Privacy policy

Last updated: 10 June 2026

This Privacy Policy explains what personal data we collect when you visit or purchase from celuxius.com, how we use it, who we share it with, and your rights under UK data protection law. By using our site, you agree to the practices described here.

1. Who We Are

Celuxius is the data controller responsible for personal data collected through celuxius.com. Our business address is:

Suite F14, Hurstwood Court, New Hall Hey Road, Rossendale, Lancashire, BB4 6HH

For privacy-related questions or requests, contact us at support@celuxius.com. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. What Personal Data We Collect

We collect the following types of personal data when you interact with our site:

  • Identity and contact data: Name, email address, shipping address, billing address, phone number
  • Transaction data: Order history, products purchased, payment amount, order dates
  • Payment data: Processed securely by our payment providers (Shopify Payments). We do not store full card details on our servers
  • Technical data: IP address, browser type, device information, operating system
  • Usage data: Pages visited, time spent on site, navigation paths, clicks
  • Marketing preferences: Whether you have subscribed to emails or opted in for marketing communications

3. How We Use Your Data

We use your personal data for the following purposes:

  • To process and fulfil your orders, including payment processing, delivery, and returns
  • To communicate with you about your order, account, or customer service enquiries
  • To comply with legal obligations such as tax, accounting, and recordkeeping requirements
  • To prevent fraud and maintain site security through monitoring and verification
  • To improve our website, products, and customer experience using analytics
  • To send marketing communications (emails about new products or offers) only where you have given explicit consent

4. Our Lawful Basis for Processing

Under UK GDPR, we process your personal data on one of the following lawful bases:

  • Contractual necessity: Processing is required to fulfil your order (e.g. delivery address, payment details)
  • Legal obligation: Processing is required to comply with UK laws (e.g. tax records, accounting)
  • Legitimate interests: Processing supports our business operations (e.g. fraud prevention, website analytics, improving services) where this does not override your rights
  • Consent: Processing is based on your explicit agreement (e.g. marketing emails, non-essential cookies)

5. Who We Share Your Data With

We may share your personal data with the following third parties, all of whom are contracted to protect your data and use it only for the purposes we specify:

  • Payment processors: Shopify Payments — for processing transactions securely
  • Delivery partners: Royal Mail, DHL, DPD, Evri — for shipping and tracking your order
  • Platform and hosting: Shopify (our website platform) and associated cloud services
  • Analytics and advertising: Google (Google Analytics, Google Ads), Meta (Facebook) - for website performance tracking and advertising, where consent is given
  • Customer service tools: Email and support platforms used to manage enquiries
  • Legal authorities: Where required by law or to prevent fraud

6. International Data Transfers

Some of our third-party providers may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO) or transfers to countries with adequacy regulations. These measures protect your data in line with UK GDPR standards.

7. Data Retention

We retain personal data only as long as necessary for the purposes outlined or as required by law. Our retention periods include:

  • Order and payment records: Up to 6 years for tax and accounting purposes
  • Account data: While your account is active
  • Marketing consent: Until you withdraw consent or unsubscribe
  • Enquiry emails: Up to 12 months unless they become part of an ongoing customer relationship

8. Cookies and Similar Technologies

Our site uses cookies and similar technologies to enhance your experience and understand how people use our website. On your first visit, you will be asked to consent to non-essential cookies via our cookie banner. You can manage or withdraw consent at any time through the banner or your browser settings. Please note that blocking essential cookies may affect site functionality.

The cookies we use fall into the following categories:

  • Essential cookies: Required for site functionality (e.g. checkout, session management, security)
  • Analytics cookies: Help us understand user behaviour and improve the site (e.g. Google Analytics, which tracks page visits, time on page, and navigation paths)
  • Marketing cookies: Used to deliver personalised ads and track campaign performance across platforms (e.g. Google Ads, Facebook/Meta) - only enabled if you consent to marketing communications

We do not store sensitive information (such as payment card numbers) in cookies. Third-party cookies from platforms like Google and Facebook operate under their own privacy policies, and you can manage these through their respective settings.

9. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Ask us to correct inaccurate or incomplete data
  • Erasure: Request deletion of your data in certain situations
  • Restriction: Ask us to limit how we use your data
  • Data portability: Request your data in a structured, commonly used format
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: Withdraw consent at any time where processing is based on consent (this does not affect prior lawful processing)
  • Complaint: File a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk

To exercise any of these rights, contact us at support@celuxius.com. We aim to respond within 24 hours and will always respond within the one-month period required by UK GDPR.

10. Children

Our site is not directed to children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us and we will delete it.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or misuse. This includes encrypted connections (SSL), secure payment gateways, access controls for staff, and regular security reviews, and we comply with UK GDPR Article 34 breach notification requirements.

12. Marketing Communications

We will only send marketing emails if you have explicitly consented to receive them. You can unsubscribe at any time using the link in our emails or by contacting us. We may also use your data for retargeting or personalised advertising on platforms like Google and Facebook, but only if you have consented to marketing cookies.

13. Updates to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, suppliers, or legal obligations. The latest version will always be available on this page with the updated "Last updated" date at the top. We recommend reviewing this policy when we make changes.

14. Contact Us

If you have any questions about how we collect, use, or protect your personal information, you can contact our customer service team using the details below or through our contact form.

Email: support@celuxius.com
Phone: +44 7348 956178

Customer Service Hours:
Mon–Fri: 9:00 a.m. – 5:00 p.m. (GMT)
Sat: 10:00 a.m. – 4:00 p.m. (GMT)
Sun: Closed

We aim to respond to all enquiries within 24 hours during business days. Enquiries received on Sunday will be answered on Monday.