Privacy policy
Last updated
This is the privacy policy for HJEM, the home store selling antique, reclaimed and vintage furniture at hjem.uk and at markets and pop-ups. It explains what personal information we collect when you shop with us or join our list, how we use it, and the rights you have over it. We only collect what we need to run the shop, and we never sell your data.
Who we are
HJEM (“we”, “us”) sells one-of-one antique and reclaimed furniture online and at markets and pop-ups, delivered across the UK. We are the data controller for the information described here.
HJEM is the trading name of HJEM LTD, a company registered in England and Wales.
Our registered office is 50 Hart Plain Avenue, Waterlooville, PO8 8RX.
For any privacy question, or to exercise any of the rights below, email hello@hjem.uk or call 07548 220 217.
What we collect
- When you order: your name, email, phone number and delivery address, and any gift note you add. Payment is handled by Stripe on their secure pages, so we never see or store your card details.
- When you join our list: your email address.
- When you contact us: whatever you choose to include in your message, whether that comes by email, phone or WhatsApp.
- When something breaks: if a page fails in your browser, it sends us a short fault report. It’s the one thing here you don’t choose to send, so it has its own section below.
How we use it
- To take payment, fulfil your order and arrange delivery.
- To send you order and delivery updates.
- To send occasional news about new pieces, only if you have asked us to.
- To answer your questions and keep records we’re legally required to keep.
- To find and fix faults on the site, from the reports described below.
Our legal bases are performing our contract with you (orders), your consent (the newsletter, which you can withdraw at any time), our legal obligation to keep accounting records of what we have sold, and our legitimate interest in running and improving a small shop, which is what covers keeping the site working.
Who we share it with
We use a small number of trusted providers who process data on our behalf: Stripe (payments), Supabase (our database, file storage and the sign-in behind our own admin pages), Vercel (website hosting), Resend (order and delivery email) and Google Workspace, which runs our mailbox, so anything you write to us is stored there. Our own team signs in to the admin area with a Google account, so Google handles that sign-in too. If you message us on WhatsApp, Meta carries and stores that conversation under its own terms as well as ours, which is worth knowing before you send anything sensitive that way. We share delivery details with the courier arranged for your piece. We do not sell or rent your information to anyone.
Where your information goes
Some of those providers are based outside the UK, or store and process data outside it: Stripe, Supabase, Vercel, Resend, Google and Meta all operate internationally, so your information may be handled in the United States or elsewhere. Where that happens the transfer relies on the safeguards UK law recognises, which for these providers means either a country covered by UK adequacy regulations or, more usually, the standard contractual clauses with the UK addendum, or the International Data Transfer Agreement, built into their published terms. We rely on those published terms rather than negotiating our own, and we’d rather say that plainly than claim more than a shop our size does. Ask us and we’ll point you at the relevant provider’s terms.
Cookies and tracking
We keep the site deliberately lightweight. We don’t use advertising or analytics trackers, there are no third-party marketing cookies, and nothing here follows you to other sites. Two things do get stored on your own device while you shop, and both are there because the shop can’t do its job without them:
- Your basket, kept in your browser’s own local storage so it survives a refresh. It stays on your device and is never sent to us as a cookie. Clearing your browser data empties it.
- A checkout cookie, named hjem_checkout_session, which we set on your browser the moment you click through to pay. It’s how the thank-you page knows that the browser coming back from Stripe is the same one that started the checkout, so a shared or forwarded link can’t show your order to somebody else. It lasts an hour, it’s only sent back to that one page, and no script can read it. It holds a Stripe checkout reference and a signature, nothing about you.
Both are strictly necessary for something you asked us to do, so under the privacy rules on cookies neither one needs your consent, and there’s nothing here to opt into or out of. We set one other cookie, the sign-in cookie for our own private admin pages, which only reaches us. The short strip of pieces you’ve recently looked at is not stored at all: it’s held in your browser’s memory for the current visit and is gone the moment you reload the page or close the tab.
When something breaks on the site
If a page or a button fails in your browser, your browser sends us a short fault report so that we find out rather than waiting for someone to tell us. That report holds the error message, which file of our own code it came from, the path of the page you were on, and your browser’s user-agent string, which is the line saying which browser and operating system you’re using. It deliberately leaves out anything after the “?” in the address, so a token in a link, or anything you typed, isn’t in it. Our hosting, Vercel, also records the internet address the report arrived from, as it does for every request to any website.
We use these only to fix faults. There’s no identifier in them, we don’t build a profile from them, we don’t count visits with them, and nothing is stored on your device to make them work. Each open tab may send at most five a minute, which stops a page stuck in a loop from flooding us without silently dropping a fault that happens later in a long visit, so a tab left open for hours can send more than five in total. They land in our host’s logs, which are kept for a short retention window (about an hour on our current plan) and then discarded. Our lawful basis is our legitimate interest in a shop whose checkout works.
How long we keep it
- Orders: six years from the end of the financial year the order falls in. An order is an accounting record and HMRC requires us to keep those, so this is one thing we can’t delete on request. It covers your name, email, phone number, delivery address, the pieces and the amount paid.
- Gift notes: a gift note is free text you write at checkout, and it often names somebody else. We use it for one thing, which is writing the card or passing the message on with the piece. It’s written into the order record, so it currently sits there for the same six years, and we’d honestly rather it didn’t: HMRC needs the sale, not the message. So keep it short, and leave out anything private about the person receiving the piece. And if a note holds something that shouldn’t sit with us that long, email us and we’ll take the note out of the record by hand. The order stays; the note goes.
- Newsletter: your email address stays on the list until you unsubscribe. After that we keep a record that you unsubscribed, so a later signup can’t quietly put you back on the list: putting someone back on is a deliberate act, and the form on the site won’t do it. If you’ve unsubscribed and want to come back, email us and we’ll add you again. Ask us instead and we’ll erase the record of your unsubscribe altogether.
- Emails and messages: kept while they’re useful to the question or the order they relate to. Anything attached to an order sits with the six-year order record; everything else we clear out once the conversation is done.
Your rights
Under UK data protection law you can ask us for a copy of the personal information we hold about you, ask us to correct it if it’s wrong, ask us to delete it, ask us to restrict what we do with it, or object to certain uses. You can also ask for portability: a copy of the information you gave us in a common, machine-readable format, or sent straight to another provider where that’s technically possible.
Deletion has one honest limit, and we’d rather set it out than promise more than we can do. Where the law requires us to keep something, we have to keep it. Order and payment records are accounting records, so for the six years described above we can’t erase them on request, and our admin tools deliberately have no way to delete an order at all. What we will do in that case is stop using the record for anything but that legal purpose, and delete it when the period ends. Everything outside that, including your newsletter entry and our correspondence with you, we can and will erase when you ask.
You can leave the mailing list at any time by emailing us, and every newsletter we send carries an unsubscribe link. To exercise any of these rights, contact hello@hjem.uk; we’ll respond within a month. If you’re unhappy with how we’ve handled your data you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
Changes to this policy
We may update this policy from time to time; the date at the top shows when it last changed.