Privacy Policy

Last Updated: 9th April 2025

Introduction

At John Greed Jewellery Ltd, we respect your privacy and are committed to protecting your personal information. This Privacy Notice tells you what to expect us to do with your personal information.


Who We Are (The Controller)

John Greed Jewellery Ltd is registered in England and our Registration Number is 04814633. When we mention “John Greed”, “we”, “us”, “our”, or “the Company” in this Privacy Notice, we are referring to John Greed Jewellery Ltd, which is the Company responsible for processing your data as the “Controller”.


How to Contact Us 

Our Data Protection Officer (DPO):

Business Compliance Manager / DPO

Email Address:

data.protection@johngreed.com 

Postal Address:

Suite 2, Firth Road Business Park, Firth Road, Lincoln, LN6 7AA

Telephone Number: 

+44 (0) 1522 718 388

 

Accessibility 

Individual needs exist. If you need a copy of our Privacy Notice in a different format, please contact us using any of the details above and we will make it happen. 

 

What Information We Collect and Use, and Why 

We collect or use the following information to provide services and goods, including delivery: 

  • Names and contact details; 

  • Addresses; 

  • Payment details (the last four digits of your card number); 

  • Account information; 

  • Information relating to loyalty programmes; 

  • Website user information (including user journeys and cookie tracking); 

  • Photographs or video recordings; 

  • Information relating to compliments or complaints. 

We collect or use the following information for the operation of customer accounts and guarantees: 

  • Names and contact details; 

  • Addresses; 

  • Payment details (the last four digits of your card number); 

  • Purchase history; 

  • Account information, including registration details; 

  • Information used for security purposes; 

  • Marketing preferences. 

We collect or use the following information to prevent, detect, investigate, or prosecute crimes: 

  • Names and contact details; 

  • Customer or client accounts and records; 

  • Video and CCTV recordings of public areas (including indoor and outdoor spaces); 

  • Video and CCTV recordings of private or staff only areas; 

  • Financial transaction information. 

We collect or use the following information for service updates or marketing purposes: 

  • Names and contact details;

  • Addresses; 

  • Marketing preferences; 

  • Location data; 

  • Purchase or viewing history; 

  • IP addresses; 

  • Website user journey information; 

  • Analytical data (from cookies etc.); 

  • Sales data;

  • Records of consent, where appropriate. 

We collect or use the following information to comply with legal requirements: 

  • Name; 

  • Contact information; 

  • Financial transaction information; 

  • Health and Safety data; 

  • Photographs or video records.

We collect or use the following information for recruitment purposes: 

  • Contact details (e.g. name, address, telephone number or personal email address); 

  • Date of birth; 

  • National Insurance number; 

  • Copies of passports or other photo ID; 

  • Employment history (e.g. job application, employment references, or secondary employment); 

  • Education history (e.g. qualification); 

  • Right to work information; 

  • Health data (special category, for example if you require reasonable adjustments to attend an interview);

  • Details of any criminal convictions. 

We collect or use the following information for dealing with queries, complaints, or claims: 

  • Names and contact details; 

  • Addresses; 

  • Payment details; 

  • Account information; 

  • Purchase or service history; 

  • Video and CCTV recordings of public areas (including indoor and outdoor spaces); 

  • Video and CCTV recordings of private or staff only areas;

  • Witness statements and contact details; 

  • Relevant information from previous investigations; 

  • Customer or client accounts and records; 

  • Financial transaction information.  

 

Lawful Bases and Data Protection Rights 

Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.

Which lawful basis we rely on may affect your data protection rights which are detailed below:

  • Your Right of Access. You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all of the information you ask for.

  • Your Right to Rectification. You have the right to ask us to correct or delete personal information that you think is inaccurate or incomplete. 

  • Your Right to Erasure. You have the right to ask us to delete your personal information.   

  • Your Right to Restrict Processing. You have the right to ask us to limit how we can use your personal information.  

  • Your Right to Data Portability. You have the right to ask that we transfer the personal information you have with us to another organisation, or to you.  

  • Your Right to Withdraw Consent. When we use consent as our lawful basis, you have the right to withdraw your consent at any time. 

You can read more about your data protection rights here.

If you make a request, we must respond to you without undue delay and in any event within one month. We can extend that period for up to an additional two months if the request is particularly complex, or we have received a number of requests from an individual. 

To make a data protection rights request, please contact us using the contact details at the top of this Privacy Notice. 

 

Our Lawful Bases for the Collection and Use of Your Data 

Our lawful bases for collection or using personal information to provide services and goods are:

  • Contract - we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object. 

  • Legal obligation - we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object, and the right to data portability.  

Our lawful bases for collecting or using personal information for the operation of customer accounts and guarantees are: 

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

  • Contract - we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object. 

  • Legal obligation - we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object, and the right to data portability.  

Our lawful bases for collecting or using personal information to prevent, detect, investigate, or prosecute crimes are: 

  • Legitimate interests - we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to data portability. Our legitimate interests are: 

    • The Company has a legitimate interest to prevent crime to ensure that the business can remain operational and profitable. 

