Privacy policy
Privacy Policy
Last updated: 28 April 2026
This Privacy Policy explains how Octagon Studio UK Ltd ("Octagon Studio", "we", "us", or "our") collects, uses, and shares personal information when you visit, use, or make a purchase from store.octagonstudio.com (the "Site") or otherwise interact with us.
We are the data controller for the personal information we collect through the Site. Our contact details are at the end of this policy.
Please read this policy carefully. By using the Site, you agree to the collection and use of your information as described here.
1. Who We Are
Octagon Studio UK Ltd is a company registered in England and Wales.
Company number: 11274897
Registered office: 93 Tabernacle Street, London, England, EC2A 4BA
Email: info@octagonstudio.com
We sell augmented reality flashcard products globally via store.octagonstudio.com and other channels.
2. What Information We Collect
The information we collect depends on how you interact with us.
Information you give us directly:
- Contact details: name, email address, phone number, billing address, and shipping address
- Order information: items purchased, order value, payment confirmation, and order history
- Communications: messages, queries, or feedback you send us
- Marketing preferences: your subscription status for our email marketing, where applicable
Information collected automatically when you use the Site:
- Device and connection information: IP address, device type, browser type, operating system, and language
- Site usage information: pages viewed, items viewed and added to cart, time spent on pages, referral source, and similar interaction data
- Cookie and tracking information: data collected via cookies, pixels, and similar technologies (see Section 7)
Information from third parties:
- Payment processors confirm successful payment but do not share full card details with us
- Advertising platforms (such as Meta) may share aggregate or audience-level data about ad performance
- Shipping carriers share tracking and delivery status
We do not knowingly collect sensitive personal information (such as health data, biometric data, or political opinions) and we do not require it to provide our products or services.
3. How We Use Your Information
We use your personal information for the following purposes:
To fulfil your order: processing payment, arranging shipping, providing tracking, handling returns, and communicating about your order. The legal basis for this is performance of our contract with you.
To provide customer support: responding to enquiries, resolving issues, and processing refund or warranty claims. The legal basis is performance of our contract with you and our legitimate interests in providing good customer service.
To run and improve the Site: ensuring the Site works correctly, analysing usage to improve performance and content, detecting and preventing fraud or abuse, and enforcing our Terms of Service. The legal basis is our legitimate interests in operating a secure and effective business.
To send marketing communications: sending you product updates, promotions, and similar messages where you have subscribed or are an existing customer with the right to receive limited marketing about similar products. The legal basis is your consent (for new subscribers) or our legitimate interests under the soft opt-in rule for existing customers. You can unsubscribe at any time using the link in any marketing email.
To run advertising and measurement: tracking the performance of our advertising on third-party platforms such as Meta and Google, building marketing audiences, and showing you relevant ads. The legal basis for non-essential tracking is your consent given via our cookie banner.
To comply with legal obligations: meeting tax, accounting, consumer protection, and other regulatory requirements.
4. Children's Privacy
Our products are designed for use by children, but the Site and ordering process are intended for adults aged 18 or over. We do not knowingly collect personal information directly from children through the Site.
Our companion app is provided by our licensor and may collect limited technical data such as device type, operating system, and crash diagnostics to improve app stability. The app does not collect personal information from users. The app is governed by its own privacy notice published on the relevant app store.
If you are a parent or guardian and believe a child has provided us with personal information in error, please contact us and we will delete it.
5. Who We Share Your Information With
We share your personal information with the following categories of third parties for the purposes described:
Service providers operating on our behalf:
- Shopify Inc. — operates the Site infrastructure, processes orders, and stores customer account data
- Shopify Payments, Stripe, and PayPal — payment processors handling card transactions and fraud screening
- Royal Mail and UPS — shipping carriers receiving your name, address, and contact details to deliver your order
- Klaviyo Inc. — email marketing platform handling our customer communications, where applicable
- Customer support and operational tools used to respond to your enquiries and run the business
Advertising and analytics partners (where you have consented):
- Meta Platforms, Inc. (Facebook and Instagram) — receives Site usage and conversion data via the Meta Pixel and Conversions API for advertising measurement and optimisation
- Google LLC — provides analytics and advertising services, including Google Analytics and Google Ads where applicable
Other parties:
- Tax authorities, regulators, and law enforcement where required by law
- Professional advisers (lawyers, accountants) where necessary
- A buyer or successor in the event of a sale, merger, or restructuring of our business
We do not sell your personal information for monetary consideration. Some of the advertising partners above may receive personal information in ways that are defined as "selling" or "sharing" under certain US state privacy laws. You can opt out of this via our cookie banner.
This list reflects our principal third parties. We will update this policy when we add or change significant partners.
