Skip to content

Legal

Privacy Policy

This notice explains how SpeedShirt handles personal data across our shop, design tools, orders, support and communications.

Last updated: 13 August 2026

This privacy notice is written for the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR) and relevant amendments made by the Data (Use and Access) Act 2025.

It covers the Website, customer accounts, design and gangsheet tools, custom printing, purchases, deliveries, support, reviews and emails. It does not replace the privacy notice of an independent service you choose to use, such as Stripe, Google or Canva.

Your artwork stays yours

We use uploaded artwork to operate the design tools, prepare and make your products, provide support and meet legal or security requirements.

Payments are handled by Stripe

Payment details are entered into Stripe's secure payment tools. We do not receive or store your full card number or card security code.

We do not sell personal data

We do not sell or rent personal data, or share it with third parties for their own unrelated targeted advertising.

You have choices

You can unsubscribe from marketing, disconnect optional integrations and ask to access, correct or delete personal data, subject to legal limits.

1. Who we are and when this notice applies

SpeedShirt, we, us and our mean the seller identified on your order confirmation or VAT invoice, trading as SpeedShirt. That seller is the controller responsible for the personal data described in this notice. Our Website is speedshirt.uk and our privacy contact is support@speedshirt.uk.

If you buy for a company, give us another person's delivery details, include an identifiable person in artwork or submit content about somebody else, you must have a lawful reason to provide that data and should make this notice available to them where appropriate.

2. Personal data we collect

Depending on how you use SpeedShirt, we may collect:

  • identity and contact data, including your name, email address, telephone number, delivery and billing addresses and business details;
  • account data, including customer ID, sign-in and verification records, password-reset records, saved addresses, preferences and account history. Passwords are handled in protected form; we never receive your Google password;
  • order and transaction data, including products, quantities, dimensions, customisation instructions, prices, discounts, VAT, payment status and identifiers, refunds, invoices, delivery method, tracking and order history;
  • artwork and design data, including uploaded files, photographs, logos, text, filenames, dimensions, previews, layouts, gangsheets, cut settings, processed image versions and saved designs;
  • communications, including support tickets, emails, messages, cancellation or complaint details and attachments;
  • review data, including ratings, written feedback, optional answers, recommendation choices and photos;
  • marketing data, including newsletter status, the source and time of a sign-up, consent or soft-opt-in records, unsubscribe and suppression status, and email delivery, open and click information where used;
  • technical and security data, including IP address, approximate country derived by our network provider, browser and device information, user agent, timestamps, request and error logs, security events and session, cart or integration identifiers; and
  • optional integration data, such as the name and email returned by Google sign-in, or Canva authorisation tokens, design titles, thumbnails and other information you permit Canva to provide.

We do not ask for special category data, such as health, biometric, religious or political data, in normal use. Please do not include it in artwork, reviews, messages or attachments unless it is genuinely necessary and you have first contacted us.

3. Where the data comes from

We collect personal data:

  • directly from you when you browse, register, upload, design, order, review, subscribe or contact us;
  • automatically from your browser or device, our servers and the networks used to deliver the Website;
  • from services you choose to connect, including Google sign-in and Canva;
  • from payment providers, delivery carriers and suppliers, for example payment status, fraud signals, delivery events or returned parcels;
  • from a person or organisation ordering on your behalf or sending an order to you; and
  • from professional advisers, regulators, law-enforcement bodies or rights holders where a dispute, legal duty or credible complaint requires it.

4. How and why we use personal data

UK data protection law requires a lawful basis for each use. More than one basis can apply where the purposes are different.

