This policy was last reviewed on 11 July 2026 and complies with UK GDPR and the Data Protection Act 2018.
1. Who We Are
Haus Jewellers ("we", "us", "our") is a luxury jewellery and watch retailer operating from 36 Hatton Garden, London, EC1N 8EB, United Kingdom.
We are the data controller responsible for your personal data collected through this website (hausjewellers.com) and our related services.
If you have any questions about how we handle your personal data, please contact us using the details above.
2. Data We Collect
We may collect and process the following categories of personal data:
Information you provide directly
- Identity data: name, title
- Contact data: email address, postal address, telephone number
- Transaction data: details of purchases, valuations and enquiries you make through our site
- Financial data: payment card details (processed securely via our payment provider; we do not store card numbers)
- Correspondence data: any messages you send us via our contact or enquiry forms
- Sell enquiry data: watch and jewellery details, photographs, and valuations submitted through our "Sell Your Watch" or "Sell Your Gold" forms
Information collected automatically
- Technical data: IP address, browser type and version, time zone, operating system and platform
- Usage data: pages visited, time spent on pages, links clicked, referring URLs
- Cookie data: see our Cookies section below
3. How We Use Your Data
We use your personal data for the following purposes:
- To process and fulfil orders, including delivering goods and sending order confirmations
- To respond to enquiries, valuations, and "sell your piece" submissions
- To manage your account and relationship with us
- To send transactional communications (e.g. order updates, shipping notifications)
- To send marketing communications where you have consented or where we have a legitimate interest
- To prevent and detect fraud and to comply with our legal obligations
- To improve our website and services through analytics
- To comply with applicable law, regulation, and legal process
We will never sell your personal data to third parties or use it for purposes incompatible with those stated here.
4. Our Legal Basis for Processing
Under UK GDPR, we must have a lawful basis for processing your personal data. Depending on the activity, we rely on:
- Contract performance: processing necessary to fulfil an order or provide a service you have requested
- Legitimate interests: fraud prevention, network and information security, direct marketing to existing customers (where not overridden by your interests)
- Legal obligation: compliance with applicable law (e.g. tax, anti-money laundering)
- Consent: where we ask for your explicit agreement (e.g. marketing sign-up, analytics cookies)
Where we rely on consent, you may withdraw it at any time by contacting us or using the unsubscribe link in any marketing email.
5. Sharing Your Data
We may share your personal data with:
- Payment processors: Cardstream Limited, for the secure processing of card payments
- Delivery partners: Royal Mail, FedEx, DHL and other couriers, for order fulfilment and insured delivery
- IT and hosting providers: our website host and platform providers, solely to operate and maintain our services
- Analytics providers: Google Analytics (anonymised data only, where cookie consent has been given)
- Professional advisers: solicitors, accountants, and insurers, where necessary
- Regulatory authorities: HMRC, the FCA, or law enforcement, where required by law
All third parties are required to respect the security of your data and treat it in accordance with applicable law. We do not permit our third-party service providers to use your data for their own purposes.
6. How Long We Keep Your Data
We retain personal data only for as long as necessary for the purposes collected and in accordance with our legal obligations:
- Customer order and transaction records: 7 years (HMRC requirement)
- Enquiry and correspondence data: 3 years from last contact
- Marketing preferences: until you unsubscribe or withdraw consent
- Website analytics data: up to 26 months (Google Analytics default)
- Cookie consent records: 1 year
After the relevant retention period, your data will be securely deleted or anonymised.
7. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access: to request a copy of the personal data we hold about you
- Right to rectification: to request correction of inaccurate or incomplete data
- Right to erasure ("right to be forgotten"): to request deletion of your data in certain circumstances
- Right to restrict processing: to request we limit how we use your data in certain circumstances
- Right to data portability: to receive your data in a structured, machine-readable format
- Right to object: to object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making: not to be subject to decisions based solely on automated processing
To exercise any of these rights, please contact us at sales@hausjewellers.com. We will respond within one calendar month. There is no charge for making a request.
Right to complain: If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at
ico.org.uk or by calling 0303 123 1113.
8. Cookies
Our website uses cookies — small text files placed on your device — to improve your experience. We categorise cookies as follows:
- Strictly necessary: essential for the website to function (shopping cart, security). These cannot be disabled.
- Analytics: help us understand how visitors use our site (e.g. Google Analytics). Only set with your consent.
- Marketing/preferences: remember your preferences and support relevant communications. Only set with your consent.
You can manage your cookie preferences at any time using the cookie banner displayed when you first visit our site, or by contacting us. You may also control cookies through your browser settings, though this may affect site functionality.
9. Data Security
We take the security of your personal data seriously. We employ appropriate technical and organisational measures including:
- SSL/TLS encryption for all data transmitted to and from our website
- PCI DSS-compliant payment processing (we do not store card data on our servers)
- Access controls restricting who within our organisation can access your data
- Regular security reviews of our systems and processes
In the event of a data breach that is likely to result in risk to your rights and freedoms, we will notify you and the ICO in accordance with our legal obligations.
10. International Transfers
Some of our service providers may process data outside the UK or European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, such as:
- UK adequacy regulations or equivalent international adequacy decisions
- Standard Contractual Clauses approved by the ICO or European Commission
- The provider's participation in an approved certification framework