Privacy policy
Return to HomeWho we are
Steelstorm (“Steelstorm”, “we”, “us”, “our”) is an online store for PC hardware and components, serving customers across the United Kingdom. It is a trading name of Wayne Enterprise Ltd, a company registered in England and Wales (company number 00000000), with its registered office at 221b Baker Street, London A00 0AA, United Kingdom. Our VAT number is GB 000 0000 00, and every price we display includes VAT at the prevailing rate.
We are the data controller for the personal data described here, which means we are the ones who decide what is collected and why, and we are accountable for it. This policy explains what we gather when you browse the store, search the catalog, create an account and place an order; how and why we use it; who we share it with; how long we keep it; and the rights you have under UK data protection law — principally the UK GDPR and the Data Protection Act 2018. It covers this website and the messages we send you about your account and your orders. It does not cover third-party sites we link to, each of which publishes a policy of its own.
Questions or requests about your data? Email us at info@steelstorm.co.uk or write to the registered office above, marking your letter “Privacy request”. You are welcome to ask what we hold before you decide to share anything further with us, and we will answer plainly rather than in legal boilerplate.
Information we collect
We collect personal data in three ways: directly from you, when you fill in a form, open an account or contact our support team; automatically, as you browse, through cookies and ordinary server logs; and occasionally from the providers who help us run the store, such as a delivery partner confirming that a parcel has arrived. The four categories below are the whole of what we hold — if something is not listed here, we are not collecting it.
Account information
- Email address
- First and last name
- Delivery and billing addresses
- Phone number, where you give us one for delivery updates
- Password — stored only as a salted hash, never in plain text
Order and activity data
- Orders, order history and returns
- Cart and wishlist contents
- Products and categories you view
- Searches you run in the store
Preferences and correspondence
- Display currency and delivery region
- Support messages you send us, and our replies
- Email preferences and any consent you give us
- Notes we add while resolving a query of yours
Technical information
- IP address
- Browser type and version
- Device and operating system
- Pages visited and session activity
- Cookies and similar identifiers
We do not intentionally collect special category data — anything revealing health, beliefs, biometrics or similar — and we ask that you do not send it to us in support messages, since a support thread is not the right place for it. We do not collect real payment card or banking details at all; see “Payments” below for why.
How we use your information
We use your personal data for the purposes set out below, and only for those purposes. If we ever want to use it for something genuinely new, we will come back to you first rather than quietly widen this list.
- Create, secure and maintain your account
- Process your orders, arrange delivery and handle returns
- Show prices in the currency and region you choose
- Keep the store running, prevent fraud and protect other customers
- Respond to your questions and support requests
- Review, in aggregate, how the store is used so we can improve it
- Comply with our legal obligations
We may combine information across those categories where it serves you — reading your delivery region alongside your cart, for instance, so the store can quote the right price and the right shipping options in one step. We do not build advertising profiles, we do not track you across other websites, and we do not sell what we learn about you to anyone, at any price.
Legal bases for processing
Data protection law requires a lawful basis for every use of personal data, and different parts of the store rely on different ones. Under the UK GDPR, ours are:
- Performance of a contract — to open your account, take your order, deliver it and deal with any return that follows
- Legitimate interests — to secure the store, prevent fraud and improve the product, balanced against your rights and freedoms; we have carried out a legitimate interests assessment and can provide a summary on request
- Consent — for any non-essential cookies or optional communications; where we rely on it, you can withdraw it at any time and we will stop
- Legal obligation — where tax, accounting or consumer law requires us to keep or disclose information regardless of what either of us would prefer
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded that the processing is unintrusive and is what you would reasonably expect an online store to do. You can ask us for that reasoning in writing, and you can object to the processing — see “Your rights”.
Marketing
We do not currently send marketing communications of any kind. If we introduce them, we will rely on your consent or another lawful basis, and you will have the right to object to direct marketing at any time — no balancing test applies to that objection, and we do not get to argue about it — using the unsubscribe link in any message or by emailing us. Service messages about your account and your orders, such as a dispatch confirmation or a security notice, are not marketing and may still be sent, because they are part of the contract you have with us rather than an attempt to sell you something else.
