Privacy Policy
Last updated 16 July 2026
This policy explains what personal information Remi Grace® ("we", "us") collects when you visit remigrace.com or place an order, why we collect it, who we share it with, how long we keep it, and the rights you have over it. We collect only what we need to run the shop.
If you are a California resident, our California Privacy Notice gives you additional rights and disclosures. For a plain-language summary of what we hold and how to get it back, see Your Data.
1. Information we collect
- Identifiers and contact details — name, email address, delivery address, billing address and telephone number, given when you order or contact us.
- Commercial information — the items you view and buy, order value, order history, returns, and correspondence with us.
- Payment information — handled entirely by Stripe. We receive confirmation of payment, the card brand and last four digits, and the billing postcode. We never receive or store your full card number.
- Technical and usage information — IP address, browser and device type, referring page, and pages viewed, collected through server logs and strictly necessary cookies.
- Marketing preferences — whether you have opted in to email, and whether you have since opted out.
We do not collect government identifiers, biometric data, precise geolocation, or any special category data. We do not ask for information about your child beyond a clothing size, and we do not need a date of birth.
2. Where the information comes from
Almost all of it comes directly from you. The rest is generated automatically when you use the site, or supplied by our payment processor and shipping carriers in the course of completing your order. We do not buy personal information from data brokers.
3. Why we use it, and our legal basis
- To perform our contract with you — processing, packing, shipping and invoicing your order; handling returns, exchanges and faults; answering your questions.
- For our legitimate interests — preventing fraud and abuse, securing the site, understanding which products and pages people use, and keeping proper business records.
- To comply with legal obligations — tax, customs, accounting, consumer protection and product safety record-keeping.
- With your consent — marketing email, which you may withdraw at any time without affecting anything else.
4. Payment processing
All payments are processed by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. Card details are collected directly by Stripe and never pass through or rest on our servers. Stripe acts as an independent controller of that data and processes it under its own privacy policy. Stripe may use transaction data to detect and prevent fraud.
5. Who we share it with
We do not sell your personal information, and we do not share it with third parties for their own marketing or advertising purposes. We disclose it only to the parties who need it to deliver what you asked for:
- Stripe — payment processing and fraud prevention.
- Shipping carriers — name, delivery address and telephone number, to deliver your parcel and, for international orders, to clear customs.
- Our hosting and email providers — to run the website and send order correspondence, under contracts that restrict them to acting on our instructions.
- Professional advisers and authorities — accountants, and law enforcement or regulators where we are legally required to disclose, or where disclosure is necessary to establish or defend legal claims.
If the business is ever sold or transferred, customer records may transfer with it; you would be notified before that happened and this policy would continue to apply to information collected under it.
6. International transfers
We are based in the United States and our service providers are principally in the United States and the European Union. If you order from outside the US, your information will be transferred to and stored in the US. Where information moves out of the UK or EEA, we rely on the UK and EU Standard Contractual Clauses or an equivalent approved transfer mechanism.
7. How long we keep it
- Order and transaction records — seven years from the end of the tax year in which the order was placed, to satisfy tax and accounting requirements.
- Customer service correspondence — three years from the last contact.
- Marketing contacts — until you unsubscribe, and then a minimal suppression record so we do not email you again by mistake.
- Server logs — a short rolling period, then deleted.
8. Cookies
We use only cookies that are strictly necessary to operate the shop: keeping your bag intact between pages, keeping you signed in to your account, and protecting checkout against fraud. We do not run advertising, retargeting or cross-site tracking cookies, and we do not embed third-party advertising pixels. Because we set no non-essential cookies, we do not show a consent banner. You can block or delete cookies in your browser settings; the shop will still load, but the bag and checkout will stop working correctly.
9. Your rights
Wherever you live, you may ask us to:
- confirm whether we hold personal information about you, and give you a copy;
- correct anything inaccurate or incomplete;
- delete information we are not legally required to keep;
- stop using your information for marketing;
- restrict or object to certain processing, and, where the law provides it, receive your information in a portable machine-readable format.
Email hello@remigrace.com. We respond within 30 days and will never charge you or treat you differently for exercising these rights. We may need to verify your identity before acting, usually by confirming details of a recent order.
If you are in the EEA or UK you may also complain to your national data protection authority. If you are in California, see the California Privacy Notice.
10. Children
We sell clothing for children, but the shop is intended for use by adults. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, email us and we will delete it.
11. Security
The site is served over HTTPS with modern TLS. Payment data never reaches our systems. Access to order records is limited to the people who need it to run the shop, over authenticated connections, and our servers are patched and backed up. No system is perfectly secure, but if a breach ever affected your information we would notify you and the relevant regulator as required by law.
12. Changes
If we change this policy we will update the date at the top of the page, and for material changes we will say so on the homepage or by email.
13. Contact
Remi Grace® — privacy inquiries: hello@remigrace.com. Postal address available on request.
← Back to Remi Grace®