Privacy Policy
Last updated: 5 June 2026
This Privacy Policy explains how ShutterLab ("ShutterLab", "we", "us", or "our") collects, uses, stores, and protects personal data when you visit shutterlab.uk (the "Website") or engage us to survey, supply, or install bespoke window shutters. We are committed to protecting your privacy in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
ShutterLab is a family-run shutter specialist established in 2015, covering Oxfordshire, Buckinghamshire, Berkshire, Hertfordshire, North/West/South London, Surrey, & Middlesex. For the purposes of UK data protection law, ShutterLab is the data controller of the personal data we collect about you.
- Trading name: ShutterLab
- VAT number: 446 5039 88
- Email: office@shutterlab.uk
- Phone: 0330 043 8767
2. Personal data we collect
We only collect the minimum information needed to respond to your enquiry and deliver our service. Depending on how you interact with us, this may include:
- Contact details — your name, email address, phone number, and the property address where shutters are to be measured or installed.
- Enquiry details — the rooms, windows, materials, and shutter styles you are interested in, plus any notes you share with us by email, phone, or via our online booking tool.
- Booking information — the date, time, and address for surveys booked through our scheduling provider (see Section 6).
- Order and payment records — invoices, deposit and balance payments, and a record of the goods supplied and installed. We do not store card numbers; payments are handled by our bank or payment provider.
- Technical data — IP address, device and browser type, referring page, pages visited on shutterlab.uk, and approximate location, captured by analytics tools (see Section 5).
3. How we use your data and our lawful bases
We process your personal data for the following purposes:
- To respond to enquiries and arrange surveys. Lawful basis: taking steps at your request prior to entering into a contract.
- To supply, manufacture, and install shutters and to manage aftercare and warranty claims. Lawful basis: performance of a contract with you.
- To meet our legal and accounting obligations (e.g. retaining invoices for HMRC). Lawful basis: legal obligation.
- To run, secure, and improve the Website using privacy-respecting analytics and basic logging. Lawful basis: legitimate interests in operating a safe, performant website.
- To run conversion measurement and remarketing via the Meta (Facebook) Pixel where you have consented. Lawful basis: consent.
4. Cookies and similar technologies
The Website uses a small number of cookies and similar storage
mechanisms. When you first visit the Website you will see a cookie
banner. Your choice is stored in your browser under
sl-cookie-consent; you can clear it at any time via your
browser's site-data settings to be asked again.
Strictly necessary
- Cookie consent — a single
localStorageentry recording that you have responded to the cookie banner. - Hosting and security — our hosting provider, Netlify, may set short-lived cookies for load-balancing and fraud-prevention purposes.
Analytics and marketing (only with your consent)
- Dotwall Monitor — a privacy-respecting first-party analytics tool that records page views, referring pages, and aggregate usage. It is operated on our behalf by our developer dotwall (dotwall.co.uk).
- Meta (Facebook) Pixel — a tag from Meta Platforms
Ireland Ltd that measures the effectiveness of our Facebook and
Instagram advertising and may set cookies on facebook.com. Pixel ID:
1654187028685652. See Meta's Data Policy.
5. Third-party services we rely on
To run the Website and our service we use the following processors and embedded services. Each may receive limited data (such as your IP address and request headers) when the relevant page or feature is loaded.
- Netlify — Website hosting and content delivery. Netlify Privacy Policy.
- Google Fonts (Google Ireland Ltd) — Cormorant
Garamond and Manrope typefaces are served from
fonts.googleapis.comandfonts.gstatic.com. Google Privacy Policy. - Squarespace Acuity Scheduling (Squarespace Ireland Ltd) — powers the booking iframe on our Contact page so you can reserve a free home survey. Any details you submit are processed by Acuity on our behalf. Squarespace Privacy Policy.
- Elfsight (Elfsight LLC) — embeds our Google reviews widget on the Reviews page. Elfsight Privacy Policy.
- Meta Platforms Ireland Ltd — Facebook Pixel measurement (only with consent).
- Email and telephone provider — calls and emails to our published contact details are routed by our telephony and email providers, who hold the message in transit and store standard metadata.
Outbound links to Trustpilot, Google Maps, Facebook, and Instagram are not embeds — those sites only receive data about you if you click through.
6. Bookings made through Acuity Scheduling
When you book a survey via the embedded scheduler, the information you enter (name, email, phone, address, time slot, and any notes) is submitted directly to Squarespace Acuity Scheduling and forwarded to us. We use this information solely to attend your survey and prepare a quotation.
7. How we share your data
We do not sell your personal data. We share it only with:
- Our shutter manufacturers and fitters, where strictly necessary to fulfil your order;
- The processors listed in Section 5;
- Our accountants, bank, and payment provider, for invoicing and financial-record purposes;
- Regulators, law enforcement, or legal advisers where we are required or permitted by law to do so.
8. International transfers
Some of our processors (notably Meta and Google) may transfer data outside the UK / EEA. Where they do, transfers are protected by UK International Data Transfer Agreements, the EU Standard Contractual Clauses, or an adequacy decision recognised by the UK government.
9. How long we keep your data
- Enquiries that don't lead to an order — typically deleted or anonymised within 24 months.
- Customer records and warranty information — kept for the duration of the 10-year product and installation warranty, plus a reasonable period afterwards.
- Tax and accounting records — kept for at least 6 years as required by HMRC.
- Analytics data — held in aggregated form by our analytics providers for the periods stated in their own policies.
10. Your rights
Under UK GDPR you have the right to:
- access a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to certain processing;
- withdraw any consent you have given (e.g. for the Pixel);
- port your data to another provider where applicable;
- complain to the UK Information Commissioner's Office at ico.org.uk if you believe we have mishandled your data.
To exercise any of these rights, email office@shutterlab.uk. We will respond within one calendar month.
11. Security
We use reasonable technical and organisational measures to protect your data, including HTTPS encryption across the entire Website, access controls on our systems, and reputable processors. No method of transmission over the internet is 100% secure, however, so we cannot guarantee absolute security.
12. Children
The Website is intended for property owners and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our service, technology, or the law. The "Last updated" date at the top of this page will always show when it was last revised.
14. Contact us
For any questions about this policy or about your data, please contact us at office@shutterlab.uk or 0330 043 8767.