Your data
Privacy Policy
How we collect, use and protect personal information when you use acne-rosacea.co.uk.
Last updated: 3 July 2026
1. Who we are
KCNS Skin Care Ltd (trading as CALMIN Rosacea) is the data controller for personal data collected through this website.
Companies House registration number: 06860223
Contact: kcnskincareltd@gmail.com
Website: acne-rosacea.co.uk
2. What personal data we collect
We only collect data we need to run the shop, fulfil orders, and respond to you.
When you place an order
Checkout is handled by Stripe. When you pay, Stripe collects information such as your name, email address, delivery address, and payment details. We receive order and customer details from Stripe so we can fulfil your order and contact you about it.
Delivery is free within the UK. We ship to UK addresses only.
We do not store your full card number on our servers. Payment card data is processed by Stripe.
When you email us
If you contact us (for example about an order, refund, or product question), we keep your email address, the content of your message, and any information you choose to provide.
When you join our email list
If you sign up for our newsletter in the footer, we collect your email address and record your consent to receive marketing emails. We receive a notification and add you to our MailPoet list in WordPress so we can send tips, product news, and offers. You can unsubscribe using the link in any email.
When you browse the site
- Basket storage: Items you add to your basket are saved in your browser using local storage (not cookies) so your basket persists between visits. This is necessary for the shopping experience.
- Google Ads: If you accept advertising cookies, we use Google Ads conversion tracking (via gtag.js) to measure when an order follows an advert. This uses cookies set by Google. You can accept or reject via our cookie banner or cookie settings.
- Server logs: Our hosting provider may automatically record technical data such as your IP address, browser type, and pages visited. This helps keep the site secure and running reliably.
What we do not use
We do not use Google Analytics or social-media advertising pixels on this site.
3. Why we use your data and our legal bases
Under UK GDPR, we rely on the following bases:
- Contract — to process and deliver your order, send order confirmations, and handle refunds under our 30-day promise.
- Consent — for Google Ads conversion cookies, when you click Accept on our cookie banner; and for marketing emails, when you tick the box on our newsletter signup form.
- Legitimate interests — to respond to enquiries, prevent fraud, keep the website secure, and maintain business records (balanced against your rights).
- Legal obligation — where we must keep records for tax, accounting, or other legal requirements.
4. Who we share data with
We share personal data only where necessary:
- Stripe Payments Europe Ltd — payment processing and checkout (Stripe privacy policy).
- Delivery and postal services — name and address to send your order.
- Google (Google Ads) — conversion measurement when you accept advertising cookies (Google privacy policy).
- MailPoet (via WordPress) — email list storage and newsletter delivery when you sign up.
- Our website host (Hostinger) — technical hosting and security.
We do not sell your personal data.
5. International transfers
Stripe and our hosting provider may process data outside the UK. Where this happens, they use appropriate safeguards (such as standard contractual clauses) as required by UK data protection law.
6. How long we keep data
- Order records — typically up to 6 years after the transaction, for tax and accounting purposes.
- Customer emails — kept as long as needed to resolve your enquiry and for a reasonable period afterwards.
- Basket data — stored in your browser until you clear it or remove items; we do not receive this data on our servers until checkout.
- Newsletter subscribers — until you unsubscribe or ask us to delete your details.
- Server logs — retained according to our host’s policies, usually for a limited period.
7. Cookies and similar technologies
Essential (no consent required)
- Shopping basket data in local storage on your device.
- Any essential security or session cookies set by our host or payment provider during checkout.
Advertising (consent required)
- Google Ads — conversion tracking cookies when you accept on our banner. Rejecting means we do not load Google’s tag.
You can change your choice at any time via cookie settings in the footer.
8. Your rights
Under UK data protection law you have the right to:
- Access the personal data we hold about you.
- Ask us to correct inaccurate data.
- Ask us to delete your data in certain circumstances.
- Object to or restrict certain processing.
- Data portability, where applicable.
- Withdraw consent, where processing is based on consent.
To exercise any of these rights, email kcnskincareltd@gmail.com. We may need to verify your identity before responding.
You also have the right to complain to the Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint.
9. Security
We take reasonable steps to protect your information, including secure checkout via Stripe (HTTPS) and limiting access to order data. No method of transmission over the internet is completely secure; please use a secure connection when ordering.
10. Children
Our products are intended for adults. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
11. Changes to this policy
We may update this page from time to time. The “Last updated” date at the top will change when we do. Continued use of the site after changes means you accept the updated policy.
12. Contact
Questions about this privacy policy or your personal data: