited operational records, such as whether an order is awaiting dispatch, from these sources.

04

Why we use it and legal bases

  • Contract: create checkout, take payment through a provider, fulfil and deliver physical goods, manage returns, refunds and memberships, and provide order support.
  • Legitimate interests: prevent fraud, secure the store, recover an abandoned checkout where permitted, improve product information, answer enquiries and keep proportionate business records.
  • Legal obligation: retain tax, accounting, dispute and consumer-rights records and respond to lawful requests.
  • Consent: optional marketing and non-essential cookies. Consent can be withdrawn without affecting earlier lawful processing.
05

Who we share it with

We disclose only what a processor needs: Vercel or an equivalent host for site delivery; Supabase for form, order-support and configuration records; Stripe and PayPal where selected for payment processing; email processors such as Resend or Postmark for receipts and support; analytics and security providers where enabled with appropriate choices; and postal, courier, customs and fulfilment partners for delivery.

Delivery partners receive recipient name, address, telephone where needed and parcel information. Professional advisers and authorities receive information only where law, fraud prevention or a dispute requires it. We do not sell personal information and do not share it for cross-context behavioural advertising.

06

Payment, order and fulfilment data

Stripe or PayPal hosts the card-entry surface and processes billing and payment data under its own privacy terms. Ironleaf receives the outcome and identifiers needed to match payment to the basket. Complete card numbers and card security codes do not touch our servers.

We use your shipping address, recipient name, telephone where needed, purchased SKU, parcel weight and delivery instructions to pick, pack, label and fulfil the order. We provide the minimum necessary data to postal and shipping carriers for delivery, tracking and customs processing. Order, carrier and support records are also used to manage delay, loss, damage, return, exchange and refund enquiries.

07

International transfers

Our worldwide store uses processors and carriers that may handle data outside the United Kingdom or European Economic Area. Where adequacy regulations do not apply, we rely on approved contractual safeguards such as the UK International Data Transfer Addendum or standard contractual clauses, plus proportionate security review. Carrier transfers may also be necessary to perform an international delivery contract.

08

How long we keep it

Checkout and enquiry leads are kept for no more than 24 months unless they become an order, dispute or legal record. Order, payment, tax and refund records are generally retained for up to seven years. Support correspondence is usually kept for 24 months after closure; security logs are normally kept for up to 12 months; cookie choices persist only for their stated duration.

When a period ends, information is deleted or irreversibly anonymised unless a legal claim, fraud review or statutory requirement justifies longer retention.

09

Security

We use encrypted transport, restricted service credentials, server-only secret keys, role-based administration, provider access controls, logging and updates. No method is risk-free. If a breach is likely to create a risk to people, we assess notification to the UK Information Commissioner's Office and affected people within applicable deadlines.

10

UK GDPR, EU GDPR and CCPA rights

Depending on location, you may request access, correction, deletion, restriction, portability or objection; withdraw consent; and complain about handling. UK residents may complain to the Information Commissioner's Office. EU residents may contact their local supervisory authority.

California residents may request categories and specific pieces collected, correction or deletion and information about disclosures. We do not sell or share personal information as those terms are defined by the CCPA, and we do not discriminate for exercising rights. We verify requests proportionately before acting. Send requests to support@riddellfabb.shop.

11

Cookies and Do Not Sell or Share

Essential cookies keep the basket, security and admin session functioning. Optional analytics or preference cookies are used only under the choices described in the Cookie Policy. Browser Global Privacy Control signals are treated as an opt-out where legally applicable. Because we do not sell or share personal information for cross-context advertising, there is no payment or penalty for choosing Do Not Sell or Share.

12

Automated decisions and children

Steel Finder uses fixed answers to recommend catalogue items; it does not profile a person or make a legal or similarly significant decision. We do not use customer information for solely automated significant decisions.

The store is not directed to children under 13. People aged 13–17 may use it only with a parent or guardian's agreement and participation in ordering. Contact us to remove information provided contrary to this rule.

13

Contact and complaints

Write to support@riddellfabb.shop, call +44 7815267425, or post to 8 Forvie Path, Bridge of Don, Aberdeen, Scotland, AB22 8TG, United Kingdom. Please describe the right or concern and the account or order email. We aim to respond within one month where UK GDPR applies. You may complain to the UK Information Commissioner's Office if our response does not resolve the issue.

Need this policy in an accessible format? Contact support.