Purpose of Privacy Policy
Our Privacy Policy is to inform you how we handle personal data and information you share through your interaction with our website, box.co.uk (the "Site"), and any related communication between us. This policy aims to clarify the collection and utilisation of your data, ensuring you are well-informed about our practices. Take the time to read through and understand this privacy policy, as it outlines the types of personal data we gather during your engagement with our website and how we leverage that information to enhance your experience at Box.
Your privacy is of utmost importance to us, and this policy is designed to uphold the transparency and trust you place in us, as you navigate our website and communicate with us.
If you have any questions or concerns regarding your privacy or this policy, please reach out to our Data Protection Officer at dataprotection@box.co.uk
About Us
Exceeding customer expectations for 27 years and counting, Box is a leading retailer in the UK's tech market, offering new tech devices, including laptops, smartphones, PCs, tablets, accessories, and more. Our aim is to provide top-quality products at unbeatable prices, making us the ultimate destination for all your computing needs. With over two decades of experience, a dedicated team, and a commitment to excellence, Box continues to inspire possibilities by ensuring that technology is accessible to all. Join us in this exciting journey of exploration and innovation, where your tech aspirations become a reality.
What Information Do We Collect from You?
We will gather and process the following data about you:
Information Provided by You when Placing an Order:
- When you place an order, we collect your name, email address, billing address, delivery address, phone number, financial information (credit card or debit card number in tokenised format), and unique identifiers (username and hashed password). Moreover, we save the order information and transactions to and from you to keep a record.
Using Our Website
We and our third-party providers (for content and ads) are authorised to handle and collect your below mentioned information:
Information You Provide:
Information filled in forms on our Site, including a subscription to join the Box Offers Newsletter.
Automatically Collected Information:
Information received and recorded from your browser or mobile device, such as URL you are coming from, IP address, unique device identifier, accepted cookies, and data about visited pages.
Device-specific information that we may automatically collect when you visit our Site, including hardware model, operating system details, browser information, and device identifiers.
Details and information of how you use our Site.
Information from Competitions or Promotions:
Information provided if you enter a competition or promotional feature on our Site, including name, address, email address, telephone number, and country of residence.
Contacting Us
Records of any correspondence we have with you. We may monitor or record any communications we have with you, including phone calls and emails.
Business Customers
Information provided by business customers, including contact details of a point of contact within your organisation and/or person whom we will be required to provide support to, including but not limited to: address, billing address, email address, telephone number, financial information (credit or debit card number and expiry date stored in a tokenised format), and unique identifiers (username and hashed passwords). Hashed passwords are not visible to us.
We confirm that any personal information you provide to us (or which is available on public registers) and any user information that can identify you, is held in accordance with the registration we have with the Data Commissioner's Office. We use your information only for the following purposes:
How Do We Use This Information?
We use information about you in the following ways:
- To open your account on our Site and maintain your records
- Process your order, arrange delivery or collection of your products
- To contact you in relation to your order, process payments, respond to requests and queries, and check payment card usage consent.
- To provide warranty support.
- Asking you to leave a review on our service.
- To train staff and improve customer service, ensuring effective presentation of content on our Site.
- To conduct survey for improving the website's performance.
- To provide suggestions and recommendations about products of interest, special offers, or promotions via the Site or by email, SMS, telephone, social media, or post.
- To telephone you to check if you need any help with your orders.
- To run competitions and contact you if you are a winner.
- Use contact details collected for marketing or contacting you via social media platforms.
Manage your account/provide customer services to you. This may include transfers to Third parties who undertake customer services/communications activities, call recording data verification, and customer complaints/queries.
Using Our Website
We and our third-party providers (for content and ads) are authorised to handle and collect your below mentioned information:
Internal Business Purposes
For Internal Purposes:
Conduct internal activities such as website and system administration.
Data Analytics:
Perform data analytics, including parts of our Site visited, for marketing, and to enhance customer experience.
Legal and Regulatory Obligations:
Comply with legal and regulatory obligations, including crime and fraud prevention purposes.
Logistics planning, demand forecasting, management information and research
By using our website, you agree to us collecting and processing your data for these purposes. If you have any questions or concerns about this, please reach out to our Data Protection Officer at dataprotection@box.co.uk.
Please note that we will only use your personal data when the law allows us to. Data protection law sets out a number of different legal grounds upon which data controllers can legally process personal data.
In most cases, we process your data to take steps at your request before entering a contract with you, or because the processing is necessary to fulfil our contract with you.
In accordance with data protection law, we make sure we consider and balance any potential impact on you and your rights before we process your data for our legitimate interests. If the potential impact on you and your rights overrides our legitimate interests, we will not process your data, unless we are able to do so using a different legal basis.
Where the processing is necessary to comply with our legal obligations, a court order or to exercise or defend legal claims.
