Privacy policy

JUNE 2026

PRIVACY POLICY

Stellar Interiors Ltd (Company No. 07527362, VAT No. 362823200), trading as Stellar & Co and Stellar Editions ("we", "us", "our"), is committed to protecting your personal data and respecting your privacy.

This Privacy Policy explains who we are, how and why we collect and use your personal data, who we share it with, how long we keep

it, your rights, and how to contact us. It applies to all personal data collected through our website stellareditions.co.uk and in the course of our business activities.

Stellar Interiors Ltd is the data controller for all personal data processed under this policy. We are registered with the Information

Commissioner's Office (ICO).

Section 1 - Who We Are

Stellar Interiors Ltd is a company registered in England and Wales (Company No. 07527362). We trade under the names Stellar & Co

and Stellar Editions and sell home interiors and furnishing products to both consumers and business customers.

Our registered address and contact details for data protection enquiries:

Stellar Interiors Ltd (trading as Stellar & Co and Stellar Editions)

Email: liz@stellarandco.co.uk

Website: stellarandco.co.uk.co.uk

Section 2 - What Personal Data We Collect

Depending on how you interact with us, we may collect and process the following categories of personal data:

Identity and Contact Data

- Full name

- Postal address (billing and/or delivery)

- Email address

- Telephone number

- Company name and job title (for business customers)

Transaction Data

- Details of products and services you have purchased from us

- Payment information (we do not store full card details — these are processed securely by our payment provider)

- Order history and correspondence relating to orders

Technical and Usage Data

- IP address

- Browser type and version

- Device information

- Pages visited, time spent on pages, and how you navigated to our website

- Cookie identifiers (see Section 9)

Communications Data

- Enquiries, messages and correspondence you send to us

- Feedback, reviews or survey responses you provide

Marketing Preferences

- Your preferences for receiving marketing communications from us

We do not collect any special category data (such as health data, racial or ethnic origin, political opinions, religious beliefs or biometric data) and ask that you do not provide any such information to us.

We do not knowingly collect personal data from children under the age of 16. If you are under 16, please do not provide personal data to us.

Section 3 - How We Collect Your Personal Data

We collect personal data in the following ways:JUNE 2026

Directly from you

- When you place an order on our website

- When you create an account on our website

- When you contact us by email, telephone or through our website

- When you sign up for marketing communications

- When you complete a survey, competition or feedback form

Automatically

- Through cookies and similar tracking technologies when you browse our website (see Section 9)

- Through our website hosting platform (Wix) analytics tools

From third parties

- Payment processors and fraud prevention services

- Delivery and logistics partners

- Social media platforms, where you interact with our content or adverts

Section 4 - How We Use Your Personal Data And Our Lawful Basis

UK GDPR requires us to have a lawful basis for processing your personal data. The points below sets out how and why we use your data and the legal basis we rely on.

- To fulfil your order and deliver products

We process your identity, contact and transaction data to process and deliver your order, handle returns, and manage payments.

Lawful basis: Performance of a contract.

- To manage our relationship with you

We process your identity, contact and communications data to respond to enquiries, resolve complaints, and notify you of changes to our products or terms. Lawful basis: Performance of a contract / Legitimate interests.

- To send marketing communications

We process your identity, contact and marketing preference data to send you information about products and promotions that may be of interest you. Lawful basis: Consent (where required) or Legitimate interests (for existing customers where we market similar products). You can opt out at any time — see Section 7.

- To improve our website and services

We process technical and usage data to analyse how our website is used, identify improvements, and ensure it functions correctly.

Lawful basis: Legitimate interests.

- To comply with legal obligations

We process identity, contact and transaction data to comply with accounting, tax and regulatory obligations. Lawful basis: Legal obligation.

- To prevent fraud and protect our business

We process identity and transaction data to detect and prevent fraudulent transactions and protect the security of our website.

Lawful basis: Legitimate interests / Legal obligation.

- For business customers — account management

We process identity, contact and transaction data to manage trade accounts, issue invoices and pursue payment. Lawful basis:

Performance of a contract / Legal obligation.

Section 5. Who We Share Your Personal Data With

We do not sell your personal data. We do not share your personal data with third parties for their own marketing purposes.

We may share your personal data with the following categories of third party, only where necessary:

Service providers and processors

- Wix (website hosting and e-commerce platform)

- Payment processors (to securely handle payments)

- Delivery and logistics companies (to fulfil and deliver your order)

- Email service providers (to send order confirmations and marketing communications)JUNE 2026

- IT and website support providers

Professional advisers

- Accountants, solicitors, insurers and other professional advisers, where necessary for the running of our business

Legal and regulatory bodies

- HM Revenue & Customs, the ICO, courts, regulators and other authorities where required by law or to protect our legal rights

All third parties with whom we share personal data are required to handle it in compliance with UK GDPR and to use it only for the specified purpose.

Section 6 - International Transfers

We aim to keep your personal data within the UK and the European Economic Area (EEA). Where any service provider processes data outside the UK or EEA, we ensure that appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or equivalent standard contractual clauses, in accordance with UK GDPR requirements.

Our website is hosted by Wix, whose servers may be located outside the UK. Wix operates under appropriate data transfer mechanisms. For further detail, please refer to Wix's privacy policy.

