Privacy & cookies
Last updated
Who we are. Tocommons Ltd (company number 15170088, registered office 128 City Road, London, EC1V 2NX) is the controller of the personal data described here. Contact: contact@tocommons.co.uk. We are registered with the Information Commissioner's Office (ICO).
What we collect and why. When you place an order we collect your email address, name, phone number (if you give one — it's optional), delivery address and billing address (the same as your delivery address unless you enter a different one). We use them to fulfil and deliver your order, send you the order confirmation and dispatch email, and handle returns, refunds and any dispute about the order. The legal basis is the performance of our contract with you (UK GDPR Article 6(1)(b)). We keep records of orders, payments and the version of this policy you accepted for accounting and legal purposes (Article 6(1)(c) — HMRC record-keeping — and Article 6(1)(f) — defending legal claims). We do not use your data for marketing unless you ask us to in your account (see "Marketing choice" below), and we do not sell it. Providing these details (other than your phone number, which is optional) is a contractual requirement: without them we cannot deliver your order.
Payment. Card payments are processed by Square (Squareup Europe Ltd, company number 08957689, authorised by the Financial Conduct Authority under the Electronic Money Regulations 2011, reference 900846). Your card details are entered directly into Square's secure payment form and never reach our servers. If you pay with Apple Pay or Google Pay, your wallet provider (Apple or Google) sends us the name, email address, phone number and delivery address that you choose in your wallet so that we can create your order, and sends Square a payment token instead of your card number; if you are signed in, we use your account email address instead. For card payments, to verify your payment (Strong Customer Authentication), we pass Square your name, email address and delivery address (sent as the billing contact, even if you gave us a different billing address); we do not send Square your phone number or your separate billing address. The order and payment records we create at Square contain the items (name, product code, quantity and price), the delivery charge, the amount, our order number and an internal payment reference; they do not contain your name or contact details. If your bank asks to verify you (3-D Secure), the information needed for that check goes to your bank through Square's authentication provider. Square processes this data on our behalf to take your payment, and also as a separate controller for its own purposes, such as preventing fraud and meeting its legal and regulatory obligations — see Square's privacy notice for customers of Square sellers (squareup.com/gb/en/legal/general/privacy-no-account). Square may process data outside the UK, including in the United States. Under our contract with Square, where Square transfers this data outside the UK on our behalf it must put in place the safeguards required by UK data protection law. Square's privacy notice for UK sellers names the UK International Data Transfer Agreement and the UK Addendum to the EU standard contractual clauses as the safeguards it uses. If you would like details of these safeguards, email us: we will ask Square and pass on the information Square provides.
Who else receives your data. Amazon Web Services (hosting and email delivery, London region only) and Google Workspace (our contact mailbox) process data on our behalf. Our delivery courier receives your name, address and, if you gave one, your phone number to deliver your parcel. Other than Square and the services listed here, we do not transfer your data outside the UK.
How long we keep it. Order and payment records (what you ordered, amounts, dates, status) are kept for six years after the end of the financial year in which the order was completed, as required by HMRC. Your contact and address details attached to an order are anonymised within one month after 24 months have passed since the order was completed. Emails waiting to be sent are deleted from our queue as soon as they are sent. Server logs are kept for 90 days and contain no personal data; load-balancer logs containing IP addresses are kept for 30 days. If you make an unusually high number of requests in a short time, we may temporarily record your IP address to protect the site from abuse; that record is kept only for the duration of the check (a few minutes) and any log entry created if a limit is hit shows only a masked IP address. Backups are retained for up to 7 days after deletion.
Product reviews. A few days after your order is shipped, we may send you one email asking you to review what you bought. We send it because you ordered from us (our legitimate interest in hearing how our products worked for you); every email has a link to stop review emails, and you won't get another one after that. We keep a note that you opted out so we don't ask again. If you write a review, we publish your star rating, title, review and the name you chose (your initials unless you change them) on the product page after we've checked it, with "Verified purchase". We don't publish your email address or order details. We publish positive and negative reviews alike and only remove reviews that are offensive, include personal details or aren't about the product. We delete reviews we don't publish after 90 days. You can ask us to remove your review at any time by emailing us.
Your account. You don't need an account to order. If you create one, we keep your email address (you confirm it with a one-time code we email you), when you created the account and when you last signed in. If you choose "Sign in with Google", Google tells us your Google account ID and email address — we don't receive your name, photo or contacts — and we store only the ID, to recognise you next time. Google acts as a separate controller for the sign-in it provides: see Google's privacy policy. If you save delivery addresses or products in your account we keep them until you remove them. Orders you place while signed in, or add to your account yourself, are linked to it so you can see them under My orders; your basket, back in stock requests made while signed in and any coupons we give you are linked to your account too. We use this only to provide your account (UK GDPR Article 6(1)(b)), and we never pass your account details to analytics tools.
Marketing choice. In your account you can turn on "Email me news and offers". It is off unless you turn it on, it is never a condition of creating an account or placing an order, and turning it off doesn't stop order, dispatch or sign-in emails. We record when you turned it on or off and which wording you agreed to, so we can show what you agreed to (UK GDPR Article 6(1)(a) — your consent, which you can withdraw at any time in your account).
