Privacy Policy
This privacy policy explains how personal information is handled when you use our website, request a quotation, submit artwork, place an order or contact our team.
Who is responsible for your data?
Custom Police Patches is the trading name used on this website. The data controller is [LEGAL BUSINESS NAME], of [TRADING/REGISTERED ADDRESS]. For privacy questions, email [PRIVACY_EMAIL].
If applicable: company number [COMPANY NUMBER]; registered office [REGISTERED OFFICE]. Only include these particulars if they apply to your business.
What information do we collect?
Depending on how you contact or order from us, we may collect your name, organisation, role, email address, telephone number, billing and delivery addresses, enquiry messages, order and payment records, and correspondence.
For police insignia enquiries, we may also need your force or organisation name, contact details of an authorised representative and reasonable evidence that you have permission to order a restricted design. Submitted artwork, reference files and approved proofs may include identifying names or numbers. Our website and security systems may also record technical information such as IP address, device/browser information, form submission data and security logs.
We do not ask you to provide more identification information than is reasonably needed to verify an order. Please avoid sending unrelated sensitive personal information.
Where does the information come from?
We receive information directly from you through quote forms, emails, orders or telephone enquiries; from your organisation where a colleague places an order on your behalf; and from technical systems that operate and secure our website. Where necessary, we may verify your purchasing authority with the organisation whose insignia you want reproduced.
Why do we use it and on what lawful basis?
| Purpose | Typical UK GDPR lawful basis |
|---|---|
| Reply to enquiries, prepare quotes, proofs and fulfil individual orders | Contract, or steps requested before entering a contract |
| Communicate with organisation contacts on business orders | Legitimate interests in handling business enquiries and providing our service |
| Check authority to reproduce official insignia and prevent misuse | Legitimate interests in responsible manufacturing, brand protection and fraud prevention; legal obligation where applicable |
| Keep invoices, tax and accounting records | Legal obligation |
| Protect our systems and resolve customer disputes | Legitimate interests in website security, business administration and establishing or defending claims |
| Send optional marketing communications | Consent where required, or another lawful marketing basis where permitted by law |
We assess which lawful basis applies to each actual processing activity before using your personal information. You can contact us for details of our legitimate interests where relevant.
Who receives your information?
We may share relevant information with staff and approved service providers who help operate our website, manage hosting and email, process payments, produce orders, deliver parcels and maintain business records. We may share limited authorisation details with the relevant force or rights holder when verification is necessary. We may also disclose data if required by law.
Before publication: identify the actual key suppliers or categories, such as [HOSTING PROVIDER], [EMAIL PROVIDER], [PAYMENT PROCESSOR, IF USED] and [COURIER(S)]. We do not sell customer personal information.
Do we transfer information outside the UK?
Some service providers may process personal information outside the UK. Where a transfer is subject to UK international-transfer rules, we take steps to use an applicable adequacy arrangement, appropriate contractual safeguards or another lawful mechanism. Contact us to ask about the safeguards relevant to your information.
Before publication: verify where your website, email, customer-service and manufacturing suppliers actually handle personal information, and record the countries and safeguards. Do not imply that all production data stays in the UK unless this is true.
How long do we keep information?
We keep enquiries, customer files, proofs, authorisation records and correspondence only for as long as reasonably necessary for the reason they were collected, including repeat orders, support, dispute resolution and lawful record-keeping. Accounting and tax records may need to be retained for the statutory period. Security logs and cookie records may have shorter retention periods.
Our retention periods are documented internally as [ADD ACTUAL RETENTION SCHEDULE]; the precise period can depend on the record and any applicable legal requirements. When no longer needed, records are securely deleted or anonymised.
How do we keep it secure?
We use reasonable organisational and technical controls intended to protect order files and personal information against unauthorised access, loss and misuse. Access to official insignia artwork and identity-verification material is limited to those who need it for the order. No internet service can guarantee absolute security.
Marketing and cookies
We use contact information to respond to your request. We will not treat a quote enquiry as permission to receive unrelated marketing. Where we send promotional messages, we follow applicable UK marketing rules and provide a way to opt out. See our Cookie Policy for information about cookies and similar technologies, including how to manage preferences.
What are your data-protection rights?
Subject to legal conditions and exceptions, you may request access to your personal data, correction, erasure, restriction, portability or object to certain processing. You can withdraw consent where we rely on it, without affecting prior lawful processing. To exercise a right, email [PRIVACY_EMAIL]. We may need reasonable information to confirm your identity before disclosing records.
How do you make a privacy complaint?
Contact [PRIVACY_EMAIL] and explain what concerns you. We will acknowledge a data-protection complaint within 30 days, investigate appropriately without undue delay, keep you informed of progress and communicate the outcome. You may also complain to the Information Commissioner’s Office (ICO). Our Complaints Procedure explains the process.
Changes to this notice
We may update this policy to reflect changes to our services, suppliers or legal requirements. The current version will be published here with its updated date. Last updated: [PUBLICATION DATE].