Last updated: 5 October 2026
This policy explains what personal data Floritta collects when you visit floritta.uk, order from us by any channel, or receive flowers from us, what we do with it, who we share it with, how long we keep it and what rights you have.
1. Who we are
Floritta Ltd ("Floritta", "we", "us") is the controller of your personal data.
Company number 13358527, registered in England and Wales. VAT number 405133247.
Registered office and studio: Unit 3 The Willows, 80 Willow Walk, London SE1 5SY, United Kingdom.
Registered with the Information Commissioner's Office, registration number ZB555605.
Email: info@floritta.uk · Telephone: +44 7458 683130.
We have not appointed a Data Protection Officer. Any question about this policy or your data goes to info@floritta.uk.
2. What we collect
- When you order (on this website, by phone, WhatsApp, Instagram, email or in our shop): your name, email address, telephone number, billing address; the recipient's name, delivery address and telephone number; the card message or the voice note you may record for the florist instead of typing (an optional audio message of up to two minutes); delivery date, time slot and instructions; what you bought and what you paid.
- When you pay: we do not see or store your full card number. Card payments are taken by Stripe (and, for subscriptions, by Revolut). We keep the payment reference, amount, result and the last four digits shown on your receipt.
- When you create an account: your login details (your password is stored only in encrypted form), saved addresses and recipients, order history, loyalty points, gift cards and your marketing choices.
- When you contact us: your contact details and what you tell us. Calls to and from our customer line are recorded and may be automatically transcribed. Messages sent through WhatsApp or Instagram reach us through our messaging provider; voice messages you send us there are kept with the conversation so our team can listen to them.
- When we deliver: our courier may take a photograph at the delivery address as proof of delivery. It shows the door or the place the flowers were left and may show the person who accepted them.
- When you use the website: your IP address, device and browser type, pages viewed, how you reached us (including an advertising click identifier, if you came from an advert and allowed advertising cookies) and similar information – through cookies and similar technologies, as described in section 9. If you allow analytics cookies, Microsoft Clarity records how pages are used (clicks, scrolling and mouse movement); text you type into forms is masked.
- If you order for a business: the work contact details of the people who deal with us and the details we need to invoice.
If someone sent you flowers. The sender gave us your name, address and usually your telephone number so that we could deliver. We use them only to deliver that order, to contact you about the delivery and to prove delivery if there is a dispute. We do not send you marketing because someone sent you a gift. You have the same rights over your data as our customers – see section 7.
3. Why we use it and our legal basis
| What we do | Legal basis (UK GDPR) |
|---|---|
| Take, prepare and deliver your order, take payment, send order and delivery updates, issue receipts and invoices | Contract with you – Article 6(1)(b) |
| Use the recipient's details to deliver and to contact them about the delivery | Our legitimate interest in delivering the order that was paid for – Article 6(1)(f) |
| Answer questions, handle complaints, replacements and refunds | Contract, and our legitimate interest in resolving issues – Article 6(1)(b) and (f) |
| Record and transcribe calls, and keep delivery photographs, to get orders right, train our team and prove what happened in a dispute or chargeback | Our legitimate interests – Article 6(1)(f) |
| Use an AI assistant to help our team read, sort, translate and draft replies to your messages (a member of our team is responsible for every reply) | Our legitimate interest in answering quickly and accurately – Article 6(1)(f) |
| Record with your order how you reached our website (the channel and campaign, the referring website and the first page you viewed), only for aggregated reports on where our orders come from. It is not used to target you and is not shared with advertising platforms | Our legitimate interest in improving our website and service – Article 6(1)(f); you can object at any time |
| Keep accounting, tax and payment records | Legal obligation – Article 6(1)(c) |
| Run your account, loyalty points, referral codes, gift cards and subscriptions | Contract – Article 6(1)(b) |
| Ask for feedback or a review after an order | Our legitimate interests – Article 6(1)(f); you can opt out at any time |
| Send existing customers marketing about our own similar products, including reminders of occasions you bought for before | Our legitimate interests, relying on the "soft opt-in" in regulation 22(3) of the Privacy and Electronic Communications Regulations (PECR). Every message has an unsubscribe option |
| Send marketing to anyone else, including our newsletter | Your consent – Article 6(1)(a) |
| Analytics, session recording and advertising cookies and pixels | Your consent through our cookie banner – PECR regulation 6 and Article 6(1)(a) |
| Share a hashed version of your email address and telephone number with Google Ads when you complete an order (see section 4) | Your consent to advertising cookies – Article 6(1)(a) |
| Prevent and investigate fraud and misuse, and keep our systems secure | Our legitimate interests, and legal obligation where it applies |
| Establish, exercise or defend legal claims | Our legitimate interests – Article 6(1)(f) |
You can withdraw consent at any time: use the unsubscribe link in any email, reply STOP to a text, change your choices through "Cookie settings" (link at the bottom of every page), or email info@floritta.uk. Withdrawing consent does not affect what we did lawfully before.
