Fabza.com Privacy Policy
Last Updated: 27/05/2025
Below is a summary of your key data protection rights. For full details on how to exercise these rights in the context of Fabza.com, Stripe, and Merchants, please refer to Section VIII of the main policy.
The right to be informed
You have the right to be provided with clear, transparent, and easily understandable information about how Fabza.com uses your information and your rights. This Privacy Policy is intended to fulfil this right.
The right of access
You have the right to obtain access to your personal information (if Fabza.com holds it or can access it via Stripe) and certain other supplementary information (similar to that provided in this Privacy Policy).
The right to rectification
You are entitled to have your information corrected if it is inaccurate or incomplete.
The right to erasure (also known as the "right to be forgotten")
This enables you to request the deletion or removal of your information where there is no compelling reason for Fabza.com (or Stripe/Merchants) to keep using it. This is not an absolute right to erasure; there are exceptions.
The right to restrict processing
You have rights to 'block' or suppress further use of your information in certain circumstances. When processing is restricted, Fabza.com (or Stripe/Merchants) can still store your information but may not use it further.
The right to data portability
You have the right to obtain and reuse your personal data for your own purposes across different services in a structured, commonly used, and machine-readable format. This right typically applies to information you have provided where processing is based on your consent or for the performance of a contract, and when processing is carried out by automated means.
The right to object
You have the right to object to certain types of processing, including processing for direct marketing (if applicable) and processing based on legitimate interests.
Rights in relation to automated decision making and profiling
You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you. Fabza.com does not currently engage in such automated decision-making.
I. Introduction
A. Who We Are
This Privacy Policy is provided on behalf of Fabza.com ("Fabza", "the platform"), which is a trading name of 30m Limited, a company incorporated and registered in England and Wales under Company Number 09386561. The registered office of 30m Limited is located at Office 3, St Ann's House, 111 Guildford Road, Lightwater, Surrey, England, GU18 5RA. Fabza.com operates as an online platform designed to connect users with a diverse range of items and products offered by various third-party merchants.
30m Limited, through Fabza.com, is committed to protecting and respecting the privacy of its users. All personal data collected and processed through the Fabza.com platform is handled in strict accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
B. Purpose of This Privacy Policy
This Privacy Policy explains the types of personal data Fabza.com collects from individuals who use its website and services (collectively, the "Services"). It details how this information is used, the legal grounds upon which processing is based, the circumstances under which it may be shared with third parties, and the rights users have concerning their personal data.
A key aspect of this policy is to clarify Fabza.com's specific role as a data intermediary, particularly in its interaction with third-party service providers such as Stripe, Inc. ("Stripe"), which facilitates payment processing (often through its secure "Stripe Elements" interface) and related communications between users and merchants. This document aims to provide the necessary information in a transparent manner, as mandated by data protection legislation, to ensure users are fully informed about Fabza.com's data practices.
C. Our Commitment to Privacy
Fabza.com takes user privacy with utmost seriousness. The Services have been developed with the core principle of data minimisation, meaning only the personal data essential for the provision of the Services is collected.
A fundamental element of the Fabza.com operational model is that Fabza.com does not store users' personal contact information (specifically, email addresses, any optionally provided mobile numbers, billing addresses, and shipping addresses) on its own persistent servers after this information has been collected and duly passed to Stripe for the purposes explicitly described within this policy. This approach of not retaining such data is a deliberate design choice to enhance user privacy and directly reflects Fabza.com's commitment to responsible data handling. Stating this at the outset ensures users have a clear understanding of Fabza.com's data management philosophy from their initial engagement with this policy, aligning with the GDPR's principles of fairness and transparency.
II. Scope of This Policy
A. Who This Policy Applies To
This Privacy Policy applies to all individuals who visit or use the Fabza.com website, including any associated services offered by Fabza.com.
B. What This Policy Covers
This policy specifically addresses the collection, use, and protection of personal data by Fabza.com. It also provides an explanation of the role of key third-party entities, most notably Stripe, in the processing of user data when individuals interact with merchants through the Fabza.com platform.
