PRIVACY POLICY — ORIGINAL MAP

Last updated: [18 September 2025]
Controller: ORIGINAL MAP (Société par actions simplifiée)
Registered office: 20 B Avenue Lacassagne, 69003 Lyon, FRANCE
Email: contact@originalmap.co.uk

Telephone: +33 9 53 57 63 71

1. Introduction

ORIGINAL MAP (“we”, “us”, “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose and retain personal data when you visit or purchase from www.originalmap.co.uk
(the “Site”), or otherwise contact us. It describes the legal bases we rely on under UK data protection law (UK GDPR and Data Protection Act 2018), your rights, and how to exercise them.

2. Key points

  • Data controller: ORIGINAL MAP (details above).
  • Data we collect: name, address, email, phone, payment references, order history, IP address, device & browser info, cookies, and optional marketing preferences.
  • Purposes: order fulfilment, payments, customer service, fraud prevention, analytics, marketing (only with consent where required).
  • Legal bases: performance of a contract, legal obligations, legitimate interests, and consent (for marketing & non-essential cookies).
  • Third-party processors: hosting (OVH), payment processors (Stripe, PayPal), analytics providers (e.g. Google Analytics), marketing platforms (e.g. Brevo), social media pixels (e.g. Meta/Facebook Pixel). Update as needed.
  • International transfers: where we use providers outside the UK/EU (e.g. US), we put in place appropriate safeguards (adequacy decisions, Standard Contractual Clauses or other lawful mechanisms).
  • Your rights: access, rectification, erasure, restriction, portability, objection, withdraw consent, and complaint to the ICO.
  • Contact for privacy: contact@originalmap.co.uk

3. What personal data we collect

We collect personal data you give us and data collected automatically:

a) Information you give us

Contact and identity data: name, billing & delivery address, email, phone.

Payment data: payment confirmations and transaction references (we do not store full card numbers; payment providers process card details).

Communications: messages you send to customer support, order notes, returns requests.

Marketing preferences: opt-in for newsletters, promotional messages.

b) Information we collect automatically

Technical data: IP address, device identifiers, browser type and version, page interactions, referring site, operating system.

Cookies and similar technologies (see Cookie section below).

Usage analytics: pages visited, session duration, events (if analytics enabled).

4. How we use your personal data & legal bases

We use personal data for the following purposes and legal bases:

4.1. To perform the contract with you (Contractual necessity)

  • Process and deliver your order, provide invoices, handle returns and refunds.

4.2. To comply with legal obligations (Legal obligation)

  • Tax, accounting, customs declarations, anti-fraud checks, consumer rights.

4.3. For customer service and account administration (Contract / Legitimate interest)

  • Respond to requests, improve products and services. Legitimate interest: providing support and improving our service.

4.4. Fraud prevention and security (Legitimate interest)

  • Detect and prevent fraudulent transactions and misuse.

4.5. Analytics & site improvement (Legitimate interest or Consent where required)

  • Aggregate, anonymised analytics to improve the Site. Where tracking may identify you across sites (e.g. some advertising cookies), we will rely on consent.

4.5. Marketing (Consent)

Email marketing or personalised advertising will only be sent where you have given consent (opt-in). You may withdraw consent at any time.

5. Cookies & tracking technologies

We use cookies and similar technologies for necessary website functions, analytics and marketing.

Cookie categories (summary)

  • Strictly necessary: required for the Site to function (e.g. basket, login). No consent required, but minimal data stored.
  • Preferences: remember language, region, basic UI settings. Consent recommended.
  • Statistics / Analytics: e.g. Google Analytics — helps us understand use of the Site. Used on legal basis of consent or legitimate interest depending on implementation (UK guidance favours consent for non-essential cookies).
  • Marketing / Advertising: tracking and pixels (Meta/Facebook Pixel, Google Ads) used for retargeting and ad performance — only with explicit consent.

(Full cookie table and durations below.)

6. Third-party services & pixels

We use third-party processors to operate the Site and provide services. Common providers we work with include:

  • Hosting: OVH (France) — stores Site data and server logs.
  • Payments: Stripe, PayPal — handle card and transaction processing. We do not store full card details.
  • Analytics: Google Analytics (Google LLC).
  • Marketing / Email: Brevo (formerly Sendinblue) or similar.
  • Advertising pixels: Meta Pixel (Facebook / Meta Platforms, Inc.), Google Ads conversion tracking.

Important: If you do not want cookies for analytics or marketing, use the Cookie Settings in the banner or contact us.

7. International transfers

Where third parties process data outside the UK/EEA (e.g. US), we ensure an adequate level of protection by relying on:

  • An adequacy decision (where available), or
  • Standard Contractual Clauses (SCCs) or other approved transfer mechanisms, and additional safeguards where appropriate.
    If you want details about safeguards for a particular processor, contact us.

8. Data retention

We retain personal data only as long as necessary for the purposes collected and to meet legal obligations:

  • Order and accounting records: typically up to 7–10 years for tax/commerce compliance.
  • Customer account details: retained until account deletion or inactivity plus a short retention period, unless legal obligations require longer storage.
  • Marketing consent: retained until you withdraw consent.
  • Analytics logs: retained in aggregated / anonymised form per provider settings.

9. Your rights

You have the right to:

  • Request access to your personal data (subject access request).
  • Request correction of inaccurate data.
  • Request erasure (right to be forgotten) in certain circumstances.
  • Request restriction of processing.
  • Object to processing (including profiling) where based on legitimate interests.
  • Request portability of data you provided in a structured, machine-readable format.
  • Withdraw consent at any time (consent withdrawal does not affect processing prior to withdrawal).
  • Lodge a complaint with the UK Information Commissioner’s Office (ICO) at https://ico.org.uk/ if you believe we have infringed your rights.

To exercise any right, contact: contact@originalmap.co.uk. We will respond within the statutory timeframe (typically one month; may extend by two months for complex requests).

10. How we protect your data

We implement reasonable technical and organisational measures: TLS/SSL encryption, access controls, regular backups, provider security measures. However no internet transmission is 100% secure. For sensitive matters contact us directly.

11. Children

Our Site is not targeted at children under 16. We do not knowingly collect personal data from children. If you are under 16, please do not submit personal data.

12. Changes to this Policy

We may update this Policy from time to time. The latest version will be posted on the Site with a revised “Last updated” date.

13. Contact & Data Protection Officer

For questions about this Privacy Policy, to exercise rights or obtain details of our processing, contact: contact@originalmap.co.uk.

If you remain unhappy after contacting us, you may complain to the Information Commissioner’s Office (ICO): https://ico.org.uk/