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
4. Who we share it with
We do not sell your personal data. We share it only with the organisations below, and only what each one needs.
Delivering and taking payment for your order
- Couriers and delivery services – our own couriers and, when needed, Uber (Uber Direct), Stuart and Gophr: the recipient's name, address, telephone number and delivery instructions.
- Stripe – card payments and refunds. Revolut – subscription payments. CryptoCloud – only if you choose to pay in cryptocurrency.
- Marketplaces – if you ordered through Uber Eats, Deliveroo, Just Eat or Flowwow, that platform collects your data under its own privacy policy and passes us what we need to fulfil the order.
- Address lookup – Google (Places and Address Validation) and Ideal Postcodes check the address you type.
Running our business
- Hosting and infrastructure – Hostinger (our servers, in the United Kingdom), Cloudflare (website delivery, security and encrypted backups), Sentry (error monitoring).
- Communications – Ringover (telephone calls, recordings and text messages), Wazzup (WhatsApp and Instagram messages), Resend and Google (email).
- AI assistant – Anthropic processes the content of customer messages on our instructions to help our team sort, translate and draft replies. It is not allowed to use your data to train its models.
- Automation – n8n (workflow automation, used to pass website events between our systems).
- Accounting – Xero and Hubdoc, and our accountants.
- Authorities – HMRC, the police, the licensing authority, the courts or other regulators where the law requires it or to establish or defend legal claims.
Analytics and advertising – only if you allow those cookies
- Google – Google Analytics (how the site is used), Google Tag Manager (the tool that loads these tags) and Google Ads (measuring which adverts lead to orders and showing our adverts). When you complete an order and have accepted advertising cookies, Google's tag creates a one-way coded version (a SHA-256 "hash") of your email address and telephone number in your browser and sends it to Google, so that Google can match your purchase to an advert you clicked ("enhanced conversions"). Google does not receive them in readable form from us. If you have declined advertising cookies, this does not happen.
- Meta (Facebook and Instagram) – Meta Pixel: pages viewed and purchases, to measure and show our adverts.
- Pinterest – Pinterest Tag: pages viewed, searches, basket and purchase events (without your name, email or telephone number), to measure and show our adverts.
- Microsoft – Clarity: heatmaps and session recordings, to find what does not work on the site.
- Awin – our affiliate network: when you arrive from a partner website and buy, Awin receives the order reference and value so the partner can be paid.
Our service providers act on our instructions under contracts that protect your data. Stripe, Revolut, the marketplaces, Google, Meta, Pinterest, Microsoft and Awin also act as independent controllers for part of what they do, under their own privacy policies.
5. Transfers outside the UK
Some of these providers process data outside the United Kingdom, mainly in the European Economic Area and the United States. For the EEA we rely on UK adequacy regulations. For the United States we rely on UK adequacy regulations for organisations certified under the UK Extension to the EU–US Data Privacy Framework (such as Google, Meta, Microsoft and Stripe), and otherwise on the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. You can ask us for details of these safeguards at info@floritta.uk.
