Last Updated: July 22, 2026
At Hezipop, we respect your privacy and are committed to handling personal data responsibly and transparently.
This page supplements our Privacy Policy and explains how individuals in the United Kingdom, European Economic Area (“EEA”), and other applicable regions may exercise their data-protection rights.
Depending on the circumstances, our processing may be governed by the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the Data (Use and Access) Act 2025, the Privacy and Electronic Communications Regulations 2003 (“PECR”), and the European Union General Data Protection Regulation (“EU GDPR”).
Nothing on this page limits a right available under applicable data-protection law.
1. Data Controller
For personal data processed in connection with the Hezipop online store, Hezipop acts as the data controller unless another party is identified as an independent or joint controller for a particular service.
Our online store is hosted by Shopify. Depending on the processing activity, Shopify and other service providers may act as processors on our behalf or as independent controllers for their own services.
Information about Shopify’s privacy practices and controls is available through the Shopify Privacy Portal.
2. Personal Data We May Process
Depending on how you interact with us, we may process:
Hezipop does not store complete payment card numbers on its own website servers. Complete payment credentials are handled by Shopify and the applicable payment provider.
Please do not send special-category information, government identification documents, complete payment card numbers, medical information, or other sensitive information unless we specifically and lawfully request it.
3. Sources of Personal Data
We may receive personal data:
4. Purposes and Lawful Bases
| Purpose | Typical Data | Lawful Basis |
|---|---|---|
| Process orders, payments, delivery, returns, and refunds | Identity, contact, order, delivery, and transaction data | Performance of a contract |
| Respond to product, order, and Customer Support inquiries | Identity, contact, order, and communication data | Performance of a contract and legitimate interests in providing Customer Support |
| Prevent fraud and protect website and payment security | Transaction, device, technical, account, and order data | Legitimate interests, legal obligations, and recognised legitimate interests where applicable |
| Maintain tax, accounting, and business records | Order, payment, refund, identity, and contact data | Legal obligations |
| Operate and improve our website | Technical, usage, device, and communication data | Legitimate interests and consent where required for non-essential technologies |
| Send direct marketing | Contact details, marketing preferences, and purchase information | Consent or another lawful electronic-marketing basis where permitted |
| Use non-essential analytics or advertising cookies | Cookie, device, interaction, and approximate-location data | Consent where required |
| Establish, exercise, or defend legal claims | Relevant order, payment, delivery, return, and communication records | Legitimate interests and legal obligations |
Where we rely on legitimate interests, we consider whether the processing is necessary, proportionate, and appropriately balanced against the individual’s rights and freedoms.
5. Consent
Where processing is based on consent, consent must be freely given, specific, informed, and capable of being withdrawn.
You may withdraw consent at any time by:
Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.
6. Cookies and Similar Technologies
Our website may use essential cookies to operate checkout, shopping-cart, account, security, and fraud-prevention functions.
With the applicable consent, we may also use non-essential cookies, pixels, tags, or similar technologies for analytics, personalisation, advertising, and marketing measurement.
Visitors in regions requiring prior consent should be provided with a Cookie Banner or Cookie Preferences control before non-essential technologies are activated.
Cookie consent should be capable of being withdrawn as easily as it was provided. Blocking essential cookies may prevent checkout or other necessary website functions from operating correctly.
7. Direct Marketing
Where permitted, we may send information about products, store updates, and promotions.
You have an absolute right to object to the use of your personal data for direct marketing. If you unsubscribe or object, we will stop using the applicable contact details for direct marketing, although we may retain a limited suppression record to ensure your preference is respected.
Marketing preferences do not prevent us from sending non-promotional messages concerning orders, payments, delivery, returns, refunds, security, or privacy requests.
8. How We Share Personal Data
We may share personal data when reasonably necessary with:
Service providers acting as processors are expected to process personal data only under applicable instructions and contractual protections. Some providers may act as independent controllers and process information under their own privacy notices.
9. International Data Transfers
Hezipop is based in the United Kingdom and serves customers in multiple countries. Shopify and other service providers may process or store personal data outside the United Kingdom or EEA.
Where a restricted international transfer requires a safeguard, we may rely on an applicable:
You may contact us for additional information about the transfer safeguards applicable to your personal data.
10. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including:
Retention periods depend on the type of data, the processing purpose, legal limitation periods, and applicable record-keeping requirements.
When personal data is no longer reasonably required, we may delete, anonymise, or securely dispose of it.
11. Data Security
We use reasonable technical and organisational measures designed to protect personal data from unauthorised access, loss, misuse, alteration, or disclosure.
However, no online transmission, website, or electronic storage method can be guaranteed to be completely secure.
Customers should protect account credentials and should not send complete payment card numbers, passwords, or one-time verification codes through email or other unsecured communications.
12. Your UK GDPR and EU GDPR Rights
Subject to applicable law and any relevant exceptions, you may have:
These rights are not absolute. A request may be limited where an applicable legal exception, retention obligation, third-party right, or legal claim applies.
Right to Object to Direct Marketing
You have the right to object at any time to the processing of your personal data for direct marketing. To object, use the unsubscribe link in a marketing email or contact hello@hezipop.com.
13. How to Exercise Your Rights
To submit a data-protection request, email hello@hezipop.com with the subject line “Data Protection Request.”
Please describe the right you wish to exercise and provide enough information to locate the relevant records. Helpful information may include your order number or the email address used to place an order.
We may request reasonable information to verify your identity and prevent unauthorised disclosure. Verification information will be used only to review and respond to the request.
Requests are ordinarily handled without charge. Where permitted by law, a reasonable fee may apply or a request may be refused if it is manifestly unfounded or excessive. If this occurs, we will explain the applicable reason and available complaint rights.
14. Response Time
We will respond to a valid rights request without undue delay and ordinarily within one calendar month after receiving the request or completing any reasonably required identity verification.
If a request is complex or multiple requests are submitted, the response period may be extended by up to two additional calendar months where permitted. We will notify you within the initial one-month period and explain the reason for the extension.
15. Automated Decision-Making
We and our service providers may use automated tools to assist with fraud prevention, payment security, website analytics, or permitted product and marketing personalisation.
Hezipop does not intend to make decisions based solely on automated processing that produce legal or similarly significant effects unless the processing is legally permitted and appropriate safeguards are provided.
If you believe a significant decision was made solely through automated processing, contact us to request information and any review rights available under applicable law.
16. Data Protection Complaints to Hezipop
You may raise a data-protection complaint by emailing hello@hezipop.com with the subject line “Data Protection Complaint.”
Please include:
We will:
Submitting a complaint to Hezipop does not prevent you from contacting an applicable supervisory authority.
17. Right to Lodge a Complaint with a Supervisory Authority
If you are in the United Kingdom, you may complain to the Information Commissioner’s Office (“ICO”):
If you are in the EEA, you may have the right to complain to the data-protection supervisory authority in the country where you live, work, or believe an infringement occurred.
We encourage you to contact us so we can review the concern, but contacting Hezipop first is not a condition for lodging a complaint with a supervisory authority.
18. Related Policies
For additional information, please review:
19. Changes to This Page
We may update this page to reflect changes in our processing activities, Shopify settings, services, or applicable data-protection requirements.
Updates will be posted on this page with a revised “Last Updated” date.
20. Contact Information
For privacy questions, rights requests, or data-protection complaints, please contact us:
Data Controller: HezipopThanks for subscribing!
This email has been registered!