Privacy Policy
Last Updated: 8th April 2026
Introduction
At John Greed Jewellery Ltd, we respect your privacy and are committed to protecting your personal information. This Privacy Notice tells you what to expect us to do with your personal information.
Who We Are (The Controller)
Our website is operated by John Greed Jewellery Limited (Registered Number: 04814633), which is the Company you enter a contract with when you place an order. Our parent company, John Greed Group Limited (Registered Number: 07160592), owns the website domain and certain related infrastructure.
For this reason, John Greed Jewellery Limited and John Greed Group Limited act as joint controllers of your personal data under the UK GDPR. This means we jointly determine how and why your personal data is used.
Day-to-day, John Greed Jewellery Limited is responsible for handling your orders, customer service, and responding to data protection requests. John Greed Group Limited provides oversight and manages contracts for some of the services that make the website function (such as housing and payment processing).
How to Contact Us
|
Our Data Protection Officer (DPO): |
Business Compliance Manager / DPO |
|
Email Address: |
|
|
Postal Address: |
Suite 2, Firth Road Business Park, Firth Road, Lincoln, LN6 7AA |
|
Telephone Number: |
+44 (0) 1522 718 388 |
Accessibility
Individual needs exist. If you need a copy of our Privacy Notice in a different format, please contact us using any of the details above and we will make it happen.
What Information We Collect and Use, and Why
We collect or use the following information to provide services and goods, including delivery:
-
Names and contact details;
-
Addresses;
-
Payment details (the last four digits of your card number);
-
Account information;
-
Information relating to loyalty programmes;
-
Website user information (including user journeys and cookie tracking);
-
Photographs or video recordings;
-
Information relating to compliments or complaints.
We collect or use the following information for the operation of customer accounts and guarantees:
-
Names and contact details;
-
Addresses;
-
Payment details (the last four digits of your card number);
-
Purchase history;
-
Account information, including registration details;
-
Information used for security purposes;
-
Marketing preferences.
We collect or use the following information to prevent, detect, investigate, or prosecute crimes, and provide training to staff members:
-
Names and contact details;
-
Customer or client accounts and records;
-
Video and CCTV recordings of public areas (including indoor and outdoor spaces);
-
Video and CCTV recordings of private or staff only areas;
-
Financial transaction information.
We collect or use the following information for service updates or marketing purposes:
-
Names and contact details;
-
Addresses;
-
Marketing preferences;
-
Location data;
-
Purchase or viewing history;
-
IP addresses;
-
Website user journey information;
-
Analytical data (from cookies etc.);
-
Sales data;
-
Records of consent, where appropriate.
We collect or use the following information to comply with legal requirements:
-
Name;
-
Contact information;
-
Financial transaction information;
-
Health and Safety data;
-
Photographs or video records.
We collect or use the following information for recruitment purposes: (if you apply to work for us)
-
Contact details (e.g. name, address, telephone number or personal email address);
-
Date of birth;
-
National Insurance number;
-
Copies of passports or other photo ID;
-
Employment history (e.g. job application, employment references, or secondary employment);
-
Education history (e.g. qualification);
-
Right to work information;
-
Health data (special category, for example if you require reasonable adjustments to attend an interview);
-
Details of any criminal convictions.
We collect or use the following information for dealing with queries, complaints, or claims:
-
Names and contact details;
-
Addresses;
-
Payment details;
-
Account information;
-
Purchase or service history;
-
Video and CCTV recordings of public areas (including indoor and outdoor spaces);
-
Video and CCTV recordings of private or staff only areas;
-
Witness statements and contact details;
-
Relevant information from previous investigations;
-
Customer or client accounts and records;
-
Financial transaction information.
Lawful Bases and Data Protection Rights
Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.
Which lawful basis we rely on may affect your data protection rights which are detailed below:
-
Your Right of Access. You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all of the information you ask for.
-
Your Right to Rectification. You have the right to ask us to correct or delete personal information that you think is inaccurate or incomplete.
-
Your Right to Erasure. You have the right to ask us to delete your personal information.
-
Your Right to Restrict Processing. You have the right to ask us to limit how we can use your personal information.
-
Your Right to Data Portability. You have the right to ask that we transfer the personal information you have with us to another organisation, or to you.
-
Your Right to Withdraw Consent. When we use consent as our lawful basis, you have the right to withdraw your consent at any time.
-
Your Right to Complain. You have the legal right to complain if you believe that we have handled your data inappropriately, or in a non-compliance with the UK GDPR, and associated legislation
You can read more about your data protection rights here.