6. International Data Transfers
We are based in the UK. Some of our service providers (such as Shopify, Meta, Google, Klaviyo, and others) are based in the United States or other countries outside the UK and EEA.
When we transfer personal information outside the UK or EEA, we rely on legally recognised transfer mechanisms, including:
- Adequacy decisions made by the UK government or European Commission, where they apply
- Standard Contractual Clauses (or the UK International Data Transfer Addendum) for transfers to countries without an adequacy decision
- Other appropriate safeguards as required by data protection law
You can request a copy of the relevant safeguards by contacting us.
7. Cookies and Tracking Technologies
The Site uses cookies and similar technologies to function correctly, remember your preferences, analyse usage, and deliver advertising.
Strictly necessary cookies (such as those that keep your shopping basket working) do not require consent.
All other cookies — including analytics, marketing, and advertising cookies — are set only where you have given consent via our cookie banner. You can change your preferences at any time by clicking the cookie settings link on the Site.
The principal third-party tracking on the Site is provided by Shopify (platform analytics), Meta (advertising and conversion measurement), and Google (analytics and advertising) where applicable. Each of these providers has its own privacy policy.
We recognise the Global Privacy Control (GPC) signal sent by some browsers as a valid request to opt out of "sale" or "sharing" of personal information for advertising purposes, where this concept applies.
8. How Long We Keep Your Information
We keep personal information only for as long as necessary for the purposes for which it was collected, plus any period required by law:
- Order and transaction records: 6 years from the date of the order, to meet UK accounting and tax requirements
- Customer support communications: 2 years from the date of the last interaction
- Marketing subscriptions: until you unsubscribe, after which we keep a suppression record indefinitely to ensure we do not contact you again
- Site analytics data: typically up to 26 months in aggregated or pseudonymised form
- Account data (where applicable): for as long as your account is active, plus 6 years from closure for record-keeping
When we no longer need your information, we delete or anonymise it.
9. Your Rights
Depending on where you live, you have rights in relation to your personal information. For UK and EEA residents, your rights under the UK GDPR and EU GDPR include:
- Right of access: to receive a copy of the personal information we hold about you
- Right to rectification: to have inaccurate information corrected
- Right to erasure: to request deletion of your information in certain circumstances
- Right to restrict processing: to limit how we use your information in certain circumstances
- Right to data portability: to receive certain information in a machine-readable format
- Right to object: to object to processing based on our legitimate interests, or to direct marketing
- Right to withdraw consent: where we rely on consent, you can withdraw it at any time
- Right not to be subject to automated decision-making with legal or similarly significant effects
Residents of California, other US states with applicable privacy laws, and other jurisdictions may have similar or additional rights, including the right to opt out of "sale" or "sharing" of personal information.
To exercise any of these rights, contact us at info@octagonstudio.com. We will respond within the timeframes required by law (typically one month under the UK GDPR).
We may need to verify your identity before responding to a request. Exercising your rights is free, though we may charge a reasonable fee for repetitive or excessive requests.
If you are not satisfied with how we handle your request, you can complain to:
- The UK Information Commissioner's Office (ICO) — ico.org.uk
- Your local EU data protection authority, if you are an EEA resident
- Your state attorney general or relevant regulator, if you are a US resident
10. Marketing Communications
If you have signed up for our marketing emails or are an existing customer, we may send you marketing about our products. You can unsubscribe at any time:
- Click the unsubscribe link at the bottom of any marketing email
- Email info@octagonstudio.com asking to be removed from marketing
Unsubscribing from marketing does not affect transactional emails such as order confirmations, dispatch notifications, or responses to your enquiries.
11. Security
We take reasonable technical and organisational measures to protect personal information against loss, misuse, unauthorised access, and disclosure. Payment processing is handled by PCI-compliant providers and we do not store full payment card details ourselves.
No system is perfectly secure. While we work to protect your information, we cannot guarantee absolute security, and you provide your information to us at your own risk.
If a data breach occurs that affects your personal information and is likely to result in a high risk to your rights, we will notify you and the relevant authorities as required by law.
12. Third-Party Sites
The Site may contain links to third-party websites, including social media platforms. We are not responsible for the privacy practices of those sites. We encourage you to read their privacy policies before providing them with your information.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent version. Material changes will be notified via the Site or by email where appropriate. The version in force at the time you use the Site will apply.
14. Contact Us
For any questions about this Privacy Policy, to exercise your rights, or to make a complaint, please contact:
Octagon Studio UK Ltd
93 Tabernacle Street, London, England, EC2A 4BA
info@octagonstudio.com
Company number: 11274897
We are the data controller for the personal information described in this policy.