PurposeData normally usedLawful basis
Create and secure accounts, sessions, carts and saved designsIdentity, contact, account, design and technical dataContract or steps before a contract; legitimate interests in providing a secure service
Quote, take payment, produce, fulfil, deliver and administer ordersIdentity, contact, transaction, artwork and technical dataContract; legal obligations for tax, accounting and consumer law
Provide design, image-enhancement and Canva featuresArtwork, integration and technical dataContract or steps you request before a contract; legitimate interests in improving production quality
Handle support, returns, cancellations, complaints and rights claimsIdentity, contact, order, communications and artwork dataContract; legal obligations; legitimate interests in resolving issues and defending claims
Prevent fraud, abuse and security incidentsAccount, transaction and technical dataLegitimate interests in protecting customers and our service; legal obligations where applicable
Send operational emails and eligible review requestsIdentity, contact, order and message interaction dataContract and legitimate interests, subject to PECR; consent where PECR requires it
Send newsletters, offers and product newsIdentity, contact, marketing and order dataConsent, or legitimate interests where the PECR existing-customer soft opt-in lawfully applies
Publish and moderate customer reviewsReview, identity, order and technical dataLegitimate interests in genuine customer feedback; consent for optional review photos where required
Operate, troubleshoot and improve the Website and understand campaign resultsTechnical, transaction and marketing-attribution dataLegitimate interests; consent or a PECR exception for device storage or access, as applicable

Our legitimate interests include operating a reliable ecommerce and custom-production service, improving print and support workflows, measuring communications, securing accounts, preventing fraud, recovering debts and establishing or defending legal claims. We balance those interests against your rights and reasonable expectations.

We need the details marked as required at account creation or checkout to provide the account or order. If you do not provide them, we may be unable to register you, take payment, make the products or deliver them. Newsletter sign-up, Canva connection, Google sign-in, reviews and review photos are optional.

5. Artwork and image processing

Uploaded artwork is Customer Content under our Terms of Service. We process it to display previews, save designs and layouts, run requested or offered preparation tools, produce print-ready files, manufacture products, support reorders, investigate quality issues, keep operational backups and protect the service.

Image tools such as upscaling, sharpening, background removal, logo clean-up or vectorisation may run on our production systems or through a specialist cloud image-processing provider, including Replicate when it is the configured provider or fallback. This can involve sending the image, an asset URL and limited job metadata to that provider and receiving the processed result. Review every processed image before ordering.

Artwork and previews must be available to the systems that render and manufacture your products and may be delivered through content-delivery URLs. Do not upload confidential records, identity documents, payment details or unnecessary personal data as artwork. Where artwork depicts another person, you are responsible for having permission to use their image and for respecting their privacy rights.

6. Payments, orders and delivery

Stripe provides our checkout and processes card or wallet details. Stripe may collect payment details, billing information, device information and fraud-prevention signals directly. We normally receive the payment result, payment-intent or transaction identifier, method type and limited method details such as card brand and last four digits, rather than full card credentials. Stripe also processes data under its own privacy policy.

We give the delivery details and contact information needed to fulfil the order to relevant production partners, suppliers and carriers. Our tracked UK carriers may include Royal Mail and DPD. A carrier may contact you about delivery and will handle that information under its own privacy responsibilities.

7. Marketing and service messages

We send service messages needed for accounts and orders, such as verification, password reset, payment, order, production, dispatch, support and safety messages. These are not promotional, so an unsubscribe from marketing does not stop them.

If you subscribe, we may send promo codes, restock notices, product news and practical printing content. We may also market similar SpeedShirt products to an existing customer only where the PECR soft opt-in requirements are met, including giving an opt-out when the details are collected and in every message. Otherwise, we ask for consent. You can unsubscribe using the link in an email or by contacting us. We keep a minimal suppression record so that we do not add the address back accidentally.

Our emails may contain identifiers that record delivery, opens and link clicks, and tagged links may connect a campaign to a later cart or order. We use this to understand whether communications work and to manage suppression. You can block remote images in your email app, avoid tagged links, unsubscribe or object to this processing.

8. Reviews and public content

After an order, we may send an eligible review invitation subject to your marketing and suppression choices. A review request link can contain your name, email, order number, products and a secure token and will expire. Opening it can record that the request was opened.

Submitted reviews are checked before publication. If approved, the Website may publicly show the rating, title, review, optional answers, recommendation, photos, product details, review date and a shortened display name such as your first name and surname initial. It does not publish your email or full order details. Public review text and photos can be copied by others, so remove personal information from them before submission and make sure everyone shown in a photo agrees to publication. Contact us to ask for a review to be corrected, anonymised or removed.

