Privacy Policy

1. Important Information and Who We Are

1.1 Introduction

Welcome to The Go To Gift Limited's Privacy and Data Protection Policy ("Privacy Policy"). At The Go To Gift Limited ("we", "us", or "our") we are committed to protecting and respecting your privacy and Personal Data in compliance with the United Kingdom General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 ("PECR"), and all other mandatory laws and regulations of the United Kingdom.

This Privacy Policy explains how we collect, process and keep your data safe. It tells you about your privacy rights, how the law protects you, and sets out our employees' and staff members' obligations and protocols when processing data.

The individuals from whom we may collect and use data can include:

  • Customers

  • Suppliers

  • Business contacts

  • Employees/staff members

  • Third parties connected to our customers (for example, a gift recipient)

and any other people with whom the organisation has a relationship or may need to contact.

This Privacy Policy applies to all our employees and staff members and to all Personal Data processed at any time by us. It should be read alongside our Cookie Policy (Section 10 below) and our Terms of Use. Where anything in this Privacy Policy conflicts with our Terms of Use on the handling of Personal Data, this Privacy Policy takes precedence.

1.2 Who Is Your Data Controller

The Go To Gift Limited is your Data Controller and is responsible for your Personal Data. We are not obliged by the GDPR to appoint a data protection officer and have not voluntarily appointed one at this time. Any enquiries about your data should be sent to us by email at contact@thegoto.com, or by letter to Henry Moore Court, Manresa Road, London, SW3 6AS, United Kingdom.

You have the right to complain at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues — www.ico.org.uk, or by telephone on 0303 123 1113. We would, however, appreciate the chance to address your concerns before you approach the ICO, so please contact us in the first instance.

1.3 Processing Data on Behalf of a Controller, and Processors' Responsibilities to You

In discharging our responsibilities as a Data Controller, we have employees and third-party service providers who deal with your data on our behalf (known as "Processors"). The responsibilities described below may be assigned to an individual or may apply to the organisation as a whole. The Data Controller and our Processors:

  • Ensure that all processing of Personal Data is governed by one of the legal bases laid out in the GDPR (see Section 3 below);

  • Ensure that Processors authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;

  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk associated with the processing of Personal Data;

  • Obtain the Controller's prior specific or general authorisation before engaging another Processor;

  • Assist the Controller in fulfilling its obligation to respond to requests to exercise data subjects' rights;

  • Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in the GDPR, and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller;

  • Maintain a record of all categories of processing activities carried out on behalf of a Controller;

  • Cooperate, on request, with the supervisory authority in the performance of its tasks;

  • Ensure that any person acting under the authority of the Processor who has access to Personal Data does not process it except on instructions from the Controller; and

  • Notify the Controller without undue delay after becoming aware of a Personal Data Breach.


2. The Data We Collect About You

"Personal Data" means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store and transfer different kinds of Personal Data about you, which we have grouped together below. Not all of the following types of data will necessarily be collected from you, but this is the full scope of data we collect and when we collect it:

  • Profile/Identity Data: first name, last name, gender, date of birth.

  • Contact Data: billing and delivery addresses, email address, telephone number.

  • Marketing and Communications Data: your preferences in receiving marketing and other information from us, and your communication preferences.

  • Billing Data: the name and billing address attached to your payment method.

  • Financial Data: where relevant, your bank account number and sort code (for example, for supplier or affiliate payouts).

  • Transactional Data: details and records of payments to and from you, and of products or services you have purchased or received from us, including gift messages and delivery instructions where you provide them.

  • Technical Data: IP address, browser type and version, time zone setting and location, operating system and platform, and other technology on the devices you use to access our site.

  • Customer Support Data: feedback, survey responses, and records of correspondence if you contact us.

  • Usage Data: information about how you use our website, products and services (see also Section 11, Cookies).

We do not collect any Special Category Data about you (this includes details about race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, health information, or genetic and biometric data), nor do we collect information about criminal convictions or offences. We do not sell your Personal Data to third parties for money.

We do not store your full payment card details ourselves. Card payments are processed on our behalf by our payment processor, Shopify Payments, in accordance with the Payment Card Industry Data Security Standard (PCI-DSS).


3. The Legal Basis for Collecting Your Data

There are a number of justifiable reasons under the GDPR that allow the collection and processing of Personal Data. The main bases we rely on are:

  • Consent: where you have given clear consent for us to process your Personal Data for a specific purpose, such as ticking a box to receive email newsletters, or opting in to a service.

