Privacy Policy

Table of Contents

PRIVACY POLICY

UK Magicmushroom-psychedelicsshop

Effective date: 1 June 2026
Last updated: 1 June 2026
Next scheduled review: 1 December 2026
Review frequency: Every six months

Business address:
Ashton Road
Bournemouth
Dorset
BH9
United Kingdom

Telephone: +44 7529 515893

Email: contact@ukmagicmushroom-psychedelicsshop.uk

Owners and CEO: Bryan T.K and Elvis John K


1. Introduction

UK Magicmushroom-psychedelicsshop respects the privacy of individuals who visit our website, communicate with us, purchase our lawful products or otherwise interact with our business.

This Privacy Policy explains how we collect, use, store, disclose and protect personal information.

It also explains the rights available to individuals under applicable UK data-protection legislation and how you can contact us about your personal information.

We aim to handle personal information fairly, lawfully and transparently.

This Privacy Policy applies to personal information collected through our website, by email, telephone, customer-service communications, orders, delivery arrangements and other legitimate interactions with our business.


2. Data Protection Legislation

We aim to comply with applicable UK data-protection legislation, including:

  • the UK General Data Protection Regulation (UK GDPR);

  • the Data Protection Act 2018;

  • the Privacy and Electronic Communications Regulations (PECR), where applicable; and

  • other applicable privacy and electronic-communications legislation.

The specific rules applicable to particular information or processing activities may depend on the circumstances.

Where UK law provides individuals with mandatory privacy rights, nothing in this Privacy Policy is intended to remove or restrict those rights.


3. Who We Are

For the purposes of applicable data-protection legislation, the organisation responsible for processing personal information through this website is:

UK Magicmushroom-psychedelicsshop

Address:
Ashton Road
Bournemouth
Dorset
BH9
United Kingdom

Telephone: +44 7529 515893

Email: contact@ukmagicmushroom-psychedelicsshop.uk

Owners and CEO: Bryan T.K and Elvis John K

Where a separate data controller is responsible for a particular processing activity, we will provide appropriate information where required.


4. What Is Personal Data?

Personal data is information relating to an identified or identifiable individual.

Depending on how you interact with us, personal data may include:

  • your name;

  • email address;

  • telephone number;

  • billing address;

  • delivery address;

  • account information;

  • order details;

  • payment-related information;

  • correspondence;

  • customer-service records;

  • preferences;

  • technical information;

  • IP address;

  • browser information;

  • device information;

  • website activity;

  • cookie identifiers; and

  • information you voluntarily provide to us.

We only seek to collect information that is reasonably necessary for legitimate business, contractual, legal, security or customer-service purposes.


5. Information We Collect Directly From You

You may provide personal information when you:

  • create an account;

  • place an order;

  • request information;

  • contact customer support;

  • contact us by telephone;

  • contact us by email;

  • submit a complaint;

  • request a refund or return;

  • provide delivery information;

  • subscribe to communications;

  • submit a review or other content; or

  • otherwise communicate with us.

The information collected depends on the nature of your interaction.


6. Information Collected Automatically

When you visit our website, certain technical information may be collected automatically.

This may include:

  • IP address;

  • browser type;

  • operating system;

  • device type;

  • approximate geographical information;

  • referring website;

  • pages visited;

  • time spent on pages;

  • website interactions;

  • error information;

  • security logs; and

  • other technical information required to operate and protect the website.

Some information may be collected using cookies or similar technologies.


7. Information Received From Third Parties

Where lawful and appropriate, we may receive information from third parties.

This may include information provided by:

  • payment providers;

  • delivery providers;

  • website hosting providers;

  • technology providers;

  • fraud-prevention services;

  • analytics providers;

  • customer-support platforms; or

  • other service providers supporting our legitimate business operations.

We will only use third-party information where there is an appropriate lawful basis for doing so.


8. How We Use Personal Information

We may use personal information for purposes including:

  • processing orders;

  • providing products and services;

  • arranging delivery;

  • managing returns;

  • processing refunds;

  • responding to enquiries;

  • providing customer support;

  • handling complaints;

  • verifying transactions;

  • preventing fraud;

  • maintaining website security;

  • managing customer accounts;

  • complying with legal obligations;

  • maintaining business records;

  • improving our website;

  • understanding website usage;

  • communicating important service information; and

  • managing legitimate business operations.

We will not use personal information for purposes incompatible with the reason it was collected unless permitted or required by law.


9. Lawful Bases for Processing

Under the UK GDPR, organisations generally need a lawful basis for processing personal data.

