Last updated: 26 August 2026. Version 2.0.

This policy explains what personal data Second Life Vault collects, why, what I do with it, how long I keep it, and the rights you have over it. I have tried to write it in plain English rather than legal boilerplate, because a policy nobody can read protects nobody.

1. Who I am

Second Life Vault is the trading name of Stephanie Gola, a sole trader selling second-hand clothing in the United Kingdom. I am the data controller for the personal data described here, which means I decide what is collected and why, and I am responsible for looking after it.

  • Trading name: Second Life Vault
  • Trader: Stephanie Gola, sole trader
  • Address: 121 Waltersgreen Crescent, Golborne, WA3 3WA, United Kingdom
  • Email: legal@secondlifevault.co.uk

This is a one person business. There is no data protection officer, because the law does not require a trader of this size to appoint one. Every enquiry comes to me.

2. The short version

I collect what I need to sell you a piece of clothing and get it to your door: your name, address, email and order details. I never see your card number. I do not sell your data, I do not share it with advertisers, and I do not track you around the internet. I keep order records for six years because tax law requires it, and I delete the rest when it is no longer needed. You can ask me at any time what I hold, and to correct or delete it.

3. What I collect

Information you give me

  • Identity and contact details. Your name, delivery address, billing address, email address and, if you provide one, a telephone number for the courier.
  • Order details. The items you bought, sizes, prices paid, postage chosen, order number and order date.
  • Account details. If you create an account, your username and an encrypted version of your password. I cannot see your password.
  • Correspondence. Emails and messages you send me, including questions about sizing, returns and complaints, and my replies.
  • Returns and refunds information. The reason for a return, any photographs you send of a fault, and the details needed to process a refund.
  • Marketing preferences. Whether you have asked to hear from me, and when you told me.

Information collected automatically

  • Technical data. Your IP address, browser type and version, operating system, and the pages you requested with dates and times. This is standard web server logging and happens on every website you visit.
  • Cookie data. The identifiers described in my cookie policy: the basket session cookie, the record of your cookie choices, and, only where you have accepted marketing cookies, the order attribution cookies that record how you found the site.

Information from others

  • Payment confirmation. My payment provider tells me whether a payment succeeded, the last four digits of the card, the card type and the result of their fraud checks. They do not give me the full card number, and I could not store it even if I wanted to.
  • Delivery updates. The courier tells me when a parcel was collected, its tracking status and whether it was delivered.

What I do not collect

I do not collect special category data, meaning information about health, race, ethnicity, religion, politics, trade union membership, genetics, biometrics, sex life or sexual orientation. I do not collect criminal offence data. Please do not send me any of this. If it appears in a message you send me, I will delete it once the matter is resolved.

This site is not aimed at children and I do not knowingly sell to anyone under 18. If you believe a child has given me personal data, tell me and I will delete it.

4. Why I use it, and my lawful basis

The UK GDPR requires a lawful basis for every use of personal data. Mine are set out below.

What I doData usedLawful basis
Take your order, take payment and send you a confirmationIdentity, contact, order, payment confirmationPerformance of our contract
Pack and post your parcel, and pass the address to the courierIdentity, contact, orderPerformance of our contract
Answer your questions before and after a saleContact, correspondence, orderPerformance of our contract, and my legitimate interest in running a helpful shop
Handle cancellations, returns, refunds and faultsIdentity, contact, order, returns informationLegal obligation under consumer law, and performance of our contract
Keep accounting and tax recordsOrder, payment confirmation, identityLegal obligation
Prevent and investigate fraud and chargebacksOrder, payment confirmation, technicalLegitimate interest in protecting the business, and legal obligation
Keep the website secure and workingTechnical, cookieLegitimate interest in site security and reliability
Manage your account, if you create oneAccount, identity, contact, orderPerformance of our contract
Send marketing emails, if you have asked for themContact, marketing preferencesConsent, which you can withdraw at any time
Defend or bring a legal claimWhatever is relevant to the claimLegitimate interest in establishing or defending legal rights

Where I rely on legitimate interests, I have considered whether my interest is outweighed by your rights and freedoms, and I have concluded that it is not, because the processing is limited to what a customer would reasonably expect from a shop they have bought from. You can object to any of it, as explained in section 9.

I do not carry out automated decision making or profiling that produces legal or similarly significant effects. My payment provider runs automated fraud checks on transactions, and a payment can be declined as a result. If that happens to you and you think it is wrong, contact me and I will look into it with the provider.

5. Who I share it with

I do not sell personal data, rent it, or trade it. I share it only with the following, and only with the part of it they need.

  • Couriers. Evri and InPost receive your name, delivery address, and a contact detail so they can deliver and notify you.
  • My payment provider. Receives the payment details you enter directly into their fields, plus the order value and reference, so the payment can be taken and reconciled.
  • My web host and website platform. Store the site and its database, which includes order records, and therefore have technical access to them.
  • My email provider. Handles messages between us.
  • An accountant, if I engage one. Would see order and payment records as part of preparing accounts and tax returns.
  • HMRC and other authorities. Where I am legally required to disclose, for example in a tax enquiry, or in response to a valid court order or a lawful request from law enforcement.
  • Professional advisers and insurers. If a dispute or claim makes it necessary.

