This privacy policy explains what we collect, why we collect it, who ever sees it, how long we keep it and what you can make us do with it. It is written to be read rather than to be survived.
The short version: we collect what an order needs and nothing more, we do not sell your data to anyone, and given what this site covers we keep the amount we hold as small as the job allows.
On this page
- What we collect
- Why we collect it
- Our lawful basis
- Payment details never reach us
- Who else sees it
- Discretion and packaging
- Where your data is held
- What we do not collect
- How long we keep it
- Your rights, and how to use them
- Marketing and how to stop it
- Security
- Age and children
- Changes to this privacy policy
- This policy in six lines
- How to check any privacy policy
- Making a subject access request
- If somebody else asks about you
- Questions about this privacy policy

What we collect
To take an order and send it to you we need a name, a delivery address, an email address and confirmation from the payment provider that you have paid. That is the whole of it, and this privacy policy does not hide a longer list further down.
If you contact us, we keep the correspondence, so that a later message about the same order makes sense to whoever picks it up. If you create an account, we hold the order history attached to it.
The site also counts how many times each page was viewed and which site a visitor arrived from. That comes from analytics we run ourselves, which sets no cookie, stores no identifier and sends nothing to any third party. Our cookie policy explains exactly how it works.
| What | Where it comes from | Do we need it |
|---|---|---|
| Name and delivery address | You, at checkout | Yes, the courier needs it |
| Email address | You, at checkout | Yes, for the order confirmation |
| Order history | Generated by the order | Yes, for returns and for tax records |
| Payment confirmation | The payment provider | Yes, but not the card details |
| Correspondence | You, if you write to us | Only while the matter is live |
| Page view counts | Our own analytics, no cookie | Nothing personal is recorded |
Why we collect it
To fulfil orders, to answer support messages, to understand which pages are worth writing more of, and, only where you have asked for it, to send marketing. Those are the four purposes and this privacy policy does not permit a fifth to be added quietly. The third of those uses no personal data at all.
Nothing collected here is used to build a profile of you, to score you, or to make an automated decision about you. There is no automated decision making on this site with legal or similarly significant effects, which is a question the law asks and most policies fail to answer.
Our lawful basis
UK GDPR requires a named lawful basis for each purpose rather than a general one for the site, so this privacy policy names them separately.
Performance of a contract covers everything needed to take and deliver your order. Legitimate interests covers running and securing the site, counting page views in a form that identifies nobody, and keeping records of what we sold to whom in case of a dispute. Consent covers marketing, and it can be withdrawn without giving a reason. Legal obligation covers the order records tax law requires us to keep.
Where the basis is legitimate interests you have the right to object, and we will stop unless there is a compelling reason not to, which we would then have to explain to you.

Payment details never reach us
Card numbers, expiry dates and security codes go straight to the payment provider and are never held by us at any point. What comes back to us is a yes or a no and a reference, which is the whole of what we need and the reason this privacy policy can be short about it.
That is not a courtesy, it is how card processing is required to work. It also means that if you want a card record deleted, the payment provider rather than this site is the place to ask, and their own privacy notice governs it.
Who else sees it
Two categories of provider, and no others. The courier gets the name and delivery address it needs to deliver the parcel. The payment provider gets what it needs to take payment. There is no third category, because the analytics runs on our own server rather than somebody else’s.
We do not sell your data, we do not rent it, and we do not pass it to advertisers or data brokers. No part of this privacy policy contains a clause permitting a sale in the event of anything, which is the clause worth checking on any site that claims the same.
Discretion and packaging
Given the subject matter of this site, discretion matters more than it would for a bookshop, so it is written into this privacy policy rather than left as an assumption.
Orders ship in plain outer packaging with no product names, no brand and no indication of contents on the outside. The billing descriptor on your statement is unremarkable. Nothing about what you bought is shared with anyone beyond the courier, who sees an address and not a contents list, and the payment provider, who sees an amount.
We do not disclose customer information to anyone else without a lawful obligation to do so, and a request that is not backed by one gets refused.
Where your data is held
Our hosting is in the United Kingdom and the European Economic Area, and so is everything this privacy policy describes. The analytics runs on the same server as the site rather than being sent to a provider abroad, which removes the international transfer question entirely rather than managing it.
The payment provider and the courier operate under their own privacy notices and their own transfer arrangements, and that is the one part of this we do not control. Everything we do control stays here, which is a stronger position than most online shops can honestly claim.
What we deliberately do not collect
A privacy policy that only lists what is taken tells you half the story. These are the things this site could collect, that plenty of shops do collect, and that we have chosen not to.
We do not ask for a date of birth, only for confirmation that you are over 18. We do not ask for a phone number, because the courier gets one from you at the point it needs one and we do not. We do not ask why you are buying something, and we do not record health information of any kind.
There are no third party advertising pixels on this site, so no advertising network learns that you were here or what you looked at. There is no session replay tool recording your mouse movements, which is more common than most people realise and would sit badly with everything else in this privacy policy.
The reason is simple enough. Data that was never collected cannot be leaked, subpoenaed, sold by a future owner or quietly repurposed by a policy change, and on a site about this subject that matters more than the marketing value of collecting it.