Payments
Steelstorm is a demonstration store. Checkout is simulated from end to end: orders are never fulfilled, nothing is dispatched, and we do not currently collect, process or store real payment card numbers, security codes or banking details. Prices are shown in pounds, dollars or euros, they include VAT, and they exist to demonstrate the storefront rather than to invite a purchase.
The platform is nonetheless built payment-ready. Before any real-money processing goes live, payments will be handled by a PCI-DSS-compliant third-party provider, card data will travel to that provider rather than to us, and we will update this policy to describe exactly what changes — before the change happens, not after.
Data security
We apply appropriate technical and organisational measures to protect your data: passwords are stored only as salted hashes, data is encrypted in transit, access is restricted to the authorised people who genuinely need it to do their jobs, and we monitor and back up our systems on a routine schedule.
No method of transmission or storage is completely secure, and anyone who tells you otherwise is selling something, but we work to keep your data protected and to limit what an incident could reach. We will report qualifying personal data breaches to the Information Commissioner’s Office within 72 hours, and we will notify affected customers directly where a breach is likely to result in a high risk to their rights and freedoms. You can help by using a password you have not reused elsewhere and by telling us promptly if anything about your account looks wrong to you.
Sharing your information
We do not sell, rent or trade your personal data. We share it in three narrow circumstances only:
- With service providers that help us run the store — hosting, infrastructure and delivery partners — under contracts that require protection equivalent to our own and forbid them from using your data for their own ends
- Where required by applicable law, regulation or a valid legal request, having first satisfied ourselves that the request is in fact valid
- To protect the rights, safety and security of the store and the people who use it, for example when investigating fraud against another customer
Where a provider processes data outside the UK or EEA, we rely on an adequacy decision or on UK-approved safeguards such as the International Data Transfer Agreement or Standard Contractual Clauses. You can ask us which countries your data may be transferred to and request a copy of the safeguards that cover the transfer.
Automated decisions and profiling
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Product suggestions and fraud-prevention checks are automated, and they do shape what you see, but neither decides anything that affects your legal position or your ability to shop with us. If we ever introduce automated decision-making of that weight, we will say so here and tell you how to contest it and how to ask for a human to look again.
Cookies
We use a small number of strictly necessary and functional cookies — to keep you signed in, remember your cart between visits, and remember the display currency and delivery region you have chosen. We do not use advertising cookies, we do not use third-party tracking, and we do not run analytics that follow you beyond this site. Our Cookies Policy lists every cookie we set, what it is for, how long it lasts and how to control it from your browser.
How long we keep your data
We keep your information only as long as we actually need it, and the clock is different for each category:
- Account data — while your account is open; if you close it, we delete or anonymise the data within 30 days
- Order records — for as long as tax and accounting law requires, currently six years from the end of the financial year the order falls in
- Cart, wishlist and preferences — for the life of the account, then deleted or anonymised along with it
- Security and fraud-prevention logs — up to 12 months, after which they are of no further use to us
You can ask us to delete your account and the data attached to it at any time. We will do it, and we will keep only the order records the law obliges us to hold — nothing beyond that, and nothing kept simply because it might be handy later.
Your rights
Under UK data protection law you have a set of rights over your personal data, and exercising them costs nothing:
- Access the personal data we hold about you
- Have inaccurate or incomplete data corrected
- Have your data erased
- Restrict or object to certain processing
- Receive your data in a portable format (data portability)
- Withdraw consent where our processing relies on it
To exercise any of these, contact us at info@steelstorm.co.uk. We will respond within one month, and we will tell you if a request will take longer because it is complex, rather than letting the deadline pass quietly. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority, at ico.org.uk — though we would appreciate the chance to put things right first.
Children
The store is not directed at children, its products are not aimed at them, and we do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete it. If you believe a child has given us their data, tell us and we will deal with it quickly rather than asking you to prove it first.
Changes to this policy
We may update this Privacy Policy from time to time, as the store grows and as the law moves. Material changes will be posted on this page with a new “last updated” date, and anything significant — a new category of data, a new recipient, a new purpose — may also be flagged to you in the store or by email, so that a change of substance does not hide in a change of wording.
Contact
Questions about this policy or how we handle your data? Email info@steelstorm.co.uk, or write to Wayne Enterprise Ltd, 221b Baker Street, London A00 0AA, United Kingdom. A real person reads both, and you are entitled to an answer you can actually understand.