Legal Document

Privacy Policy

📅 Last updated: 19 March 2026  |  🔒 UK GDPR Compliant  |  🌐 maibo.uk

Data Controller: Maibo Limited, Luton, United Kingdom
Contact: maibo@maibo.uk
ICO Registration:

This Privacy Policy explains how Maibo Limited (“Maibo”, “we”, “us”) collects, uses, stores, and shares personal data when you use maibo.uk. We are committed to protecting your privacy in compliance with the UK GDPR and the Data Protection Act 2018.

1

Information We Collect

CategoryExamples
Identity & ContactName, email address, phone number
AccountUsername, encrypted password, preferences
Order & TransactionItems purchased, order history, returns, refunds
Delivery & BillingShipping address, billing address
Technical & UsageIP address, device/browser info, pages viewed, timestamps
Customer SupportMessages and info provided when contacting us
💳 Payment details: Processed by Stripe and PayPal. We do not store full card details on our servers.

2

How We Use Your Data

🛒
Order Processing
Process orders, payments, deliveries and returns.
👤
Account Management
Create and manage your customer account.
💬
Customer Support
Respond to requests, queries and complaints.
🔒
Security & Fraud
Prevent fraud and keep the website secure.
📈
Improvement
Improve site performance and product selection.
⚖️
Legal Compliance
Meet legal obligations and enforce our terms.

3

Legal Bases (UK GDPR)

Legal BasisWhen We Rely on It
ContractTo fulfil your order, process returns, and manage your account
Legitimate InterestsTo operate and improve our business, prevent fraud, secure the website
Legal ObligationTax, accounting, and regulatory compliance
ConsentFor optional marketing emails or non-essential cookies

4

Cookies & Tracking Technologies

We use cookies and similar technologies to enable core site functions, remember preferences, help prevent fraud, and understand how the website is used.

TypePurposeExamples
EssentialRequired for the website to functionSession, cart, login
AnalyticsUnderstand how visitors interact with the siteGoogle Analytics
MarketingShow relevant ads and measure campaign effectivenessFacebook Pixel

You can manage cookie preferences via your browser settings. Disabling non-essential cookies may affect certain website features.

5

Sharing Your Data

We may share personal data only where necessary. We do not sell your personal data to third parties.

💳

Payment ProvidersStripe, PayPal — to securely process your transactions.
📦

Delivery & Logistics PartnersTo ship orders and provide tracking information.
🖥️

IT & Security ProvidersTo host and protect our website and systems.
📋

Professional AdvisorsAccountants and legal advisors where required.
🏛️

AuthoritiesWhere we are legally required to disclose information.

6

International Transfers

Some service providers may process data outside the UK. Where international transfers occur, we take appropriate measures — such as standard contractual clauses and security controls — consistent with UK GDPR requirements.

7

Data Retention

Data TypeRetention Period
Order & transaction records7 years (legal/accounting requirement)
Customer account dataDuration of account + 2 years after closure
Marketing consent recordsUntil consent is withdrawn
Customer support communications3 years from resolution
Technical/analytical logsUp to 26 months

8

Your Rights

👁️

Right of AccessRequest a copy of the personal data we hold about you.
✏️

Right to RectificationHave inaccurate or incomplete data corrected.
🗑️

Right to ErasureRequest deletion of your data (“right to be forgotten”).
⏸️

Right to RestrictionAsk us to restrict how we process your data in certain cases.
🚫

Right to ObjectObject to processing based on legitimate interests or for direct marketing.
📤

Right to Data PortabilityReceive your data in a structured, machine-readable format.
↩️

Right to Withdraw ConsentWithdraw consent at any time where processing is based on consent.
🏛️

Right to ComplainLodge a complaint with the ICO (ico.org.uk) if you believe your rights have been violated.

To exercise any of these rights, contact us at maibo@maibo.uk. We will respond within 30 days as required by UK GDPR.

9

Security

We implement appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration, or misuse. Data transmissions are protected using SSL/TLS encryption. Access to personal data within our organisation is restricted on a need-to-know basis.

⚠️ If you believe your account or personal data has been compromised, please contact us immediately at maibo@maibo.uk.

10

Children’s Privacy

Our website is not intended for children under the age of 13. We do not knowingly collect personal data from children under 13. If we become aware that such data has been collected, we will delete it promptly.

11

Marketing Communications

We may send marketing emails where you have given consent or where we have a legitimate interest as an existing customer. You can opt out at any time by clicking Unsubscribe in any marketing email or by contacting maibo@maibo.uk. Opting out of marketing will not affect transactional emails related to your orders.

12

Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be posted on this page with an updated date. Where changes are significant, we will notify you by email or a prominent notice on the website.

13

Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

📌 As a UK-registered business serving UK customers under UK GDPR, English law applies. Our supervisory authority is the Information Commissioner’s Office (ICO).

Questions or Requests?

For any privacy-related questions, data subject requests, or complaints — we aim to respond within 30 days.

Contact Us · maibo@maibo.uk