Privacy Policy
Last updated: 14 July 2026
Page title: Privacy Policy · Shopify slug: privacy-policy
Protecting your personal data matters a great deal to MIREXO ("we", "us", "our"). This Privacy Policy sets out openly which personal data we collect, why we collect it, and how we look after it. It's drawn up with reference to the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) and the Data Protection Act 2018.
1. Data Controller
For the purposes of the UK GDPR, the data controller is the operator of mirexo.com. Any queries about this policy, or how your data is used, can be sent to contact@mirexo.com. Full provider particulars are set out in our Legal Notice.
2. Types of Data We Process
When you order something or get in touch with an enquiry, we process:
- Your first and last name and email address
- Delivery and billing address
- Telephone number (optional — used to keep you posted on delivery status)
- Payment particulars (handled securely by our payment partner; we don't retain card details ourselves)
- Your order and purchase history
- Technical data about your device and how you browse our site (IP address, browser type, pages visited)
3. Purposes of Processing and Legal Bases
- Fulfilling your order — your name, address, email and payment particulars are needed to carry out the sales contract concluded with you (Art. 6(1)(b) UK GDPR).
- Staying in touch — order confirmations, dispatch updates and customer service correspondence (Art. 6(1)(b) UK GDPR).
- Improving what we offer — analysing how our site is used lets us keep making it better (Art. 6(1)(f) UK GDPR — legitimate interest).
- Meeting legal duties — records are kept in line with applicable tax and company law requirements (Art. 6(1)(c) UK GDPR).
4. Payment Processing
Payments run through our partners (such as Stripe, PayPal, Klarna or Viva Wallet), each certified to PCI DSS Level 1. Card particulars are entered directly into their secure environment; MIREXO never sees or stores the full card number, CVV code or expiry date.
5. Data Retention Period
Order records are kept for 6 to 10 years to meet UK tax and accounting obligations (including those set by HMRC and the Companies Act 2006). Marketing preferences stay on file until you unsubscribe. Anything no longer needed is deleted or anonymised once its purpose has been served.
6. Recipients of the Data
We only share your data with third parties where needed to fulfil your order:
- Delivery partners (e.g. Royal Mail, DHL, DPD, Evri, UPS)
- Payment providers, to process transactions securely
- Email service providers, for transactional messages
- Hosting providers, to keep the site running
- Accountants and legal advisers, where needed to meet legal obligations
We've put appropriate data processing agreements in place with each of these processors, in line with Art. 28 UK GDPR.
7. Data Transfers to Third Countries
Data only leaves the United Kingdom or European Economic Area (EEA) where an adequacy decision applies, or where suitable safeguards — such as the Standard Contractual Clauses adopted by the UK or the EU Commission — are in place under Art. 45 ff. UK GDPR.
8. Cookies and Tracking
Our site uses cookies and similar technologies. You'll find full particulars in our Cookie Policy. Non-essential cookies can be turned off or adjusted at any time via the cookie banner and your browser settings.
9. Your Rights as a Data Subject
You hold the following rights over your personal data:
- Right of access (Art. 15 UK GDPR) — find out what data we hold about you
- Right to rectification (Art. 16 UK GDPR) — get inaccurate data fixed
- Right to erasure (Art. 17 UK GDPR) — where no legal duty to retain applies
- Right to restriction of processing (Art. 18 UK GDPR)
- Right to data portability (Art. 20 UK GDPR)
- Right to object (Art. 21 UK GDPR) — to processing based on legitimate interest
- Right to withdraw consent at any time (Art. 7(3) UK GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 UK GDPR)
To use any of these rights, just send a short message to contact@mirexo.com.
10. Security of Your Data
We've put appropriate technical and organisational safeguards in place to keep your data safe from unauthorised access, loss or misuse — including SSL/TLS encryption, secure server environments, restricted access rights and regular security checks.
11. Automated Decision-Making
We don't use automated decision-making or profiling as defined under Art. 22 UK GDPR.
12. Right to Complain
If you think our handling of your data breaches UK GDPR, you can lodge a complaint with a data protection supervisory authority — in particular the Information Commissioner's Office (ICO) in the United Kingdom (www.ico.org.uk), or the supervisory authority in the EU member state where you live, work, or where the alleged breach happened.
13. Updates to This Policy
We may update this Privacy Policy periodically to reflect changes in the law or in how we run our business. You can always find the current version here on this page.