Legal
Privacy Policy
Last updated 2026.
01
Who we are
This privacy policy applies to the website operated by Madaia Ltd (“Madaia”, “we”, “us”, “our”), a company registered in the United Kingdom. We are the data controller for the personal data we collect through this site.
For any privacy enquiry, contact us at info@madaia.ch.
02
What we collect
We collect only what we need to fulfil orders, run the site and communicate with you:
- Account details: name, email, phone, city, date of birth, password (hashed).
- Order details: items, sizes, billing and shipping address, currency.
- Payment details: handled directly by Stripe. We do not store full card numbers.
- Browser and device data: IP address, user agent, referring page, basic analytics.
- Wishlist: the products you save for later, tied to your account.
03
How we use your data
- To process your orders and arrange delivery.
- To run your account, including login, password reset and saved items.
- To contact you about your order, returns and customer-care matters.
- If you opt in, to send you the Madaia newsletter and promotional emails. You can unsubscribe at any time.
- To improve the site and protect against fraud or misuse.
04
Lawful basis
We rely on the following lawful bases under UK GDPR:
- Contract: to fulfil orders and run your account.
- Legitimate interest: to keep the site running, prevent fraud and improve our service.
- Consent: for marketing emails and non-essential cookies.
- Legal obligation: tax, accounting and consumer-rights legislation.
05
Cookies
We use a small number of cookies and similar storage on this site. Essential cookies keep you signed in and remember your basket and preferred currency. Analytics and marketing cookies are only set with your consent.
You can clear cookies in your browser at any time. Doing so may sign you out and reset your basket.
06
Third parties
We share data only with the providers we need to run the service:
- Stripe (payments and checkout).
- Supabase (account storage and authentication).
- Royal Mail or other carriers we use for delivery.
- Email providers we use for transactional and newsletter emails.
These providers may process data outside the UK. Where they do, we rely on the appropriate safeguards required by UK GDPR.
07
How long we keep it
We keep account and order data for as long as your account is active, and for as long as we are legally required to (typically up to seven years for tax and accounting). After that, we delete or anonymise it.
08
Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Correct anything that is wrong.
- Ask us to delete it, where the law allows.
- Restrict or object to certain uses.
- Receive your data in a portable format.
- Withdraw consent for marketing at any time.
- Complain to the UK Information Commissioner’s Office (ico.org.uk).
To exercise any of these, email info@madaia.ch.
09
Security
We protect your data with industry-standard measures: TLS encryption in transit, hashed passwords, restricted internal access. No system is perfectly secure, but we work to keep yours safe.
10
Changes to this policy
We may update this policy from time to time. The latest version will always live on this page. If a change materially affects your rights, we will let you know.
