Privacy

Privacy Policy

Last updated: January 2026

Steppas Ltd (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal data transparently and securely.

This Privacy Policy explains how we collect, use, store and protect your personal information when you visit or make a purchase from steppas.com.


1. Who we are (Data Controller)

Legal entity: Steppas Ltd
Country of registration: United Kingdom
Contact email: help@steppas.com

Steppas Ltd is the data controller responsible for your personal data under UK GDPR and EU GDPR.


2. What personal data we collect

When you interact with our website or place an order, we may collect:

  • Name
  • Billing and delivery address
  • Email address
  • Phone number (if provided)
  • Order details and purchase history
  • Payment confirmation (we do not store card details)
  • IP address and basic technical data (via cookies)

3. How and why we use your data (legal basis)

We only process personal data where we have a lawful reason to do so:

a) To fulfil your order (Contract)

  • Processing payments
  • Shipping orders
  • Order confirmations and customer support

b) Legal obligations

  • Accounting, tax, and record-keeping requirements

c) Legitimate interests

  • Fraud prevention
  • Website security
  • Improving our services and user experience

d) Consent

  • Sending marketing emails and newsletters
  • Using non-essential cookies

You can withdraw your consent at any time.


4. Marketing emails

If you opt in, we may send you updates about new releases, events, and offers.

  • Marketing emails are sent via Brevo
  • You can unsubscribe at any time using the link in every email
  • Withdrawing consent will not affect previous lawful processing

5. Cookies

We use cookies to ensure the website functions correctly and to improve your experience.

Cookies may be used for:

  • Essential site functionality (shopping cart, checkout)
  • Remembering preferences
  • Basic performance and analytics

Non-essential cookies are only used with your consent.
You can manage or withdraw cookie consent at any time via your browser settings.


6. Who we share your data with

We only share personal data with trusted third parties where necessary to run our business:

  • WooCommerce – website and order management
  • PayPal & Stripe – secure payment processing
  • Brevo – email communications
  • Royal Mail – to deliver your order
  • Hosting and IT providers – website operation and security

We never sell your personal data.


7. International data transfers

Some of our service providers are located outside the UK or EU.
Where data is transferred internationally, appropriate safeguards are in place, such as Standard Contractual Clauses, to protect your information.


8. How long we keep your data

We only keep personal data for as long as necessary:

  • Order and billing data: retained as required by UK tax and accounting law
  • Marketing data: kept until you unsubscribe
  • Customer support communications: kept only as long as needed to resolve enquiries

9. Your rights

Under UK GDPR and EU GDPR, you have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of your data
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent at any time
  • Lodge a complaint with a data protection authority (UK ICO or your local EU authority)

To exercise any of these rights, contact us at help@steppas.com.


10. Data security

We take appropriate technical and organisational measures to protect your data, including:

  • Secure servers and encrypted connections
  • Trusted payment providers
  • Limited access to personal information

11. Changes to this policy

We may update this Privacy Policy from time to time.
Any changes will be posted on this page with an updated revision date.