Depending on the circumstances, we may rely on one or more of the following lawful bases.

9.1 Contract

We may process personal data where it is necessary to enter into or perform a contract with you.

For example, we may need your:

  • name;

  • contact details;

  • billing details;

  • delivery address; and

  • order information

to process and fulfil an order.


9.2 Legal Obligation

We may process personal information where necessary to comply with a legal obligation.

This may include obligations concerning:

  • accounting;

  • taxation;

  • financial records;

  • fraud prevention;

  • consumer protection;

  • regulatory compliance;

  • court orders; or

  • other applicable legal requirements.


9.3 Legitimate Interests

We may process information where it is necessary for our legitimate interests or those of a third party, provided that those interests are not overridden by your fundamental rights and freedoms.

Examples may include:

  • maintaining website security;

  • preventing fraud;

  • improving our services;

  • managing customer relationships;

  • protecting our business;

  • analysing website performance; and

  • administering our operations.

Where we rely on legitimate interests, we consider whether the processing is necessary and whether your interests and rights outweigh our legitimate interests.


9.4 Consent

In circumstances where consent is required, we will seek your consent before carrying out the relevant processing.

You may generally withdraw consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.


10. Orders and Customer Accounts

If you place an order or create a customer account, we may process information necessary to administer the transaction.

This may include:

  • name;

  • email address;

  • telephone number;

  • billing information;

  • delivery information;

  • order history;

  • transaction information;

  • account details; and

  • customer correspondence.

We use this information to provide the requested service and manage the customer relationship.


11. Payment Information

Payments may be processed through third-party payment providers.

Where possible, payment information may be processed directly by the relevant payment provider rather than being stored by us.

We may receive limited transaction information necessary to:

  • confirm payment;

  • identify the transaction;

  • process refunds;

  • manage disputes;

  • prevent fraud; and

  • maintain appropriate financial records.

Payment providers may have their own privacy policies and terms.


12. Delivery Information

To fulfil an order, we may need to provide relevant information to a delivery provider.

This may include:

  • recipient name;

  • delivery address;

  • postcode;

  • telephone number, where necessary; and

  • delivery instructions.

We only aim to share information reasonably necessary to arrange delivery.

Delivery providers may process personal information under their own privacy policies.


13. Customer Support

If you contact us by telephone, email or another support channel, we may keep a record of the communication.

This may include:

  • your name;

  • contact details;

  • order information;

  • enquiry;

  • complaint;

  • return or refund information;

  • correspondence; and

  • information needed to resolve the matter.

We use this information to provide customer support and maintain appropriate business records.


14. Telephone Communications

If you contact us by telephone on:

+44 7529 515893

we may collect personal information that you voluntarily provide during the conversation.

Unless expressly stated otherwise, customers should not assume that telephone calls are recorded.

Where call recording is introduced in the future, we will provide appropriate information about the recording and its purpose where required by law.


15. Email Communications

If you contact:

contact@ukmagicmushroom-psychedelicsshop.uk

we may retain the correspondence to:

  • respond to your enquiry;

  • resolve a complaint;

  • process an order;

  • handle a return or refund;

  • maintain business records; or

  • comply with legal obligations.

We may also retain relevant email correspondence as evidence of communications where reasonably necessary.


16. Marketing Communications

Where permitted by law, we may send marketing communications about products, services, offers or updates.

Where consent is required, we will obtain it before sending relevant marketing communications.

You can unsubscribe from marketing communications using the unsubscribe mechanism provided in the relevant message or by contacting us.

You may continue to receive essential transactional communications where necessary, such as:

  • order confirmations;

  • delivery information;

  • refund notifications;

  • account security notices; or

  • important service announcements.


17. Cookies

Our website may use cookies and similar technologies.

Cookies are small files or identifiers that can be placed on your device when you visit a website.

Depending on how the website is configured, cookies may be used for:

  • essential website functionality;

  • security;

  • remembering preferences;

  • analytics;

  • performance monitoring;

  • improving user experience; and

  • marketing.

Where consent is legally required for non-essential cookies, we will seek consent before using them.


18. Managing Cookies

Depending on your browser and our cookie-management tools, you may be able to:

  • accept cookies;

  • reject cookies;

  • delete existing cookies;

  • block certain categories of cookies; or

  • change your browser settings.

Blocking essential cookies may affect website functionality.

For more information about how cookies work, customers should review their browser’s privacy and cookie settings.


19. Website Analytics

We may use analytics tools to understand how visitors interact with our website.

Analytics may help us understand:

  • which pages are visited;

  • how visitors navigate the website;

  • website performance;

  • technical problems;

  • general usage patterns; and

  • areas where the website can be improved.

