CUFF Privacy Policy
Legal

Privacy Policy

Effective 21 August 2026 · Last updated 21 August 2026

We sell wrist bands, not data. This policy sets out what Cuff (“Cuff”, “we”, “us”) collects when you shop with us, why we hold it, who else sees it, and how you get it back or get it deleted.

Scope

This policy covers this website and the orders placed through it. It does not cover any other company's site or service you reach from here, including the manufacturer of whatever tracker you fit our band to — those have their own policies, and we have no control over them.

Where the law calls for it, Cuff is the controller of the personal data described below.

What we collect

Order details
Your name, delivery and billing address, email address, phone number where you give one, and what you bought. We need these to fulfil an order and cannot complete one without them.
Payment information
Handled by our payment processor. We receive confirmation that a payment succeeded, the payment method type, and the last four digits of the card. We never receive or store your full card number, expiry date, or security code.
Correspondence
Emails you send us, including any photographs attached to a damage claim, and our replies.
Technical data
IP address, browser and device type, referring page, and the pages you viewed here. This arrives automatically in server logs and analytics whenever any site is loaded.
Marketing preferences
If you subscribe to email updates, your address and whether you have opened or unsubscribed.

We do not ask for, and do not want, special-category data: no health information, no biometric data, and nothing read from a fitness tracker. Our products are fabric — they measure nothing and transmit nothing.

Cookies and browser storage

Your cart is kept in your own browser's local storage under the key cuff.cart.v1, which is how it is still there when you close the tab and come back. It records only which band variants you chose and how many of each; it holds no name, address, or payment detail, it is not sent to our servers, and it is discarded automatically 30 days after your last visit. Clearing your browser's site data for this domain removes it immediately.

Beyond that we use cookies that are strictly necessary to run the site and complete checkout, and, where you have agreed to them, analytics cookies that tell us which pages people find useful. You can block or delete cookies in your browser settings; the strictly necessary ones cannot be turned off without breaking checkout.

Why we use it

  • To take payment for an order, dispatch it, and keep you updated on where it is.
  • To answer support enquiries and assess refund claims for damaged goods.
  • To keep records we are required by tax and accounting law to hold.
  • To detect and prevent fraud, chargeback abuse, and misuse of the site.
  • To understand, in aggregate, how the site is used so we can improve it.
  • To send marketing email, only if you asked for it, and only until you tell us to stop.

We do not use your data for automated decision-making that produces legal effects for you.

Legal bases

Where the UK GDPR or EU GDPR applies, we rely on:

  • Contract — to process and deliver the order you placed.
  • Legal obligation — to keep transaction and tax records.
  • Legitimate interests — to secure the site, prevent fraud, and improve what we sell, balanced against your interests.
  • Consent — for marketing email and for non-essential analytics cookies. You can withdraw consent at any time.

Who we share it with

We share the minimum necessary with service providers who act on our instructions:

  • our payment processor, to take payment and handle chargebacks;
  • delivery carriers, who receive the name, address, and contact details needed to deliver a parcel;
  • our fulfilment, email, hosting, and analytics providers;
  • our accountants and, if we ever need them, our lawyers.

We also disclose data where we are legally required to, and to a buyer or successor if the business is sold — in which case this policy continues to apply to data transferred with it.

We do not sell your data

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act and similar laws. We have not done so in the past twelve months.

International transfers

Some of our providers operate outside your country. Where personal data leaves the UK or the EEA, we rely on an adequacy decision or on standard contractual clauses, together with appropriate technical safeguards. You can ask us for details of the mechanism used for a particular transfer.

How long we keep it

Order records
For 6 years after the order, as tax and accounting law requires.
Support correspondence
For 2 years after the enquiry is closed.
Marketing list
Until you unsubscribe, plus a suppression record so we do not email you again by mistake.
Analytics
In aggregated or de-identified form, on the retention schedule of our analytics provider.
Saved cart
30 days in your own browser. Never stored on our servers.

Your rights

Depending on where you live, you may have the right to:

  • ask for a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • have data deleted, where we have no continuing obligation to keep it;
  • object to or restrict certain processing;
  • receive your data in a portable format;
  • withdraw consent to marketing at any time, using the unsubscribe link in any email or by writing to us; and
  • not be discriminated against for exercising any of these rights.

Write to support@wearcuff.com and we will respond within 30 days. We may need to verify your identity first — usually by confirming details of an order. If you are unhappy with our answer, you can complain to your data protection regulator; in the UK that is the Information Commissioner's Office.

Security

The site is served over HTTPS, payment details go directly to our processor, and access to order data is limited to the people who need it to do their job. No system is perfectly secure, but if a breach ever affects your personal data we will notify you and the relevant regulator as the law requires.

Children

This site is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us their details, contact us and we will delete them.

Changes to this policy

We update this policy when what we do with data changes. The “last updated” date at the top always reflects the current version, and material changes will be flagged on this page before they take effect.

How to reach us

Cuff — support@wearcuff.com

Email us for anything, including privacy requests. We answer every message ourselves.