It is important to note that this policy does not extend to the privacy practices of the individual merchants to whose websites users may be directed or with whom users may ultimately transact. Users are strongly encouraged to review the privacy policies of these independent merchants.
This Privacy Policy should be read in conjunction with the Fabza.com Cookie Policy, which provides detailed information about the use of cookies and similar technologies on the platform. The Cookie Policy is available at: https://www.fabza.com/policies/cookies.
III. Information We Collect (and What We Don't Store)
Fabza.com collects minimal personal data, acting primarily as a conduit or intermediary for information necessary to facilitate interactions between users and merchants.
A. Information You Provide Directly to Us
Contact Information: When a user utilises the Services to connect with a merchant or express interest in a product or item, Fabza.com collects the user's email address. Optionally, a user may also choose to provide a mobile phone number.
Transaction-Related Information: When you initiate a transaction to purchase a product or item, Fabza.com collects your Billing Address and Shipping Address.
Purpose: This contact information, along with billing and shipping addresses, is collected for the sole purpose of enabling communication between the user and the relevant merchant, processing payments, and facilitating order fulfilment. These processes are facilitated through Stripe's platform.
Crucial Clarification: No Persistent Storage by Fabza.com: Fabza.com operates as a data intermediary for this information. Upon collection, the user's email address, any provided mobile number, billing address, and shipping address are passed directly to Stripe. Fabza.com does not store this personal information on its own persistent systems or servers after successful transmission to Stripe. This practice is in line with the data minimisation and storage limitation principles of the UK GDPR, ensuring that Fabza.com retains only the data necessary for the brief period of transmission and for any transient processing required to facilitate the service.
B. Information Collected Automatically (Indirectly)
Log Data/Usage Information: Consistent with common website practice, when an individual visits Fabza.com, the platform's servers may automatically record certain information that the user's browser sends. This "Log Data" can include the computer's Internet Protocol (IP) address, browser type and version, the specific pages of the Fabza.com Service visited, the time and date of the visit, the duration spent on those pages, and other related statistics.
Purpose: This Log Data is utilised for the technical administration of the website, to monitor and enhance the performance and security of the Services, and for analytical purposes to understand service usage. Generally, IP addresses are not linked to any personally identifiable information unless such a link is necessary for security investigations or is required by law. This data is typically processed in an anonymised or aggregated form.
Cookies and Similar Technologies: Fabza.com employs cookies and similar tracking technologies to improve the user experience on the website, analyse usage trends, administer the site effectively, and track users' movements and interactions within the platform.
For comprehensive details regarding the types of cookies used, their specific purposes, and how users can manage their cookie preferences, please refer to the separate Fabza.com Cookie Policy, accessible via the URL provided in Section II.B of this document. The use of cookies is also governed by PECR, which requires informed consent for non-essential cookies.
C. Information We DO NOT Collect or Store (Details on Payment Information)
Payment Card Details: Fabza.com does not collect, process, access, or store your full payment card details (such as credit/debit card numbers or CVC codes). When you make a payment, this sensitive payment card information is provided directly to Stripe through its secure, hosted payment fields (often referred to as "Stripe Elements" or a similar PCI-compliant solution), which are integrated into our platform. This means your payment card details do not pass through Fabza.com's servers.
Billing and Shipping Addresses: As stated in Section III.A, Fabza.com does collect your billing and shipping addresses when you initiate a transaction. This information is immediately passed to Stripe to be associated with your payment and to facilitate order fulfilment by the merchant. Fabza.com does not store these addresses on its own persistent systems but may access them via the Stripe API as described in Section V.B.
Sensitive Personal Data: Fabza.com does not intentionally collect or process "special categories of personal data" as defined under the UK GDPR. This includes information such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification purposes, health data, or data concerning an individual's sex life or sexual orientation.
