Privacy Policy
Effective Date: April 2025
This Privacy Policy applies to the website www.toggi.com ("Website"), owned and operated by Finest Brands International Limited ("we," "us," or "our"). We are committed to safeguarding your privacy and handling your personal data transparently and securely.
This Privacy Policy outlines the types of data we collect, how we use and share it, and your rights regarding your personal data under UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. About Us
For purposes of applicable Data Protection Laws, Finest Brands International Limited is the "data controller." Our registered office is:
Finest Brands International
Laurel House, 146–148 Garnet Road
Leeds, West Yorkshire, LS11 5HP
hello@toggi.com | 0113 270 7007
2. What Data We Collect
We may collect and process the following categories of personal data:
- Personal Information: Name, gender, and contact details (email, phone, and address).
- Demographic Data: Postcode, preferences, and interests.
- Technical Data: IP address, browser type/version, operating system, device information.
- Interaction Data: Information about your visit, including browsing behaviour, page interaction, time on page, and marketing preferences.
- Transactional Data: Order history, payment status, refunds, and delivery status.
3. How We Collect Data
We collect personal data through:
- Direct Collection: When you provide data through account creation, orders, surveys, contact forms, or email/SMS communications.
- Automated Technologies: Cookies, web beacons, and tracking pixels used as you browse the Website. For more on this, see our [Cookie Policy].
- Third-Party Platforms:
- Shopify (ecommerce platform)
- Klarna (Buy Now, Pay Later services)
- Social and Ad Platforms (e.g., Meta, TikTok, Google Ads for retargeting)
4. How We Use Your Data
We use personal data to provide, improve, and personalise our services, fulfil orders, manage our relationship with you, and comply with legal obligations. Specifically:
- Account Management: To register, verify, and manage your user account.
- Order Fulfilment & Support: To process orders, handle payments, deliver products, and provide customer service.
- Marketing & Communications: To send marketing communications, if you have opted in. You can opt out at any time.
- Personalisation: To customise your experience based on your preferences and usage.
- Advertising & Retargeting: To show relevant ads based on browsing and purchasing history.
- Site Performance: To monitor usage and improve the functionality, performance, and usability of the Website.
- Compliance & Auditing: To meet legal, financial, and compliance obligations.
5. Legal Basis for Processing
We rely on the following lawful bases for processing your data:
- Performance of a Contract: For fulfilling your orders or delivering requested services.
- Consent: Where required for direct marketing (email/SMS), cookies, or profiling. Consent can be withdrawn at any time.
- Legitimate Interests: For improving our services, fraud prevention, IT security, and business analytics.
- Legal Obligation: Where processing is necessary to comply with legal or regulatory duties (e.g., record-keeping, consumer rights).
6. Sharing Your Data
We only share personal data when necessary, and with trusted third parties that agree to handle your data responsibly:
- Shopify: Ecommerce hosting and checkout operations.
- Klaviyo: Email and SMS marketing delivery.
- Klarna: Payment processing and instalment plans.
- Couriers and Fulfilment Partners: For dispatch and delivery of products.
- Legal and Professional Advisors: For compliance, legal claims, or audits.
All third-party data processors are bound by contract to act only on our instructions, implement appropriate safeguards, and support your rights under the UK GDPR.
7. Security Measures
We implement industry-standard security measures to protect your personal data from loss, unauthorised access, alteration, or misuse. These include:
- Encrypted communication (HTTPS / TLS)
- Access control and internal data handling protocols
- Periodic security reviews of third-party vendors
- Role-based access restrictions to sensitive systems
In the event of a suspected personal data breach, we follow our Data Breach Response Plan, which includes prompt investigation and reporting to affected users and the ICO (Information Commissioner's Office), where required.
8. Data Retention
We retain your personal data only for as long as necessary to:
- Fulfil the purpose for which it was collected
- Comply with legal and regulatory obligations
- Defend legal claims or exercise rights
When no longer needed, your data will be securely deleted, anonymised, or archived in accordance with our Data Retention & Deletion Policy. You may request earlier deletion where appropriate (see Section 9).
9. Your Rights
You have the following rights under the UK GDPR:
- Right to Access – Request a copy of your personal data.
- Right to Rectification – Correct inaccuracies or incomplete data.
- Right to Erasure – Ask us to delete your data (subject to limitations).
- Right to Restrict Processing – Request limited use of your data.
- Right to Data Portability – Obtain a machine-readable copy to transfer elsewhere.
- Right to Object – Object to processing based on our legitimate interests or for direct marketing.
- Right to Withdraw Consent – Withdraw consent for optional data uses (e.g., marketing).
- Right to Lodge a Complaint – With the ICO or a relevant authority.
To exercise your rights, contact: hello@toggi.com. We may request identity verification and aim to respond within one month.
10. Cookies
Our Website uses cookies and similar tracking technologies to improve functionality, analyse traffic, and personalise content and ads.
You can manage your cookie preferences via our cookie banner or through your browser settings. Learn more by visiting our full [Cookie Policy].
11. Data Documentation & Training
We maintain internal documentation of:
- Our lawful basis for each processing activity
- Data protection training records for staff
- Records of Processing Activities (RoPA) under Article 30 UK GDPR
- Records of user consents and marketing preferences
These are reviewed regularly to ensure ongoing compliance and accountability.
12. Changes to This Privacy Policy
We may periodically update this Privacy Policy to reflect changes in legislation, technology, or business operations. Where required, we will notify you of material updates directly.
The latest version will always be available on this page. Your continued use of the Website signifies acceptance of any changes.
Contact Us
If you have any questions about this Privacy Policy or how we use your personal data, please contact:
Email: hello@toggi.com
Telephone: 0113 270 7007
You also have the right to contact the Information Commissioner’s Office (ICO) at www.ico.org.uk.