PRIVACY POLICY
Last updated: March 2026
Introduction
Lucy Hoddinott trading as Lains Creative ("I," "me," "my") respects your privacy and is committed to protecting your personal data. This policy sets out how I collect your personal data when you visit my website (www.lainscreative.co.uk), how I use it, and what your rights are in relation to my use of that data.
1. Who I Am
I am the data controller responsible for your personal data. I am registered with the Information Commissioner's Office (ICO) under registration reference ZB503906.
If you have any questions about this policy or how I handle your data, please contact me at
lucy@lainscreative.co.uk.This site is not intended for children and I do not knowingly collect data relating to children under 18.
2. What Data I Collect
The information I may collect about you includes:
Identity and Contact Data — first name, last name, email address, billing address, and telephone number.
Financial and Transaction Data — details of products and services you have purchased from me. Payment card details are processed directly by Stripe and are not stored by me.
Usage and Technical Data — information about how you use my site, including your IP address, browser type and version, time zone, operating system, pages visited, and time spent on those pages.
Marketing and Communications Data — your preferences for receiving marketing from me, your communication preferences, interests, and feedback.
Tracking and Cookies Data — cookies and similar tracking technologies used to improve and analyse my site. For full details, please see my Cookie Policy at
https://lainscreative.co.uk/cookies-policy.I do not collect any Special Categories of Personal Data, including information about race, ethnicity, religion, health, sexual orientation, or political opinions, nor do I collect information about criminal convictions or offences.
3. How I Collect Your Data
I collect personal data when you:
- purchase a template or any other product or service from me
- subscribe to my email list or newsletter
- complete an enquiry or contact form on my site
- contact me by email, phone, or social media
- accept cookies on my site
- enter a competition, promotion, or survey
- work with me in a commercial capacity
4. How and Why I Use Your Data
I use your personal data on the following legal bases under UK GDPR, linked to the specific activities they cover:
Performance of a contract — used when processing and fulfilling your purchase, delivering your template share code, managing payment, and providing after-sales support. This also covers sending you transactional emails such as purchase confirmations and template delivery emails, which are sent on a contractual basis and do not require separate consent.
Consent — used when sending you marketing emails and newsletters. You can withdraw your consent at any time by clicking the unsubscribe link in any email I send you, or by contacting me at
lucy@lainscreative.co.uk.Legitimate interests — used for maintaining and improving my website and services, analysing how my site is used, providing customer support, and detecting or preventing fraud or technical issues, where this does not override your rights and interests. If you purchase a template from me, I may also contact you on this basis with template-specific follow-up communications, such as support check-ins or relevant product updates. You can opt out of these at any time by contacting me.
Legal obligation — used where I am required by law to collect, use, or retain your data, for example for tax or accounting purposes or in response to a legal order.
5. How Long I Retain Your Data
I retain your personal data only for as long as necessary for the purposes set out in this policy or as required by law:
- Purchase records are retained for six years in line with HMRC requirements
- Email subscriber data is retained for as long as you remain subscribed and deleted within 30 days of unsubscribing
- Enquiry and contact data is retained for up to two years from the date of last contact
- Website usage data is retained in line with the retention periods set by the relevant analytics tools
I may also retain personal data for longer where necessary to establish, exercise, or defend legal claims.
6. Transactional and Marketing Emails
Transactional emails — purchase confirmations, template delivery, and support-related communications are sent on a contractual basis. These are not marketing emails and do not require your consent.
Marketing emails — I will only send you marketing communications if you have given your explicit consent. You can opt out at any time via the unsubscribe link in any email or by contacting lucy@lainscreative.co.uk.
Template purchaser communications — if you purchase a template from me, I may contact you separately with relevant follow-up information relating to your purchase, such as support guidance or updates specific to your template. This is distinct from my main marketing list and is carried out on the basis of legitimate interests. You can opt out at any time.
I will never share your personal data with any third party for their own marketing purposes without your express consent.
7. Third-Party Data Processors
I work with the following trusted third-party companies who may process your personal data on my behalf. Each is contractually obligated to handle your data securely and only for the purposes I specify.
Stripe — payment processing. When you make a purchase, Stripe processes your payment card details securely on a contractual basis. I do not store your card details. You can read their privacy policy here: https://stripe.com/gb/privacy
Flodesk — email marketing and checkout processing. When you subscribe to my email list or complete a purchase via Flodesk checkout, Flodesk processes and stores your name and email address. You can read their privacy policy here: https://flodesk.com/privacy-policy
Dubsado — client relationship management. When you contact me or work with me as a client, Dubsado may process and store your name, email address, and telephone number. You can read their privacy policy here: https://www.dubsado.com/legal/privacy-policy
Google Analytics — website analytics. Google Analytics uses cookies to analyse how visitors use my site on the basis of legitimate interests. This may include your IP address. You can read their privacy policy here: https://policies.google.com/privacy
8. International Data Transfers
Some of the third-party processors listed above are based outside the United Kingdom, including in the United States. Where your personal data is transferred outside the UK, I ensure appropriate safeguards are in place in accordance with UK GDPR, including Standard Contractual Clauses (SCCs) or reliance on adequacy regulations where applicable.
9. Your Rights Under UK GDPR
You have the following rights in relation to your personal data:
Right to access — you can request a copy of the personal data I hold about you.
Right to rectification — you can ask me to correct any inaccurate or incomplete data I hold about you.
Right to erasure — you can ask me to delete your personal data where there is no legitimate reason for me to continue processing it.
Right to restrict processing — you can ask me to suspend processing of your personal data in certain circumstances.
Right to data portability — you can request that I transfer your personal data to you or a third party in a structured, commonly used format.
Right to object — you can object to my processing of your personal data where I am relying on legitimate interests as my legal basis.
Right to withdraw consent — where I am processing your data based on your consent, you can withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, please contact me at lucy@lainscreative.co.uk. I will respond within one month. You will not be charged a fee unless your request is clearly unfounded or excessive.
10. Automated Decision-Making
I do not carry out any automated decision-making or profiling that produces legal or similarly significant effects on you.
11. Right to Complain
If you have concerns about how I handle your personal data, please contact me in the first instance at lucy@lainscreative.co.uk so I can try to resolve the matter.
You also have the right to make a complaint to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, at any time. You can contact the ICO at www.ico.org.uk or by calling 0303 123 1113.
12. Third-Party Links
My site may contain links to third-party websites not operated by me. I am not responsible for the content, privacy policies, or practices of those sites. I encourage you to read the privacy policy of any third-party site you visit before submitting any personal data.
13. If You Fail to Provide Personal Data
Where I need to collect personal data by law or under the terms of a contract with you, and you fail to provide it when asked, I may not be able to fulfil that contract. I will notify you if this is the case.
14. Security
I take the security of your personal data seriously and implement reasonable technical and organisational measures to protect it against loss, misuse, or unauthorised access. Payment data is handled entirely by Stripe and is never stored on my systems. However, no method of transmission over the internet is completely secure and I cannot guarantee absolute security.
15. Changes to This Policy
I may update this privacy policy from time to time. Any changes will be published on this page with an updated date at the top. Where changes are significant, I will notify you by email or by displaying a notice on my site.
If you have any questions about this policy, please contact me at lucy@lainscreative.co.uk.