Table: Personal Data Processing Overview
Data Element | Collected by | Purpose of Collection/Use by Fabza.com (or reason for passing to Stripe) | Legal Basis (for Fabza.com's processing/transfer) | Passed to / Shared With by Fabza.com | Stored by |
---|---|---|---|---|---|
Email Address | Fabza.com | Facilitate merchant communication via Stripe | Performance of a Contract | Stripe, Merchant (via Stripe) | Stripe (Fabza.com: No persistent storage, passed to Stripe; can access via Stripe API) |
Mobile Number (optional) | Fabza.com | Facilitate merchant communication via Stripe | Performance of a Contract | Stripe, Merchant (via Stripe) | Stripe (Fabza.com: No persistent storage, passed to Stripe; can access via Stripe API) |
Billing Address | Fabza.com | Facilitate transaction processing and order fulfilment by merchant via Stripe | Performance of a Contract | Stripe, Merchant (via Stripe) | Stripe (Fabza.com: No persistent storage, passed to Stripe; can access via Stripe API) |
Shipping Address | Fabza.com | Facilitate order fulfilment by merchant via Stripe | Performance of a Contract | Stripe, Merchant (via Stripe) | Stripe (Fabza.com: No persistent storage, passed to Stripe; can access via Stripe API) |
Payment Card Details (e.g., PAN, CVC) | Stripe (via Stripe Elements or similar secure interface on Fabza.com) | Process payments | Not Applicable (Collected directly by Stripe) | Not Applicable (Collected directly by Stripe) | Stripe |
IP Address | User's Browser for Fabza.com | Website operation, security monitoring, analytics | Legitimate Interest | Service Providers (e.g., hosting) | Fabza.com (Temporarily in logs, then anonymised/deleted), Service Providers (as per their policies) |
Cookie Data (as per policy) | User's Browser for Fabza.com / Third Parties | Website functionality, user experience, analytics, marketing (if consented) | Consent (for non-essential), Legitimate Interest | Service Providers (e.g., analytics with Microsoft Clarity) | User's Browser, Fabza.com (limited/aggregated), Service Providers (as per their policies and cookie types) |
This table is designed to provide users with an accessible summary of how different types of data are handled, who is responsible at each stage, and critically, who ultimately stores the information. This level of detail is provided to meet the transparency requirements of the UK GDPR and to clearly articulate Fabza.com's role as a data intermediary.
IV. How We Use Your Information
Fabza.com's use of directly identifiable personal information is limited, reflecting its role as a data intermediary and its commitment to not storing such data long-term.
A. To Provide and Facilitate Our Services
The primary use of information collected by Fabza.com is to enable users to discover products and items and to establish a connection with merchants offering those products and items.
Specifically, Fabza.com uses the collected contact information (email address and optional mobile number), as well as billing and shipping addresses provided during a transaction, to pass these details to Stripe. Stripe, in turn, makes this information available to the relevant merchant for communication purposes, to process payments, and to fulfil orders. This transfer is the core function for which this specific data is collected.
B. Communications with You
Fabza.com does not use the contact information (email address or optional mobile number), billing address, or shipping address it collects and passes to Stripe to initiate any direct communications with you, whether for service-related announcements or marketing purposes. The sole purpose of handling this information is to facilitate communication between you and the Merchant (initiated by the Merchant as needed), payment processing, and order fulfilment via the Stripe platform.
C. For Website Operation and Improvement
Fabza.com may use aggregated or anonymised data, such as Log Data and certain types of cookie data (including data from Microsoft Clarity, as detailed in our Cookie Policy), for the operation, maintenance, and improvement of the Fabza.com website and Services. This includes analysing usage patterns to enhance functionality and user experience. This processing is conducted in a way that does not identify individual users.
As detailed in Section V.B, Fabza.com may access certain transaction-related data via the Stripe API for internal analytics on an aggregated basis to understand service usage.
D. To Comply with Legal Obligations
Fabza.com may process personal data if and when necessary to comply with applicable laws, regulations, legal processes (such as court orders), or enforceable governmental requests.