What We Use Your Personal Information For | Reasons (Legal Basis) | Explanation / Legitimate Interests |
---|---|---|
Set up your Account when you Sign-up | • Legitimate interest | Process efficiency in dealing with such activity. |
Storing payment related info | • Consent | Required for Order / Invoice Details |
Process your orders | • Fulfilling a contract | Required for Order / Invoice Details |
Notify you of your order status. | • Legitimate interests | Process efficiency in dealing with such activity, and to make improvements to our services. |
Manage your account/ provide customer services to you. This may include: transfers to Third Countries who undertake customer services/communications activities call recording data verification customer complaints/queries | • Legal obligation/ Legitimate interests (depending on nature of services) | Keeping our records up to date, handling our customer contact efficiently and effectively, working out which of our products and services may interest you and telling you about them. |
To detect, investigate and report any Fraud or financial crime | • Legal Obligation / legitimate reason | Developing and improving how we deal with financial crime. Complying with any legal obligation placed on us by regulators. Complying with any regulations that apply to us. Process efficiency in dealing with such activity, and to make service and process improvements. |
Undertake website personalisation and administration. | • Legitimate reason | Developing products, services, applications and designs that attract and retain customers. Improving customer interaction with our sites. Defining types of customers for new products or services |
Marketing communications to inform you of special offers, promotions, new lines and Sales. Provide you with online advertising. | • Legitimate reasons | Developing products, services, applications and designs that attract and retain customers. Improving customer interaction with our sites. |
Notifying you about enhancements to our services, such as changes to the website and new services that may be of interest to you. | • Legitimate reasons | Developing products, services, applications and designs that attract and retain customers. Improving customer interaction with our sites. |
Contact you to undertake customer satisfaction surveys, invite you to provide product reviews or for market research. | • Legitimate reasons | Developing products, services, applications and designs that attract and retain customers. Improving customer interaction with our sites. |
Maintaining network and data security | • Legitimate reasons | To maintain the security of our network this in turn helps us to maintain the safety and confidentiality of your information. |
Logistics planning, demand forecasting, management information and research | • Legitimate interests | We use information about shopping habits, products bought and volumes, to help us to respond to demand, ensure the right products get to the right areas and to help us plan our ranges. |
How long will we keep your data for?
If you have ordered through our website, we will store your data for a maximum of 7 years. This is to enable us to retrieve your data if there is a dispute or you bring a claim against us during the statutory 6-year limitation period and to comply with HMRC’s requirements in relation to keeping records. Our customer database is cleared annually and all customer data that is no longer required is deleted. The only exceptions to this are where:
- The law requires us to hold your personal information for a longer period, or delete it sooner.
- You exercise your right to have the information erased (where it applies) and we do not need to hold it in connection with any of the reasons permitted or required under the law such as for Accounts and Invoice legal bindings.
- We bring or defend a legal claim or other proceedings during the period we retain your personal information, in which case we will retain your personal information until those proceedings have concluded and no further appeals are possible; or
- In limited cases, existing or future law or a court or regulator requires us to keep your personal information for a longer or shorter period.
Protection of Your Personal Information
At Box, your privacy is our utmost priority. We want you to feel confident that any personal information you share with us is protected and secured. Rest assured that we are committed to safeguarding your data and using it exclusively for legitimate purposes.
We are committed to transparency and accountability in how we handle your personal information. You can find more detailed information about our data protection practices in our GDPR policies.
Temporary Data Retention: We understand the importance of privacy and data minimisation. Therefore, any information provided for security checks that we request from you will be stored for a maximum of 14 days (about 2 weeks) after submission. This period allows us to perform the necessary checks while respecting your right to data protection
Immediate Deletion: Once the required checks have been successfully completed and cleared, please be assured that any information we receive is promptly deleted. Your data will not linger in our systems beyond what is necessary to fulfil its intended purpose.
Who do we disclose your information to?
Our Distribution Partners
There are many service providers who work and provide services on our behalf so we may need to share your information with them. All these distributors undergo security checks, and we only provide the necessary information that is required to carry out the process smoothly.
At the time of writing this Privacy Policy, we use the following service providers to provide us with services:
- Payment services providers: We integrate third-party payment providers like PayPal, Pay in 3, Apple Pay, Google Pay, and Stripe into our site. You will be redirected to the respective provider's portal when utilising these platforms for transactions. Your engagement with these services is governed by the terms, conditions, and privacy policies of the individual payment providers.
- IT security services providers
- Third-party databases, against which we validate your details to verify your identity and prevent fraud. To perform these checks, your personal information may be disclosed to a registered Credit Reference Agency, which may retain a record of this information. It's important to note that this disclosure is solely for identity confirmation purposes, and no credit check is conducted, preserving the integrity of your credit rating. Additionally, Box collaborates with businesses that endorse our website and other corporate systems, such as Norton and Microsoft Office.
- Delivery service providers
- Email distribution service providers
- Google Customer Reviews, Trust Pilot and Reevoo: These services enable you to provide feedback on your purchase experience with us.
- Manufacturers and providers of warranty services.
Other Third Parties
We may provide your information to the manufacturer of any device you have bought, so that they can repair it under warranty.
On occasion, if we do not have items in stock, we may ask our supplier to send your items to you directly. In that case, we will need to provide them with your order and delivery details.
We may disclose your personal information to any member of our group, which means our ultimate holding company and its subsidiaries, as defined in section 1159 of the UK Companies Act 2006.