  • Contractual necessity: where processing is necessary to perform a contract with you (for example, to take and fulfil an order) or to take steps at your request before entering into a contract.

  • Legal obligation: where we are required by law to collect and process certain data, such as records needed to detect or prevent fraud or other illegal activity, or to meet our tax and accounting obligations.

  • Legitimate interests: where processing is necessary for our legitimate interests, or those of a third party, provided your interests and fundamental rights do not override those interests. Examples include using your delivery address to fulfil an order, or keeping a record of your contact details so we know who to correspond with. Where we rely on legitimate interests we have considered and balanced any potential impact on you.

  • Vital interests: in the rare circumstance that processing is necessary to protect someone's life.

  • Public task: in the rare circumstance that processing is necessary to perform a task carried out in the public interest, or in the exercise of official authority (this basis is not expected to apply to most of our processing, but is listed here for completeness).

Where we rely on your consent for direct marketing by email, text or phone, you can withdraw it at any time (see Section 5). Where the law permits a "soft opt-in" — for example, where you bought or negotiated to buy a similar product or service from us and were given a simple opportunity to refuse marketing at the time — we may email you about similar products or services unless and until you opt out.


4. How We Use Your Personal Data

4.1 Our Uses

We will only use your Personal Data when the law allows us to. The lawful bases described in Section 3 apply across the following broad purposes: taking and fulfilling your orders; managing payments and preventing fraud; managing your account and our relationship with you; providing customer support; sending you service and transactional communications; sending you marketing communications (where you have consented or the soft opt-in applies); improving and administering our website; and complying with our legal and regulatory obligations.

The examples above are indicative and the purposes for which we use your data may be broader than described, but we will never process your data without a legal basis for doing so, and any further processing will be for a purpose related to those set out above. Please contact us for further information.

4.2 Marketing and Content Updates

You will receive marketing and new content communications from us if you have created an account or otherwise opted in to receiving those communications, or where the soft opt-in described in Section 3 applies. From time to time we may make suggestions and recommendations to you about goods or services that may be of interest to you, based on what you have bought from us before or told us you are interested in.

4.3 Change of Purpose

We will only use your Personal Data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you would like an explanation of how the processing for a new purpose is compatible with the original purpose, please contact us. If we need to use your Personal Data for an unrelated purpose, we will notify you and explain the legal basis that allows us to do so. We may process your Personal Data without your knowledge or consent, in compliance with the above rules, only where this is required or permitted by law.

4.4 Automated Decision-Making

We do not carry out any processing based solely on automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you. We do use automated checks (for example, as part of fraud and payment-risk screening) as one input alongside human review; these do not result in a decision about you being made without the possibility of human involvement. If this changes, we will update this Privacy Policy and tell you about your right to obtain human intervention, to express your point of view, and to contest the decision.


5. Marketing Preferences

5.1 Opting Out of Marketing

You can ask us to stop sending you marketing messages at any time by clicking the "unsubscribe" link found at the bottom of any marketing email we send you, by updating your preferences in your account, or by contacting us at contact@thegoto.com.

Where you opt out of receiving marketing messages, we will keep a record of your preference so we can honour it, and we will continue to retain other Personal Data provided to us as a result of interactions with us that are not related to your marketing preferences (for example, records of an order you have placed).


6. Your Rights

6.1 Your Rights Under the UK GDPR

Subject to certain exceptions and conditions set out in law, you have the following rights in relation to your Personal Data:

  • Right of access: to ask us for copies of your Personal Data and other supplementary information about how we use it.

  • Right to rectification: to ask us to correct Personal Data you think is inaccurate, or to complete Personal Data you think is incomplete.

  • Right to erasure: to ask us to erase your Personal Data in certain circumstances (sometimes known as the "right to be forgotten").

  • Right to restrict processing: to ask us to restrict the processing of your Personal Data in certain circumstances.

  • Right to object: to object to our processing of your Personal Data in certain circumstances, including processing carried out for direct marketing.

  • Right to data portability: to ask us to transfer the Personal Data you gave us to another organisation, or to you, in certain circumstances.

  • Right to withdraw consent: where we rely on consent to process your Personal Data, to withdraw that consent at any time (this will not affect the lawfulness of processing carried out before you withdrew consent).

  • Rights related to automated decision-making: as described in Section 4.4.

You will not have to pay a fee to access your Personal Data or to exercise any of the other rights above. However, we may charge a reasonable fee, or refuse to comply, if your request is clearly unfounded, repetitive or excessive.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to anyone who has no right to receive it. We may also contact you for further information in relation to your request, to speed up our response. We try to respond to all legitimate requests within one month; occasionally it may take us longer if your request is particularly complex, in which case we will notify you and keep you updated.