6. How long we keep it
| Information | How long |
|---|---|
| Orders, payments, refunds and invoices | 6 years after the end of the financial year in which the order was placed (UK tax law) |
| Your customer account, contact details and order history | 6 years after your last order or login; then we remove your personal details and keep only anonymous sales figures |
| Recipient details | Kept with the order for 6 years, only as evidence of delivery |
| Card messages, voice notes for the florist and order comments | 24 months |
| Emails, chats, WhatsApp and Instagram messages | 6 years after the last message |
| Call recordings and transcripts | 24 months |
| Delivery photographs | 24 months |
| Complaints, disputes and chargebacks | 6 years after they are closed |
| Gift cards | Until the card expires, plus 6 years |
| Marketing | Until you unsubscribe. If you have not ordered for 24 months, we stop sending you marketing |
| Records of your marketing consent or opt-out | For as long as the consent lasts, plus 6 years |
| "Do not contact" list | Indefinitely, with the minimum details needed to keep our promise |
| Enquiries that did not lead to an order | 24 months |
| How you reached our website and advertising click identifiers, stored with your order | 13 months after the order |
| Website analytics (Google Analytics) | 14 months |
| Session recordings (Microsoft Clarity) | As set by Clarity: recordings for about 30 days, summary reports for up to 13 months |
| Security and error logs | Up to 12 months |
We keep information for these periods because UK tax law requires it or because a claim about an order can be brought within six years. When a period ends we delete the data or anonymise it so that it can no longer identify you. Copies can remain in our encrypted backups for up to about a month until they are overwritten.
7. Your rights
You have the right to:
- access – get a copy of the personal data we hold about you;
- rectification – have inaccurate or incomplete data corrected;
- erasure – ask us to delete your data (we may have to keep some of it, for example invoices, where the law requires);
- restriction – ask us to pause using your data while a question about it is resolved;
- portability – receive the data you gave us in a common machine-readable format, or have it sent to another organisation;
- object – to any use based on our legitimate interests, and at any time to direct marketing, which we will then stop;
- withdraw consent – where we rely on consent.
Email info@floritta.uk. We reply within one month (we may extend this by up to two further months for complex requests, and will tell you if we do). There is no charge. We may ask you to confirm your identity – usually through the email address or telephone number on your order.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You can also complain to the Information Commissioner's Office: ico.org.uk, telephone 0303 123 1113.
8. Security
Access to customer data is limited to staff who need it and protected by individual logins; our systems use encrypted connections; backups are encrypted. No system is completely secure; if a breach affecting your data were likely to put you at high risk, we would tell you.
9. Cookies and similar technologies
Strictly necessary cookies keep the site working – your basket, checkout, login, security and your cookie choices – and are always on. Analytics, session recording and advertising cookies are used only if you allow them in our cookie banner. You can change your choices at any time through "Cookie settings" (link at the bottom of every page).
| Category | Examples | What for | Lifetime |
|---|---|---|---|
| Strictly necessary | session and security cookies, your cookie choices (cookiePreferences, flo_nostat), promo and referral code, gift card code, last basket | Basket, checkout, login, remembering your cookie choices and a code you applied | Session up to 1 year |
| Site statistics | flo_src (Floritta, first party) | Remembers how you first and most recently arrived (for example from a Google search, Instagram, our newsletter or a campaign link) and the first page you viewed, so we can count in aggregate which channels bring visitors and orders. It contains no identifier and is not used for advertising or shared with anyone. It is set under the statistical purposes exception in PECR (Schedule A1, paragraph 5) and is switched off by "Decline" or at any time in Cookie settings | 30 days |
| Site functions | recently viewed products (viewed_products), the delivery postcode and date you entered on a product page (kept in your browser), the version of the size selector you were shown (fl_ssv) | Showing you back what you looked at or entered, and keeping the page the same between visits. They hold no name, email address or telephone number and are not shared with anyone. You can remove them by clearing cookies and site data in your browser | Up to 12 months |
| Analytics | Google Analytics _ga, _ga_*; Microsoft Clarity _clck, _clsk | Understanding how the site is used | Up to 13 months |
| Advertising | Google Ads _gcl_*; Meta _fbp, _fbc; Pinterest _pin_unauth; Awin awc; our flo_attr | Measuring and showing our adverts, paying affiliate partners | Up to 13 months |
10. Children
Our website is not intended for children under 16 and we do not knowingly collect their personal data. If you believe a child has given us their data, email info@floritta.uk and we will delete it. Alcoholic products are sold only to adults aged 18 or over.
11. Other websites
Links to other websites are not covered by this policy.
12. Changes to this policy
We may update this policy. The current version is always on this page, with its date at the top. We keep previous versions and will send you one on request.
13. Contact us
Email: info@floritta.uk
Phone: +44 7458 683130
Address: Unit 3 The Willows, 80 Willow Walk, London SE1 5SY