Privacy Policy and GDPR | Railwayscenics
Facebook
Instagram
X Formerly Twitter

Privacy Policy and GDPR

cookies

This Privacy Policy includes important information about your personal data and we encourage you to read it carefully.

Here at Railwayscenics we are committed to ensuring that your privacy is protected, but we want to go even further with internet security. As a result, we have made our website 100% secure with SSL on all pages. SSL (Secure Sockets Layer) is the standard security technology for establishing an encrypted link between a web server and a browser. This link ensures that all data passed between the web server and browsers remain private and integral.

We also fully understand that you care about how information about you is used and shared, and we appreciate your trust and want you to feel confident in our services and security as it relates to your personal information. To better protect your privacy, we are providing this notice explaining our online information practices and the choices you can make regarding the way your personal information is collected and used. By visiting Railwayscenics, you are accepting the practices described in this Privacy Notice.

The laws that govern personal data in the UK are:
(a) The Data Protection Act (1998)
(b) REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) ("GDPR").

The independent authority that upholds information rights in the public interest in the United Kingdom is the Information Commissioners Office (the "ICO"). Further information can be found at https://ico.org.uk.

We agree to take reasonable measures to protect your data in accordance with applicable laws and in accordance with our General Terms and Conditions which can be found at https://www.railwayscenics.com/conditions.php.

Introduction

Railwayscenics are committed to safeguarding the privacy of our website visitors.

This policy applies where we are acting as a data controller with respect to the personal data of our website visitors, where we determine the purposes and means of the processing of that personal data.

We will ask you to consent to our use of cookies in accordance with the terms of this policy when you first visit our website.

Our website incorporates privacy controls which affect how we will process your personal data. By using the privacy controls, you can specify whether you would like to receive direct marketing communications.

In this policy, "we", "us" and "our" refer to Railwayscenics.

Who is the data controller for this website?

The data controller for this website is Stephen Lane and he can be contacted at our business address which can be found at the bottom of every page on the website.

What personal information does Railwayscenics gather?

During the account creation and the checkout process we ask for the minimum of information from you. The information we obtain from our customers helps us personalise and continually improve your shopping experience at Railwayscenics. Here are the types of information we gather.

Information you give us:
The information which you provide via the Railwayscenics online Model Railway Shop will be processed by Railwayscenics in order to process your order. You will be required to register as a customer on the Railwayscenics online Model Railway Shop which will include creating a user name and password and providing contact details which include your first and last names, your address and a contact phone number plus any other information required to process your order. This information will also be used for accounting and auditing purposes and to deal with any enquiries and complaints that we may receive from you.

During the registration process, you will have the option to consent to Railwayscenics using your personal data for our own marketing purposes. If you decide to opt-in, you may change your mind at any time, and opt-out of receiving marketing communications and newsletters from us by clicking the unsubscribe link at the bottom of all newsletters, or changing the setting from within your account.

You can also choose not to provide certain information, but then you might not be able to take advantage of many of our website features. If you contact us by email, or through a web page to request information, report a problem or provide feedback on our services or products, we will use the information you provide to respond to your message, address the issue you have raised, and to make improvements to our services. We do not use this information for other purposes.

Should you contact us using our online Contact Us form, we gather your email address and the contents of the message. We only keep that information until your question has been answered, or your query has been resolved. Copies of all emails are then deleted.

How long do we keep your information?

The information that we are given when you place an order is usually kept for 6 years from the end of the financial year that you placed the order. This is done because we need to keep tax records in accordance to any tax rules and regulations.

Any information you give us when making an enquiry about our products or services is only kept as long as we need it. Ideally once we have answered your query, we destroy or delete any information you give us.

Personal information accuracy

The information we obtain from the website will be kept up to date. Should we receive notice from you that some of your information has changed, we will update our data in accordance to that given by you. It is also possible for you to access all your account information and to update it yourself by accessing your personal account.

Does Railwayscenics share the information it receives?

We respect your privacy and appreciate your business. At no time do we ever provide your account contact or payment information to any third-party vendor, associate or service provider unless absolutely necessary in order to complete your transaction and order. Your payment card details are collected and held by our secure payment service providers. Only the card type and last 4 digits of your card number are shared with us for accounting and audit purposes.

We use two payment processors to take payments on the website. The first is PayPal. You can review the PayPal privacy policy at www.paypal.com. We will share information with PayPal only to the extent necessary for the purposes of processing payments you make via our website and dealing with complaints and queries relating to such payments.

