Privacy policy

SHIFAH® PRIVACY POLICY

This Privacy Policy explains how SHIFAH Global Ltd, trading as SHIFAH® (“SHIFAH®”, “we”, “us” or “our”), collects, uses, stores, shares and protects personal information when you visit our website, purchase products, create an account, use a subscription service, communicate with us or otherwise interact with our business.

Website: shifah.co
Email: info@sxcglobal.com

For the purposes of applicable UK data-protection legislation, including the UK GDPR and Data Protection Act 2018, SHIFAH Global Ltd is the data controller where we determine the purposes and means of processing your personal information.

Nothing in this Privacy Policy limits any rights you have under applicable data-protection law.

1. PERSONAL INFORMATION WE MAY COLLECT

Depending on how you interact with SHIFAH®, we may collect and process:

Identity and contact information
Your name, billing address, delivery address, email address, telephone number and customer/account identifiers.

Account information
Your account details, account status, preferences, subscription information and relevant account activity.

Order and transaction information
Information relating to purchases, orders, subscriptions, recurring transactions, refunds and other transactions made through our website. This may include your name, contact details, products purchased, order value, transaction status, payment method information made available to us, transaction references, subscription information, fulfilment information and related transaction records.

Payments are processed through payment and ecommerce service providers. We process information made available to us that is reasonably necessary to administer orders, subscriptions, refunds, disputes, fraud prevention and our legal and business obligations.

Subscription information
Subscription enrolment, products subscribed to, frequency, subscription status, renewals, skips, pauses, modifications, cancellation activity and associated timestamps.

Delivery and fulfilment information
Shipping address, courier information, tracking numbers, dispatch information, delivery status, delivery confirmation and information supplied by fulfilment and delivery providers.

Communications
Emails, customer-service enquiries, complaints, return or refund requests, cancellation requests, social-media communications and other correspondence between you and SHIFAH®.

Technical and usage information
This may include IP address, device information, browser, operating system, approximate geographical information, referral source, pages viewed, interactions, timestamps and website activity.

Security and fraud-prevention information
Information generated or made available by our ecommerce, payment, security and fraud-prevention systems relating to transaction risk, account activity, device information, IP information and suspected misuse.

Marketing information
Marketing preferences, consent records and engagement with marketing communications.

2. HOW WE USE PERSONAL INFORMATION

We may process personal information to:

Process, fulfil and deliver orders;
Administer payments, refunds and transactions;
Create and administer customer accounts;
Operate subscription and recurring-purchase services;
Process subscription renewals;
Provide customer support;
Respond to enquiries and complaints;
Administer returns and cancellations;
Send transactional and service communications;
Maintain appropriate transaction and business records;
Investigate delivery disputes;
Detect, prevent and investigate fraud, abuse and unauthorised transactions;
Protect our customers, website, systems and business;
Investigate suspected breaches of our terms and policies;
Establish, exercise or defend legal claims;
Investigate and defend chargebacks and payment disputes;
Provide relevant evidence to payment providers, banks, card networks and other parties involved in resolving payment disputes;
Meet legal, regulatory, accounting and tax obligations;
Analyse and improve our website, services and operations;
Measure the effectiveness of our marketing;
Personalise content and advertising where permitted;
Conduct marketing where legally permitted; and
Maintain the security and integrity of our systems.
3. LAWFUL BASES FOR PROCESSING

We process personal information only where we have an appropriate lawful basis.

Depending on the circumstances, this may include:

Performance of a contract — where processing is necessary to process an order, provide products, administer a subscription, fulfil our contractual obligations or take steps requested before entering into a contract.

Legal obligation — where processing or retention is necessary to comply with legal, regulatory, accounting, tax or other obligations.

Legitimate interests — where processing is reasonably necessary for our legitimate business interests and those interests are not overridden by your applicable rights and freedoms.

Our legitimate interests may include:

Operating and protecting our business;
Maintaining accurate records;
Providing customer service;
Protecting our systems;
Preventing and detecting fraud;
Investigating suspicious activity;
Protecting against misuse;
Establishing the authenticity of transactions;
Investigating complaints and delivery disputes;
Defending chargebacks and payment disputes;
Enforcing our contractual rights;
Establishing, exercising or defending legal claims; and
Improving our products, website and operations.
Consent — where applicable law requires us to obtain your consent, including for certain marketing, advertising, cookies or tracking technologies.

