Privacy policy
Last updated: 21 May 2026
This policy explains how Smrthi Ltd, trading as EcoJay ("we", "us", "our") collects, uses, and protects your personal data when you visit or purchase from our website. We are the data controller under UK GDPR and the Data Protection Act 2018. Our store is hosted on Shopify.
1. What We Collect
- Name, email, phone number, delivery and billing address
- Order history and browsing behaviour on our site
- Device and browser data via cookies and analytics tools
We never see or store your payment card details. All transactions are processed by Shopify Payments directly. See Shopify's Privacy Policy for how they handle payment data.
2. Why We Use It
| Purpose | Lawful basis |
|---|---|
| Fulfilling and managing your order | Contract |
| Customer support | Contract |
| Fraud prevention and site security | Legitimate interests |
| Improving our website | Legitimate interests |
| Order updates | Contract |
| Marketing communications | Consent — withdraw anytime |
3. Who We Share It With
We don't sell your data. We share it only where necessary with:
- Shopify — our platform provider, which hosts our store and processes payments. They act as a data processor under our instructions
- Delivery partners — to ship your order
- Analytics and marketing tools — to help us improve our service
- Legal authorities — where required by law
4. International Transfers
Shopify is headquartered in Canada and operates infrastructure in the US and elsewhere. Your data may be processed outside the UK, subject to appropriate safeguards. See Shopify's Privacy Policy for details. Any other third-party services we use involving international transfers are subject to equivalent protections.
5. How Long We Keep Your Data
Order and account data is retained for 6 years in line with HMRC requirements and the Limitation Act 1980. After this, data is deleted or anonymised. Marketing data is deleted when you withdraw consent.
6. Cookies
We use cookies for core functionality, personalisation, and analytics. Some are set by Shopify as our platform provider; others by third-party tools. Manage your preferences via the cookie banner on your first visit, or see our Cookie Policy for a full breakdown.
7. Your Rights
Under UK GDPR you have the right to access, correct, erase, restrict, object to, or port your personal data. To exercise any of these rights, contact us below.
8. Security
Payments are handled by Shopify Payments under PCI-DSS compliant infrastructure — your card data never touches our systems. For all other data we hold, we apply appropriate technical and organisational security measures and will notify you promptly of any breach affecting your information.
