Welcome to the world of PrettyLittleThing.com Fierce fashion at your fingertips, delivered straight to your doorstep, 24/7!
Where in the world are you?
You have no items in your shopping cart.
Your Guide to All Things Privacy
You have our word that we’ll treat and protect your data.
We’ll keep you updated with what you need to know.
Let us know your preferences - you decide what and how you hear from us.
We won’t keep your data for no reason. If we don’t need your data, we’ll delete it
Protecting your Privacy At PrettyLittleThing.com Limited (‘PLT’), we’ve got your back when it comes to your style and those all-important personal details. Our customers are super important to us, which means protecting our customers by keeping their personal data and information secure at all costs is a main priority. It applies to data collected when you use our websites, iOS and android applications, when you interact with us through social media, email, or phone, or when you participate in our competitions or events. It also applies to the extent that someone has nominated you through our "refer a friend" function or purchased an e-gift card on your behalf.
We know the world of data security can be tricky (and a little zzzz), but we want you to be fully clued up on everything you need to know when it comes to your personal information and how it’s used. Consider this your guide to all things privacy related, which covers the following:
PLT is a leading online fashion retail company known for taking over your social media feeds with our killer looks and next-level aesthetic that’ll have you double tapping. We design, source, market and sell clothing, shoes, accessories and beauty products to consumers in almost every country in the world.
Details of our Data Protection Officer responsible for overseeing questions in relation to this privacy notice, and our details are set out in the “Say Hey and Contact Us” section at the end of this notice.
We take the protection of your personal data seriously and will process your personal data fairly, lawfully and transparently.
We will only collect and use your personal data for the following purposes, to:
We have appropriate organisational safeguards and security measures in place to protect your data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.
The communication between your browser and our website uses a secure encrypted connection wherever your personal data is involved.
We require any third party who is contracted to process your personal data on our behalf to have security measures in place to protect your data and to treat such data in accordance with the law.
In the unfortunate event of a personal data breach, we will notify you and any applicable regulator when we are legally required to do so.
Personal data means any information about an individual from which that person can be identified. It does not include anonymised data, where the identity and identifying information has been removed.
While our website is designed for a general audience, we will not knowingly collect any data from children under the age of 13 or sell products to children. If you are under the age of 13, you are not permitted to use or submit your data to the website.
The following groups of personal data are collected:
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
Most of the data we collect is provided by you, the customer, when you’re engaging with us and our brand in the following ways:
Direct interactions – you may give us your Identity, Contact, Financial, Transaction, Profile, and Marketing and Communications data by filling in forms, entering information online or by corresponding with us by post, phone, email, telephone or otherwise. This includes personal data you provide, for example, when you:
Automated technologies or interactions – as you interact with our website, we may automatically collect the following types of data (all as described above): Technical Data about your equipment, Usage Data about your browsing actions and patterns, and Contact Data where tasks carried out via our website remain uncompleted, such as incomplete orders or abandoned baskets. We collect this data by using cookies, server logs and other similar technologies. Please see our Cookie section (below) for further details.
Third parties – we may receive personal data about you from various third parties, including:
The legal basis for processing your personal data
We will only collect and process your personal data where we have a legal basis to do so. As a data controller, the legal basis for our collection and use of your personal data varies depending on the manner and purpose for which we collected it.
We will only collect personal data from you when:
Uses made of your personal data
Your personal data is used by PLT to support a range of different activities. These are listed in the table below together with the types of data used and the legal basis we rely on when processing them, including where appropriate, our legitimate interests. Please be aware that we may process your personal data using more than one lawful basis, depending on the specific activity involved. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we wish to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. We may process personal data without your consent, in compliance with the above rules, where this is required or permitted by law.
If you have any questions about how PLT use any of your personal data, please contact our Data Protection Officer at DPO@boohoo.com.
When it comes to keeping your details on file, we basically hold your personal data for:
In certain cases, we may keep hold of some of your information after you have closed your account, or it is no longer needed to provide the services to you. This type of situation may arise if your details are needed to meet legal or regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions.
We may send you marketing communications and promotional offers:
We may use your Identity, Contact, Technical, Transactional, Usage, Profile Data and Marketing and Communications Data to form a view on what we think you may like, or what may be of interest to you, and to send you details of products and offers which may be relevant for you.We will ask you for your preferences in relation to receiving marketing communications by email, post, SMS and other communication channels.From time to time we may also include with your order, inserts advertising goods, services or offers from other third-party companies that you may be interested in.In respect of third party marketing communications, we will obtain your express opt-in consent before we share your personal data with any third party for marketing purposes.You will always have full control of your marketing preferences. If you do not wish to continue receiving marketing information from us (or any third party, if applicable) at any time:
We will process all opt-out requests as soon as possible, but please note that due to the nature of our IT systems and servers it may take a few days for any opt-out request to be implemented.
