Privacy Policy
Post Hubb Ltd Privacy Policy
Last updated: 28/04/26
This Privacy Policy explains how POST HUBB LTD (“Post Hubb”, “we”, “us”, “our”) collects, uses, stores, shares, and protects personal data when you:
- visit www.posthubb.com or any related webpages we operate;
- place an order with us;
- contact us;
- create or use a Post Hubb account;
- download, access, or use the Post Hubb mobile application;
- use a Post Hubb device and related connected services; or
- otherwise interact with us as a customer, prospective customer, or website visitor.
This Privacy Policy should be read together with our:
- Terms & Conditions
- Cookie Policy
- App EULA
- Returns / Refund Policy
1. Who we are
POST HUBB LTD is the controller of your personal data for the purposes described in this Privacy Policy, except where another party clearly acts as controller in its own right, such as a payment provider, app store, or other third-party service.
POST HUBB LTD
Company number: 10617439
Registered office: Kingsnorth House, Blenheim Way, Birmingham, England B44 8LS, United Kingdom
Email: info@posthubb.com
If you have privacy-related questions or wish to exercise your data protection rights, please contact us using the details above.
2. The personal data we collect
We may collect the following categories of personal data.
A. Identity and contact data
- name
- billing address
- shipping address
- email address
- telephone number
- account login details
- customer support contact details
B. Order and transaction data
- products ordered
- order history
- payment status
- delivery details
- invoices and confirmations
- fraud/risk screening outcomes
We do not store your full payment card details ourselves. Payments are typically processed by third-party payment providers.
C. Website and device usage data
When you visit our website, we may automatically collect information such as:
- IP address
- browser type and version
- device type
- operating system
- time zone
- referring pages or search terms
- pages viewed
- website interactions
- approximate location derived from IP where applicable
- cookie, pixel, tag, and similar technology data
UK PECR rules apply not only to cookies, but to a broader set of storage and access technologies, including tracking pixels, scripts, tags, web storage, and similar techniques, and the ICO expects clear information plus consent for non-essential uses.
D. App and connected-device data
If you use the Post Hubb app or device, we may collect:
- account and app profile information
- paired device identifiers
- app usage events
- device configuration data
- firmware version data
- diagnostics and fault logs
- battery / health / status information
- lock event history
- update / recovery status
- pairing history
- delivery, access, and event-log information where implemented
- notification preferences
Where relevant, certain device and app data may relate to access events, delivery events, timestamps, lock/open/close events, and security-related activity associated with your device.
E. Customer support and correspondence data
- emails
- contact form submissions
- complaints
- support requests
- photographs or videos you send us
- troubleshooting notes
- call or chat records where used
F. Marketing and preference data
- marketing preferences
- subscription status
- cookie and consent choices
- survey or feedback responses
3. How we collect your personal data
We collect personal data:
- directly from you when you place an order, create an account, contact us, or use our app/device;
- automatically through our website, app, device, and related technologies;
- from Shopify and other service providers who help us run our store and services;
- from payment processors, fraud prevention providers, analytics providers, delivery partners, and support tools;
- from app stores where relevant to app delivery and support.
Shopify provides tools that can help merchants manage customer privacy settings, but it also states that compliance with applicable privacy law remains the merchant’s responsibility.
4. How we use your personal data
We use personal data for the following purposes.
A. To provide our products and services
Including to:
- process and fulfil orders;
- take payment and manage transactions;
- arrange shipping and delivery;
- provide invoices, receipts, and order confirmations;
- provide access to the app and connected services;
- support device setup, pairing, operation, updates, and diagnostics.
B. To manage your account and customer relationship
Including to:
- create and manage your account;
- authenticate logins;
- provide customer support;
- respond to complaints or warranty enquiries;
- contact you about your order, account, app, or device.
C. To operate, secure, and improve our website, app, device, and services
Including to:
- understand how customers use our website and services;
- troubleshoot issues;
- develop and improve features;
- monitor performance and reliability;
- detect, investigate, and prevent fraud, abuse, misuse, or security incidents.
D. To send service communications
Including:
- transactional emails
- order updates
- delivery updates
- app/device operational notices
- maintenance, safety, firmware, or security notifications
E. To send marketing communications
Where lawful, we may send you product news, offers, launch updates, or related marketing by email, SMS, or similar channels. You can unsubscribe or opt out at any time.
F. To comply with law and protect our legal position
Including:
- compliance with legal obligations;
- responding to lawful requests from authorities;
- enforcing our contracts, rights, and policies;
- handling disputes, complaints, and claims.
