Last updated: 13 August 2026
This privacy notice is written for the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (“PECR”) and relevant amendments made by the Data (Use and Access) Act 2025.
It covers the Website, customer accounts, design and gangsheet tools, custom printing, purchases, deliveries, support, reviews and emails. It does not replace the privacy notice of an independent service you choose to use, such as Stripe, Google or Canva.
Your artwork stays yours
We use uploaded artwork to operate the design tools, prepare and make your products, provide support and meet legal or security requirements.
Payments are handled by Stripe
Payment details are entered into Stripe's secure payment tools. We do not receive or store your full card number or card security code.
We do not sell personal data
We do not sell or rent personal data, or share it with third parties for their own unrelated targeted advertising.
You have choices
You can unsubscribe from marketing, disconnect optional integrations and ask to access, correct or delete personal data, subject to legal limits.
1. Who we are and when this notice applies
“SpeedShirt”, “we”, “us” and “our” mean the seller identified on your order confirmation or VAT invoice, trading as SpeedShirt. That seller is the controller responsible for the personal data described in this notice. Our Website is speedshirt.uk and our privacy contact is support@speedshirt.uk.
If you buy for a company, give us another person's delivery details, include an identifiable person in artwork or submit content about somebody else, you must have a lawful reason to provide that data and should make this notice available to them where appropriate.
2. Personal data we collect
Depending on how you use SpeedShirt, we may collect:
- identity and contact data, including your name, email address, telephone number, delivery and billing addresses and business details;
- account data, including customer ID, sign-in and verification records, password-reset records, saved addresses, preferences and account history. Passwords are handled in protected form; we never receive your Google password;
- order and transaction data, including products, quantities, dimensions, customisation instructions, prices, discounts, VAT, payment status and identifiers, refunds, invoices, delivery method, tracking and order history;
- artwork and design data, including uploaded files, photographs, logos, text, filenames, dimensions, previews, layouts, gangsheets, cut settings, processed image versions and saved designs;
- communications, including support tickets, emails, messages, cancellation or complaint details and attachments;
- review data, including ratings, written feedback, optional answers, recommendation choices and photos;
- marketing data, including newsletter status, the source and time of a sign-up, consent or soft-opt-in records, unsubscribe and suppression status, and email delivery, open and click information where used;
- technical and security data, including IP address, approximate country derived by our network provider, browser and device information, user agent, timestamps, request and error logs, security events and session, cart or integration identifiers; and
- optional integration data, such as the name and email returned by Google sign-in, or Canva authorisation tokens, design titles, thumbnails and other information you permit Canva to provide.
We do not ask for special category data, such as health, biometric, religious or political data, in normal use. Please do not include it in artwork, reviews, messages or attachments unless it is genuinely necessary and you have first contacted us.
3. Where the data comes from
We collect personal data:
- directly from you when you browse, register, upload, design, order, review, subscribe or contact us;
- automatically from your browser or device, our servers and the networks used to deliver the Website;
- from services you choose to connect, including Google sign-in and Canva;
- from payment providers, delivery carriers and suppliers, for example payment status, fraud signals, delivery events or returned parcels;
- from a person or organisation ordering on your behalf or sending an order to you; and
- from professional advisers, regulators, law-enforcement bodies or rights holders where a dispute, legal duty or credible complaint requires it.
4. How and why we use personal data
UK data protection law requires a lawful basis for each use. More than one basis can apply where the purposes are different.