We’re pretty big on putting ourselves and our brand out there to keep our customers up to date on our goings on and latest product offering. We do this through advertising. With this, we look to target you, the customer, with our banners and adverts - even when you’re using other websites and services not associated with us.Like many companies, we may target PLT banners and ads to you when you use other websites and apps, based on your Contact, Technical, Usage and Profile Data. We do this using a variety of digital marketing networks and ad exchanges, and a range of advertising technologies such as web beacons, pixels, ad tags, cookies, and mobile identifiers, as well as specific services offered by some sites and social networks, such as Facebook’s Custom Audience Service.
We use a range of analytics and targeted advertising tools to display relevant website content on our website and online advertisements on other websites and apps (as described above) to you, deliver relevant content to you in marketing communications (where applicable), and to measure the effectiveness of the advertising provided. For example, we use tools such as Google Analytics to analyse Google's interest-based advertising data and/or third-party audience data (such as age, marital status, life event, gender and interests) to target and improve our marketing campaigns, marketing strategies and website content. We may also use tools provided by other third parties, such as Facebook, Tik Tok, Adroll, Emarsys, Conversant and Bing to perform similar tasks, using your Contact, Technical, Usage and Profile Data.In order to opt out of targeted advertising you need to disable your ‘cookies’ in your browser settings or opt-out of the relevant third-party Ad Settings.The Digital Advertising Alliance (which includes companies such as Google, Responsys and Facebook) provides a tool called WebChoices that can perform a quick scan of your computer or mobile devices, find out which participating companies have enabled customised ads for your browser, and adjust your browser preferences accordingly.If you would like any further information about the data collected by these third parties or the way in which the data is used, please contact us.
Our website may include links to and from the websites of our partner networks, advertisers and affiliates, or to social media platforms. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to their websites.
We may disclose and share your personal data with the parties set out below:
to our professional advisers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services.
The personal data we collect from you may be transferred to, and stored at, destinations outside the European Economic Area ("EEA") using legally-provided mechanisms to lawfully transfer data across borders. It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers. Such staff may be engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of support services. We will take all steps necessary to ensure that your data is treated securely and in accordance with this privacy notice.
Whenever we transfer personal data outside the EEA, we will ensure a similar degree of protection is afforded to it by ensuring appropriate safeguards, as required by law, are in place. This may include using specific contractual clauses approved by the European Commission which give personal data the same protection as it has in Europe. More information about these is available herePlease contact us if you want further information on the countries to which we may transfer personal data and the specific mechanism used by us when transferring your personal data outside the EEA.
When it comes to your personal data, you have a lot of rights. These include:
If you want to exercise your rights, have a complaint to make, or just have a question for us - get in touch by emailing us at DPO@boohoo.com.
Request access to your personal dataYou have the right to obtain a copy of the personal data we hold about you and certain information relating to our processing of your personal data.
Request correction of your personal dataYou are entitled to have your personal data corrected if it is inaccurate or incomplete. You can update your personal data at any time by logging into your account and updating your details directly, or by emailing us at DPO@boohoo.com.
Request erasure of your personal dataThis enables you to request that PLT delete your personal data, where there is no good reason for us continuing to process it. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Request restriction of processing of your personal dataYou have a right to ask PLT to suspend the processing of your personal data in certain scenarios, for example if you want us to establish the accuracy of the data, or you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it. Where processing is restricted, we are allowed to retain sufficient information about you to ensure that the restriction is respected in future.
Request the transfer of your personal dataYou have the right to obtain a digital copy of your personal data or request the transfer of your personal data to another company. Please note though that this right only applies to automated data which you initially provided consent for us to use or where we used the data to perform a contract with you.
Object to processing of your personal dataYou have the right to object to the processing of your personal data where we believe we have a legitimate interest in processing it (as explained above). You also have the right to object to our processing of your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your data which override your rights and freedoms.
Request human intervention for automated decision making and profilingYou have the right to request human intervention where we are carrying out automated decision making when processing your personal data. This form of processing is permitted where it is necessary as part of our contract with you, providing that appropriate safeguards are in place or your explicit consent has been obtained.We will try to respond to all legitimate requests within one month. Occasionally, it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated. We may need to request specific information from you to help us confirm your identity and ensure your right to exercise any of the above rights. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
Right to lodge a complaintIf you have any concerns or complaints regarding the way in which we process your data, please email us directly at DPO@boohoo.com. You also have the right to make a complaint to the ICO (the data protection regulator in the UK), or (if you are located in the European Union) any other competent supervisory authority in your country of residence (a list of supervisory authorities can be found here: https://edpb.europa.eu/about-edpb/about-edpb/members_en) We would, however, appreciate the chance to deal with your concerns before you approach the ICO, or any other supervisory authority so please do contact us in the first instance.
Representative in the EUFor supervisory authorities and customers located in the European Union, if you have any questions about our privacy notice or the information we hold about you, please feel free to contact us by email at: firstname.lastname@example.org.
From time to time we may change this privacy notice. If there are any significant changes we will post updates on our website, applications or let you know by email.
Our customers are super important to us so feel free to hit us up with any questions, comments or requests you have about your data by contacting our nominated representative and Data Protection Officer at DPO@prettylittlething.com.
If you are a California resident, please click here for more information about your specific privacy rights.
Registered Company Number: 07352417,
UK VAT Number: 100 5694 47
Item(s) added to cart