Where required, we will obtain appropriate consent before using non-essential analytics technologies.


20. Website Security

We may process technical and personal information to protect our website, systems and customers.

Security processing may include:

  • monitoring suspicious activity;

  • detecting attempted attacks;

  • preventing fraudulent transactions;

  • protecting customer accounts;

  • maintaining security logs;

  • investigating security incidents; and

  • preventing unauthorised access.

Security information may be retained for an appropriate period based on operational and legal requirements.


21. Fraud Prevention

We may carry out reasonable fraud-prevention checks.

These may involve reviewing:

  • transaction information;

  • account activity;

  • delivery information;

  • device information;

  • IP address;

  • unusual website activity; and

  • other relevant security indicators.

Where a transaction raises legitimate concerns, we may delay, decline or investigate an order.

We will seek to ensure that any such processing has an appropriate lawful basis.


22. Data Sharing

We may share personal information with selected third parties where necessary and lawful.

These may include:

  • payment providers;

  • delivery providers;

  • website hosts;

  • IT service providers;

  • email providers;

  • customer-support platforms;

  • analytics providers;

  • fraud-prevention providers;

  • professional advisers;

  • insurers;

  • regulators;

  • law-enforcement authorities; and

  • courts or other competent authorities.

We do not intend to sell personal information to third parties.


23. Service Providers

Some organisations may process personal information on our behalf.

These organisations may provide services such as:

  • website hosting;

  • payment processing;

  • delivery;

  • email communication;

  • technical support;

  • data storage;

  • security;

  • analytics; or

  • customer support.

Where a service provider processes personal data on our behalf, we aim to ensure appropriate contractual and security arrangements are in place where required by law.


24. Legal and Regulatory Disclosure

We may disclose personal information where reasonably necessary to:

  • comply with a legal obligation;

  • respond to a lawful request from an authority;

  • comply with a court order;

  • prevent fraud;

  • investigate suspected unlawful activity;

  • protect our legal rights;

  • protect customers or other individuals; or

  • comply with applicable regulatory requirements.

We will seek to disclose only information reasonably necessary for the relevant purpose.


25. Professional Advisers

Where reasonably necessary, personal information may be shared with professional advisers such as:

  • solicitors;

  • accountants;

  • auditors;

  • insurers; or

  • other professional advisers.

Such disclosures may be necessary for legal, financial, insurance, compliance or business-management purposes.


26. International Data Transfers

Some third-party service providers may process personal information outside the United Kingdom.

Where personal information is transferred internationally, we will take appropriate steps to ensure that the transfer is lawful under applicable UK data-protection legislation.

Depending on the destination and circumstances, this may involve:

  • an adequacy decision;

  • appropriate contractual safeguards;

  • UK-approved transfer mechanisms; or

  • another lawful transfer mechanism.

We will not knowingly transfer personal information internationally without an appropriate lawful basis and safeguard where one is required.


27. How Long We Keep Personal Information

We do not retain personal information indefinitely.

We aim to keep information only for as long as reasonably necessary for the purpose for which it was collected, including where necessary to:

  • provide services;

  • maintain business records;

  • meet legal obligations;

  • resolve disputes;

  • enforce agreements;

  • prevent fraud; or

  • establish, exercise or defend legal claims.

Retention periods vary depending on the type of information and the reason for processing.


28. Factors Used to Determine Retention

When determining how long information should be kept, we may consider:

  • legal requirements;

  • tax and accounting obligations;

  • contractual requirements;

  • limitation periods;

  • the likelihood of disputes;

  • fraud-prevention needs;

  • security requirements;

  • operational requirements; and

  • whether the information remains necessary.

When information is no longer required, we aim to securely delete, anonymise or otherwise dispose of it.


29. Data Security

We take reasonable technical and organisational measures to protect personal information against:

  • unauthorised access;

  • accidental loss;

  • misuse;

  • alteration;

  • disclosure;

  • destruction; and

  • other inappropriate processing.

Security measures may include:

  • access controls;

  • passwords;

  • authentication;

  • secure systems;

  • restricted staff access;

  • security monitoring;

  • backups; and

  • appropriate technical safeguards.

No internet transmission or electronic storage system can be guaranteed to be completely secure.


30. Customer Responsibility

Customers should take reasonable steps to protect their own information.

If you create an account, you should:

  • use an appropriate password;

  • avoid sharing your login details;

  • log out on shared devices;

  • keep your contact information current; and

  • notify us if you suspect unauthorised account access.

