Privacy Policy
Last updated: 7 May 2026
This Privacy Policy explains how PrintXYZ (“we”, “us”, “our”) collects, uses, stores and protects your personal information when you visit printxyz.uk or place an order with us. We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
PrintXYZ is a UK-based custom apparel printing service. For the purposes of UK GDPR, the data controller is:
- XSSUK Ltd, Bristol – Old Stock Exchange 3rd Floor Old Stock Exchange
St Nicholas Street
Bristol
BS1 1TG
United Kingdom - Email: [email protected]
2. Information we collect
2.1 Information you give us directly
- Account & order details: name, billing and delivery address, email address, phone number, password (encrypted).
- Payment details: we do not store full payment card details. Card payments are handled directly by our payment provider (e.g. Stripe, PayPal). We receive a payment confirmation token and the last four digits of the card for reference.
- Custom design uploads: any artwork, images, photos or text you upload to our product designer (Lumise) or send to us by email for printing.
- Communications: messages you send via our contact form, email, phone or live chat.
- Marketing preferences: if you opt in to our newsletter.
2.2 Information collected automatically
- Technical data: IP address, browser type and version, operating system, device type, time zone setting.
- Usage data: pages visited, time on site, referring URL, links clicked, products viewed and added to basket.
- Cookies and similar technologies: see our Cookie Policy for full details.
3. How we use your information
We use your personal data for the following purposes:
- To process and fulfil your orders (printing, packing, dispatch, delivery, returns).
- To take payment and prevent fraud.
- To create and manage your customer account.
- To respond to your enquiries and provide customer support.
- To send order confirmations, dispatch notifications and service emails.
- To send marketing emails about new products, offers and promotions — only where you have opted in.
- To improve our website, products and services through analysis of usage data.
- To detect and prevent fraud, abuse and security incidents.
- To comply with our legal and regulatory obligations (e.g. tax records, accounting).
4. Legal basis for processing
Under UK GDPR we rely on the following lawful bases:
- Contract (Article 6(1)(b)): processing necessary to fulfil your order and provide the services you have requested.
- Legitimate interests (Article 6(1)(f)): running and improving our business, fraud prevention, securing our website, and limited direct marketing to existing customers about similar products.
- Consent (Article 6(1)(a)): sending newsletters and marketing emails to non-customers, and for non-essential cookies. You can withdraw consent at any time.
- Legal obligation (Article 6(1)(c)): retaining transaction records for HMRC and accounting purposes.
5. Who we share your information with
We do not sell your personal data. We share it only with the following categories of recipient, and only as necessary:
- Payment providers: Stripe, PayPal, Klarna or similar — to process payments securely.
- Delivery couriers: Royal Mail, Evri, DPD or similar — to deliver your order. They receive your name, address and phone number.
- Email service providers: for transactional and marketing email delivery.
- Hosting and IT providers: our website is hosted in the UK/EEA. Cloudflare provides our content delivery and security layer.
- Professional advisers: accountants, lawyers and auditors, where required.
- Authorities: if required to do so by law, court order or to protect our rights.
6. International transfers
Most of our processing takes place within the UK or the European Economic Area (EEA). Some of our service providers (such as Stripe and Cloudflare) may transfer data outside the UK. Where they do, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, Standard Contractual Clauses, or transfers to countries the UK has determined offer adequate protection.
7. How long we keep your data
- Order and transaction records: 6 years from the end of the financial year in which the order was placed (HMRC requirement).
- Customer account data: for as long as your account is active. You may close your account at any time.
- Custom design files: we keep uploaded artwork for up to 12 months after fulfilment so we can re-print on request, then delete it.
- Marketing data: until you unsubscribe or withdraw consent, or after 24 months of inactivity.
- Website analytics & logs: typically up to 12 months.
8. Your rights
Under UK GDPR you have the following rights, free of charge:
- Right of access — to request a copy of the personal data we hold about you.
- Right to rectification — to ask us to correct inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”) — in certain circumstances.
- Right to restrict processing — in certain circumstances.
- Right to data portability — to receive your data in a portable format.
- Right to object — to processing based on legitimate interests, and to direct marketing at any time.
- Right to withdraw consent — where consent is the legal basis.
- Rights related to automated decision-making — we do not use solely automated decision-making that produces legal or similarly significant effects.
To exercise any of these rights, contact us at [email protected]. We will respond within one calendar month.
9. Complaints
If you have a concern about how we handle your personal data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
- Website: https://ico.org.uk
- Helpline: 0303 123 1113
10. Cookies
Our website uses cookies and similar technologies. For full information including cookie categories, third-party cookies and how to manage them, please see our Cookie Policy.
11. Security
We use technical and organisational measures to protect your personal data, including TLS/SSL encryption for all data in transit, encrypted password storage, restricted staff access, server-level firewalls and Cloudflare’s security layer. No method of transmission over the internet is 100% secure, but we work hard to safeguard your information.
12. Children
Our services are not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
13. Links to other websites
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites. We encourage you to read their privacy policies before sharing any personal information.
14. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will reflect the most recent revision. Material changes will be notified to registered customers by email where appropriate.
15. Contact us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- XSSUK Ltd, Bristol – Old Stock Exchange 3rd Floor Old Stock Exchange
St Nicholas Street
Bristol
BS1 1TG
United Kingdom - Email: [email protected]