Where processing is based on consent, you may withdraw that consent subject to applicable law.

4. ORDERS AND SUBSCRIPTIONS

When you purchase from SHIFAH® or select a recurring subscription, records may be created relating to your transaction.

These may include:

Date and time of purchase;
Products selected;
One-time or subscription purchase selection;
Subscription frequency;
Subscription price;
Discounts;
Order and renewal history;
Subscription status;
Subscription changes;
Cancellation status and timestamps;
Transaction references;
Relevant customer account activity;
Fulfilment information; and
Delivery information.
We may retain these records where reasonably necessary to administer our contractual relationship, maintain business records, investigate complaints, prevent fraud, comply with legal obligations and establish, exercise or defend legal claims.

5. CHARGEBACKS, PAYMENT DISPUTES AND FRAUD PREVENTION

Where an order, payment, subscription, refund or delivery is disputed, we may process and disclose relevant information to investigate and respond to that dispute.

Relevant evidence may include, where lawfully available:

Order and transaction records;
Subscription enrolment information;
Subscription status and history;
Cancellation records and timestamps;
Customer account activity;
Communications;
IP or device information;
Security or fraud-prevention information;
Website/account activity;
Fulfilment records;
Courier tracking;
Delivery confirmation;
Proof of delivery;
Refund records; and
Customer-facing terms, disclosures and purchasing options applicable at the relevant time.
Relevant information may be provided to payment processors, acquiring or issuing banks, card networks, ecommerce/payment providers, fraud-prevention services, professional advisers, insurers or other parties reasonably involved in investigating or determining a dispute.

A request to erase personal information does not necessarily require us to erase information that we remain lawfully entitled or required to retain, including information necessary to comply with legal obligations or establish, exercise or defend legal claims.

6. DATA RETENTION

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including applicable contractual, legal, accounting, tax, fraud-prevention, security and dispute-resolution purposes.

Different categories of information may therefore have different retention periods.

Order, transaction, invoice, subscription and accounting records may need to be retained for longer periods where reasonably or legally necessary.

Information relating to a complaint, chargeback, suspected fraud, regulatory matter or legal claim may be retained for as long as reasonably necessary to investigate, establish, exercise or defend the relevant rights or claims.

When personal information is no longer reasonably required, it may be securely deleted, anonymised or otherwise disposed of in accordance with our procedures.

7. WHO WE MAY SHARE INFORMATION WITH

We may share personal information where reasonably necessary with organisations supporting our business, including providers involved in:

Ecommerce and website services;
Payment processing;
Subscription management;
Order fulfilment;
Warehousing;
Delivery and courier services;
Customer communications;
IT, hosting and security;
Fraud prevention;
Analytics and performance measurement;
Advertising and marketing;
Customer service;
Accounting, insurance, auditing and professional advice; and
Payment-dispute and chargeback administration.
We may also disclose information to regulators, courts, law-enforcement bodies or other competent authorities where legally required or permitted.

Our service providers and technology stack may change as our business develops.

Where required, appropriate contractual, technical and organisational safeguards will be used.

8. INTERNATIONAL DATA TRANSFERS

Some service providers may process personal information outside the United Kingdom.

Where international transfers are subject to data-protection requirements, we will take appropriate measures required by applicable law to protect the information.

9. SECURITY

We take appropriate technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, accidental loss, destruction or misuse.

No internet transmission or electronic storage system can, however, be guaranteed to be completely secure.

Customers are responsible for maintaining the confidentiality and security of their account credentials.

If you believe your SHIFAH® account has been compromised, please contact us promptly.

10. YOUR DATA-PROTECTION RIGHTS

Depending upon applicable law and the circumstances, you may have rights including:

Access to your personal information;
Correction of inaccurate or incomplete information;
Erasure of personal information;
Restriction of processing;
Objection to certain processing;
Data portability;
Withdrawal of consent where processing relies on consent; and
The right to complain to the Information Commissioner’s Office.
These rights are not absolute and may be subject to legal limitations and exemptions.

For example, we may continue retaining certain information where we have a lawful basis or legal obligation to do so, including where information is reasonably necessary to establish, exercise or defend legal claims.

To exercise an applicable right, contact:

info@sxcglobal.com

We may need to verify your identity before acting upon a request.

11. DIRECT MARKETING

Where legally permitted, SHIFAH® may send communications concerning products, offers, launches, promotions and other marketing.