Section 7- Your Rights Under UK GDPR

As a data subject, you have the following rights in relation to your personal data. These rights are not absolute and may be subject to exemptions in certain circumstances.

Right of access

You have the right to request a copy of the personal data we hold about you (a Subject Access Request). We will respond within one calendar month.

Right to rectification

You have the right to ask us to correct personal data that is inaccurate or incomplete.

Right to erasure

You have the right to ask us to delete your personal data where there is no good reason for us to continue processing it. This right does not apply where we are required to retain data for legal or contractual reasons.

Right to restriction of processing

You have the right to ask us to suspend processing of your personal data in certain circumstances, for example while the accuracy of data is contested.

Right to data portability

Where we process your data by automated means on the basis of your consent or a contract, you have the right to receive that data in a structured, machine-readable format and to transfer it to another controller.

Right to object

You have the right to object to processing of your personal data where we rely on legitimate interests as the lawful basis, including for direct marketing. Where you object to direct marketing, we will stop processing your data for that purpose immediately.

Rights in relation to automated decision-making

We do not carry out solely automated decision-making or profiling that produces legal or similarly significant effects.

Right to withdraw consent

Where we process your data on the basis of consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, please contact us at contact@stellareditions.co.uk. We will not charge a fee for legitimate requests, though we reserve the right to charge a reasonable fee or refuse a request that is manifestly unfounded or excessive.

Section 8 – Marketing Communications

We may send you marketing communications about our products and services where you have given your consent, or where we have a legitimate interest in doing so as an existing customer.

You can opt out of receiving marketing communications at any time by:

- Clicking the "unsubscribe" link in any marketing email we send you;

- Emailing us at contact@stellareditions.co.uk with your request.JUNE 2026

Please note that opting out of marketing does not affect transactional communications relating to orders you have placed.

Section 9 - Cookies

Our website uses cookies and similar tracking technologies. Cookies are small text files placed on your device that help us recognise you and understand how you use our website.

We use the following types of cookies:

Strictly necessary cookies

These are essential for the website to function and cannot be switched off. They are set in response to actions you take such as logging in or filling in forms.

Analytics / performance cookies

These allow us to count visits and understand how visitors move around our website so we can improve it. We use Wix Analytics for this purpose. Data collected is aggregated and anonymous where possible.

Marketing / targeting cookies

These may be set by us or by third-party providers (such as social media platforms) to build a profile of your interests and show you relevant adverts. They do not store directly personal information but identify your browser and device.

When you first visit our website you will be asked to consent to non-essential cookies. You can change your cookie preferences at any time through the cookie settings on our website, or by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality of our website.

Section 10 – Data Retention

We retain personal data only for as long as is necessary for the purposes for which it was collected, in accordance with our legal obligations. Our standard retention periods are as follows:

Order and transaction data

Retained for 7 years from the date of the transaction, in accordance with our statutory accounting and tax obligations under the

Companies Act 2006 and HMRC requirements.

Customer account data

Retained for the duration of the customer relationship and for 3 years following the last interaction, after which it will be reviewed and deleted unless a legal obligation requires retention.

Marketing data

Retained until you opt out or withdraw consent, after which it will be removed from our active marketing lists within 28 days.

Suppression records may be retained to ensure we do not contact you again.

Correspondence and enquiries

Retained for 3 years from the date of the last correspondence.

Website analytics data

Retained in aggregated or anonymised form; individual-level data is not retained beyond 26 months.

Where we are legally required to retain data for longer periods, we will do so but will not use it for any other purpose.

Section 11 - Data Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction or alteration. These include:

- Secure, encrypted transmission of payment data;

- Access controls limiting who within our organisation can access personal data;

- Use of reputable, UK GDPR-compliant service providers;

- Regular review of our data security practices.

However, no transmission of data over the internet can be guaranteed to be entirely secure. You provide your data at your own risk and should take appropriate precautions when sharing personal information online.JUNE 2026

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where required, notify you directly.

Section 12 - Third-Party Websites

Our website may contain links to third-party websites. This Privacy Policy applies only to our website and our business activities. We are not responsible for the privacy practices of any third-party sites and recommend you read their privacy policies before providing any personal data to them.

Section 13 – Complaints

If you have any concerns about how we handle your personal data, please contact us in the first instance at

liz@stellarandco.co.uk. We will investigate and respond to your complaint within 28 days.

If you are not satisfied with our response, or if you believe we are not handling your data in accordance with the law, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Tel: 0303 123 1113

Website: www.ico.org.uk

Section 14 - Changes To This Policy

We reserve the right to update this Privacy Policy at any time. We will post any changes to this page with a revised "last updated" date. Where changes are significant, we will endeavour to notify you by email or by a prominent notice on our website. Your continued use of our website following any changes constitutes your acceptance of the updated policy.

Section 15 - Contact US

For any questions, requests or complaints relating to this Privacy Policy or our data practices, please contact:

Stellar Interiors Ltd (trading as Stellar & Co and Stellar Editions)

Company No: 07527362 | VAT No: 362823200

Email: contact@stellareditions.co.uk

Website: stellareditions.co.uk

This Privacy Policy was last reviewed June 2026.