Privacy Notice

This privacy notice explains how we collect and use your personal data when you visit our website, get in touch, or place an order with Mercian Cycles Derby Limited.

1. Important information and who we are

This privacy notice explains how Mercian Cycles Derby Limited collects and uses your personal data when you use our website or interact with us, including when you register, sign up to our newsletter, or order a bike or renovation service.

Our website is not intended for children, and we do not knowingly collect data relating to children.

Mercian Cycles Derby Limited is the controller and responsible for your personal data (referred to as “Mercian Cycles”, "we", "us" or "our").

If you have any questions about this notice, including requests to exercise your legal rights (see paragraph 9), please contact us using the details in paragraph 10.

2. The types of personal data we collect about you

We may collect, use, store and transfer the following types of personal data:

Identity Data: name, username or similar identifier

Contact Data: address, email address, telephone numbers

Financial Data: payment card details given by phone or in person (we do not keep card details after payment)

Transaction Data: details of payments and purchases

Technical Data: IP address, login data, browser type and version, time zone, location, browser plug-ins, operating system, platform, device ID and other technology used to access our site

Profile Data: username, password, purchases/orders

Usage Data: information about how you use our website

Marketing & Communications Data: preferences for receiving marketing and communication choices

We also collect aggregated, non-identifiable statistical or demographic data.

3. How we collect your personal data

We collect data through:

Direct interactions: when you order, create an account, request marketing, give feedback, or contact us

Automated technologies: cookies, analytics tools, and usage tracking

Analytics: such as Google Analytics (stored anonymously)

Card payment services: such as Stripe (we do not receive card details)

4. How we use your personal data

We process your personal data for the following purposes and legal bases:

To register you as a new customer — Identity & Contact data (Contract)

To process and deliver your order — Identity, Contact, Financial, Transaction, Marketing & Communications data (Contract; Legitimate interests for debt recovery)

To manage our relationship with you — Identity, Contact, Profile, Marketing & Communications data (Contract; Legal obligation; Legitimate interests to keep records updated)

To administer and protect our business and website — Identity, Contact, Technical data (Legitimate interests; Legal obligation)

To use analytics to improve services and measure marketing effectiveness — Technical & Usage data (Legitimate interests)

To send you marketing communications and personalised recommendations — Identity, Contact, Technical, Usage, Profile, Marketing & Communications data (Consent)

Direct marketing: You may receive marketing from us if you have consented or previously purchased from us without opting out.

Third-party marketing: We will get your consent before sharing your data with third parties for their own marketing.

Opting out: You can unsubscribe at any time via links in marketing emails or by contacting us.

Cookies: Our site uses cookies to distinguish you from other users and improve your experience. Types include:

Strictly necessary cookies

Analytical/performance cookies

Functionality cookies

Targeting cookies

5. Disclosures of your personal data

We may share data with:

Mailchimp (or similar) for marketing

Stripe (or similar) for payment processing

Business partners or successors in the event of a sale, transfer, or merger

6. International transfers

If transferring outside the UK, we ensure appropriate safeguards such as adequacy decisions, standard contractual clauses, or Data Privacy Framework certification.

7. Data security

We implement appropriate security measures, restrict access to authorised persons, and have breach procedures in place.

8. Data retention

We keep data only as long as necessary, including:

Six years after ceasing to be a customer (legal requirement)

Ten years for bike purchases with a ten-year guarantee

Up to three years for inactive online accounts (we may contact you before deletion)

Until you unsubscribe from marketing lists

9. Your legal rights

You have the right to:

Access your data

Correct inaccurate data

Request erasure (subject to legal exceptions)

Object to processing (especially for marketing)

Request data transfer (if in portable format)

Restrict processing in certain cases

We may need proof of identity before responding. We aim to respond within one month.

10. Contact details

Email: info@merciancycles.com

Post: Mercian Cycles, Unit 2 Duffield Road Industrial Estate, Little Eaton, Derby DE21 5DR

Tel: +44 1332 752468

11. Complaints

You can complain to the ICO (www.ico.org.uk) but we ask you to contact us first so we can resolve your concern.

12. Changes to this notice

We keep this privacy notice under review and may update it. Please notify us of any changes to your personal data.

13. Third-party links

Our site may contain links to other websites. We are not responsible for their privacy notices and encourage you to read them.