| Purpose | Data normally used | Lawful basis |
|---|---|---|
| Create and secure accounts, sessions, carts and saved designs | Identity, contact, account, design and technical data | Contract or steps before a contract; legitimate interests in providing a secure service |
| Quote, take payment, produce, fulfil, deliver and administer orders | Identity, contact, transaction, artwork and technical data | Contract; legal obligations for tax, accounting and consumer law |
| Provide design, image-enhancement and Canva features | Artwork, integration and technical data | Contract or steps you request before a contract; legitimate interests in improving production quality |
| Handle support, returns, cancellations, complaints and rights claims | Identity, contact, order, communications and artwork data | Contract; legal obligations; legitimate interests in resolving issues and defending claims |
| Prevent fraud, abuse and security incidents | Account, transaction and technical data | Legitimate interests in protecting customers and our service; legal obligations where applicable |
| Send operational emails and eligible review requests | Identity, contact, order and message interaction data | Contract and legitimate interests, subject to PECR; consent where PECR requires it |
| Send newsletters, offers and product news | Identity, contact, marketing and order data | Consent, or legitimate interests where the PECR existing-customer soft opt-in lawfully applies |
| Publish and moderate customer reviews | Review, identity, order and technical data | Legitimate interests in genuine customer feedback; consent for optional review photos where required |
| Operate, troubleshoot and improve the Website and understand campaign results | Technical, transaction and marketing-attribution data | Legitimate interests; consent or a PECR exception for device storage or access, as applicable |
Our legitimate interests include operating a reliable ecommerce and custom-production service, improving print and support workflows, measuring communications, securing accounts, preventing fraud, recovering debts and establishing or defending legal claims. We balance those interests against your rights and reasonable expectations.
We need the details marked as required at account creation or checkout to provide the account or order. If you do not provide them, we may be unable to register you, take payment, make the products or deliver them. Newsletter sign-up, Canva connection, Google sign-in, reviews and review photos are optional.
5. Artwork and image processing
Uploaded artwork is Customer Content under our Terms of Service. We process it to display previews, save designs and layouts, run requested or offered preparation tools, produce print-ready files, manufacture products, support reorders, investigate quality issues, keep operational backups and protect the service.
Image tools such as upscaling, sharpening, background removal, logo clean-up or vectorisation may run on our production systems or through a specialist cloud image-processing provider, including Replicate when it is the configured provider or fallback. This can involve sending the image, an asset URL and limited job metadata to that provider and receiving the processed result. Review every processed image before ordering.
Artwork and previews must be available to the systems that render and manufacture your products and may be delivered through content-delivery URLs. Do not upload confidential records, identity documents, payment details or unnecessary personal data as artwork. Where artwork depicts another person, you are responsible for having permission to use their image and for respecting their privacy rights.
6. Payments, orders and delivery
Stripe provides our checkout and processes card or wallet details. Stripe may collect payment details, billing information, device information and fraud-prevention signals directly. We normally receive the payment result, payment-intent or transaction identifier, method type and limited method details such as card brand and last four digits, rather than full card credentials. Stripe also processes data under its own privacy policy.
We give the delivery details and contact information needed to fulfil the order to relevant production partners, suppliers and carriers. Our tracked UK carriers may include Royal Mail and DPD. A carrier may contact you about delivery and will handle that information under its own privacy responsibilities.
7. Marketing and service messages
We send service messages needed for accounts and orders, such as verification, password reset, payment, order, production, dispatch, support and safety messages. These are not promotional, so an unsubscribe from marketing does not stop them.
If you subscribe, we may send promo codes, restock notices, product news and practical printing content. We may also market similar SpeedShirt products to an existing customer only where the PECR soft opt-in requirements are met, including giving an opt-out when the details are collected and in every message. Otherwise, we ask for consent. You can unsubscribe using the link in an email or by contacting us. We keep a minimal suppression record so that we do not add the address back accidentally.
Our emails may contain identifiers that record delivery, opens and link clicks, and tagged links may connect a campaign to a later cart or order. We use this to understand whether communications work and to manage suppression. You can block remote images in your email app, avoid tagged links, unsubscribe or object to this processing.
8. Reviews and public content
After an order, we may send an eligible review invitation subject to your marketing and suppression choices. A review request link can contain your name, email, order number, products and a secure token and will expire. Opening it can record that the request was opened.
Submitted reviews are checked before publication. If approved, the Website may publicly show the rating, title, review, optional answers, recommendation, photos, product details, review date and a shortened display name such as your first name and surname initial. It does not publish your email or full order details. Public review text and photos can be copied by others, so remove personal information from them before submission and make sure everyone shown in a photo agrees to publication. Contact us to ask for a review to be corrected, anonymised or removed.
11. International transfers
We are UK-based, but some technology providers, support teams or infrastructure may process data outside the UK, including in the United States. The privacy laws in another country may differ from UK law.
Where UK transfer rules apply, we use a permitted safeguard appropriate to the recipient and transfer. This may be a UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, another legally recognised safeguard or, in limited cases, a statutory exception. We carry out the assessment required for the safeguard used. Contact us for more information about a relevant safeguard; confidential commercial terms may be redacted.
