Who We Are
Sugar Ruffles is a sole trader business operated by CWM UK, specialising in personalised wedding gifts. We are the data controller responsible for your personal information.
Trading As: Sugar Ruffles
Email: hello@sugarruffles.co.uk
Website: www.sugarruffles.co.uk
We are committed to protecting your personal data and being transparent about how we use it. This privacy policy explains what information we collect, why we collect it, and what we do with it. It applies to all visitors to our website and all customers who place orders with us.
What Information We Collect
Information You Provide to Us
When you place an order, create an account, or contact us, we may collect the following:
- Full name
- Email address
- Telephone number
- Delivery address
- Billing address
- Personalisation details you submit for your order (such as names, dates, or messages)
- Any correspondence you send to us
Information Collected Automatically
When you browse our website, certain technical information is gathered automatically, including your IP address, browser type and version, operating system, pages visited, and referring website. This information is used to maintain website security and to understand how visitors use our site. More detail can be found in our Cookie Policy.
Information We Do Not Collect
We do not collect sensitive personal data such as information about your racial or ethnic origin, religious beliefs, political opinions, health, sexual orientation, or criminal record.
We do not collect or store your credit or debit card details. All payment processing is handled securely by our third-party payment providers, Stripe and PayPal. We receive only confirmation that payment has been successfully completed.
How We Use Your Information
We use your personal data only where we have a lawful basis to do so. The purposes and legal bases are as follows:
To fulfil your order (contractual necessity): Processing your payment, personalising your product, arranging delivery, and sending you order updates including dispatch and tracking notifications.
To communicate with you (contractual necessity / legitimate interest): Responding to enquiries, resolving complaints, and notifying you of any issues with your order.
To comply with legal obligations (legal obligation): Retaining records for tax, accounting, and regulatory purposes as required by HMRC and other authorities.
To improve our website and service (legitimate interest): Understanding how visitors use our site so we can improve the browsing and shopping experience. This is done using anonymised or aggregated data wherever possible.
To send marketing communications (consent): If you have opted in to our mailing list, we may send you product updates, promotions, or other news. You can withdraw your consent at any time — see “Your Rights” below.
Who We Share Your Data With
We will never sell, rent, or trade your personal information to third parties for marketing purposes. We only share your data where it is necessary to operate our business and fulfil your orders:
- Payment processors: Stripe and PayPal, to securely process your transactions
- Delivery partners: Royal Mail or courier services, to deliver your order (we share your name, delivery address, and contact number)
- Website hosting and infrastructure: Our hosting provider, which stores website data on secure servers
- Legal and regulatory bodies: Where required by law, such as HMRC for tax reporting
All third parties we work with are required to handle your personal data securely and in accordance with applicable data protection law. We only share the minimum information necessary for each purpose.
How Long We Keep Your Data
We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected:
- Order records: Up to 7 years from the date of purchase, as required for tax and accounting compliance
- Customer account data: For as long as your account remains active, or until you request deletion
- Correspondence: For a reasonable period following resolution of your enquiry or complaint
- Marketing preferences: Until you withdraw consent or unsubscribe
How We Protect Your Data
Our website is secured using SSL (Secure Sockets Layer) encryption, ensuring that data transmitted between your browser and our server is protected. We implement appropriate technical and organisational measures to safeguard your personal data against unauthorised access, alteration, disclosure, or destruction.
While we take every reasonable precaution to protect your information, no method of transmission over the internet is entirely secure. We cannot guarantee absolute security, but we are committed to maintaining robust protections.
Your Rights
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights regarding your personal data:
- Right of access: You can request a copy of the personal data we hold about you
- Right to rectification: You can ask us to correct any inaccurate or incomplete data
- Right to erasure: You can ask us to delete your personal data, subject to our legal obligations
- Right to restrict processing: You can request that we limit how we use your data
- Right to data portability: You can request your data in a structured, commonly used format
- Right to object: You can object to processing based on our legitimate interests
- Right to withdraw consent: Where we rely on your consent, you can withdraw it at any time
To exercise any of these rights, please email us at support@sugarruffles.co.uk. We will respond to all legitimate requests within one calendar month. We may ask you to verify your identity before processing your request.
There is no charge for exercising your rights, unless a request is clearly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline the request.
Marketing Communications
We will only send you marketing emails if you have given your explicit consent. Every marketing email we send includes an unsubscribe link at the bottom. You can also opt out at any time by emailing hello@sugarruffles.co.uk. Withdrawing from marketing will not affect any other communications related to your orders.
Third-Party Links
Our website may contain links to other websites. We are not responsible for the privacy practices or content of those sites. We encourage you to read the privacy policy of any website you visit after leaving ours.
Children’s Privacy
Our website and services are not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected information from a minor, please contact us and we will take steps to delete it.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. Any significant changes will be posted on this page with a revised “last updated” date. We recommend checking this page periodically.
How to Contact Us
If you have any questions about this privacy policy, wish to exercise your data protection rights, or have concerns about how your data is being handled, please contact us:
Email: hello@sugarruffles.co.uk
Right to Complain
If you are unsatisfied with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Website: ico.org.uk
Telephone: 0303 123 1113
We would appreciate the opportunity to address your concerns directly before you contact the ICO, but you are of course entitled to do so at any time.
Last updated: April 2026