V. Our Role as a Data Intermediary and Interaction with Third Parties (Stripe)
Understanding the distinct roles of Fabza.com and its key third-party partner, Stripe, is crucial for users to comprehend how their data is managed.
A. Fabza.com as a Data Intermediary
Fabza.com functions as an intermediary or "connector." Its primary role is to facilitate the connection between users and merchants. To achieve this, Fabza.com collects a minimal set of personal data (email address, if provided a mobile number, billing address, and shipping address) which is necessary for this facilitation and promptly passes this information to Stripe. Fabza.com does not engage in the direct sale of products or items to users, nor does it undertake the primary processing or persistent storage of users' payment card details or associated addresses on its own systems.
B. Stripe's Role in Processing Your Data
Stripe is a global third-party payment services provider that Fabza.com utilises to enable merchants to communicate with users, securely process payments for products or items, and facilitate order fulfilment.
Passing Contact and Transaction-Related Information to Stripe: When a user provides their email address (and optional mobile number) through the Fabza.com platform to connect with a merchant, or provides billing and shipping addresses when initiating a transaction, Fabza.com securely transmits this information to Stripe. Stripe then makes this information available to the respective merchant.
Stripe's Direct Collection of Payment Card Data via Secure Interface (e.g., Stripe Elements): If a user proceeds to make a purchase from a merchant, the user will provide their sensitive payment card information (such as credit or debit card number, CVC code, expiry date) directly to Stripe through Stripe's secure, embedded payment interface (e.g., "Stripe Elements") on the Fabza.com platform. This ensures that Fabza.com does not have access to, nor does it collect or store, users' full payment card details, as these details are sent directly from the user's browser to Stripe's secure servers. Stripe is solely responsible for the collection, security, processing, and storage of this payment card data. The billing and shipping addresses collected by Fabza.com are passed to Stripe to be associated with this payment transaction.
Merchant Access to Data via Stripe: Merchants with whom a user interacts will have access to the contact information, billing address, shipping address, and transaction/payment information (collected and processed by Stripe, with addresses passed by Fabza.com) through their Stripe merchant accounts. This access is necessary for merchants to fulfil orders, provide customer service, and manage their transactions.
Stripe's Responsibilities: Stripe acts as an independent data controller for the payment data it processes and for the contact and address information it receives and manages for the purpose of merchant communication, payment processing, and order fulfilment. As such, Stripe is responsible for its own compliance with applicable data protection laws, including the UK GDPR, for all personal data it controls and processes.
Fabza.com's Access to Information via Stripe API: While Fabza.com does not store your billing address, shipping address, or detailed transaction data (such as specific items ordered or payment status) on its own persistent systems, it may access this information from Stripe via Stripe's Application Programming Interface (API). This access is for limited, legitimate operational purposes, such as:
* Assisting with customer service inquiries (e.g., helping you or a merchant clarify order details or shipping status if issues arise).
* Conducting internal analytics on an aggregated and anonymised basis to understand service usage and improve our platform.
* Assisting in dispute resolution processes between users and merchants, or with Stripe.
Fabza.com's access to data via the Stripe API is governed by its agreement with Stripe and is restricted to the data necessary for these specified purposes. Any data accessed is handled in accordance with this Privacy Policy.
Stripe's Privacy Policy: Users are strongly encouraged to review Stripe's Privacy Policy to gain a comprehensive understanding of how Stripe collects, uses, shares, and protects personal data. Stripe's UK privacy policy can typically be found at https://stripe.com/gb/privacy
. (Please verify this link is current and appropriate for your users).
C. Other Third Parties
Fabza.com may engage other third-party service providers for various operational purposes, such as website hosting, data analytics (e.g., Microsoft Clarity – see our Cookie Policy for more details), and other technical services. These providers are contractually obligated to protect any data they process on behalf of Fabza.com and are restricted to using such data solely for the services they are engaged to provide. Any sharing of personal data with these providers is done in compliance with data protection laws.