9. Cookies and local storage

Cookies, local storage and session storage let a website save or read information on a device. We use the following types. Exact names can change as security and providers are updated, but their purposes do not change without an update to this notice or another clear notice.

Type and examplesPurposeTypical duration
Account and securitymedusa_customer_token; sign-in redirect and maintenance-security tokensKeep you signed in, return you safely after authentication and protect requested services.Authentication is normally up to 30 days; short-lived security tokens range from minutes to hours.
Anonymous session and baskettf_session_token, tf_cart_id and anonymous-session local storageAssociate uploads, saved work and a basket with the correct visitor before sign-in.The session cookie is normally 30 days; local storage remains until cleared or the cart/session is removed.
Checkout conveniencetf_last_checkoutRemember name, email and delivery address on the device for a later checkout.Until browser site data is cleared or overwritten.
Preferencestf_display_currency, unit, theme and editor-view preferencesAdapt prices, measurements and appearance to choices made on the Website.Currency is normally one year; local preferences remain until cleared.
Approximate countrytf_detected_countryCache the country supplied by our network provider to choose sensible shipping and currency defaults.Up to 24 hours in session storage.
Optional Canva connectionCanva state, verifier, access, refresh and expiry cookiesSecure the connection you request and let you browse permitted Canva designs.Connection checks are about 15 minutes; access follows Canva's token lifetime; refresh information is up to 30 days or until disconnected.
Marketing attributiontfx_email_attribution and tagged email linksRecord the campaign, landing page and later cart or order so we can measure communication results.Local attribution remains until cleared; order attribution follows the order retention period.
Third-party checkout or supportStripe and, when enabled, the eDesk support widgetProvide payment, fraud-prevention or interactive support features.Set by the provider and described in its own notice or on-screen controls.

Account, security, basket, checkout and integration technologies are used where necessary to provide a service you request. Preference technologies may use the PECR appearance or functionality exception. Statistical technologies can be used without consent only where the statutory exception applies: they must be used solely to improve the service, individual-level data must not be kept longer than needed to aggregate it, and you must have a simple way to object. Consent is required before using storage or access technology where no PECR exception applies, including for advertising or non-exempt tracking.

The current storefront does not contain a general-purpose audience analytics package or advertising pixel. Optional services, including Stripe, Canva or an enabled support widget, may set their own technologies when you use them. You can clear or block site data in your browser, but blocking necessary items may stop sign-in, uploads, the basket, checkout or connected services from working. You can also email us to object to exempt statistical processing or marketing attribution.

10. Who we share data with

We disclose only what is reasonably needed to:

  • payment and wallet providers, including Stripe, and fraud-prevention providers;
  • hosting, content-delivery, database, file-storage, security, email and infrastructure providers, including Amazon Web Services and Cloudflare;
  • our ecommerce, order-management, production, support and communications systems and authorised staff;
  • production partners and product suppliers where they help make or source an order;
  • delivery carriers, including Royal Mail and DPD where selected for the order;
  • optional services you connect or open, including Google, Canva and, when configured, eDesk;
  • specialist image processors, including Replicate when used by the artwork pipeline;
  • professional advisers, insurers, auditors, banks and prospective buyers or investors under suitable confidentiality controls;
  • tax, regulatory, court, law-enforcement or other public bodies when required or permitted by law; and
  • a rights holder or customer where reasonably necessary to investigate an artwork, fraud, safety or legal complaint.

Some recipients act as our processors and must follow our instructions; others act as independent controllers for their part of a service. We do not sell or rent personal data.

11. International transfers

We are UK-based, but some technology providers, support teams or infrastructure may process data outside the UK, including in the United States. The privacy laws in another country may differ from UK law.

Where UK transfer rules apply, we use a permitted safeguard appropriate to the recipient and transfer. This may be a UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, another legally recognised safeguard or, in limited cases, a statutory exception. We carry out the assessment required for the safeguard used. Contact us for more information about a relevant safeguard; confidential commercial terms may be redacted.

