Your information, respected
Privacy policy.
Last updated: 1 September 2026
1. Who controls your data
MadeFondly.com is the data controller for the personal data described in this policy. We are responsible for deciding how and why it is used.
This policy explains what we collect, why, who we share it with, and the rights you have under the UK GDPR and the Data Protection Act 2018.
2. What we collect
- Order and account details: your name, email address, delivery address, billing address and telephone number where you give it.
- Design content: everything you put into a product — photographs you upload, names, dates, messages, map locations, coordinates and style choices. Photographs of people are personal data, and can be special category data where an image reveals something such as health, religion or ethnicity. You choose what to upload.
- Payment details: handled directly by Stripe. We receive confirmation of the payment and the last four digits and card type. We never receive or store your full card number.
- Technical data: IP address, browser and device type, pages viewed, and referring site.
- Correspondence: messages you send us by email or through the contact form, and our replies.
- Marketing preferences: whether you have opted in to email from us, and whether you opened or clicked those emails.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Producing and delivering your order, taking payment, and dealing with questions about it | Performance of our contract with you |
| Sending order confirmations, dispatch notices and tracking | Performance of our contract with you |
| Processing photographs you upload, including automated and AI-assisted enhancement where you use those tools | Performance of our contract with you; explicit consent where the image is special category data |
| Keeping accounting and tax records | Legal obligation |
| Preventing fraud, abuse and unlawful content | Our legitimate interest in protecting the business and our production partners |
| Understanding how the site is used so we can improve it | Our legitimate interest in improving our service, and consent for any non-essential cookies |
| Marketing email | Your consent, or our legitimate interest in contacting existing customers about similar products, which you can stop at any time |
4. Who we share it with
We do not sell your personal data and we do not share it for anyone else's marketing. We share it with the following processors, only as far as each needs it:
- Gelato — our print and fulfilment partner. To produce and deliver your order, Gelato receives your name, delivery address, contact details and the finished print file, which contains the content of your design including any photograph you uploaded.
- Gelato's production partners and carriers — the local printing facility that makes your order and the carrier that delivers it, including couriers such as Royal Mail, DHL and FedEx, which receive your name, address and contact details.
- Stripe — payment processing and fraud prevention.
- Our hosting and file storage provider — the servers this website runs on and where uploaded images and finished print files are stored.
- Replicate — the platform running the AI models used by our portrait and image tools, where you choose to use them. It receives the image you are working on.
- Our email provider — to send order and, where you have opted in, marketing email.
We also disclose data where the law requires it, or to establish or defend legal claims.
5. Transfers outside the UK
Gelato produces each order at the facility nearest to the delivery address, so if you ask us to deliver outside the UK your delivery details and print file are processed in that country. Some of our other providers also process data outside the UK.
Where data leaves the UK, we rely on UK adequacy regulations for the destination country, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with additional safeguards where they are needed. You can ask us for details of the safeguards that apply to a specific transfer.
6. How long we keep it
- Order records, including invoices: 6 years from the end of the tax year they relate to, because tax law requires it.
- Uploaded images and print files: kept for up to 12 months after delivery so that we can reprint if something is wrong or you ask for a repeat, then deleted. Designs saved to your account are kept until you delete them or close your account.
- Account details: until you ask us to close your account.
- Marketing preferences: until you unsubscribe, plus a record of the unsubscribe so we do not contact you again.
- Correspondence: up to three years after the matter is closed.
7. Cookies
We use cookies that are strictly necessary for the site to work — keeping you signed in, remembering your basket and your chosen currency, and protecting forms against cross-site request forgery. These do not need your consent.
Any analytics or advertising cookies are set only if you agree to them, and you can change your mind at any time. Blocking essential cookies will stop checkout working.
8. Your rights
You have the right to:
- Ask what personal data we hold about you, and get a copy of it
- Have inaccurate data corrected
- Ask us to delete data, where we no longer need it
- Ask us to restrict how we use it while a concern is resolved
- Object to processing carried out on the basis of legitimate interests
- Receive data you gave us in a portable format, or have it sent to another provider
- Withdraw consent at any time, where we relied on consent
- Unsubscribe from marketing email, using the link in any message or by contacting us
These rights are not absolute — for example, we cannot delete an invoice we are required by tax law to keep. To exercise any of them, use our contact form. We respond within one month and do not charge.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would prefer the chance to put it right first.
9. Security
The site is served over HTTPS, payment details go directly to Stripe, passwords are stored hashed, and access to order data is restricted to the people who need it. No system is completely secure, but we take appropriate technical and organisational measures to protect your data and will tell you and the ICO about a breach where we are required to.
10. Children
Our products are sold to adults. We do not knowingly collect data from anyone under 16. If you upload a photograph of a child, you confirm you are the parent or guardian or have their permission.
11. Automated decision-making
We do not make decisions with legal or similarly significant effects about you by automated means alone. Our payment provider carries out automated fraud screening, which may result in a payment being declined; if that happens you can contact us and we will look at it.
12. Changes to this policy
We may update this policy. The date at the top shows when it was last revised, and we will tell you directly about significant changes that affect how we use your data.
13. Contact
Use our contact form with any question about this policy or your data.