Privacy Policy
Your data. Your rights. Plainly explained.
We are a UK-based company. We collect only what we need. We never sell your information.
Legal
Privacy Policy
We keep this policy plain and honest. We are a UK-based company selling a sleep supplement. We collect only what we need to fulfil your order and improve our service. We do not sell your data. We do not spam you. You have full rights over your information under UK GDPR — and we make it easy to exercise them.
1. Who we are
CLARIA operates the website getclaria.net and sells CLARIA Sleep Formula. We are the data controller for personal data collected via this website.
Contact: support@getclaria.net · 01224 023 151
2. What data we collect
Information you give us
- Name and delivery address (to fulfil your order)
- Email address (order confirmation, shipping updates, and — with your consent — marketing)
- Phone number, if provided at checkout
- Payment details — processed securely by Shopify Payments / Stripe. We never see or store your full card number.
- Messages sent via our contact form
Information collected automatically
- IP address and browser/device type
- Pages visited, time on site, referring URL
- Cookie identifiers (see Section 7)
- Google and Meta advertising interaction data (clicks, conversions) via pixel and server-side tracking
3. How we use your data
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Process and fulfil your order | Contract (Art. 6(1)(b)) |
| Send order confirmation and shipping updates | Contract (Art. 6(1)(b)) |
| Respond to customer service enquiries | Legitimate interest (Art. 6(1)(f)) |
| Send marketing emails (if opted in) | Consent (Art. 6(1)(a)) |
| Run retargeting ads on Google and Meta | Consent (Art. 6(1)(a)) via cookie banner |
| Prevent fraud and maintain security | Legitimate interest (Art. 6(1)(f)) |
| Comply with legal obligations (tax, accounting) | Legal obligation (Art. 6(1)(c)) |
| Analyse site performance and improve our service | Legitimate interest (Art. 6(1)(f)) |
4. Who we share your data with
We do not sell your personal data. We share it only with the service providers needed to run our business:
- Shopify Inc. — our e-commerce platform and order management system. Data may be processed in the US under Shopify's Data Processing Agreement. Shopify Privacy Policy
- Shopify Payments / Stripe — secure payment processing. We transmit only what is needed for the transaction.
- Royal Mail / courier partners — your name and delivery address, to fulfil your order.
- Google LLC — Google Analytics and Google Ads conversion tracking. Data may be processed in the US. Google Privacy Policy
- Meta Platforms Inc. — Meta Pixel and Conversions API for Facebook/Instagram advertising. Meta Privacy Policy
- Email service provider — to send transactional and marketing emails on our behalf.
All third-party processors are bound by data processing agreements and are required to handle your data securely and in accordance with applicable law.
5. International transfers
Some of our service providers (including Shopify, Google, and Meta) process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place — including UK International Data Transfer Agreements (IDTAs) or reliance on the UK's adequacy regulations — in line with UK GDPR requirements.
6. How long we keep your data
- Order data — retained for 7 years to meet HMRC accounting requirements.
- Customer accounts — retained while your account is active, then deleted within 12 months of account closure.
- Marketing consent — retained until you unsubscribe or withdraw consent.
- Contact form messages — retained for 2 years, then deleted.
- Analytics/cookie data — typically 26 months (Google Analytics default), or as configured.
7. Cookies
We use cookies and similar technologies on this website. These fall into the following categories:
| Category | Purpose | Examples |
|---|---|---|
| Strictly necessary | Required for the site to function — cart, checkout, security | Shopify session, cart token |
| Analytics | Understanding how visitors use our site | Google Analytics (_ga, _gid) |
| Marketing | Retargeting ads and measuring ad effectiveness | Meta Pixel (_fbp), Google Ads (GCLID) |
| Preferences | Remembering your choices (e.g. currency) | Shopify preference cookies |
Analytics and marketing cookies are only set with your consent, which you can give or withdraw at any time via our cookie preferences. Strictly necessary cookies are set automatically as they are required for the site to operate.
To manage or delete cookies already on your device, visit your browser's privacy settings. For more information: aboutcookies.org
8. Your rights under UK GDPR
You have the following rights in relation to your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure — ask us to delete your data ("right to be forgotten"), subject to legal retention obligations.
- Right to restriction — ask us to pause processing of your data in certain circumstances.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interest, including direct marketing.
- Rights related to automated decision-making — we do not make solely automated decisions that significantly affect you.
- Right to withdraw consent — where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at support@getclaria.net or call 01224 023 151. We will respond within one calendar month.
You also have the right to lodge a complaint with the UK supervisory authority: Information Commissioner's Office (ICO) — ico.org.uk · 0303 123 1113.
9. Marketing communications
We will only send you marketing emails if you have given your explicit consent — for example, by ticking an opt-in box at checkout or subscribing via our website. Every marketing email includes an unsubscribe link. You can also email us at any time to opt out.
We do not buy, rent, or obtain mailing lists from third parties.
10. Children's privacy
Our products are intended for adults. We do not knowingly collect personal data from anyone under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it.
11. Links to other websites
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and recommend you review their policies separately.
12. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or in applicable law. The "last updated" date at the top of this page will always reflect the most recent version. Where changes are material, we will notify you by email or via a notice on the website.
13. Contact us
If you have any questions about this policy or how we handle your data:
- Email: support@getclaria.net
- Phone: 01224 023 151 (Monday – Friday, 9am – 5pm GMT)
- Address: CLARIA, United Kingdom