12. How long we keep data

We keep personal data only for the period needed for the stated purpose, including providing reorders, meeting tax and accounting duties, resolving complaints, preventing fraud and establishing or defending legal claims. Typical periods and criteria are:

  • anonymous work: an anonymous session normally expires after 30 days; uploads, designs and gangsheets not linked to an account or order are then eligible for deletion;
  • accounts and saved designs: while the account remains open or until you delete the item, followed by the limited period needed for closure, security, backups or a legal issue;
  • orders, payments, invoices and delivery: normally six years after completion or cancellation, and longer only where tax law, a dispute, fraud investigation or another legal duty requires it;
  • order-linked artwork and support: for the order period where needed to reproduce it, resolve quality issues or defend a claim. You can delete unneeded library items or ask us to remove them, but this may prevent a reorder;
  • marketing: until you unsubscribe, withdraw consent or we decide the record is no longer useful, while keeping the minimal suppression evidence needed to honour an opt-out;
  • reviews: while the review remains published or relevant, with customer email, order linkage and moderation records kept only as needed to verify and manage it; and
  • technical and security records: for a period proportionate to their sensitivity and the time needed to investigate errors, abuse, chargebacks or security incidents.

When a retention period ends, we delete or anonymise the data. Copies may remain for a limited additional period in protected backups and are overwritten on the applicable backup cycle rather than restored to ordinary use. We may preserve specific records if a legal hold or active claim requires it.

13. How we protect data

We use proportionate technical and organisational measures designed to protect personal data, including encrypted transport, restricted administrative access, protected authentication cookies, access checks, logging, backups and controls around production and support systems. Payment card entry is hosted by Stripe so full card credentials do not pass through our application servers.

No internet service is completely secure. Keep your password and review or account links private, sign out on shared devices and tell us promptly if you suspect unauthorised access. If a personal-data breach creates a legal notification duty, we will notify the ICO and affected people as required.

14. Your data protection rights

Depending on the use and lawful basis, you may have the right to:

  • ask whether we use your personal data and receive a copy of it;
  • correct inaccurate data or complete incomplete data;
  • ask us to delete data in certain circumstances;
  • ask us to restrict how data is used in certain circumstances;
  • receive data you provided in a structured, commonly used, machine-readable format, or have it transferred where technically feasible, when portability applies;
  • object to processing based on legitimate interests;
  • withdraw consent at any time, without affecting processing already carried out lawfully; and
  • ask for safeguards and human intervention where a significant decision is made solely by automated means.

Your right to object

You can object at any time to our use of personal data for direct marketing, including related profiling, and we will stop using it for that purpose. You can also object to another use based on legitimate interests; we will stop unless we demonstrate compelling legitimate grounds or need the data for legal claims.

We do not ourselves use personal data to make solely automated decisions that have legal or similarly significant effects. Stripe or another payment provider may independently use automated fraud checks that can affect whether it authorises a payment. Contact that provider or us if you want the outcome explained or reviewed.

To exercise a right, email support@speedshirt.uk. Tell us the right you wish to exercise and provide enough detail to find the records. We may ask for proportionate proof of identity and clarification. We normally respond without charge and within one month after we have the information needed to handle the request. Rights are not absolute, and if an exemption or another person's rights limit the response, we will explain that unless the law prevents us.

15. Children

SpeedShirt is not directed to children and a person must be at least 18 to place an order under our Terms. We do not knowingly create customer accounts for children. If you believe a child has provided personal data without appropriate authority, contact us so we can investigate and delete it where required. A customer must take particular care before including a child's image or data in artwork or a public review.

16. Questions and complaints

Send a privacy question, rights request or data-protection complaint to support@speedshirt.uk, or use our contact form and choose the most relevant category. Put Privacy complaint in the subject line. We will acknowledge it, investigate it and tell you the outcome without undue delay.

You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority. The ICO asks people to raise the issue with the organisation first where possible. You can find current contact details and the complaint process at ico.org.uk.

17. Changes to this notice

We may update this notice when our products, providers or legal obligations change. We will post the revised version here and change the date above. If a change materially affects how we use existing data, we will provide an additional notice or seek consent where the law requires it. Please check this page periodically.