The clear delineation of responsibilities between Fabza.com and Stripe is essential. Fabza.com acts as a controller for the initial collection and decision to transfer contact and address information. Once Stripe receives this data for merchant communication and payment processing, or collects payment card data directly (e.g., via Stripe Elements), Stripe assumes the role of data controller for that processing. This distinction is vital for users to understand who is accountable for their data at different stages of the interaction.
VI. Legal Basis for Processing Your Personal Data (UK GDPR)
Fabza.com will only collect and process users' personal data where a lawful basis to do so exists under the UK GDPR. The lawful bases relied upon by Fabza.com include:
A. Performance of a Contract
The processing of a user's email address, optional mobile number, billing address, and shipping address – specifically, its collection by Fabza.com and subsequent transfer to Stripe – is necessary for Fabza.com to perform its core service of connecting users with merchants and facilitating transactions. This action is taken at the user's request when they use the Fabza.com platform to explore products or items, initiate contact with a merchant, or proceed with a purchase. This processing can be considered as steps taken at the user's request prior to potentially entering into a contract with a merchant, or as part of Fabza.com's contractual service to the user to facilitate such connections and transactions. This is the primary legal basis for Fabza.com's handling of this information, as the processing is integral to fulfilling the user-initiated service.
B. Consent
For the use of non-essential cookies and similar tracking technologies on the Fabza.com website (including those used by services like Microsoft Clarity), Fabza.com relies on the user's consent, typically obtained through a cookie banner and preference management tool. Users are directed to the Fabza.com Cookie Policy for more information on managing their consent. Consent must be informed, specific, and unambiguous. (Note: Marketing communications are not sent by Fabza.com, so consent for this purpose is not applicable to Fabza.com's direct activities).
C. Legitimate Interests
Fabza.com may process certain data, such as Log Data or specific types of cookie data, based on its legitimate interests. These interests include maintaining and improving the website's functionality, ensuring the security of the Services, and analysing usage trends to enhance user experience (including accessing aggregated transaction data via Stripe API for such analysis, and using tools like Microsoft Clarity as described in our Cookie Policy). Such processing will only occur provided that it does not override the fundamental rights and freedoms of the users.
D. Legal Obligation
Fabza.com may process personal data if it is necessary to comply with a legal or regulatory obligation to which 30m Limited is subject.
VII. Data Sharing and Disclosure
Fabza.com shares personal data only in limited circumstances, as described below:
VIII. Your Data Protection Rights under UK GDPR
Under the UK GDPR, individuals have several important rights concerning their personal data. Fabza.com is committed to upholding these rights.
A. Your Rights
- The right to be informed: You have the right to be provided with clear, transparent, and easily understandable information about how Fabza.com uses your information and your rights. This Privacy Policy is intended to fulfil this right.
- The right of access: You have the right to obtain access to your personal information (if Fabza.com holds it or can access it via Stripe) and certain other supplementary information (similar to that provided in this Privacy Policy).
- The right to rectification: You are entitled to have your information corrected if it is inaccurate or incomplete.
- The right to erasure (also known as the "right to be forgotten"): This enables you to request the deletion or removal of your information where there is no compelling reason for Fabza.com (or Stripe/Merchants) to keep using it. This is not an absolute right to erasure; there are exceptions.
- The right to restrict processing: You have rights to 'block' or suppress further use of your information in certain circumstances. When processing is restricted, Fabza.com (or Stripe/Merchants) can still store your information but may not use it further.
- The right to data portability: You have the right to obtain and reuse your personal data for your own purposes across different services in a structured, commonly used, and machine-readable format. This right typically applies to information you have provided where processing is based on your consent or for the performance of a contract, and when processing is carried out by automated means.
- The right to object: You have the right to object to certain types of processing, including processing for direct marketing (if applicable) and processing based on legitimate interests.
- Rights in relation to automated decision making and profiling: You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you. Fabza.com does not currently engage in such automated decision-making.
B. Exercising Your Rights with Fabza.com
Given Fabza.com's operational model, where it does not store your email address, optional mobile number, billing address, or shipping address on its persistent systems after these have been passed to Stripe, the way you exercise certain rights for this specific data is affected. Requests for access, rectification, or erasure of stored copies of this information will primarily need to be directed to Stripe or the relevant merchant who received your data via Stripe.