12. How long we keep data
We keep personal data only for the period needed for the stated purpose, including providing reorders, meeting tax and accounting duties, resolving complaints, preventing fraud and establishing or defending legal claims. Typical periods and criteria are:
- anonymous work: an anonymous session normally expires after 30 days; uploads, designs and gangsheets not linked to an account or order are then eligible for deletion;
- accounts and saved designs: while the account remains open or until you delete the item, followed by the limited period needed for closure, security, backups or a legal issue;
- orders, payments, invoices and delivery: normally six years after completion or cancellation, and longer only where tax law, a dispute, fraud investigation or another legal duty requires it;
- order-linked artwork and support: for the order period where needed to reproduce it, resolve quality issues or defend a claim. You can delete unneeded library items or ask us to remove them, but this may prevent a reorder;
- marketing: until you unsubscribe, withdraw consent or we decide the record is no longer useful, while keeping the minimal suppression evidence needed to honour an opt-out;
- reviews: while the review remains published or relevant, with customer email, order linkage and moderation records kept only as needed to verify and manage it; and
- technical and security records: for a period proportionate to their sensitivity and the time needed to investigate errors, abuse, chargebacks or security incidents.
When a retention period ends, we delete or anonymise the data. Copies may remain for a limited additional period in protected backups and are overwritten on the applicable backup cycle rather than restored to ordinary use. We may preserve specific records if a legal hold or active claim requires it.
13. How we protect data
We use proportionate technical and organisational measures designed to protect personal data, including encrypted transport, restricted administrative access, protected authentication cookies, access checks, logging, backups and controls around production and support systems. Payment card entry is hosted by Stripe so full card credentials do not pass through our application servers.
No internet service is completely secure. Keep your password and review or account links private, sign out on shared devices and tell us promptly if you suspect unauthorised access. If a personal-data breach creates a legal notification duty, we will notify the ICO and affected people as required.
14. Your data protection rights
Depending on the use and lawful basis, you may have the right to:
- ask whether we use your personal data and receive a copy of it;
- correct inaccurate data or complete incomplete data;
- ask us to delete data in certain circumstances;
- ask us to restrict how data is used in certain circumstances;
- receive data you provided in a structured, commonly used, machine-readable format, or have it transferred where technically feasible, when portability applies;
- object to processing based on legitimate interests;
- withdraw consent at any time, without affecting processing already carried out lawfully; and
- ask for safeguards and human intervention where a significant decision is made solely by automated means.
Your right to object
You can object at any time to our use of personal data for direct marketing, including related profiling, and we will stop using it for that purpose. You can also object to another use based on legitimate interests; we will stop unless we demonstrate compelling legitimate grounds or need the data for legal claims.
We do not ourselves use personal data to make solely automated decisions that have legal or similarly significant effects. Stripe or another payment provider may independently use automated fraud checks that can affect whether it authorises a payment. Contact that provider or us if you want the outcome explained or reviewed.
To exercise a right, email support@speedshirt.uk. Tell us the right you wish to exercise and provide enough detail to find the records. We may ask for proportionate proof of identity and clarification. We normally respond without charge and within one month after we have the information needed to handle the request. Rights are not absolute, and if an exemption or another person's rights limit the response, we will explain that unless the law prevents us.
15. Children
SpeedShirt is not directed to children and a person must be at least 18 to place an order under our Terms. We do not knowingly create customer accounts for children. If you believe a child has provided personal data without appropriate authority, contact us so we can investigate and delete it where required. A customer must take particular care before including a child's image or data in artwork or a public review.
16. Questions and complaints
Send a privacy question, rights request or data-protection complaint to support@speedshirt.uk, or use our contact form and choose the most relevant category. Put Privacy complaint in the subject line. We will acknowledge it, investigate it and tell you the outcome without undue delay.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority. The ICO asks people to raise the issue with the organisation first where possible. You can find current contact details and the complaint process at ico.org.uk.
17. Changes to this notice
We may update this notice when our products, providers or legal obligations change. We will post the revised version here and change the date above. If a change materially affects how we use existing data, we will provide an additional notice or seek consent where the law requires it. Please check this page periodically.