6.2 Managing Your Account

You may delete your account at any time — this will remove your account and associated profile information from our systems, save for any data we are required or permitted to retain in accordance with Section 9 (for example, order records we must keep for tax purposes).

Your account is protected by a password for your privacy and security. Please help us keep your data safe by choosing a strong password, keeping it confidential, limiting access to your devices, and signing out after you have finished using your account.

6.3 California Privacy Rights

Under California Civil Code sections 1798.83–1798.84, California residents may ask us for a notice identifying the categories of Personal Data which we share with our affiliates and/or third parties for marketing purposes, and providing contact information for such affiliates and/or third parties. If you are a California resident and would like a copy of this notice, please submit a written request to contact@thegoto.com.


7. Data Security

We take the security of your Personal Data seriously and use a variety of measures to protect it, including:

  • Encrypting data in transit and at rest, both within our own systems and those of our suppliers;

  • Hashing and salting passwords using best-practice techniques;

  • Requiring two-factor authentication for staff accounts with access to systems holding Personal Data;

  • Applying a role-based approach to access, so staff only have access to the data they need;

  • Using payment processing that is PCI-DSS compliant, provided by industry-leading providers.

Any Personal Data collected by us is only accessible to a limited number of employees who have appropriate access rights and who are bound by obligations of confidentiality. Where we use subcontractors or processors to store or process your data, we take steps to ensure they do not expose it to security risks beyond those that would arise were the data to remain in our possession, and we put a written data processing agreement in place with them.

No transmission of data over the internet, or method of electronic storage, can be guaranteed to be completely secure. We work hard to protect your Personal Data, but we cannot guarantee its absolute security, and any transmission is at your own risk. If you have reason to believe your interaction with us is no longer secure, please contact us immediately at contact@thegoto.com.

We have procedures in place to deal with any suspected Personal Data breach, and will notify you and any applicable regulator of a breach where we are legally required to do so.


8. How Long We Retain Your Data

We only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. As a guide:

  • Account and profile data: for as long as you maintain an active account with us, and for a limited period afterwards in case you wish to reactivate it or raise a query.

  • Order, transaction and billing data: for 6 years from the end of the tax year in which the transaction took place, in line with our obligations under UK tax and company law.

  • Marketing preference data: for as long as needed to honour your preferences, including a record that you have opted out, even after you unsubscribe.

  • Customer support correspondence: for 2 years after the matter is resolved, or longer if needed to deal with a related complaint or dispute.

We may retain your Personal Data for a longer period than usual in the event of a complaint, or if we reasonably believe there is a prospect of litigation in respect of our relationship with you. When we no longer need your Personal Data, we will securely delete or anonymise it.


9. Sharing Your Information With Third Parties

9.1 Will We Share Your Data With Third Parties?

We may share your Personal Data with the following categories of third party, each acting as our processor under a data processing agreement (unless stated otherwise), and only to the extent needed for the purpose described:

  • Our e-commerce and hosting platform — Shopify, which powers our online store and processes Personal Data on our behalf as part of that service.

  • Payment processors — Shopify Payments, to take payment for your order securely.

  • Delivery and fulfilment partners — couriers and fulfilment providers such as Royal Mail / DPD / DHL / Fedex, to deliver your order to you or your gift recipient.

  • Marketing and communications platforms — such as Klaviyo, to send you email marketing and service communications where you have agreed to receive them.

  • Analytics and advertising partners — such as Google Analytics, and, where you have consented via our cookie banner, advertising partners such as Meta/Facebook, Google Ads (see Section 10, Cookies, for more detail and how to opt out).

  • Professional advisers — such as our accountants, auditors, insurers and lawyers, where necessary for them to provide us with professional advice or services.

  • IT and customer support providers to help us respond to your enquiries.

  • Regulators and law enforcement — where we are required to do so by law, or to establish, exercise or defend our legal rights.

  • A buyer or prospective buyer — if we sell, transfer, or are in negotiations to sell or transfer, all or part of our business or assets, in which case Personal Data held by us may be one of the transferred assets.

We require all third parties to respect the security of your Personal Data and to treat it in accordance with the law. We do not allow our third-party service providers to use your Personal Data for their own purposes, and only permit them to process it for specified purposes and in accordance with our instructions.