However, you can contact Fabza.com to:
Request information about what contact details, billing address, and shipping address were collected from you by Fabza.com and subsequently passed to Stripe.
Enquire about data Fabza.com may have accessed via the Stripe API in relation to your transactions for the purposes outlined in Section V.B.
Request the erasure of any transient Log Data that Fabza.com might hold which is identifiable to you (subject to Fabza.com's retention policies for such data and any legal obligations to retain it).
Object to or request the restriction of Fabza.com's processing of any data it does control (e.g., for its own limited analytics based on data accessed via Stripe API or through tools like Microsoft Clarity, if such data is identifiable and processing is based on legitimate interests).
(Note: As Fabza.com does not send marketing communications, withdrawing consent for this is not applicable to Fabza.com's direct activities).
To exercise any of these rights in relation to data that Fabza.com may control or has processed, please contact Fabza.com using the details provided in Section XV. Fabza.com will respond to your request within one calendar month, as required by UK GDPR, and will assist in directing you to Stripe or merchants where appropriate.
C. Exercising Your Rights with Stripe and Merchants
For personal data held by Stripe (which includes your contact details, billing/shipping addresses passed by Fabza.com, and all payment and transaction data collected and processed by Stripe), you will need to contact Stripe directly to exercise your data protection rights. Please refer to Stripe's Privacy Policy (e.g., https://stripe.com/gb/privacy
) for information on how to do this.
Similarly, for data held by individual merchants with whom you have interacted or transacted, you should contact those merchants directly to exercise your rights. Their privacy policies should provide the necessary contact information.
This practical guidance is essential. Simply listing rights is insufficient; users need to understand how these rights apply within Fabza.com's specific data intermediary model and its reliance on Stripe. This manages user expectations and directs them to the appropriate entity for effective recourse.
Table: Summary of Your Data Protection Rights
Your Right | Brief Description | How to Exercise with Fabza.com | How to Exercise with Stripe/Merchants |
---|---|---|---|
Right to be Informed | To receive clear, transparent information about how your data is processed. | This Privacy Policy aims to provide this information. Contact Fabza.com for clarifications. | Review Stripe's and relevant merchants' privacy policies. |
Right of Access | To know what personal data is held about you and receive a copy. | Contact Fabza.com for information on data passed to Stripe, data accessed via Stripe API, or for access to its own limited processing records (e.g., website logs if identifiable and retained). | Contact Stripe directly for access to data they store (contact details, addresses, payment info, transaction history). Contact merchants for data they hold. |
Right to Rectification | To have inaccurate personal data corrected, or completed if it is incomplete. | If Fabza.com holds inaccurate data it controls (e.g., in logs, if identifiable), contact Fabza.com. For data passed to/held by Stripe, rectification should be sought from Stripe/merchant. | Contact Stripe to rectify data they hold. Contact merchants to rectify data they hold. |
Right to Erasure ("Right to be Forgotten") | To request the deletion of your personal data where there's no compelling reason for its continued processing. | Contact Fabza.com to request erasure of data it controls (e.g., transient logs). Fabza.com does not persistently store contact/address details post-transfer to Stripe. | Contact Stripe to request erasure of data they hold (subject to their legal retention obligations). Contact merchants for data they hold. |
Right to Restrict Processing | To block or suppress the processing of your personal data in certain circumstances. | Contact Fabza.com to request restriction of processing for data it controls or accesses. | Contact Stripe or merchants to request restriction of processing for data they control. |
Right to Data Portability | To obtain and reuse your personal data for your own purposes across different services. | Limited applicability for Fabza.com due to minimal persistent data storage. Contact Fabza.com to discuss if applicable to any data it controls or has accessed. | Contact Stripe or merchants regarding portability of data they hold, as per their policies and the applicability of this right. |
Right to Object | To object to processing based on legitimate interests or for direct marketing. | Contact Fabza.com to object to any processing it conducts based on legitimate interests (including use of data accessed via Stripe API or through Microsoft Clarity). (Direct marketing objection not applicable to Fabza.com). | Contact Stripe or merchants to object to their processing based on legitimate interests or for their direct marketing activities. |
Rights related to Automated Decision Making & Profiling | To not be subject to decisions based solely on automated processing that significantly affect you. | Fabza.com does not currently engage in such processing. | Review Stripe's and merchants' policies regarding automated decision-making. |
IX. Data Security
Fabza.com takes the security of personal data seriously, implementing measures appropriate to its role and the nature of the data it handles briefly or accesses.