We also use a payment processor called Stripe. You can see the Stripe privacy policy at www.stripe.com. We will share information with Stripe only to the extent necessary for the purposes of processing payments you make via our website and dealing with complaints and queries relating to such payments.

To ensure that your credit/debit card is not being used fraudulently our payment providers will actively check the address you provide along with the CV2 value you entered against the card issuers records. In performing these actions, your address and CV2 will be sent to the card issuers systems. The card issuer will then return a response indicating if it has matched or not. We are not responsible for the values returned.

We also share your contact information with our delivery partners, so that items ordered can be delivered to you in a timely manner.

How secure is information about me?

Railwayscenics uses industry standard encryption technologies to securely protect any information when sending and receiving customer data.

Any passwords stored on the site are encrypted and even we cannot see what you have entered. As with most other online shops, we do recommend that you do not use the same password on multiple sites. You are responsible for keeping your password confidential, and you agree not to share that password with anyone else.

In the event of a data breach, we shall ensure that our obligations under applicable data protection laws are complied with where necessary.

Which information can I access?

Railwayscenics gives you access to a broad range of information about your account and your interactions with us for the limited purpose of viewing and, in certain cases, updating that information. Whilst all the information that we hold on you is accessible by you in your account area, you do have the right to see all the information that we hold. This has been made possible within your account area, where you can see, alter, update and download all the information that we hold.

If you have a concern about the way we are collecting or using your personal data, we request that you raise your concern with us in the first instance. Alternatively, you can contact the Information Commissioners Office at https://ico.org.uk/concerns/

How do we store and protect your personal information?

Railwayscenics are committed to protecting your personal information once we have it. We implement physical, business and technical security measures to protect your information. Our hosting service also has measures to stop information theft.

We also do not want to keep your personal information for any longer than we need it, so we only keep it long enough to do what we collected it for. Once we do not need it, we take steps to destroy it unless we are required by UK law to keep it longer.

However, no website or internet transmission is completely secure. We urge you to take your own steps to keep your personal information safe, such as choosing a strong password and keeping it private, as well as logging out of your user account, and closing your web browser when you have finished using the Railwayscenics website on a shared or unsecured device.

Your rights

As a data subject, you have the following legal rights:
(a) the right of access to personal data relating to you
(b) the right to correct any mistakes in your information
(c) the right to ask us to stop contacting you with direct marketing
(d) the right to prevent your personal data being processed in some circumstances
(e) the right to erasure in some circumstances

If you would like to exercise your rights please contact us. We will respond to any rights that you exercise within a month of receiving your request, unless the request is particularly complex, in which case we will respond within three months. Please note that exceptions apply to some of these rights which we will apply in accordance with the law and provision of such information will be subject to the supply of appropriate evidence of your identity.

Unsubscribing from promotional emails

Customers who wish to stop receiving any marketing email communications or amend their preferences can do so quickly and easily. All marketing emails include an Unsubscribe link. Alternatively, it is possible to alter your settings within your account page on the website. Please note that emails relating to the status of orders or transactions will still be sent and received.

Payment card information

Railwayscenics conform to PCI (Payment Card Industry) Legislation regarding the protection of cardholders data and personal information. All transactions take place outside of our website on a secured server. Personal payment card information is not published in any form on the website and is not accessible to staff at Railwayscenics.

Children

The Website is not intended for use by children, especially those under 16. No one under the age of 16 is allowed to provide any personal information or to use our reviews without parental consent. Accordingly, it is up to parents to ensure that their children abide by our Terms and Conditions. If you are concerned about your child's activities or their privacy on the website then please contact us.

What about cookies?

On 26 May 2011, the rules about cookies on websites changed. Railwayscenics may use both "session" cookies and "persistent" cookies on the website. Session cookies will be deleted from your computer when you close your browser. These types of cookies are used to track you whilst you navigate the website, and check your login status and shopping basket. Persistent cookies will remain stored on your computer until deleted, or until they reach a specified expiry date. These cookies will remember things like your user preferences, settings and information for future visits.

For further information look here on the ICO website.

Most browsers allow you to reject all cookies, whilst some browsers allow you to reject just third-party cookies. However, if you select this setting you may be unable to access certain parts of our site. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you log on to our site.

Visiting our website and the use of cookies

Cookies are small text files, used by your web browser to store visitor session data on your computer for websites that you visit. They are commonly used on the internet in order to make websites work more efficiently and to enhance user experience, as well as to provide relevant information to our website team.

Cookies are not intended to harm your system in any way.

Cookie consent

When you visit our website for the first time, you will be presented with a cookie information message stating that our site tries to use cookies.