We will never knowingly ask customers to disclose unnecessary passwords or security credentials by email.


31. Data Breaches

If we become aware of a personal-data breach, we will assess the incident and take appropriate action.

Where required by UK GDPR or other applicable legislation, we may notify:

  • the Information Commissioner’s Office (ICO); and/or

  • affected individuals.

The content and timing of any notification will depend on the nature and severity of the incident and applicable legal requirements.


32. Children’s Privacy

Our website is not intended to encourage children to provide personal information.

Where products or services are subject to age restrictions, we may use appropriate verification procedures.

We do not knowingly collect children’s personal information for purposes that are not legally permitted.

If you believe that a child has provided personal information to us improperly, contact us so that we can assess the situation.


33. Special Category Data

UK GDPR provides additional protection for certain categories of personal data, including information concerning:

  • health;

  • racial or ethnic origin;

  • religious or philosophical beliefs;

  • political opinions;

  • trade-union membership;

  • genetic data;

  • biometric data used for identification;

  • sex life; and

  • sexual orientation.

We do not generally require special-category data to process ordinary website orders.

Customers should avoid providing unnecessary sensitive personal information through ordinary website forms, emails or customer-service channels.

Where special-category data is legitimately required, we will process it only where an appropriate legal condition applies.


34. Criminal Offence Data

Information relating to criminal convictions and offences receives additional protection under UK data-protection law.

We do not generally require such information for ordinary customer transactions.

Where such information is processed, we will do so only where legally permitted and where appropriate safeguards apply.


35. Automated Decision-Making

We do not intend for customers to be subject to solely automated decisions producing legal or similarly significant effects unless permitted by applicable law and appropriate safeguards are in place.

Where applicable law provides rights relating to automated decision-making or profiling, those rights will be respected.


36. Your Data Protection Rights

Depending on the circumstances, UK GDPR gives individuals a number of rights.

These may include the right to:

  • access personal data;

  • correct inaccurate personal data;

  • request deletion;

  • restrict processing;

  • object to processing;

  • request data portability;

  • withdraw consent where processing is based on consent; and

  • complain to the Information Commissioner’s Office.

Not every right applies in every circumstance.

Certain exemptions and limitations may apply under UK law.


37. Right of Access

You may have the right to request a copy of the personal data we hold about you.

This is commonly known as a Subject Access Request (SAR).

When making a request, please provide sufficient information for us to identify you and locate the relevant information.

We may need to verify your identity before responding.


38. Right to Rectification

You may ask us to correct personal information that is inaccurate or incomplete.

If your information has changed, we encourage you to contact us so that our records can be updated where appropriate.


39. Right to Erasure

In certain circumstances, you may ask us to delete personal information.

This is sometimes referred to as the right to be forgotten.

However, this right is not absolute.

We may be legally permitted or required to retain information for reasons including:

  • legal obligations;

  • accounting;

  • taxation;

  • fraud prevention;

  • legal claims;

  • contractual records; or

  • other lawful purposes.


40. Right to Restrict Processing

In certain circumstances, you may request that we restrict the processing of your personal information.

This may apply where:

  • you dispute the accuracy of information;

  • processing is unlawful but you do not want deletion;

  • we no longer need the information but you require it for a legal claim; or

  • you have objected to processing and the relevant assessment is ongoing.


41. Right to Object

You may have the right to object to certain processing based on our legitimate interests.

You may also have an absolute right to object to direct marketing.

If you object to direct marketing, we will stop sending it unless another lawful basis permits us to continue.


42. Right to Data Portability

Where applicable, you may have the right to receive certain personal information in a structured, commonly used and machine-readable format.

You may also have the right to request that the information is transmitted to another organisation where technically feasible and where the legal requirements are met.

This right generally applies only to certain types of processing.


43. Withdrawing Consent

Where processing is based on your consent, you may withdraw your consent at any time.

To withdraw consent, contact us using the details below.

Withdrawal does not affect processing that took place lawfully before consent was withdrawn.


44. How to Exercise Your Rights

To exercise a data-protection right, contact:

UK Magicmushroom-psychedelicsshop

Email:
contact@ukmagicmushroom-psychedelicsshop.uk

Telephone:
+44 7529 515893

Postal address:
Ashton Road
Bournemouth
Dorset
BH9
United Kingdom

Please clearly identify the nature of your request.

We may ask for additional information to verify your identity before releasing or changing personal information.


45. Identity Verification

We take privacy and security seriously.

Before responding to certain requests, we may need to verify your identity.

The information requested for verification will depend on the nature and sensitivity of the request.