A. Fabza.com's Measures
Fabza.com implements reasonable technical and organisational measures to protect the personal data it collects during its brief transit through its systems before it is passed to Stripe, and for any data it accesses via the Stripe API. This includes the use of secure communication protocols, such as HTTPS (Hypertext Transfer Protocol Secure), for its website to encrypt data transmitted between the user's browser and Fabza.com's servers. Access to any data that Fabza.com might temporarily process, log (such as server logs), or access via API is restricted to authorised personnel who require access for legitimate operational purposes.
B. Stripe's Security
Once a user's contact and address information is passed to Stripe, and when a user provides payment card information directly to Stripe (e.g., via Stripe Elements), the security of that data is governed by Stripe's comprehensive and robust security measures. Stripe is a PCI DSS (Payment Card Industry Data Security Standard) Level 1 certified service provider, which is the most stringent level of certification available in the payments industry. This certification signifies that Stripe adheres to high standards for managing and securing payment card data. Stripe employs various security technologies and procedures, including encryption of sensitive data both in transit and at rest, to protect personal information from unauthorised access, use, or disclosure. Fabza.com relies on Stripe's established expertise and security infrastructure for the ongoing protection of the data that Stripe stores and processes.
C. General Disclaimer
While Fabza.com and its partners like Stripe strive to use commercially acceptable and industry-standard means to protect personal information, it is important for users to understand that no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, while significant efforts are made to safeguard data, its absolute security cannot be unconditionally guaranteed.
This approach reflects a shared, albeit sequential, responsibility for data security. Fabza.com is responsible for security during the brief period it handles data for transmission and when it accesses data via API. Subsequently, the primary responsibility for the security of stored contact details, addresses, and all payment information shifts to Stripe.
X. Data Retention
Fabza.com's data retention practices are guided by the principle of storage limitation and its role as a data intermediary.
A. Fabza.com's Retention Policy
Contact Information, Billing and Shipping Addresses: As explicitly stated throughout this Privacy Policy, Fabza.com does not retain this personal information on its persistent storage systems after it has been successfully collected from the user and passed to Stripe for the purposes of merchant communication and transaction processing. This "no persistent storage" approach for these specific identifiers is a core aspect of Fabza.com's privacy commitment. Data accessed via the Stripe API is not persistently stored by Fabza.com either; it is accessed on an as-needed basis.
Log Data/Usage Information: Any server logs or usage data collected automatically by Fabza.com (which may include IP addresses or other technical identifiers) are retained only for a limited period necessary for security monitoring, troubleshooting, and aggregated analytical purposes. This period is typically [Specify a reasonable, short period, e.g., "30 to 90 days"], after which such data is securely deleted or fully anonymised so that it can no longer identify an individual. This practice aligns with the UK GDPR's storage limitation principle.
B. Stripe's and Merchants' Retention Policies
Stripe retains personal data, including contact information, addresses passed to it, and all payment and transaction data it processes, in accordance with its own data retention policies and its legal and regulatory obligations. These obligations often arise from financial regulations, anti-money laundering laws, and tax requirements, and may necessitate the retention of data for several years.
Individual merchants with whom users interact will also have their own data retention policies governing the information they receive and process.
Users are encouraged to review Stripe's Privacy Policy and the privacy policies of the relevant merchants for detailed information on their specific data retention practices.
