Coming Soon — we’re putting the finishing touches on. Sign up for early access

Legal

Privacy Policy

Last updated: April 2026

Harbor (“we”, “us”, “our”) is committed to protecting your personal data. This policy explains what information we collect, how we use it, and your rights under UK GDPR and the Data Protection Act 2018. If you have any questions, contact us at hello@harborcards.com.

1. Who We Are

Harbor is an online greeting card retailer based in the United Kingdom, operating at harborcards.com.

We are the data controller for the personal information you provide to us.

2. What Data We Collect

We collect the following personal data:

• Email address — when you sign up for festival reminders or place an order

• Name and delivery address — when you place an order

• Payment information — processed securely by Stripe; we never store card details

• Order history — to fulfil your orders and handle any queries

• IP address and browser data — collected automatically for security and analytics

3. Why We Collect It

We use your data for the following purposes:

• To process and fulfil your orders (legal basis: contract)

• To send festival reminders and occasional news, where you have given explicit consent (legal basis: consent)

• To respond to customer service enquiries (legal basis: legitimate interest)

• To comply with legal obligations such as tax and fraud prevention (legal basis: legal obligation)

We will never sell your data to third parties or use it for any purpose beyond what is stated here.

4. Festival Reminder Emails

If you have signed up to receive festival reminders, your email address is stored with MailerLite, our email marketing provider. You gave explicit consent at the point of sign-up by ticking the consent checkbox.

You can unsubscribe at any time by clicking the unsubscribe link in any email we send, or by emailing us at hello@harborcards.com. We will remove you from our list within 5 working days.

5. Who We Share Your Data With

We share your data only where necessary to operate our service:

• Stripe — payment processing (stripe.com/gb/privacy)

• Our print and fulfilment partner — to produce and deliver your order

• MailerLite — email marketing, festival reminders (mailerlite.com/privacy)

All third parties are required to handle your data securely and in compliance with applicable data protection law.

6. How Long We Keep Your Data

• Order data — retained for 7 years to comply with HMRC requirements

• Email subscribers — retained until you unsubscribe

• Customer service emails — retained for 2 years

When data is no longer needed, it is securely deleted.

7. Your Rights

Under UK GDPR you have the right to:

• Access the personal data we hold about you

• Correct any inaccurate data

• Request deletion of your data ("right to be forgotten")

• Restrict or object to how we use your data

• Withdraw consent at any time (where processing is based on consent)

• Receive your data in a portable format

• Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk

To exercise any of these rights, contact us at hello@harborcards.com. We will respond within 30 days.

8. Cookies

Our website uses only essential cookies necessary for the site to function (such as your shopping cart). We do not use advertising or tracking cookies. No cookie consent banner is required for essential cookies only.

9. Data Security

We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss or misuse. Our site is served over HTTPS. Payment data is handled entirely by Stripe and never passes through our servers.

10. Changes to This Policy

We may update this policy from time to time. Any significant changes will be noted at the top of this page with a revised date. Continued use of our site after changes constitutes acceptance of the updated policy.

Contact

For any privacy-related queries or to exercise your rights, please contact us at hello@harborcards.com. We aim to respond within 5 working days.