1. Introduction

LoftRoll.co.uk (“we”, “us”, “our”, or “Company”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (the “Website”) and make purchases of loft insulation rolls and related products (“Products”).

Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our Website or purchase our Products.

2. Information We Collect

2.1 Information You Provide Directly:

  • Account information (name, email address, password)
  • Billing and delivery addresses
  • Payment information (processed securely through payment gateways; we do not store full card details)
  • Phone number and contact information
  • Communications and inquiries sent to us
  • Customer reviews and feedback

2.2 Information Collected Automatically:

  • Browser and device information (IP address, browser type, operating system)
  • Website usage data (pages visited, time spent, links clicked)
  • Cookies and similar tracking technologies
  • Location data (if you enable it)

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Processing and fulfilling your orders
  • Providing customer service and support
  • Sending order confirmations and delivery updates
  • Responding to your inquiries and requests
  • Improving our Website and Products
  • Sending promotional emails and marketing communications (with your consent)
  • Preventing fraud and ensuring Website security
  • Complying with legal obligations
  • Analysing website performance and user behaviour

4. Legal Basis for Processing

Under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018, we process your personal data on the following legal grounds:

  • Contract: Processing necessary to perform our contract with you
  • Consent: Where you have explicitly consented to processing
  • Legal obligation: To comply with UK law and regulations
  • Legitimate interests: For business purposes that do not override your rights

5. Cookies and Tracking Technologies

We use cookies to enhance your experience on our Website. Cookies are small text files stored on your device that help us:

  • Remember your preferences and login information
  • Understand how you use our Website
  • Personalise content and advertisements
  • Measure advertising effectiveness

You can control cookie settings through your browser preferences. Note that disabling cookies may affect Website functionality.

6. Third-Party Data Sharing

We only share your personal information with trusted third parties when necessary:

  • Payment Processors: To process your payments securely
  • Delivery Partners: To arrange delivery of your Products (we share only name, address, and phone)
  • Email Service Providers: To send newsletters and marketing communications
  • Analytics Providers: To understand website usage (anonymised data only)
  • Legal Requirements: When required by law, court orders, or government authorities

We never sell your personal data to third parties for marketing purposes.

7. Data Retention

We retain your personal information for as long as necessary to:

  • Fulfil the purposes for which it was collected
  • Comply with legal and tax obligations (typically 6 years for business records)
  • Resolve disputes and enforce our agreements

You may request deletion of your data at any time, subject to legal requirements.

8. Your Rights

Under the UK GDPR, you have the following rights:

  • Right of Access: You can request a copy of your personal data
  • Right to Rectification: You can correct inaccurate information
  • Right to Erasure: You can request deletion of your data (“right to be forgotten”)
  • Right to Restrict Processing: You can limit how we use your data
  • Right to Data Portability: You can receive your data in a portable format
  • Right to Object: You can object to marketing and other processing
  • Rights Related to Automated Decision Making: You have rights regarding profiling and automated decisions

To exercise any of these rights, please contact us at the details below.

9. Data Security

We implement industry-standard security measures to protect your personal information, including:

  • Secure Socket Layer (SSL) encryption for data in transit
  • Secure password storage with hashing
  • Regular security audits and updates
  • Access controls limiting staff access to personal data
  • Secure payment processing through PCI DSS compliant gateways

While we take security seriously, no system is entirely secure. We cannot guarantee absolute protection against data breaches.

10. Children’s Privacy

Our Website and Products are not intended for children under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will delete it immediately. Parents or guardians who believe their child has provided information to us should contact us immediately.

11. External Links

Our Website may contain links to external websites. We are not responsible for the privacy practices of third-party websites. We encourage you to review their privacy policies before providing your information.

12. International Data Transfers

Your personal data is primarily stored and processed in the United Kingdom. If we transfer data internationally, we ensure appropriate safeguards are in place, including standard contractual clauses or your explicit consent.

13. Data Protection Officer

If you have concerns about our data processing practices or wish to exercise your rights, you can contact our Data Protection Officer at the details below.

14. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated policy on our Website and updating the “Last Updated” date.

15. Contact Information

If you have questions about this Privacy Policy or our privacy practices, please contact us:

  • Email: info@loftroll.co.uk
  • Phone: 0115 795 2895
  • Address: Unit 6F, Nottingham road, Nuthall, NG16 1DP

16. Complaints and Supervisory Authority

If you believe we have violated your data protection rights, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent authority for data protection:

Last Updated: March 2026