Skip to content

Fast EU Shipping

Privacy policy

Last updated: March 10, 2026

kneepillow.co.uk is operated by AFA Ecommerce Limited ("we", "us", or "our"), a company registered in England and Wales (Company No: 11688147). AFA Ecommerce Limited is the Data Controller for the personal information collected through this store and website. Our registered office is located at 207 Regent Street, Third Floor, Suite 8-120, London, W1B3HH. kneepillow.co.uk is powered by Shopify, which enables us to provide the Services to you. This Privacy Policy describes how we collect, use, and disclose your personal information in accordance with the UK Data Protection Act 2018 and the UK GDPR. If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy controls with respect to the collection, processing, and disclosure of your personal information.

Please read this Privacy Policy carefully. By using and accessing any of the Services, you acknowledge that you have read this Privacy Policy and understand the collection, use, and disclosure of your information as described in this Privacy Policy.

Personal Information We Collect or Process

When we use the term "personal information," we are referring to information that identifies or can reasonably be linked to you or another person. We may collect or process the following categories of personal information, including inferences drawn from this personal information, depending on how you interact with the Services, where you live, and as permitted or required by applicable law:

  • Contact details including your name, address, billing address, shipping address, phone number, and email address.
  • Financial information including transaction details, form of payment, payment confirmation and other payment details (all processed securely via Shopify's encrypted payment infrastructure).
  • Account information including your username, password, security questions, preferences and settings.
  • Transaction information including the items you view, put in your cart, add to your wishlist, or purchase, return, exchange or cancel and your past transactions.
  • Communications with us including the information you include in communications with us, for example, when sending a customer support inquiry.
  • Device information including information about your device, browser, or network connection, your IP address, and other unique identifiers.
  • Usage information including information regarding your interaction with the Services, including how and when you interact with or navigate the Services.

Personal Information Sources

We may collect personal information from the following sources:

  • Directly from you including when you create an account, visit or use the Services, communicate with us, or otherwise provide us with your personal information;
  • Automatically through the Services including from your device when you use our products or services or visit our websites, and through the use of cookies and similar technologies (such as Shopify's native analytics);
  • From our service providers including when we engage them to enable certain technology and when they collect or process your personal information on our behalf;
  • From our partners or other third parties.

Legal Basis for Processing (UK & EEA)

Under the UK GDPR, we rely on the following legal bases to process your information:
(1) Contractual Necessity: To fulfill your orders and perform our contract with you.
(2) Legal Obligations: To comply with UK tax and consumer laws.
(3) Legitimate Interests: For fraud prevention, site security, and improving our customer experience.
(4) Consent: For marketing communications and non-essential cookies.

How We Use Your Personal Information

  • Provide, Tailor, and Improve the Services. We use your personal information to provide you with the Services, including to perform our contract with you, to process your payments, to fulfill your orders, to remember your preferences and items you are interested in, to send notifications to you related to your account, to process purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for shipping, to facilitate any returns and exchanges, to enable you to post reviews, and to create a customized shopping experience for you.
  • Marketing and Advertising. We use your personal information for marketing and promotional purposes, such as to send marketing, advertising and promotional communications by email or text message where you have provided explicit consent.
  • Security and Fraud Prevention. We use your personal information to authenticate your account, provide a secure payment experience, and take action regarding possible fraudulent activity. We utilize Shopify’s advanced fraud screening for all transactions.
  • Legal Reasons. We use your personal information to comply with applicable UK law or respond to valid legal process.

How We Disclose Personal Information

In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy. Such circumstances may include:

  • With Shopify, vendors and other third parties who perform services on our behalf (e.g. IT management, payment processing, data analytics, cloud storage, fulfillment and shipping).
  • With business and marketing partners to provide marketing services and advertise to you. You can exercise your rights to opt-out of those uses here.
  • With our affiliates or otherwise within our corporate group.
  • In connection with a business transaction such as a merger or bankruptcy, or to comply with any applicable UK legal obligations (including to respond to valid law enforcement requests).

Relationship with Shopify

The Services are hosted by Shopify, which collects and processes personal information about your access to and use of the Services in order to provide and improve the Services for you. Shopify acts primarily as a Data Processor on our behalf. Information you submit to the Services will be transmitted to and shared with Shopify as well as third parties that may be located in countries other than the UK, in order to provide and improve the Services for you. To learn more about how Shopify uses your personal information, you can visit the Shopify Consumer Privacy Policy. Depending on where you live, you may exercise certain rights with respect to your personal information here Shopify Privacy Portal Link.

Security and Retention of Your Information

No security measures are perfect, and we cannot guarantee "perfect security." We use SSL/TLS encryption for all data in transit. How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, provide Services, comply with UK legal/tax obligations, resolve disputes or enforce policies.

Your Rights and Choices (UK Residents)

As a UK resident, you have the following rights under the UK GDPR:

  • Right to Access: You have a right to request access to personal information that we hold about you.
  • Right to Delete: You have a right to request that we delete personal information we maintain about you.
  • Right to Correct: You have a right to request that we correct inaccurate personal information.
  • Right of Portability: You have a right to receive a copy of your personal information in a machine-readable format.
  • Managing Communication Preferences. You may opt out of promotional emails at any time by using the unsubscribe option.

Complaints to the Regulator

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection. You can contact them at www.ico.org.uk.

International Transfers

If we transfer your personal information out of the United Kingdom, we rely on recognized transfer mechanisms such as the UK’s International Data Transfer Agreement (IDTA) or equivalent contracts issued by the relevant competent authority of the UK.

Contact Information

Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please email us at sale@kneepillow.co.uk or contact us using the information below. For the purpose of UK data protection laws, AFA Ecommerce Limited is the Data Controller of your personal information.

207 Regent Street, Third Floor, Suite 8-120
kneepillow - AFA Ecommerce Limited
London England W1B3HH

Company No: 11688147
VAT Reg No: GB440399294
Phone: +447441395503
Email: sale@kneepillow.co.uk
Support Hours: Mon–Fri, 9:00 AM – 5:00 PM (GMT)