You may unsubscribe from electronic marketing using the unsubscribe mechanism provided in the communication or by contacting us.

Opting out of marketing does not prevent us from sending necessary transactional, account, security, subscription, order, delivery or customer-service communications.

12. COOKIES, PIXELS AND SIMILAR TECHNOLOGIES

SHIFAH® and service providers acting on our behalf may use cookies, pixels, tags, software development kits and other similar storage, tracking or measurement technologies in connection with our website and services.

The technologies used may change from time to time as our website, ecommerce platform, advertising, analytics, security and other business systems develop.

They may be used for purposes including:

Essential website operation;
Maintaining shopping carts and sessions;
Authentication and account functionality;
Remembering preferences;
Security and fraud prevention;
Analytics and performance measurement;
Understanding website interactions;
Measuring orders and conversions;
Advertising measurement and attribution;
Personalising content or advertising where permitted;
Improving our website and services; and
Supporting integrations with ecommerce, marketing and technology providers.
Some technologies are necessary for our website and services to function.

Other technologies may require consent under applicable law.

Where consent is required, appropriate choices will be provided through our cookie or privacy controls.

You may change or withdraw applicable consent using the controls made available to you.

Browser and device settings may also allow you to block or delete certain technologies. Blocking essential technologies may affect website functionality.

The specific technologies and providers used by SHIFAH® may change as our systems and services develop. Where required by law, further information and appropriate controls will be provided through our website, consent interface or relevant privacy notices.

13. ANALYTICS, ADVERTISING AND MEASUREMENT

Subject to applicable law and consent requirements, we may use analytics, advertising, attribution and measurement services to understand website usage, improve our services, measure marketing effectiveness, identify relevant audiences and understand customer journeys and conversions.

The specific providers and technologies we use may change over time.

Third-party providers may process information in accordance with their applicable privacy notices and contractual arrangements with us.

14. THIRD-PARTY WEBSITES AND SERVICES

Our website may contain links to third-party websites, social-media platforms or other independent services.

Those organisations may process personal information under their own privacy policies.

SHIFAH® is not responsible for the privacy practices of independent third-party websites or services.

15. CHILDREN

Our website and services are not intended to knowingly collect children’s personal information where doing so would be unlawful.

Where we become aware that personal information has been collected contrary to applicable law, we will take appropriate action.

16. ACCURACY OF INFORMATION

Customers should provide accurate and current information when placing orders, creating accounts, managing subscriptions or communicating with us.

Please contact us where personal information we hold about you requires correction.

17. FRAUD AND RISK ASSESSMENT

Our ecommerce, payment, security and fraud-prevention providers may use automated technologies to assess transactions, accounts or activity for fraud, security and payment risk.

This may involve transaction, account, device, IP, behavioural or other relevant information.

Any rights applicable to solely automated decision-making under data-protection law remain unaffected.

18. LEGAL DISCLOSURE

We may preserve, process or disclose personal information where reasonably necessary and legally permitted to:

Comply with applicable law;
Respond to lawful requests;
Cooperate with regulators or competent authorities;
Prevent or investigate fraud or crime;
Protect customers, SHIFAH® or others;
Enforce contractual rights;
Investigate payment disputes; or
Establish, exercise or defend legal claims.
19. BUSINESS TRANSFERS

If SHIFAH Global Ltd undergoes a merger, acquisition, restructuring, financing, sale of assets or similar business transaction, relevant personal information may be disclosed or transferred where reasonably necessary in connection with that transaction and subject to applicable data-protection requirements.

20. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes to our operations, technology, services, legal obligations or processing activities.

The latest version will be published on our website with an updated revision date.

Where required by law, we will provide additional notice or obtain consent in relation to material changes.

21. COMPLAINTS

If you have concerns about how we process your personal information, please contact us so that we have an opportunity to investigate.

You also have the right to complain to the UK’s data-protection regulator, the Information Commissioner’s Office (ICO).

22. CONTACT

SHIFAH®
Operated by SHIFAH Global Ltd
Website: shifah.co
Email: info@sxcglobal.com

For privacy enquiries, data-protection requests or questions concerning this Privacy Policy, please contact us using the email address above.

Suggested Shopify meta description:
Read the SHIFAH® Privacy Policy explaining how we collect, use, protect and retain personal information, cookies, order and subscription data.