We will aim to avoid requesting unnecessary personal information.


46. Response Times

We aim to respond to valid data-protection requests within the timeframe required by applicable law.

Under the UK GDPR, many requests should generally be answered without undue delay and within one month.

Where a request is particularly complex or multiple requests have been submitted, the applicable legal rules may allow additional time.

If an extension applies, we will provide the relevant information where required.


47. Charges for Data Requests

Most data-protection requests should be handled without charge.

However, UK GDPR permits organisations in certain circumstances to charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.

Any decision to charge a fee or refuse a request will be made in accordance with applicable law.


48. Complaints About Privacy

If you believe that we have handled your personal information incorrectly, we encourage you to contact us first.

Email: contact@ukmagicmushroom-psychedelicsshop.uk

Telephone: +44 7529 515893

We will review your concern and seek to resolve it appropriately.

You also have the right to complain to the UK’s data-protection regulator.


49. Information Commissioner’s Office

The Information Commissioner’s Office (ICO) is the UK’s independent supervisory authority for data protection.

If you remain dissatisfied after contacting us, you may contact the ICO directly.

The ICO provides guidance about data-protection rights, privacy concerns and complaints through its official website.

ICO website: https://ico.org.uk/

Customers should use the ICO’s official channels for current contact information and complaint procedures.


50. Third-Party Websites

Our website may contain links to third-party websites.

We are not responsible for the privacy practices of third-party websites.

A link to another website does not mean that we endorse its privacy practices or content.

Customers should read the privacy policy of each third-party website before providing personal information.


51. Social Media

If we operate social-media pages or use social-media integrations, interactions with those services may involve processing by the relevant social-media provider.

Those organisations may process personal information under their own privacy policies.

We encourage customers to review the privacy settings and policies of any social-media platform they use.


52. Business Transfers

If our business is reorganised, sold, merged, acquired or transferred, personal information may form part of the relevant business assets.

Where personal information is transferred as part of a business transaction, we will take reasonable steps to ensure that it continues to be handled in accordance with applicable data-protection requirements.

Where required, affected individuals will be provided with appropriate information.


53. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

Changes may be required because of:

  • changes to UK data-protection legislation;

  • guidance from the ICO;

  • changes to our website;

  • new services;

  • new technology;

  • changes to our suppliers;

  • changes in how we process information; or

  • improvements to our privacy practices.

The most recent version will display the applicable effective and review dates.


54. Six-Month Review

We intend to review this Privacy Policy every six months.

Effective date: 1 June 2026

Last updated: 1 June 2026

Next scheduled review: 1 December 2026

Review frequency: Every six months

An earlier review may be undertaken where there is a material change to UK data-protection legislation, our business operations, website functionality or the way personal information is processed.


55. Contact Us About Privacy

If you have questions about this Privacy Policy or how your personal information is processed, please contact us.

UK Magicmushroom-psychedelicsshop

Email:
contact@ukmagicmushroom-psychedelicsshop.uk

Telephone:
+44 7529 515893

Postal address:
Ashton Road
Bournemouth
Dorset
BH9
United Kingdom

When contacting us about your personal information, please provide enough information for us to understand your enquiry.


56. Founder and Business Approval

Bryan T.K
Founder / Owner

Signature: ______________________________

Date: 1 June 2026

Elvis John K
Founder / Owner

Signature: ______________________________

Date: 1 June 2026


57. Privacy Policy Summary

Who We Are

UK Magicmushroom-psychedelicsshop

Ashton Road
Bournemouth
Dorset
BH9
United Kingdom

Contact

Telephone: +44 7529 515893

Email: contact@ukmagicmushroom-psychedelicsshop.uk

What We May Collect

  • Name

  • Email address

  • Telephone number

  • Billing and delivery details

  • Order information

  • Payment-related transaction information

  • Customer correspondence

  • Technical and website information

  • Cookie information

  • Information required for security and fraud prevention

Why We Use It

We may use personal information to:

  • process orders;

  • provide services;

  • arrange delivery;

  • manage returns and refunds;

  • communicate with customers;

  • provide support;

  • prevent fraud;

  • protect website security;

  • comply with legal obligations; and

  • operate and improve our business.

Your Rights

Depending on the circumstances, you may have rights to:

  • access your information;

  • correct inaccurate information;

  • request deletion;

  • restrict processing;

  • object to certain processing;

  • request data portability;

  • withdraw consent; and

  • complain to the ICO.

Review

Last updated: 1 June 2026

Next review: 1 December 2026

Review frequency: Every six months

Owners and CEO: Bryan T.K and Elvis John K