GDPR

eCommerce Assist

ecommerceassist.co.uk

Last updated: April 2026

1. Who We Are

eCommerce Assist is a sole-trader e-commerce virtual assistance business based in Hove, East Sussex, UK. We provide operational, administrative, and creative support to e-commerce founders and entrepreneurs.

For the purposes of UK GDPR and the Data Protection Act 2018, the data controller is:

eCommerce Assist

Hove, East Sussex, BN3, United Kingdom

Email: hello@ecommerceassist.co.uk

Website: https://ecommerceassist.co.uk


As a small business without a statutory requirement to appoint a Data Protection Officer (DPO), any data protection queries should be directed to the email address above.

2. What This Policy Covers

This policy explains how we collect, use, store, and protect personal data when you:

  • visit our website at ecommerceassist.co.uk

  • sign up to our mailing list or newsletter

  • book a discovery call or consultation

  • engage us as a client for virtual assistant services

  • get in touch via email or any other channel

It does not cover third-party websites we may link to. Those sites have their own privacy policies, and we encourage you to read them.

3. What Personal Data We Collect

3.1 Website Visitors

When you visit our website, we automatically collect limited technical data via cookies and analytics tools, including:

  • IP address (anonymised where possible)

  • Browser type and version

  • Pages visited and time spent on site

  • Referring website

  • Device type

This is collected via Google Analytics (GA4) and Google Tag Manager. See Section 8 for more on cookies.

3.2 Newsletter / Mailing List

If you sign up to receive updates or communications from us, we collect:

  • Your email address

  • Your first name (if provided)

Emails are sent directly from our Hostinger-hosted business email account. We do not use a third-party email marketing platform.

3.3 Enquiries and Bookings

When you contact us or book a call, we collect:

  • Name

  • Email address

  • Business name

  • Any information you voluntarily share about your e-commerce store or needs

Calls are booked via TidyCal. Please refer to TidyCal's own privacy policy for how they handle your data during the booking process.

3.4 Clients

During the course of providing services, we may collect and process additional personal data, including:

  • Contact details (name, email, phone number)

  • Business and financial information relevant to your store

  • Login credentials or access to tools (e.g. Shopify, Trello, email platforms) stored securely and never shared

  • Communications between us (emails, messages)

  • Any personal data contained within your customer, product, or order data that we access on your behalf

The scope of data we access as your VA is limited to what is necessary to carry out the agreed work. Where you grant us access to your business systems, you remain the data controller for your customers' data. We act as a data processor on your behalf.

4. Our Lawful Basis for Processing

Under UK GDPR, we rely on the following lawful bases for processing personal data:

  • Contract: to fulfil our obligations as your VA and deliver the services you have engaged us for

  • Legitimate interests: to send relevant business communications, improve our services, and manage our business operations, balanced against your rights

  • Consent: where you have signed up to our mailing list or opted in to marketing communications

  • Legal obligation: to comply with applicable laws (e.g. tax and accounting records)

5. How We Use Your Data

We use the personal data we collect to:

  • Deliver the virtual assistant services you have contracted us for

  • Respond to enquiries and book discovery calls

  • Send newsletters or business updates (only where you have consented)

  • Improve and maintain our website

  • Fulfil any legal or contractual obligations

  • Manage invoicing, payments, and bookkeeping

We do not use your data for automated decision-making or profiling.

6. Who We Share Your Data With

We do not sell, rent, or trade your personal data. We may share limited data with trusted third-party service providers where necessary to operate our business:

  • Google (Analytics, Tag Manager) website analytics

  • TidyCal - booking management

  • Hostinger - email hosting for business communications and client contact

  • Trello / Notion / project management tools - client task management

  • Accounting software - invoicing and financial records

All third parties we work with are required to handle your data in compliance with applicable data protection law. Where these providers are based outside the UK, we ensure appropriate safeguards are in place (e.g. Standard Contractual Clauses or adequacy decisions).

7. How Long We Keep Your Data

We only retain personal data for as long as necessary for the purposes it was collected:

  • Client data: retained for 6 years after the end of the contract, in line with UK tax and accounting obligations

  • Enquiry data: retained for up to 12 months if no contract follows

  • Mailing list data: retained until you unsubscribe

  • Website analytics data: subject to Google Analytics retention settings (typically 14 months)

Once data is no longer needed, we delete or anonymise it securely.

8. Cookies

Our website uses cookies to help it function and to understand how visitors use the site. Cookies are small text files stored on your device.

We use the following types of cookies:

  • Essential cookies: required for the website to function correctly

  • Analytics cookies: Google Analytics and Google Tag Manager, used to understand visitor behaviour in aggregate (IP anonymisation is enabled where possible)

You can control cookies through your browser settings. Disabling analytics cookies will not affect your ability to use the site. For more detail on Google's data practices, visit policies.google.com.

9. Data Security

We take reasonable technical and organisational measures to protect your personal data from unauthorised access, loss, or misuse. These include:

  • Secure email and communications

  • Password management and access controls for all business tools

  • Cyber insurance through Hiscox

Where we are granted access to your business systems, credentials are stored securely and access is revoked at the end of our engagement. No security measures are completely infallible, but we take our responsibilities seriously.

10. Your Rights Under UK GDPR

You have the following rights in relation to your personal data:

  • Right of access: you can request a copy of the personal data we hold about you

  • Right to rectification: you can ask us to correct inaccurate or incomplete data

  • Right to erasure: you can ask us to delete your data in certain circumstances

  • Right to restrict processing: you can ask us to limit how we use your data

  • Right to data portability: you can request your data in a portable format

  • Right to object: you can object to processing based on legitimate interests or for direct marketing

  • Rights related to automated decision-making: we do not carry out automated decision-making or profiling

To exercise any of these rights, contact us at hello@alewk.club. We will respond within one month. We may need to verify your identity before fulfilling a request.

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

ico.org.uk | 0303 123 1113

11. Third-Party Links

Our website may contain links to other websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies independently.

12. Children's Privacy

Our services are not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately and we will delete it.

13. Changes to This Policy

We may update this privacy policy from time to time. When we do, we will update the 'Last updated' date at the top of this page. We encourage you to review this policy periodically. Continued use of our website or services after changes constitutes acceptance of the updated policy.

Significant changes will be communicated to existing clients directly where relevant.

14. Contact Us

If you have any questions, concerns, or requests relating to this privacy policy or how we handle your personal data, please get in touch:

eCommerce Assist

Email: hello@ecommerceassist.co.uk

Website: https://ecommerceassist.co.uk

Location: Hove, East Sussex, UK

We aim to respond to all data protection queries within 5 business days.