PRIVACY POLICY

Who we are

Celeste Starre Ltd is the data controller responsible for your personal data.

Registered address:
Celeste Starre Limited, 4th Floor Fitzrovia House, 153–157 Cleveland Street, London W1T 6QW, United Kingdom.

Email: info@celestestarre.com

We are committed to protecting your personal data and respecting your privacy.

What personal data we collect

We may collect and process the following types of personal data:

  • Identity Data: name, username
  • Contact Data: email address, phone number, shipping and billing address
  • Order Data: purchase history, items ordered, order value
  • Payment Data: payment method details (processed securely via third-party providers; we do not store full card details)
  • Technical Data: IP address, browser type, device information
  • Usage Data: how you use our website
  • Marketing Data: your preferences in receiving marketing from us
  • Customer Support Data: any communication you send to us
  • Review Data: reviews or comments you leave on our site

How we use your data

We use your personal data for the following purposes:

To process and fulfil your order

  • Manage payments, delivery, and returns
  • Communicate order updates

Legal basis: Contract

To manage our relationship with you

  • Customer service support
  • Responding to enquiries

Legal basis: Contract / Legitimate Interest

To improve our website and experience

  • Analyse website traffic and behaviour
  • Improve product offering and user experience

Legal basis: Legitimate Interest

For marketing and communications

  • Send you emails or SMS about new products, launches, and offers

Legal basis: Consent (where required) or Legitimate Interest

You can unsubscribe at any time via the link in our emails.

To comply with legal obligations

  • Fraud prevention
  • Accounting and tax requirements

Legal basis: Legal obligation

Cookies

We use cookies and similar tracking technologies to enhance your browsing experience, analyse website traffic, and deliver personalised content and advertising.

These may include cookies set by third-party services such as Google Analytics, Meta (Facebook), TikTok, and Shopify.

Cookies can be categorised as:

  • Necessary cookies, which are required for the website to function properly
  • Analytics cookies, which help us understand how visitors use our website
  • Advertising cookies, which are used to deliver relevant ads and measure campaign performance

Non-essential cookies (such as analytics and advertising cookies) are only placed with your consent.

You can manage or withdraw your consent at any time through our cookie banner.

Third-party services

We share your data with trusted third parties where necessary, including:

  • E-commerce platform (Shopify)
  • Payment providers
  • Shipping and logistics partners
  • Email and SMS marketing platforms (e.g. Klaviyo, Shopify Message)
  • Analytics providers (e.g. Google Analytics, Meta Ads, TikTok Pixel)
  • Review platforms (e.g. Judge.me)

These providers only process your data on our behalf and in accordance with data protection laws.

International transfers

Your data may be transferred outside the UK/EEA.

Where such transfers occur, we ensure appropriate safeguards are in place, including the use of standard contractual clauses or equivalent legal mechanisms.

How long we keep your data

We retain your data only for as long as necessary:

  • Orders and financial data: up to 6–7 years (legal requirement)
  • Marketing data: until you unsubscribe or withdraw consent
  • Customer support data: as needed to provide support and improve service
  • Website analytics data: typically up to 26 months

Your rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Restrict or object to processing
  • Withdraw consent at any time
  • Request transfer of your data

To exercise your rights, contact us at: info@celestestarre.com

We aim to respond to all legitimate requests within one month.

You also have the right to lodge a complaint with your local data protection authority (such as the Information Commissioner’s Office in the UK).

Automated decision-making

We take appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, misuse, or disclosure.

Security

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, loss, alteration, or disclosure. We use secure HTTPS connections, access controls restricting data to authorised personnel, and PCI-DSS compliant payment processors. We do not store full card details.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where required, notify you directly.

Updates to this policy

We may update this Privacy Policy from time to time.

Last updated: March 25th, 2026