If The Go To Gift Limited is sold, or makes a sale or transfer of its business or assets, the Personal Data we hold about you may be transferred as part of that transaction. Following such a transfer, the privacy policy of the acquiring entity may govern the further use of your Personal Data; in all other respects, your data will continue to be protected in accordance with this Privacy Policy (as amended from time to time).

9.2 Third-Party Links

Our website may include links to third-party websites, plug-ins and applications. Clicking on those links, or enabling those connections, may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. When you leave our website, we encourage you to read the privacy policy of every website you visit.


10. Cookies

10.1 What Are Cookies?

Cookies are small text files placed on your device when you visit our website. They help our website work properly, let us understand how visitors use our site, and, where you agree, allow us and our partners to show you more relevant advertising.

10.2 Categories of Cookies We Use

Category

Purpose

Can you opt out?

Strictly necessary

Required for core site functions such as your shopping basket, checkout and account log-in.

No — the site will not work properly without these.

Functional/preference

Remember your settings and preferences, such as language or currency.

Yes, via our cookie banner/settings.

Analytics/performance

Help us understand how visitors use our site (for example, Google Analytics), so we can improve it.

Yes, via our cookie banner/settings.

Advertising/targeting

Used by us and our advertising partners (for example, Meta/Facebook Pixel, Google Ads) to show you more relevant adverts on our site and elsewhere, and to measure the effectiveness of our marketing.

Yes, via our cookie banner/settings.

10.3 Managing Cookies

When you first visit our website, you will be shown a cookie banner where you can accept or reject non-essential cookies, and change your choice at any time via cookie settings. You can also control cookies through your browser settings, including deleting existing cookies and blocking new ones — see your browser's help pages for instructions, as the steps differ by browser and device. Blocking some cookies may affect how our website works.

Where we or our advertising partners use cookies for behavioural advertising, you can also opt out directly through:


11. International Transfers of Data

We are based in the United Kingdom and our data is primarily stored and processed in the UK. Some of the third parties we work with (see Section 9) may store or process Personal Data outside the UK, including in countries that have not been assessed by the UK government as providing an adequate level of data protection.

Whenever we transfer your Personal Data outside the UK, we ensure a similar degree of protection is afforded to it by using one or more of the following safeguards:

  • Transferring it only to countries that the UK government has deemed to provide an adequate level of protection for Personal Data; or

  • Using specific contracts approved for use in the UK — such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — which give Personal Data the same protection it has in the UK.

Please contact us if you would like further information about the specific mechanism used for a particular transfer.


12. Age Limit for Our Users

You must not use The Go To Gift Limited's services unless you are aged 18 or older. If you are under 18 and access our services by misrepresenting your age, you must immediately stop using them. Our website is not directed at children and we do not knowingly collect Personal Data relating to children under 18. If we become aware that we have inadvertently collected Personal Data from a child, we will take steps to delete it as soon as possible.


13. Changes to This Policy

We keep this Privacy Policy under review and will place any updates on this webpage. This version is dated 28 August 2026. By using The Go To Gift Limited's services, you consent to the collection and use of data by us as set out in this Privacy Policy. Continued access to or use of our services following a change to this Privacy Policy constitutes your acceptance of that change. Where changes are significant, we will take reasonable steps to notify you directly (for example, by email or a prominent notice on our website).


14. Interpretation

All uses of the word "including" mean "including but not limited to", and the enumerated examples are not intended to limit the term they serve to illustrate. Email addresses set out in this policy may be used solely for the purpose for which they are stated to be provided, and unrelated correspondence will be ignored. Unless otherwise required by law, we reserve the right not to respond to emails, even if they relate to a legitimate subject matter for which we have provided an email address. As a matter of common sense, you are more likely to receive a reply if your request or question is polite and reasonable, and there is no obvious alternative way to deal with it (for example, our FAQs or other areas of our website).

Our staff are not authorised to contract on behalf of The Go To Gift Limited, waive rights, or make representations (whether contractual or otherwise). If anything contained in an email from a The Go To Gift Limited address contradicts this policy, our Terms of Use, or an official public announcement on our website, or is inconsistent with or amounts to a waiver of any of The Go To Gift Limited's rights, the email content will be read down in favour of the latter. The only exception is genuine correspondence expressed to be from The Go To Gift Limited's legal department.

This Privacy Policy and any dispute arising out of or in connection with it are governed by the laws of England and Wales.


15. Terms of Use

Please also see our Terms of Use, which set out the terms, disclaimers and limitations of liability governing your use of The Go To Gift Limited's services.