  • Substantial Public Interest - we’re collecting or using your information for the performance of a task (crime detection and investigation) carried out in the public interest.

Our lawful bases for collecting or using personal information for service updates or marketing purposes are: 

  • Legitimate interests - we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to data portability. Our legitimate interests are: 

    • The Company has a legitimate interest to update our services, and engage in marketing to ensure that the business can remain operational and profitable. 

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

  • Contract - we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object. 

  • Legal obligation - we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object, and the right to data portability.  

Our lawful bases for collecting or using personal information for legal requirements are: 

  • Legal obligation - we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object, and the right to data portability.  

Our lawful bases for collecting or using personal information for recruitment purposes are: 

  • Legitimate interests - we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to data portability. Our legitimate interests are: 

    • The Company has a legitimate interest to engage in recruitment activities to employ sufficient personnel to ensure that the business can remain operational and profitable. 

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

  • Legal obligation - we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object, and the right to data portability.  

Our lawful bases for collecting or using personal information for dealing with queries, complaints, or claims are: 

  • Contract - we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object. 

  • Legal obligation - we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object, and the right to data portability.  

 

Where we Get Personal Information From 

We get personal information: 

  • Directly from you (or the person that orders a product from us - i.e. family and friends); 

  • From CCTV footage or other recordings; 

  • From publicly available sources (e.g. LinkedIn, Indeed, or other websites); 

  • From market research organisations; 

  • From suppliers and service providers. 

If we receive personal information from other sources, we will let you know within one month, in line with Article 14 of the GDPR. For more information regarding the right to be informed, please visit the ICO website

 

Retention (How Long we Keep Your Information For)

We will only keep your personal data for as long as we need to, to fulfil the purpose we collected it for, including any legal, regulatory, tax, accounting, or reporting requirements. We may keep your personal information for longer in the event of a complaint or if we believe there is the possibility of litigation (court action). 

Our retention schedule for this Notice is below, in Appendix A.

 

Who we Share Information With 

Klarna 

At some point, you might choose to pay using Klarna and that’s great, that’s why we have it as an option. 

If you do use Klarna, they will be the controller of your payment data (not us) and they will simply send us a virtual token as proof of payment. 

You can look at Klarna’s Privacy and Security information here.  

Trust Pilot

We use an external company, Trustpilot A/S (“Trustpilot”), to collect your feedback which means that we will share your name, email address and reference number with Trustpilot for this purpose. If you want to read more about how Trustpilot processes your data, you can find their Privacy Policy here. 

Our data processors include: 

  1. John Greed Group 

    1. Why: John Greed Group (our Parent Company), owns the website domain, and rents this to us. 

  2. Laser Red

    1. Why: Laser Red develops and maintains our website - keeping everything running smoothly. 

  3. Adobe Commerce (Previously Magento)

    1. Why: Adobe Commerce provides our e-commerce platform, which means we can sell items online. 

  4. Braintree

    1. Why: Braintree takes our payments, which keeps us in business. 

  5. Meta (Facebook, Instagram etc.) 

    1. Why: Meta is our largest provider of social media advertising, which means we can show off our products to more people. Sometimes, Meta will look at who engages with our adverts, and then advertise to other people who ‘look’ the same (i.e. same age, gender etc.). 

  6. Google

    1. Why: Google provides us with search engine advertising, and we also use their workspace for email, Google Docs and Sheets etc. 

  7. Microsoft Bing 

    1. Why: Microsoft Bing provides us with search engine advertising. 

  8. Dot Digital and Fresh Relevance  

    1. Why: Dot Digital deals with all of our email and sms marketing campaigns, and Fresh Relevance (their sister company) is a product recommendation provider. 

  9. Criteo and Other Analytic Providers

    1. Why: If you consent to cookies, we will share some data with suppliers to make sure you get advertising that matches your shopping preferences. 

  10. DPD and Royal Mail

    1. Why: DPD and Royal Mail are our couriers, they will ship your purchases to you. 

Other Third Parties 

In some circumstances, we may share information with the following organisations: 

  • HMRC (and other regulatory bodies); 

  • External auditors; 

  • Suppliers and service providers; 

  • Debt collection agencies; 

  • Professional consultants and legal representatives; 

  • Our insurance provider; 

  • UK law enforcement.

 

Sharing Information Outside the UK 

Where necessary, we may transfer personal information outside of the UK. When doing so, we comply with the UK GDPR, making sure appropriate safeguards are in place. 

For further information or to obtain a copy of the appropriate safeguard for any of our transfers, please contact us using the contact information provided at the top of this Privacy Notice. 