XI. International Data Transfers
Personal data may be transferred and processed in countries outside of the user's country of residence.
A. Fabza.com's Transfers
Fabza.com is based in the United Kingdom. The personal data that Fabza.com collects and passes to Stripe is primarily processed within the UK or the European Economic Area (EEA) during its transit. If Fabza.com needs to transfer any personal data it directly controls (e.g., Log Data before anonymisation) or accesses via API to a location outside the UK or EEA (for example, through the use of a third-party service provider based elsewhere for analytics), it will ensure that appropriate safeguards are in place as required by the UK GDPR. These safeguards may include relying on an Adequacy Decision from the UK government for the recipient country, or implementing Standard Contractual Clauses (SCCs) as approved by the UK Information Commissioner's Office (ICO), including the UK Addendum to the EU SCCs.
B. Stripe's International Transfers
Stripe is a global company and, as such, may transfer and process users' personal data (including contact details, addresses passed by Fabza.com, and payment information collected by Stripe) in countries outside of the user's country of residence, including but not limited to the United States.
Stripe implements robust safeguards for such international data transfers to protect user data. These measures include the use of Standard Contractual Clauses and adherence to recognised data transfer frameworks such as the EU-U.S. Data Privacy Framework (DPF) and its UK Extension, as applicable.
For more detailed information on Stripe's international data transfer practices, users should consult Stripe's Privacy Policy.
XIII. Children's Privacy
The Fabza.com Services are not intended for or directed at individuals under the age of 18. While the UK GDPR sets the age for a child to give their own consent for information society services at 13, Fabza.com, operating in an e-commerce context where contractual capacity is relevant, defines its services as not being for those under 18.
Fabza.com does not knowingly collect personal data from children under the age of 18 without verifiable parental consent. If a parent or guardian becomes aware that their child has provided Fabza.com with personal data without their consent, they should contact Fabza.com immediately using the details provided in Section XV. If Fabza.com learns that it has inadvertently collected personal data from a child under 18 without appropriate consent, it will take steps to delete such information from its records (and instruct Stripe to do likewise for data passed to them, where feasible) as soon as reasonably practicable.
XIV. Changes to This Privacy Policy
Fabza.com may update this Privacy Policy from time to time to reflect changes in its data processing practices, service offerings, technological advancements, or applicable legal and regulatory requirements.
Any changes made to this Privacy Policy will be posted on this page. If the changes are significant or materially alter the way Fabza.com processes personal data, Fabza.com will provide a more prominent notice. This may include, for example, an email notification (if Fabza.com has a user's email address for service-related communications, though currently it does not use it for this) or a clear announcement on the Fabza.com website.
Users are encouraged to review this Privacy Policy periodically to stay informed about how Fabza.com is protecting their information. The "Effective Date" and "Last Reviewed" date at the top of this Privacy Policy indicate when it was last revised. Continued use of the Services after any changes take effect will constitute acceptance of the revised Privacy Policy, subject to applicable laws regarding consent for material changes.
XV. How to Contact Us
A. For Queries or to Exercise Your Rights with Fabza.com
If you have any questions about this Privacy Policy, Fabza.com's data protection practices, or if you wish to exercise any of your rights as described in Section VIII in relation to personal data that Fabza.com may control or has processed (including data accessed via Stripe API), please contact 30m Limited:
By email: [email protected]
By post: Data Protection Query, 30m Limited, Office 3 St Anns House, 11 Guildford Road, Lightwater, Surrey, GU18 5RA
B. Right to Lodge a Complaint
If you are not satisfied with Fabza.com's response to any complaint you raise, or if you believe that Fabza.com's processing of your personal information does not comply with applicable data protection law, you have the right to lodge a complaint with the UK's supervisory authority for data protection issues. This is the Information Commissioner's Office (ICO).
The ICO's contact details are:
Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline number: 0303 123 1113
Website: https://www.ico.org.uk
Fabza.com would, however, appreciate the opportunity to address your concerns directly before you approach the ICO, so please contact Fabza.com in the first instance using the details provided above.