Privacy Policy

Privacy Policy

Last updated: February 2026

TwentyTwo Scents ("we", "us", or "our") operates twentytwoscents.com. This page outlines our Privacy Policy and informs you about the policies related to collecting, using, and disclosing personal data when you use our service. It also explains your choices concerning your data.

Information We Collect

Personal Data
While using our service, we may ask you to provide specific personally identifiable information. This information helps us contact or identify you. It may include, but is not limited to:

  • Email address
  • First name and last name
  • Phone number
  • Address, postcode, city
  • Cookies and usage data

Usage Data
We might also gather information on how you access and use the service. This includes details such as your computer's Internet Protocol address (IP address), browser type and version, the pages you visit on our service, the time and date of your visit, and the time spent on those pages. We also collect other diagnostic data.

How We Use Your Information

The data we collect serves several purposes:

  • To provide and maintain our service
  • To notify you about changes to our service
  • To offer customer support
  • To gather analysis and valuable information so we can improve our service
  • To monitor service usage
  • To detect, prevent, and address technical issues
  • To fulfill orders and process payments
  • To send you marketing communications (with your consent)

Legal Basis for Processing (UK GDPR)

We process your personal data based on the following legal bases:

  • Contract: Processing is necessary to fulfill our contract with you (e.g., processing your order)
  • Consent: You have given consent for specific uses (e.g., marketing emails)
  • Legitimate Interests: Processing is necessary for our legitimate interests (e.g., fraud prevention, improving our service)
  • Legal Obligation: Processing is necessary to comply with legal obligations

Your Data Protection Rights (UK GDPR)

Under UK data protection law, you have these rights:

  • Right to Access: You can request copies of your personal data
  • Right to Rectification: You can ask for correction of inaccurate or incomplete data
  • Right to Erasure: You can request deletion of your personal data
  • Right to Restrict Processing: You can request that we restrict processing of your data
  • Right to Data Portability: You can request transfer of your data to another organization
  • Right to Object: You can object to our processing of your personal data
  • Right to Withdraw Consent: Where we rely on consent, you may withdraw it at any time

To exercise these rights, please contact us using the details below.

Data Retention

We will retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy. We use and keep your data to comply with legal obligations. For example, we may need to retain data to comply with applicable laws, resolve disputes, and enforce our legal agreements and policies.

Order information is usually retained for 7 years to comply with UK tax and accounting rules.

Data Security

The security of your data is important to us. We use commercially acceptable methods to protect your personal data. This includes encryption and secure servers. However, no method of transmission over the Internet or electronic storage is 100% secure, so we cannot guarantee absolute security.

Cookies

We use cookies and similar tracking tools to monitor activity on our service and store certain information. Cookies are files with small amounts of data. These may include anonymous unique identifiers.

Types of cookies we use:

  • Essential Cookies: Necessary for website functions like shopping cart and checkout
  • Analytics Cookies: Help us understand visitors’ usage of our website
  • Marketing Cookies: Used to deliver relevant ads (with your consent where needed)

You can set your browser to refuse all cookies or notify when cookies are sent. But if you reject cookies, some parts of our service may be unavailable.

Third-Party Service Providers

Our store operates on Shopify Inc. Shopify provides an e-commerce platform allowing us to sell fragrance samples to you. Your data is stored using Shopify’s data storage, databases, and general application. Your data might be transferred to and stored on servers outside the UK, including Canada and the United States.

We may also use other third-party companies and people to support our service, provide the service, manage payment processing, email delivery, analytics, or help analyze how the service is used. These third parties have access to your personal data only to perform these tasks and must not disclose or use your data for other reasons.

For more about how Shopify handles your personal data, see Shopify’s Privacy Policy: https://www.shopify.com/legal/privacy

Complaints

If you think we misused your personal data in breach of UK data protection laws, you can lodge a complaint with the Information Commissioner's Office (ICO). Contact the ICO at:

  • Website: https://ico.org.uk
  • Phone: 0303 123 1113
  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us.