By configuring your browser to accept cookies, we take this as consent to store them and they will be used. Otherwise, cookies will not be used unless, and until you consent by configuring your browser to allow them.

If you have configured your web browser to accept cookies, then you can clear the cookie information message which will store a cookie to say that you have done so (the Site cookie acceptance is detailed below).

You may also choose to delete any cookies from your computer between visits to our website. We recommend that if you have concerns about the privacy implications of the cookies this website or any potentially integrated third party sites uses, then you should investigate how to do this by using the cookie management tools in your web browser.

What cookies does the Railwayscenics website use?

Railwayscenics website only uses a few cookies, none of these are classed as intrusive and all are explained below.

Site cookie acceptance
This cookie is used to record if a user has accepted the use of cookies on the Railwayscenics website.

OSCid
This cookie is essential to be able to use our website. It is created as soon as you visit our website, and stores a unique identifier for your session. This session cookie is not permanently stored on your hard drive and expires as soon as you leave the website. This cookie is used to enhance your shopping experience.

Session cookies allow users to be recognised within a website so any page changes or item or data selection you do is remembered from page to page. The most common example of this functionality is the shopping cart feature of any e-commerce site. When you visit one page of a catalogue and select some items, the session cookie remembers your selection so your shopping cart will have the items you selected when you are ready to check out. Without session cookies, if you click CHECKOUT, the new page does not recognize your past activities on prior pages and your shopping cart will always be empty.

You can adjust your session cookies through the settings feature of your browser.

Google Analytics Cookies (_utma, _utmb, _utmc, _utmz)
Railwayscenics website uses Google Analytics, a web analytics service provided by Google Inc. Google Analytics sets a cookie in order to evaluate your use of the website and compile reports for us on activity on the website. The usage data may include your IP address, geographical location, browser version and type, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your visit. It is using these reports that we base our decisions on where information should be placed to make it easier for you to find.

Google have developed a browser Add-on which excludes Google Analytics recording your activities on any websites using Google Analytics. It is totally free and can be installed on most browsers. Please visit the Google website for more information. Googles privacy policy is available at: http://www.google.com/privacypolicy.html.

How do I disable cookies?

If you want to disable cookies you need to change your website browser settings to reject cookies. How to do this will depend on the browser you use and the correct information can be found by searching online.

If you disable or delete cookies you may not be able to shop or access important parts of our site, although some areas may be visible to you.

Do Not Track notifications

Some browsers allow you to automatically notify websites you visit not to track you using a "Do Not Track" signal. There is no consensus among industry participants as to what "Do Not Track" means in this context. Like many websites and online services, we currently do not alter our practices when we receive a "Do Not Track" signal from a visitor's browser. To find out more about "Do Not Track", you may wish to visit www.allaboutdnt.com..

Conditions of use policies, and revisions

If you choose to visit Railwayscenics, your visit and any dispute over privacy is subject to this notice and our Website Usage Policy. If you have any concern about privacy of your personal information as used and collected within our website, please send us a thorough description and we will try to resolve it.

Our business changes constantly, and our Privacy Policy and the Conditions of Use will change also. We may email periodic reminders of our policies and conditions, unless you have instructed us not to, but you should check our website frequently to see recent changes. Unless stated otherwise, our current Privacy Policy applies to all information that we have about you and your account. We stand behind the promises we make however, and will never materially change our policies and practices to make them less protective of customer information collected in the past without the consent of affected customers.

Disclosures

We may disclose information about you to any of our employees, officers, agents, suppliers or subcontractors in so far as reasonably necessary for the purposes as set out in this Privacy Policy.

In addition, we may disclose your personal information:
(a) to the extent that we are required to do so by law;
(b) in connection with any legal proceedings or prospective legal proceedings;
(c) in order to establish, exercise or defend our legal rights including providing information to others for the purposes of fraud prevention and reducing credit risk;

Except as provided in this Privacy Policy, we will not provide your information to third parties.

Links to other websites

Our website may contain links to enable you to visit other websites of interest easily. However, once you have used these links and leave our site, we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites, and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.

Acceptance of these Conditions

We assume that all visitors of our website have carefully read this document and agree to its contents. If someone does not agree with this Privacy Policy, they should refrain from using our website.

Changes to our privacy policy

Any changes we may make to our Privacy Policy in the future will be posted on this page and, where appropriate, notified to you by email and in our newsletter if you are subscribed. Continued use of Railwayscenics website after having been informed of any such changes to these conditions implies acceptance of the revised Privacy Policy. This privacy policy is an integral part of our terms and conditions.