Privacy policy

Last updated: 7 May 2026

BlendMade respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, store and share your personal data when you visit our website blendmade.com ("Website"), place an order, or otherwise interact with us.

We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

BlendMade is a trading name of BlendMade Nutrition Ltd, a company registered in England and Wales (company number 17182700).

For the purposes of data protection law, we are the "controller" of the personal data we process about you.

Contact details:

  • Email: You can contact us via our contact form.
  • Address: 3 Mayhew Road, Rendlesham, Suffolk, IP12 2GT, United Kingdom

If you have any questions about this privacy policy or wish to exercise your data protection rights, please contact us using the details above.

You also have the right to make a complaint to the Information Commissioner's Office (ICO) at ico.org.uk/. We would appreciate the chance to resolve your concerns before you contact the ICO.

2. What Personal Data We Collect

We may collect and process the following categories of personal data:

Category Examples
Identity Data First name, last name
Contact Data Email address, delivery address, billing address, phone number
Financial Data Payment card details (processed by our payment provider; we do not store full card numbers)
Transaction Data Details of products you have ordered, order history, amounts paid
Technical Data IP address, browser type and version, time zone, operating system, device type
Usage Data How you use our Website, pages visited, blend configurations created
Marketing & Communications Data Your preferences for receiving marketing and how you prefer to be contacted

We do not knowingly collect any Special Category Data (such as health data, race, religious beliefs or political opinions) about you.

We do not knowingly collect personal data from children under the age of 18.

3. How We Collect Your Data

  • Direct interactions: when you create an account, place an order, subscribe to emails, contact us, or provide feedback.
  • Automated technologies: as you browse our Website, we automatically collect Technical and Usage Data using cookies and similar technologies.
  • Third parties: we may receive data from analytics providers (such as Google Analytics), payment providers (such as Shopify Payments), and delivery partners.

4. How We Use Your Data and Our Legal Basis

Purpose Legal Basis
Register you as a customer and manage your account Performance of a contract
Process and fulfil your orders Performance of a contract
Communicate about your orders Performance of a contract
Respond to your queries and complaints Performance of a contract / Legitimate interest
Send marketing communications Consent / Legitimate interest (soft opt-in under PECR)
Improve our Website, products and services Legitimate interest
Administer and protect our business and Website Legitimate interest / Legal obligation
Comply with legal and regulatory obligations Legal obligation

5. Who We Share Your Data With

  • Shopify: our e-commerce platform, which processes orders and payments on our behalf.
  • Payment processors: such as Shopify Payments, PayPal or Stripe.
  • Delivery partners: such as Royal Mail or courier services.
  • Cloud hosting providers: such as Microsoft Azure, which hosts our pricing and product configuration services.
  • Analytics providers: such as Google Analytics.
  • Email service providers: to send order confirmations and marketing emails.
  • Professional advisors: including accountants, lawyers and auditors.
  • HMRC, regulators and law enforcement: where required by law.

We do not sell your personal data to any third party.

6. International Transfers

Some of our third-party service providers may be based outside the United Kingdom. Where we transfer your personal data outside the UK, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement or transfers to countries with an adequacy decision from the UK Government.

7. Data Security

  • Use of HTTPS/TLS encryption across our Website;
  • Secure payment processing through PCI-DSS compliant providers;
  • Access controls limiting who can view personal data;
  • Regular review of our security practices.

8. Data Retention

  • Order and transaction data: retained for 7 years (HMRC requirements).
  • Account data: retained while your account is active; deleted after 3 years inactivity.
  • Marketing preferences: retained until you withdraw consent or unsubscribe.
  • Website analytics data: retained in anonymised or aggregated form.

9. Cookies

Type Purpose Examples
Strictly necessary Essential for the Website to function Shopify session cookies
Analytics Help us understand how visitors use the Website Google Analytics
Marketing Used to show relevant advertising Facebook Pixel (if enabled)

You can manage cookie preferences through Shopify's cookie consent banner. Visit allaboutcookies.org for more information.

10. Your Rights

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to data portability
  • Right to object
  • Right to withdraw consent

To exercise any of these rights, contact us via our contact form. We will respond within one month.

11. Marketing

We will only send marketing emails where you have given explicit consent, or where you are an existing customer and we are marketing similar products (soft opt-in under PECR). Every email includes an unsubscribe link.

12. Third-Party Links

Our Website may contain links to third-party websites. We are not responsible for their privacy practices.

13. Changes to This Policy

We may update this policy from time to time. The updated version will be posted on this page with a revised "Last updated" date.

14. Contact Us

  • You can contact us via our contact form.
  • Address: 3 Mayhew Road, Rendlesham, Suffolk, IP12 2GT, United Kingdom

You also have the right to lodge a complaint with the ICO: ico.org.uk / 0303 123 1113