5. Our legal bases for processing
Where UK GDPR or EU GDPR applies, we rely on one or more of the following legal bases:
- performance of a contract with you;
- compliance with a legal obligation;
- our legitimate interests, where these are not overridden by your rights and interests;
- your consent, where required.
Examples:
- order fulfilment and app/device operation: contract
- fraud prevention and platform security: legitimate interests
- tax, accounting, and regulatory recordkeeping: legal obligation
- non-essential cookies and certain marketing: consent, where required
6. Cookies and similar technologies
We use cookies and similar technologies on our website and, where applicable, in app/device environments.
These technologies may be used to:
- make the site function properly;
- remember user preferences;
- keep the site secure;
- measure site traffic and usage;
- understand campaign performance;
- support marketing and retargeting where permitted.
The ICO says PECR applies to cookies and similar technologies, and users must receive clear and comprehensive information. Consent is generally required for non-essential uses.
For more detail, please see our Cookie Policy and our cookie banner / preference tools.
7. Marketing and advertising
We may use personal data to send you marketing communications or to show you relevant advertising, where lawful.
This may include use of:
- email marketing tools
- advertising platforms
- analytics providers
- retargeting technologies
- customer audience tools
You can opt out of marketing communications at any time by:
- clicking the unsubscribe link in emails;
- changing your account preferences, where available; or
- contacting us.
8. Who we share personal data with
We may share personal data with trusted third parties where reasonably necessary, including:
- Shopify and related commerce infrastructure providers
- payment processors
- fraud prevention and risk screening providers
- shipping, logistics, and fulfilment partners
- customer support software providers
- analytics and performance tools
- cloud hosting and infrastructure providers
- app distribution platforms such as Apple App Store and Google Play
- marketing, email, and advertising providers
- professional advisers such as lawyers, accountants, insurers, and auditors
- regulators, law enforcement, courts, and government bodies where required
Where third parties act as our processors/service providers, we expect them to process personal data only on our instructions and with appropriate safeguards.
If you use Shopify-powered checkout or store services, Shopify may also process certain personal data in accordance with its own policies and roles. Shopify states that if a consumer has questions about how a merchant processes data, they should contact the merchant or view the merchant’s policy.
9. International transfers
Some of our service providers may process personal data outside the UK or your country of residence, including in countries that may not have the same data protection laws.
Where we transfer personal data internationally, we will take steps required by applicable law to protect it, such as using:
- adequacy regulations/decisions where available;
- contractual safeguards such as approved standard contractual clauses or the UK equivalent; or
- other lawful transfer mechanisms.
10. Data retention
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including for:
- order fulfilment
- customer support
- product safety
- warranty administration
- dispute resolution
- fraud prevention
- tax, accounting, and legal compliance
Retention periods may vary depending on the type of data and legal obligations that apply.
When data is no longer needed, we will delete, anonymise, or securely dispose of it where appropriate.
11. Security
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.
However, no system can be guaranteed to be completely secure. You are responsible for maintaining the security of your own account credentials and devices.
12. Your data protection rights
Depending on your location and applicable law, you may have rights including:
- the right of access
- the right to rectification
- the right to erasure
- the right to restrict processing
- the right to object
- the right to data portability
- the right to withdraw consent, where processing is based on consent
- the right to complain to a supervisory authority
If you are in the UK, you can complain to the Information Commissioner’s Office (ICO).
To exercise your rights, contact us at info@posthubb.com. We may need to verify your identity before responding.
13. California and other U.S. state privacy rights
If U.S. state privacy laws apply to you, you may have additional rights, such as rights to:
- know what categories of personal data we collect and disclose;
- access specific personal data;
- request deletion;
- correct inaccurate personal data;
- opt out of certain forms of targeted advertising or sale/sharing where applicable;
- limit certain sensitive data uses where applicable.
We do not sell personal data in the ordinary meaning of the word “sell.” If applicable law treats certain advertising or analytics disclosures as “sale” or “sharing,” your rights will be addressed through our privacy choices and request channels.
14. Third-party links and services
Our website, app, or communications may contain links to third-party sites, tools, or services. We are not responsible for the privacy practices of those third parties. You should review their privacy notices separately.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal obligations, or business practices.
When we do so, we will update the “Last updated” date above. Where required by law, we will provide additional notice or obtain consent.
16. Contact us
If you have any questions about this Privacy Policy or our handling of personal data, please contact:
POST HUBB LTD
Kingsnorth House, Blenheim Way, Birmingham, England B44 8LS, United Kingdom
Email: info@posthubb.com