If you make a request, we must respond to you without undue delay and in any event within one month. We can extend that period for up to an additional two months if the request is particularly complex, or we have received a number of requests from an individual.
To make a data protection rights request, please contact us using the contact details at the top of this Privacy Notice.
Our Lawful Bases for the Collection and Use of Your Data
Our lawful bases for collection or using personal information to provide services and goods are:
-
Contract - we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
-
Legal obligation - we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object, and the right to data portability.
Our lawful bases for collecting or using personal information for the operation of customer accounts and guarantees are:
-
Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
-
Contract - we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
-
Legal obligation - we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object, and the right to data portability.
Our lawful bases for collecting or using personal information to prevent, detect, investigate, or prosecute crimes and provide training to staff members are:
-
Legitimate interests - we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to data portability. Our legitimate interests are:
-
The Company has a legitimate interest to prevent crime to ensure that the business can remain operational and profitable.
-
The Company has a legitimate interest to provide training to staff members to ensure that the business can remain compliant, efficient, and profitable.
-
Substantial Public Interest - we’re collecting or using your information for the performance of a task (crime detection and investigation) carried out in the public interest.
Our lawful bases for collecting or using personal information for service updates or marketing purposes are:
-
Legitimate interests - we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to data portability. Our legitimate interests are:
-
The Company has a legitimate interest to update our services, and engage in marketing to ensure that the business can remain operational and profitable.
-
Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
-
Contract - we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
-
Legal obligation - we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object, and the right to data portability.
Our lawful bases for collecting or using personal information for legal requirements are:
-
Legal obligation - we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object, and the right to data portability.
Our lawful bases for collecting or using personal information for recruitment purposes (if you apply to work for us) are:
-
Legitimate interests - we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to data portability. Our legitimate interests are:
-
The Company has a legitimate interest to engage in recruitment activities to employ sufficient personnel to ensure that the business can remain operational and profitable.
-
-
Contract (or Taking Reasonable Steps to Enter into a Contract) - we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
-
Legal obligation - we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object, and the right to data portability.
-
Employment, social security and social protection - We need to collect and process some personal data in order to look after you at work, for example necessary medical information.
-
Vital Interests - In life and death situations we may need to process sensitive personal data about you without seeking additional consent, for example informing paramedics what medication you are currently taking.
Our lawful bases for collecting or using personal information for dealing with queries, complaints, or claims are:
-
Contract - we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
-
Legal obligation - we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object, and the right to data portability.
Where we Get Personal Information From
We get personal information:
-
Directly from you (or the person that orders a product from us - i.e. family and friends);
-
From CCTV footage or other recordings;
-
From publicly available sources (e.g. LinkedIn, Indeed, or other websites);
-
From market research organisations;
-
From suppliers and service providers.
If we receive personal information from other sources, we will let you know within one month, in line with Article 14 of the GDPR. For more information regarding the right to be informed, please visit the ICO website.
Retention (How Long we Keep Your Information For)
We will only keep your personal data for as long as we need to, to fulfil the purpose we collected it for, including any legal, regulatory, tax, accounting, or reporting requirements. We may keep your personal information for longer in the event of a complaint or if we believe there is the possibility of litigation (court action).
Our retention schedule for this Notice is below, in Appendix A.
Who we Share Information With
Klarna
At some point, you might choose to pay using Klarna and that’s great, that’s why we have it as an option.
If you do use Klarna, they will be the controller of your payment data (not us) and they will simply send us a virtual token as proof of payment.
You can look at Klarna’s Privacy and Security information here.
Trust Pilot
We use an external company, Trustpilot A/S (“Trustpilot”), to collect your feedback which means that we will share your name, email address and reference number with Trustpilot for this purpose. If you want to read more about how Trustpilot processes your data, you can find their Privacy Policy here.
Our data processors include:
-
John Greed Group (Joint Controller)
-
Why: John Greed Group (our Parent Company), owns the website domain, and rents this to us.
-
Laser Red
-
Why: Laser Red develops and maintains our website - keeping everything running smoothly.
-
Adobe Commerce (Previously Magento)
-
Why: Adobe Commerce provides our e-commerce platform, which means we can sell items online.
-
Braintree
-
Why: Braintree takes our payments, which keeps us in business.
-
Meta (Facebook, Instagram etc.)
-
Why: Meta is our largest provider of social media advertising, which means we can show off our products to more people. Sometimes, Meta will look at who engages with our adverts, and then advertise to other people who ‘look’ the same (i.e. same age, gender etc.).