How long we keep it
Order records are kept for six years because tax law requires it, and that requirement overrides a deletion request for those specific records. Everything else goes when it stops being needed.
| Data | Kept for | Why |
|---|---|---|
| Order and invoice records | Six years | HMRC record keeping requirements |
| Account details | Until you close the account | So your order history works |
| Support correspondence | Two years | So a later message about it makes sense |
| Marketing consent | Until you withdraw it | Consent has to be evidenced |
| Page view counts | Kept indefinitely | Aggregate totals, nothing personal in them |
| Abandoned basket data | Until the session ends | It has no purpose after that |
Your rights, and how to use them
Under UK GDPR you can ask what we hold about you, ask for it to be corrected, ask for it to be deleted, ask for a portable copy, restrict what we do with it, and object to processing based on legitimate interests. This privacy policy commits us to answering within one month.
Email Contact@peakprotocol.co.uk and say which right you are using. There is no form, no fee and no requirement to give a reason, and asking will never affect how an order is handled.
The only limit is the tax records above. If you ask for deletion, everything that is not legally required to be kept goes, and we will tell you exactly what remains rather than refusing the whole request.
If you are unhappy with how we handle it, you can complain to the Information Commissioner’s Office, which regulates this in the UK. You do not have to come to us first, although it is usually quicker.

Marketing and how to stop it
Marketing email is sent only to people who asked for it. Buying something does not sign you up, and there is no pre ticked box anywhere on this site.
Every marketing email carries an unsubscribe link that works immediately rather than within the ten days some senders claim. You can also reply to any of them, or email Contact@peakprotocol.co.uk, and it stops. Order confirmations and dispatch notices are not marketing and continue, because you need them.
Security
The site runs over HTTPS throughout, administrative access is limited to the people who need it, and card data never touches our systems at all, which removes the single most attractive target.
Accounts are optional. Checking out as a guest leaves less behind than creating an account does, and this privacy policy treats that as a legitimate choice rather than nudging you out of it.
No system is perfect and this privacy policy is not going to claim otherwise. If a breach ever occurred that was likely to risk your rights, we would tell the ICO within 72 hours and tell you without undue delay, which is both the legal requirement and the only decent option.
Age and children
This site is for adults, and this privacy policy assumes an adult reader throughout. Products are not intended for anyone under 18 and the age check on entry exists for that reason. We do not knowingly collect data from children, and if we learn that we have, it is deleted.
Changes to this privacy policy
This privacy policy will change as the site does. The current version is always the one on this page, and a material change to what we collect or who sees it will be flagged rather than slipped in. Nothing changed here applies retrospectively to data already collected under a narrower version.
This privacy policy in six lines
If you read nothing else here, read this. We collect a name, an address, an email and a payment confirmation. Card details never reach us. The courier and the payment provider are the only companies that see anything about your order, and our analytics sets no cookie and identifies nobody.
We keep invoices for six years because tax law says so, and delete everything else on request. We never sell data, there are no advertising pixels on this site, and parcels arrive with nothing on the outside that says what is inside. Every promise in this privacy policy is one you can test, and the packaging one you can test on your first order.
Anything in this privacy policy that turns out not to match what we actually do is a bug, and Contact@peakprotocol.co.uk is where to report it.
How to check any privacy policy
Rather than ask you to trust this one, here is how to audit any privacy policy in about three minutes, including ours. Every check below can be run from a browser.
Search the page for the word sell. A policy that says it does not sell data will say so in one sentence, and a policy that allows it will bury the permission in a clause about business transfers. Search for the word partners, which is where an unlimited list of recipients usually hides.
Look for a retention period expressed in units of time rather than as long as necessary, which means nothing. Look for a named regulator and a route to complain that does not go through the company first. Then open the site with a content blocker running and count what it reports, because that number is the part of any privacy policy that cannot be written rather than done.
Run those five checks here and then run them somewhere else. The comparison is more persuasive than anything we could write about ourselves.
Making a subject access request
The formal name for asking what we hold about you is a subject access request, and this privacy policy deliberately does not make it feel formal. Email Contact@peakprotocol.co.uk and say what you want.
You do not need to use the phrase, quote a regulation, explain why, or fill in a form. There is no fee. We may ask one question to confirm you are the person whose data it is, usually the email address an order was placed with, and that is the only hurdle.
The answer comes within one month and arrives as a plain list rather than a database export nobody can read. If we hold nothing, we will say we hold nothing, which is the most common answer for anyone who has only ever read the guides.
If somebody else asks about you
Occasionally a company or an individual asks us to confirm whether someone is a customer. The answer is no, and this privacy policy makes that unconditional rather than case by case.
We do not confirm or deny that any person has an account or has placed an order, to an employer, a family member, an insurer, a journalist or anyone else, without either that person’s instruction or a lawful obligation such as a court order. A request that arrives without one of those gets a refusal and nothing more, including no acknowledgement that there was anything to refuse.
Given the subject matter of this site, that rule is doing real work rather than filling space, and it is the reason the discretion section above is written into this privacy policy at all.
Questions about this privacy policy
Do you sell my data?
No. Not to advertisers, not to data brokers, not to anyone. The courier and the payment provider are the only companies that receive anything at all.
Can you delete everything you hold about me?
Almost everything. Order and invoice records have to be kept for six years for tax purposes. Everything outside that is deleted on request and we will tell you what remains.
Do you store my card details?
No. They go directly to the payment provider and never reach us. We receive a payment reference and nothing more.
Will the parcel say what is inside it?
No. Plain outer packaging with no product names or branding, and an unremarkable billing descriptor on your statement.
How do I complain?
Email Contact@peakprotocol.co.uk first if you want it fixed quickly, or go straight to the Information Commissioner’s Office, which regulates this and costs nothing.
Does this privacy policy cover the guides as well as the shop?
Yes. It covers everything on this domain, including pages you can read without ordering anything.
Do you use Google Analytics?
No. We run our own analytics on our own server. It sets no cookie, stores no identifier that survives the day, and sends nothing to Google or anyone else.
Our cookie policy covers what is stored in your browser, and our terms cover the contract itself. The ICO publishes independent guidance on all of it.