Deleting your account. You can delete your account at any time under My account (if you haven't signed in within the last 10 minutes, we ask for a new code first). We then straight away delete your account, its Google link, your saved addresses and saved items, your marketing choice, your pending back in stock requests, any coupons we gave you and reviews you wrote for your orders, and we anonymise the contact and address details on your dispatched or cancelled orders. Order and payment records we must keep for HMRC stay, but are no longer linked to you. If an order hasn't been dispatched yet, you can delete your account once it has been, or contact us. If you don't sign in for 24 months, we delete your account in the same way. Deleted data may remain in backups for up to 7 days.
Your rights. You can ask for a copy of your data, ask us to correct or delete it, restrict or object to processing, or ask for it in a portable format. Email contact@tocommons.co.uk with your order number, the email address and delivery postcode used for the order; we reply within one month. If you have an account, you can see your orders, saved addresses and saved items and delete your account yourself under My account; if you email us instead, we confirm it's you by sending a one-time code to your account's email address and asking you to send it back to us (the code works once and expires after 7 days). We cannot delete order and payment records we are legally required to keep, but we will anonymise your contact details. Deleted data may remain in backups for up to 7 days. You have the right to complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113).
Cookies and storage.
The cookies and storage in this list are strictly necessary to run the shop, so we do not ask for your consent to them (PECR regulation 6, Schedule A1 paragraph 4):
- cart_token — remembers your basket; expires after 14 days.
- XSRF-TOKEN — protects your basket and order from cross-site request forgery; deleted when you close the browser.
- Browser session storage checkout.order — carries your order reference from the details page to the payment page; deleted when you close the tab.
- customer_session — keeps you signed in to your account; it ends when you sign out, after 30 days without use, or after 90 days at most.
- customer_oauth — used only while you sign in with Google, to check that the reply from Google belongs to your sign-in; expires after 10 minutes.
- Browser session storage account.login.email — remembers the email address you typed while you wait for your sign-in code; deleted when you close the tab.
- cookie_consent — remembers whether you allowed analytics; expires after 1 year.
Recent searches. Our search box remembers your last 5 searches in this browser's local storage (howsit.recent-searches) so you can pick them again. That list stays on your device and we never upload it, but each search you type or pick is sent to our server to show suggestions and results, and appears in the page address (/search?q=…). Keeping the list is not strictly necessary, so we tell you about it here (PECR Schedule A1 paragraph 6).
To stop it at any time (free, and even before your first search): click the search box and choose "Turn off" ("Turn off and clear" if a list is already saved) on the line "Recent searches are saved on this device". We then delete the list, stop saving new searches and remember only that choice in this browser. "Undo" appears for a few seconds, you can choose "Turn on" in the same place at any time, and "Clear recent searches" deletes the current list.
On the payment step only, once you agree, Square's payment form (loaded from Square's own website) sets cookies on Square's domain:
- __cf_bm — set by Square's payment service (via Cloudflare) to detect automated abuse; expires after 30 minutes.
- _savt — a Square cookie that lasts up to 3 years. Square says it uses it to recognise your browser across visits for its own analytics, testing and bot detection (Square's cookie settings list it as an analytics cookie). It is not strictly necessary, so we load Square's payment form only after you agree on the payment step. If you don't agree, we don't load the form, so you can't pay by card — contact us if you need help. See Square's cookie notice.
If you use Google Pay at checkout, Google may set cookies (for example NID) in your browser, and Google's own sign-in window sets its own cookies. See Google's cookie information.
Changing your mind. You can take back your agreement at any time:
- Click "Payment cookies" at the bottom of any page. From then on we don't load Square's payment form until you agree again.
- This doesn't remove a cookie Square has already set, because it belongs to Square's website. To remove it, open your browser's settings, go to cookies (or "site data"), search for squareup.com and delete it.
When we tested Square's payment form in Square's test environment, it did not use your browser's local storage, session storage or IndexedDB. If your bank asks you to verify a payment (3-D Secure), your bank's verification page opens inside the payment form and is run by your bank.
Analytics. We count visits to our shop ourselves, on our own servers, so we can see which pages and products people look at and improve the shop. This sets no cookies, stores nothing on your device, and no visit data is shared with anyone else. We count each visitor with a code that changes every day, made from your connection address, browser type and the date; we do not use it to identify you, and we never store your IP address. We record only the page address (without search terms or order details), where the visit came from (for example a search engine or a link we shared), the kind of device (phone, tablet or computer), the country, whether a visit led to adding to the basket or starting checkout, and which link an order came from. Individual visit records are kept for at most 4 days, counting today, and then deleted; we keep only daily totals. We do this under our legitimate interest in running and improving the shop. If your browser sends a "Do Not Track" or "Global Privacy Control" signal, we do not count your visit. You can also turn analytics off at any time with "Cookie settings" at the bottom of every page; we remember your choice in the cookie_consent cookie. We use no advertising or social-media cookies.
Automated decisions. Square's fraud checks may decline a payment automatically; if that happens you can contact us or your bank. We make no other automated decisions about you.