-
Google
-
Why: Google provides us with search engine advertising, and we also use their workspace for email, Google Docs and Sheets etc.
-
Use of reCAPTCHA: To ensure the security of our website and protect against automated abuse, spam, and bot attacks, we use the reCAPTCHA service. This service is provided by Google (acting as our Data Processor). reCAPTCHA works by collecting hardware and software information, such as device and application data, and sending these results to Google for analysis to determine if a user is human.
-
Microsoft Bing
-
Why: Microsoft Bing provides us with search engine advertising.
-
Dot Digital and Fresh Relevance
-
Why: Dot Digital deals with all of our email and sms marketing campaigns, and Fresh Relevance (their sister company) is a product recommendation provider.
-
Criteo and Other Analytic Providers
-
Why: If you consent to cookies, we will share some data with suppliers to make sure you get advertising that matches your shopping preferences.
-
DPD and Royal Mail
-
Why: DPD and Royal Mail are our couriers, they will ship your purchases to you.
Other Third Parties
In some circumstances, we may share information with the following organisations:
-
HMRC (and other regulatory bodies);
-
External auditors;
-
Suppliers and service providers;
-
Debt collection agencies;
-
Professional consultants and legal representatives;
-
Our insurance provider;
-
UK law enforcement.
Sharing Information Outside the UK
Where necessary, we may transfer personal information outside of the UK. When doing so, we comply with the UK GDPR, making sure appropriate safeguards are in place.
For further information or to obtain a copy of the appropriate safeguard for any of our transfers, please contact us using the contact information provided at the top of this Privacy Notice.
-
Organisation name: Google (including Workspace and reCAPTCHA)
-
Category of recipient: IT infrastructure provider
-
Country the personal information is sent to: United States of America
-
How the transfer complies with UK data protection law: The country, organisation, or sector has a UK data bridge
-
Organisation name: Braintree
-
Category of recipient: Payment Provider
-
Country the personal information is sent to: United States of America
-
How the transfer complies with UK data protection law: The organisation utilises Binding Corporate Rules.
-
Organisation name: Microsoft Bing
-
Category of recipient: Advertising Provider
-
Country the personal information is sent to: United States of America
-
How the transfer complies with UK data protection law: The country, organisation, or sector has a UK data bridge
-
Organisation name: Meta
-
Category of recipient: Social Media Advertising
-
Country the personal information is sent to: United States of America
-
How the transfer complies with UK data protection law: The country, organisation, or sector has a UK data bridge
-
Organisation name: Indeed
-
Category of recipient: Recruitment Service
-
Country the personal information is sent to: United States of America
-
How the transfer complies with UK data protection law: The country, organisation, or sector has a UK data bridge
-
Organisation name: XodoSign
-
Category of recipient: E-Signature software
-
Country the personal information is sent to: Canada
-
How the transfer complies with UK data protection law: Adequacy
-
Organisation name: Grammarly
-
Category of recipient: Grammar and spelling software
-
Country the personal information is sent to: United States of America
-
How the transfer complies with UK data protection law: The country, organisation, or sector has a UK data bridge
Artificial Intelligence
We use various Artificial Intelligence (AI) tools and platforms for administrative and efficiency tasks such as generating reports, drafting communications, and conducting research. These tools, which may include large language models and generative AI software, are used to enhance our operational efficiency. While this may sometimes involve processing your personal information, we want to assure you that we do not use AI for automated decision-making. We fully vet the security and privacy controls of all tools prior to use, and your data is not used to train these models. Your privacy and the security of your information are our top priorities.
Abandoned Cart Emails
If you are shopping on our website, and get to the final stages of making your purchase, but then ‘abandon’ your cart - we might send you an email to ask if you would like to complete the purchase. This will only be possible if you are logged into your John Greed account, or you have already entered your email address (our tracking cookies will capture this).
We have a legitimate interest to process your data in this way, as putting items in your basket is like requesting a quote from a tradesperson - it’s only natural that we would follow up! If you don’t want to complete the purchase, please feel free to ignore our nudge. Your personal data won’t be used for any other purpose - for example, we won’t add it to our mailing list.
Applicant Filtering
If you apply for a role, communicate with us, and attend the interview (if offered one) but are unsuccessful, we will retain your information for six months, and then we will delete it. The fact you were unsuccessful that year will have no impact on any further applications you make.
