Who we are
Suggested text: Our website address is: https://getmrg.co.uk.
Last updated: February 21, 2026
Mr. G Grooming Ltd (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal data in a transparent, secure, and lawful way. This Privacy Policy explains how we collect, use, share, and protect your personal information when you visit our website getmrg.co.uk, purchase products (such as OASIS Beard Oil and NOIR Beard Butter), create an account, sign up for newsletters, or interact with us in any other way.
We are the data controller for the personal data we process. Our company details are:
- Company name: Mr. G Grooming Ltd
- Registered office: 82a James Carter Road, IP28 7DE, United Kingdom
- Contact for privacy queries: help@getmrg.co.uk
This policy complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you are in the EU/EEA, we also adhere to the EU GDPR where applicable.
1. What personal data do we collect?
We collect the following types of personal data:
- Identity and contact information: Name, email address, billing and delivery address, phone number (if provided).
- Account information: Username, password (hashed), order history if you create an account.
- Payment information: We do not store full card details — these are processed securely by our payment provider Stripe.
- Order and transaction data: Products purchased, order value, date, delivery status.
- Marketing and communication data: Email preferences, newsletter subscriptions via Mailchimp.
- Technical and usage data: IP address, browser type, device information, pages visited, time spent on site, referral sources (via Google Analytics and Meta Pixel).
- Cookies and similar technologies: See our Cookie Policy section below.
We do not collect special category data (e.g., health, race, religion) or information about children.
2. How do we collect your data?
We collect data directly from you when you:
- Place an order or checkout as a guest.
- Create an account or log in.
- Sign up for newsletters or marketing emails.
- Contact us (e.g., via email or form).
- Browse our website (automatically via cookies/trackers).
We also receive data indirectly from:
- Stripe (payment confirmation, no card details).
- Shipping couriers (e.g., Royal Mail/DPD) — we provide your name, address, and order details only when posting items.
- Google Analytics and Meta Pixel (website usage and advertising performance).
- Mailchimp (email engagement if you subscribe).
3. How and why do we use your personal data?
We process your data on the following lawful bases under UK GDPR:
- Performance of a contract (Art. 6(1)(b)): To process orders, deliver products, handle payments, manage accounts, and provide customer support.
- Legal obligation (Art. 6(1)(c)): To comply with tax, accounting, and consumer law (e.g., keep order records for 6 years).
- Legitimate interests (Art. 6(1)(f)): To improve our website (analytics), prevent fraud, send service-related emails (e.g., order updates), and show relevant ads (Meta Pixel/Google Ads).
- Consent (Art. 6(1)(a)): For marketing emails/newsletters (you can withdraw consent anytime via unsubscribe link or by contacting us).
- Vital interests (rarely applicable).
We do not use automated decision-making or profiling that produces legal effects.
4. Who do we share your data with?
We share data only when necessary and with appropriate safeguards:
- Payment processors: Stripe (processes payments securely; we do not store card details).
- Email marketing: Mailchimp (for newsletters; data stored in the US — see international transfers below).
- Shipping couriers: Royal Mail, DPD, or similar (name, address, order details only for delivery).
- Analytics and advertising: Google Analytics (US-based), Meta Pixel (Meta Platforms, US-based) — for website improvement and targeted ads.
- Hosting and IT providers: Our website host and any cloud storage (UK/EU-based where possible).
- Legal authorities: If required by law (e.g., fraud investigations or court orders).
We do not sell your data to third parties.
5. International transfers of data
Some of our service providers (e.g., Google, Meta, Mailchimp, Stripe) are based in the US or other non-UK/EEA countries. Where we transfer personal data outside the UK/EEA, we ensure adequate safeguards:
- Standard Contractual Clauses (SCCs) approved by the UK ICO/EU Commission.
- UK International Data Transfer Addendum (IDTA) where required.
- Adequacy decisions (where applicable).
- Binding corporate rules or other approved mechanisms.
We only transfer data to providers who commit to equivalent protection levels.
6. How long do we keep your data?
We retain personal data only as long as necessary:
- Order and account data: 3 years after your last interaction (or longer if required for tax/legal purposes, up to 6 years).
- Marketing data: Until you unsubscribe or withdraw consent.
- Analytics/cookies data: As per cookie durations (see below).
- Inactive accounts: We may delete or anonymize after 3 years of inactivity.
After retention periods, we securely delete or anonymise data.
7. Cookies and similar technologies
We use cookies and tracking technologies to improve your experience, analyse site usage, and show relevant ads.
- Essential cookies: Strictly necessary for site function (e.g., cart, login).
- Analytics cookies: Google Analytics (usage stats).
- Advertising cookies: Meta Pixel (targeted ads), Google Ads.
- Marketing cookies: For personalized content.
We use a cookie consent banner/tool from Clickio to obtain your consent for non-essential cookies. You can manage preferences via the banner or browser settings.
For full details, see our separate Cookie Policy (link on website footer).
8. How do we protect your data?
We take security seriously and implement appropriate technical and organisational measures:
- Encryption (SSL/TLS on website).
- Secure payment processing via Stripe.
- Access controls, firewalls, and regular security updates.
- Staff training on data protection.
No method is 100% secure, but we strive to protect your data.
9. Your rights under UK GDPR
You have rights regarding your personal data, including:
- Right to be informed (this policy).
- Right of access (request what data we hold).
- Right to rectification (correct inaccurate data).
- Right to erasure (“right to be forgotten”).
- Right to restrict processing.
- Right to data portability.
- Right to object (e.g., to marketing or legitimate interest processing).
- Rights related to automated decision-making (we do not use this).
To exercise any right, email help@getmrg.co.uk. We usually respond within one month (free of charge, unless requests are excessive).
You can also complain to the UK Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint.
10. Changes to this policy
We may update this policy from time to time (e.g., due to legal changes or new services). We will post the revised version on our website with the updated date. Significant changes will be notified via email (if we hold your email) or a prominent notice on the site.
11. Contact us
If you have questions about this Privacy Policy or our data practices:
- Email: help@getmrg.co.uk
- Post: Mr. G Grooming Ltd, 82a James Carter Road, IP28 7DE, United Kingdom
Thank you for trusting Mr. G with your data. We value your privacy and are committed to protecting it.