Everyone in that list who processes data on my behalf is bound by a contract requiring them to keep it secure, use it only on my instructions, and delete or return it when the work is finished. If I ever sell or transfer the business, customer records may pass to the buyer, who would be bound by this policy until they told you otherwise.

6. Sending data outside the UK

Some of the services I use may store or process data outside the United Kingdom, most commonly in the European Economic Area or the United States. Where that happens, the transfer is protected by one of the safeguards UK law recognises: an adequacy decision by the UK government covering that country, the International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses. If you would like to know which safeguard applies to a particular service, ask me and I will tell you.

7. How long I keep it

RecordKept forWhy
Orders, invoices and payment records6 years from the end of the tax year they relate toHMRC requires business records to be kept for this period
Returns, refunds and complaints6 yearsThe limitation period for a contract claim in England and Wales
General correspondence with no order attached2 years from our last exchangeLong enough to pick up a conversation, no longer
Account detailsUntil you close the account, then 30 daysThe delay allows recovery if you change your mind
Marketing list entryUntil you unsubscribe, then a permanent suppression recordA suppression record is the only way to be sure I never email you again
Web server logsTypically 30 to 90 days depending on the hostSecurity monitoring and fault diagnosis
Cookie consent record6 monthsAfter which you are asked again

When a retention period ends I delete the data or anonymise it so it can no longer be linked to you.

8. How I keep it safe

  • The whole site is served over an encrypted HTTPS connection.
  • Card details are entered into my payment provider’s own hosted fields and never touch my systems, so there is no card data for me to lose.
  • Administrative access to the site is limited to me, protected by a strong unique password.
  • Passwords in the database are stored as salted hashes, not as readable text.
  • Software and plugins are kept updated so known vulnerabilities are closed.
  • Paper records, such as packing slips, are shredded once an order is complete.

No system is perfectly secure, and I will not pretend otherwise. If a breach happens that is likely to result in a risk to your rights and freedoms, I will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and I will tell you directly if the risk to you is high.

9. Your rights

Under the UK GDPR you have the following rights. They are free to exercise.

  • Access. Ask for a copy of the personal data I hold about you, and an explanation of what I do with it.
  • Rectification. Have inaccurate data corrected and incomplete data completed.
  • Erasure. Ask me to delete data, where there is no good reason for me to keep it. This right is not absolute: I cannot delete an order record that tax law requires me to keep, though I can delete everything around it.
  • Restriction. Ask me to pause using your data while a dispute about its accuracy or my basis for holding it is resolved.
  • Portability. Receive the data you gave me in a common machine readable format, or have it sent to another provider, where processing is based on consent or contract and carried out by automated means.
  • Object. Object to processing based on legitimate interests. You have an absolute right to object to direct marketing, and I must stop immediately.
  • Withdraw consent. Where I rely on consent, withdraw it at any time. This does not affect anything done before you withdrew it.
  • Complain. Raise the matter with the Information Commissioner’s Office, as described in section 13.

To exercise any of these, email legal@secondlifevault.co.uk and say what you want. I may ask you to confirm your identity, so that I do not hand your data to somebody pretending to be you. I will respond within one month. If a request is unusually complex I may extend that by up to two further months, and I will tell you within the first month if that happens and why.

10. Marketing

I will only send you marketing emails if you have asked for them, or if you have bought from me and I am telling you about similar items, which the law calls the soft opt-in. Every marketing email carries an unsubscribe link that works with one click and takes effect straight away. Unsubscribing does not stop transactional emails such as order confirmations and dispatch notices, because those are part of fulfilling your order rather than marketing.

11. Measuring my emails

If you are on my mailing list, the emails I send you contain a single invisible image and links that pass through my own site before taking you where you were going. Between them these tell me how many people opened an email and how many clicked something. I use this only to work out whether what I am sending is worth reading, and to stop sending things nobody opens.

Two honest caveats about those numbers. Open tracking does not work if your email program blocks images, so it undercounts. It also overcounts, because Apple Mail loads images automatically whether or not you actually read the message. I treat them as a rough trend rather than a fact about any individual.

My lawful basis is legitimate interests, specifically understanding whether my own emails are useful. If you would rather not be measured at all, unsubscribing stops it completely, since I only track emails I send to the list. Unsubscribe links are never tracked. Order confirmations, dispatch notices and other transactional emails contain no tracking of any kind.

If you are sent a discount code that is unique to you, redeeming it tells me the order came from that email. Shared codes tell me nothing about who used them.

12. Other websites

This site may link to other websites. Once you follow a link, this policy no longer applies. I have no control over how other operators handle your data and I am not responsible for their practices, so it is worth reading their policies before giving them anything.

13. Complaints

If you are unhappy with how I have handled your personal data, please tell me first at legal@secondlifevault.co.uk. I would rather fix it than have you go elsewhere frustrated.

You also have the right to complain directly to the Information Commissioner’s Office at any time, whether or not you have raised it with me. They can be reached at ico.org.uk, on 0303 123 1113, or by post at the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

14. Changes to this policy

I will update this page when what I do with data changes. The version number and date at the top show when it last happened. If a change is significant, for example a new purpose or a new category of recipient, I will tell customers directly rather than relying on you to notice.