On the other hand, if you decide not to attend an interview without telling us, don’t communicate with us, or behave inappropriately (swearing at us etc. - yes, people do this) then we may retain your information for longer, so that we can filter any future applications you make. This type of behavior costs the Company a lot of time and money, and we want to prioritise candidates who want to work for us, where we can.
We do understand that things happen, so if you think your application has been filtered for an unjust reason (or, you’ve matured etc.) then get in touch and we will consider this on a case-by-case basis.
Medical Information
Routine Processing: If you start working for us, we will collect certain medical and next of kin information from you. We will then ask if this information has changed at regular intervals, to make sure that the information we have is up to date and complete. We have a legal and moral responsibility to do this so that we can look after you at work, and fulfill our legal obligations as an employer. Such information will always be shared with and assessed by the HR Department and Business Compliance Department to ensure that appropriate control measures are in place. Where necessary, this information will also be shared with the Board of Directors (i.e. if a new control measure needs financial authorisation). This processing, as described, does not rely on your consent and instead relies on Legal Obligation, and Employment, Social Security, and Social Protection.
Internal Sharing and Consent: You will be asked whether you consent to your medical and next of kin information being shared with your Manager, and / or our team of first aiders. This is a personal decision and you have the right to retract this consent (if given) at any time.
Emergency Situations (Vital Interests): In the event of a serious incident, for example an accident at work requiring hospitalisation or that leaves you temporarily incapacitated, or if you do not attend work and we cannot contact you, we may share your medical and next of kin information regardless of whether you have consented for us to do so. This may in fact be the complete opposite of what you have asked us to do. This will only occur in situations we deem to be life threatening, and when we believe that the information we hold about you could have a material impact on the situation. In this kind of situation, we may share your medical and next of kin information with our team of first aiders, your Manager, your next of kin, and the Emergency Services. This processing relies on Article 6(1)(d) (Vital Interests) of the UK GDPR, which stipulates that data may be processed if it is essential to someone's life.
Cookie-less Tracking
When you visit our website you can opt-out of all non-essential cookies. If you do this, we will use a cookieless tracker to monitor your website behaviour, so that we can provide you with tailored recommendations and personalised content.
Don’t worry - the only information captured is your device ID and this is deleted within 24 hours.
Refunds and Exchanges
If you are unhappy with your order, it may be possible to offer you a refund or an exchange - please refer to our Terms and Conditions for more information.
For refunds, nothing changes in terms of how your data is processed. If you have checked out using your John Greed account, there will also be no changes to how your data is processed for exchanges.
If you would like to exchange a product, and you have checked out as a guest, we will need to create a customer account for you to allow us to process the exchange - this is due to how our ecommerce platform works. The account will be deleted once the exchange has been processed, and there are no other changes to how your data is processed.
How to Complain
If you have any concerns about our use of your personal data, you can complain to us using this form or the contact details at the top of this Privacy Notice. Under the UK GDPR, you should complain directly to us before escalating the issue to the Information Commissioners Office (ICO).
We take all complaints seriously, will acknowledge all complaints within 30 days, and respond fully within one calendar month unless the complaint is particularly complex.
Whilst we hope that we can resolve any problems you have ourselves, If you remain unhappy with how we’ve used your data after raising a complaint with us, you can then complain to the ICO.
ICO Contact Details
|
Website: |
|
|
Helpline Number: |
0303 123 1113 |
|
Website: |
Information Commissioner's Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF |
Appendix A: Retention Schedule
|
CCTV Footage |
30 Days (unless required for additional processing, in the event of a dispute / insurance claim etc.) |
|
Photographs Submitted for Engraving |
30 Days (unless required for additional processing, in the event of a dispute / insurance claim etc.) |
|
Customer Sales Information
|
Current + 6 Years |
|
Reviews |
Indefinitely |
|
BigQuery Records (Data Analysis) |
Indefinitely (data is pseudo anonymised) (retention begins when the information is obtained) |
|
Social Media Data |
2 Years retention begins when the information is obtained) |
|
Email Addresses (Email Marketing) |
For the Length of the Relationship + 6 Months (dependent on engagement) |
|
Phone Numbers (SMS Marketing) |
For the Length of the Relationship + 6 Months (dependent on engagement) |
|
Engagement Data |
2 Years (retention begins when the information is obtained) |
|
Recruitment Data
|
6 Months (unsuccessful applicants), Current + 6 Years (staff members) Details of applicants who do not attend interviews / communicate poorly with us may be retained for longer, so that we can filter any applications they make in the future. |