Privacy Policy
Last Updated: June 2026
This Privacy Policy describes how JIA Active (referred to as "we", "us", or "our") collects, uses, and discloses your personal data when you visit, use our website, make a purchase or other transaction through our platform, or otherwise communicate with us (collectively, the “Services”).
JIA Active is the Data Controller for the personal data collected through our website and Services under UK data protection laws.
Our store is powered by Shopify Inc., which enables us to provide the Services to you. If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy takes precedence in relation to the collection, processing, and disclosure of your personal data.
Please read this Privacy Policy carefully. By using and accessing any of the Services, you acknowledge that you understand how your personal data will be collected, used, and disclosed as described in this document.
PERSONAL DATA WE COLLECT OR PROCESS
When we refer to “personal data”, we mean any information relating to an identified or identifiable individual. This does not include anonymous or aggregated data that cannot reasonably identify you.
We may collect and process the following categories of personal data, depending on how you interact with the Services and as permitted or required by law:
- Contact details: including your name, billing address, delivery address, email address, and telephone number.
- Financial information: including payment card details, payment method, billing information, and transaction details. (Note: Full payment card details are processed securely by our third-party payment providers via Shopify Payments and are never stored or seen by us).
- Account information: including login details, password, preferences, and saved settings.
- Transaction information: including purchases, returns, cancellations, and order history.
- Communications: including information you provide when contacting our customer support team or interacting with us on social media.
- Device information: including IP address, browser type, device identifiers, time zone, and network information.
- Usage data: including how you interact with our website, pages viewed, search terms, and general browsing behaviour.
HOW WE COLLECT YOUR DATA
We collect personal data through the following methods:
- Directly from you: For example, when you place an order, create an account, sign up to our newsletter, or contact us.
- Automatically via cookies and similar tracking technologies: When you browse our website, Shopify automatically collects certain device and usage data.
- From third-party service providers: Such as Shopify, payment gateways, and delivery/fulfilment partners who pass information to us to complete your order.
HOW WE USE YOUR PERSONAL DATA
We will only use your personal data where we have a valid lawful basis under the UK GDPR. These include performance of a contract, legal obligation, legitimate interests, or your explicit consent.
We use your personal data to:
- Provide our Services (Performance of a Contract): To process orders, take payments, fulfil deliveries, manage returns, provide customer support, and maintain your account.
- Improve our Services (Legitimate Interests): To optimise and improve our website performance, product offering, and general customer experience based on analytics.
- Marketing (Consent / Legitimate Interests): To send you marketing communications regarding new collections or events where permitted by law. You may opt out or unsubscribe completely at any time.
- Security and Fraud Prevention (Legitimate Interests / Legal Obligation): To detect, investigate, and prevent fraudulent, unauthorised, or unlawful activity.
- Legal Compliance: To comply with applicable UK laws, tax regulatory obligations, or lawful law enforcement requests.
COOKIES AND SIMILAR TECHNOLOGIES
Our store uses cookies powered by Shopify to ensure a seamless shopping experience. These include Functional Cookies (necessary for the shopping cart and checkout to remember your items) and Analytical Cookies (used to understand traffic patterns). You can control or block cookies through your internet browser settings, though blocking essential cookies may impact your ability to use the checkout functionality.
HOW WE SHARE PERSONAL DATA
We may share your personal data with select third parties who help us run our business:
- Shopify and related IT infrastructure service providers.
- Payment providers (such as Shopify Payments, Apple Pay, or PayPal).
- Delivery and fulfilment partners (couriers used to ship your orders).
- Analytics and marketing providers (to help us understand our audience).
- Professional advisers (including legal, accounting, and insurance services).
- Regulatory bodies or law enforcement where strictly required to comply with UK statutory obligations.
We ensure that all third-party partners process your data in accordance with strict contractual data protection agreements that match UK GDPR standards.
INTERNATIONAL TRANSFERS & SHOPIFY
Because our store is hosted by Shopify, your personal data may be transferred, stored, and processed outside the United Kingdom (for example, in Canada or the United States). Where international transfers occur, we rely on legally recognised safeguards approved by the UK Government, such as UK-approved Standard Contractual Clauses (SCCs) or the International Data Transfer Addendum (IDTA), ensuring your data receives the same high level of protection it has within the UK.
AUTOMATED DECISION-MAKING
We utilise Shopify’s automated systems to help prevent fraud. Shopify uses automated decision-making to block transactions that show severe indicators of fraud (such as stolen payment details). This processing has a minimal, temporary effect on you as a consumer; however, if your transaction is declined and you believe it was an error, you have the right to contact us to request a manual review.
DATA SECURITY AND RETENTION
- Security: We and Shopify take appropriate technical and organisational measures (including SSL encryption) to protect your personal data. However, no digital transmission over the internet can be guaranteed as 100% secure.
- Retention: We retain your personal data only for as long as necessary to fulfil the purposes we collected it for, including satisfying any legal, accounting, or statutory reporting requirements (such as retaining commercial transaction data for UK tax purposes).
YOUR LEGAL RIGHTS (UK GDPR)
Under UK data protection law, you hold the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request that we correct inaccurate or incomplete data.
- Right to erasure: Request that we delete your data ("the right to be forgotten").
- Right to restrict processing: Ask us to temporarily stop processing your data.
- Right to object: Object to our processing of your data based on legitimate interests or direct marketing.
- Right to data portability: Request the transfer of your data to another service provider.
- Right to withdraw consent: Withdraw your consent at any time where consent is our legal basis.
To exercise any of these rights, please contact us using the details below. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection (https://ico.org.uk).
CHILDREN
Our Services are not intended for children under 18, and we do not knowingly collect personal data from children.
CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. Any updates will be posted on this page with a revised “Last updated” date.
CONTACT DETAILS
If you have any questions about this Privacy Policy or wish to exercise your legal rights, please contact us at:
- Email: hello@jiaactive.com
- Postal Address: 124 City Road, London, EC1V 2NX