We may also disclose your personal information to third parties:
- In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.
- You request or authorize the disclosure of information to a third party.
- If we or substantially all of our assets are acquired by a third party, in which case personal data held by us about our customers is likely to be one of the transferred assets.
- If we are under a duty to disclose or share your personal data in order to comply with any legal or regulatory obligation.
Your rights
As a data subject, you have the following rights to:
- Request access to your personal information, commonly known as “data subject access request”, and details about how we process it. This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it. More information is available on the Information Commissioner's website: www.ico.org.uk.
- Have your personal information corrected if it is inaccurate or incomplete.
- Request the erasure of your personal information, commonly known as “right to be forgotten” – under above set scenarios.
- The right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law.
- Restrict the processing of your personal information.
- The right to object to the processing on grounds relating to your particular situation, where we are relying on a legitimate interest (or those of a third party). In some cases, we may demonstrate that we have compelling legitimate grounds to process your information, which overrides your rights and freedoms. You also have the right to object to where we are processing your personal data for direct marketing purposes.
- Object to processing based on legitimate interest or for direct marketing purposes.
- Request your data in a machine-readable format (in limited circumstances).
If you have questions or want to exercise these rights, contact dataprotection@box.co.uk
Identity Verification and Fraud Prevention Measures
Before providing services, goods, or financing, we conduct checks to prevent fraud and verify your identity, requiring proof of address.
The personal data collected (name, address, etc.) is used to prevent fraud and money laundering and verify identity.
We may share data with law enforcement for crime prevention.
Processing is based on a legitimate interest and contractual requirements. Fraud prevention agencies may retain data for up to seven years.
Consequences of Processing: If a fraud risk is determined, we may refuse requested services, financing, employment, or cease existing services. Contact us for inquiries, click here.
Do we transfer your data outside of the UK?
Some of our third-party service providers are operating outside of the UK. We may transfer your data outside of the UK in case these providers are involved in order processing.
When we transfer your personal data outside the UK, we ensure the security and protection of your data complied with data protection laws. This is achieved by implementing at least one of the following:
- Transferring data only to countries that have been determined to offer an adequate level of protection for personal data.
- When using specific service providers, we may use specific contracts approved for use in the UK which give personal data the same protection it has in the UK.
The cookies, we use, fall into four types:
Strictly Necessary Cookies
These cookies are essential in helping you move around our Site and use its features, such as accessing secure website areas. Without these cookies, services you have requested, such as setting up an account, cannot be provided. These cookies do not gather information about you that could be used for marketing or remembering where you've been on the Internet.
Analytical/Performance Cookies
To keep the Site and its services and products relevant, easy to use, and up to date, we use web analytics services to help us understand how people use our Site. For example, we can see which parts of the Site and products are most popular, identify when errors occur, and test different versions of a page or feature to see which works best.
Functionality Cookies
These cookies allow websites and applications to remember choices you make (such as your username, language or the region you are in) and provide enhanced, more personal features. The information these cookies collect is usually anonymised, so we can't identify you personally. They do not gather any information about you that could be used for selling advertising or remembering where you've been online. Still, they do help us serve you with advertising that is more relevant to you.
Targeted Marketing Cookies
We also use cookies to assist in targeted advertising. These cookies are necessary for online advertisements you encounter to be more relevant to you and your interests. We also use them to measure the effectiveness of our marketing communications, for example, by asking us if you have responded to an advert we sent you.
If you would like more information on any of these types of Cookies, including how to opt out, please visit www.youronlinechoices.com/
Details of our Third-Party Cookies
Box allows certain third parties, engaged in our marketing program, to place cookies during your visit to our website. These cookies allow us to monitor ads you view and click on to access our site.
Details of the third-party cookies are in the following table. We, as a company, do not take responsibility for the privacy policy or content of these third parties, so we recommend verifying these independently.
The following cookies are for analytical and targeting purposes.
Google Tag Manager | Google Policies |
Google Analytics | Google Policies |
Google Ads | Google Policies |
Google Audiences | Google Policies |
Bing Ads | Microsoft Advertising Privacy Policy |
Oracle Marketing Cloud | Oracle Advertising Privacy Policy |
DoubleClick | DoubleClick Privacy Policy |
Facebook Connect | Facebook Privacy Policy |
Facebook Custom Audiences | Facebook Privacy Policy |
Twitter / X | Twitter / X Privacy Policy |
Reevoo | Reevoo Privacy Policy |
Affiliate Future | Affiliate Future Privacy Policy |
Opting Out
Website visitors who don't want their data used by Google Analytics can install the Google Analytics opt-out browser add-on. To opt out of Analytics for the web, visit the Google Analytics opt-out page and install the add-on for your browser. Learn more about the opt-out and how to install the browser add-on here.
Visitors can also opt out of Google Analytics for Display Advertising and customise Google Display Network ads using Ads Settings
How to contact us
If you have any questions about how we use your personal data or if you'd like to exercise any of your rights, please contact us. You can get in touch by emailing us at dataprotection@box.co.uk using subject: “Security and Privacy Query”.