  1. Organisation name: Google Workspace (Including GMail)

    1. Category of recipient: IT infrastructure provider

    2. Country the personal information is sent to: United States of America

    3. How the transfer complies with UK data protection law: The country, organisation, or sector has a UK data bridge

  2. Organisation name: Braintree

    1. Category of recipient: Payment Provider

    2. Country the personal information is sent to: United States of America

    3. How the transfer complies with UK data protection law: The organisation utilises Binding Corporate Rules. 

  3. Organisation name: Microsoft Bing

    1. Category of recipient: Advertising Provider

    2. Country the personal information is sent to: United States of America

    3. How the transfer complies with UK data protection law: The country, organisation, or sector has a UK data bridge 

  4. Organisation name: Meta

    1. Category of recipient: Social Media Advertising 

    2. Country the personal information is sent to: United States of America

    3. How the transfer complies with UK data protection law: The country, organisation, or sector has a UK data bridge 

  5. Organisation name: Indeed

    1. Category of recipient: Recruitment Service

    2. Country the personal information is sent to: United States of America

    3. How the transfer complies with UK data protection law: The country, organisation, or sector has a UK data bridge 

  6. Organisation name: XodoSign 

    1. Category of recipient: E-Signature software

    2. Country the personal information is sent to: Canada

    3. How the transfer complies with UK data protection law: Adequacy 

  7. Organisation name: Grammarly 

    1. Category of recipient: Grammar and spelling software

    2. Country the personal information is sent to: United States of America

    3. How the transfer complies with UK data protection law: The country, organisation, or sector has a UK data bridge 

Abandoned Cart Emails

If you are shopping on our website, and get to the final stages of making your purchase, but then ‘abandon’ your cart - we might send you an email to ask if you would like to complete the purchase. This will only be possible if you are logged into your John Greed account, or you have already entered your email address (our tracking cookies will capture this).

We have a legitimate interest to process your data in this way, as putting items in your basket is like requesting a quote from a tradesperson - it’s only natural that we would follow up! If you don’t want to complete the purchase, please feel free to ignore our nudge. Your personal data won’t be used for any other purpose - for example, we won’t add it to our mailing list.

 

Applicant Filtering

If you apply for a role, communicate with us, and attend the interview (if offered one) but are unsuccessful, we will retain your information for six months, and then we will delete it. The fact you were unsuccessful that year will have no impact on any further applications you make. 

On the other hand, if you decide not to attend an interview without telling us, don’t communicate with us, or behave inappropriately (swearing at us etc. - yes, people do this) then we may retain your information for longer, so that we can filter any future applications you make. This type of behavior costs the Company a lot of time and money, and we want to prioritise candidates who want to work for us, where we can. 

We do understand that things happen, so if you think your application has been filtered for an unjust reason (or, you’ve matured etc.) then get in touch and we will consider this on a case-by-case basis. 

 

Refunds and Exchanges 

If you are unhappy with your order, it may be possible to offer you a refund or an exchange - please refer to our Terms and Conditions for more information. 

For refunds, nothing changes in terms of how your data is processed. If you have checked out using your John Greed account, there will also be no changes to how your data is processed for exchanges.

If you would like to exchange a product, and you have checked out as a guest, we will need to create a customer account for you to allow us to process the exchange - this is due to how our ecommerce platform works. The account will be deleted once the exchange has been processed, and there are no other changes to how your data is processed. 

 

How to Complain 

If you have any concerns about our use of your personal data, you can complain to us using the contact details at the top of this Privacy Notice. We take all complaints seriously, and will respond to you as quickly as we can. 

Whilst we hope that we can resolve any problems you have ourselves, If you remain unhappy with how we’ve used your data after raising a complaint with us, you can then complain to the ICO. 

ICO Contact Details

Website:

https://www.ico.org.uk/make-a-complaint 

Helpline Number:

0303 123 1113 

Website:

Information Commissioner's Office

Wycliffe House

Water Lane

Wilmslow 

Cheshire

SK9 5AF

 

Appendix A: Retention Schedule

CCTV Footage

30 Days (unless required for additional processing, in the event of a dispute / insurance claim etc.) 

Photographs Submitted for Engraving

30 Days (unless required for additional processing, in the event of a dispute / insurance claim etc.)

Customer Sales Information 

  • Payment information

  • Full Name

  • Email Address

  • Delivery and Billing Address

  • Phone Number 

  • Enquiries, Feedback, Complaints

  • Order and Return Data

  • Engraving Data

Current + 6 Years 

Reviews

Indefinitely 

BigQuery Records (Data Analysis)

Indefinitely (data is pseudo anonymised)

(retention begins when the information is obtained)

Social Media Data

2 Years 

retention begins when the information is obtained)

Email Addresses (Email Marketing)

For the Length of the Relationship + 6 Months (dependent on engagement) 

Phone Numbers (SMS Marketing)

For the Length of the Relationship + 6 Months (dependent on engagement) 

Engagement Data

2 Years 

(retention begins when the information is obtained)

Recruitment Data

  • CV’s and Covering Letters

  • Indeed Recruitment Data

6 Months (unsuccessful applicants), Current + 6 Years (staff members) 


Details of applicants who do not attend interviews / communicate poorly with us may be retained for longer, so that we can filter any applications they make in the future. /p>

Basket