Privacy Policy
Effective date: 9 October 2026 · Version 1.0
Operator: Sag Hussain trading as Retail Shield Group (a sole trader) trading as RetailShield Compliance · 52 Woodlands Road, Middlesbrough TS1 3BW
Privacy contact: sagarhussain2020@gmail.com
1. Privacy at a glance
RetailShield Compliance helps retail businesses organise checks, staff training and operational records. This policy explains how personal information is handled when you visit our website, contact us, create an account or use the service.
There are two main situations:
- Our own business information: we decide how to use website enquiries, account administration, billing, support and security information. We are the data controller for that processing.
- Your organisation's records: your employer or the organisation managing your store normally decides what staff, incident, training and compliance information is entered, who can access it and how long it is kept. That organisation is normally the controller, and we process the records on its instructions.
Accepting our service terms does not give us blanket consent to use personal information. Different activities have different lawful bases. You can raise a privacy concern without cancelling your account or paying a fee.
2. Who this policy covers
This policy covers website visitors; prospective customers; business owners and billing contacts; managers, designated premises supervisors and authorised staff; people contacting support; and individuals whose information is recorded by customer organisations.
It is not a replacement for an employer's staff privacy notice or a retailer's notice for people mentioned in its records. Those notices explain the organisation's own purposes, legal grounds, access decisions and retention periods.
Where another company provides an independently controlled payment, communication or integration service, its privacy notice may also apply. Details of the providers we use are available on request from sagarhussain2020@gmail.com.
3. Information we handle
Depending on your relationship with us and enabled features, information may include:
| Category | Examples | Typical role |
|---|---|---|
| Account and business contacts | Name, work email, account identifier, organisation, store assignment, contact details and role | Controller for account administration; processor for customer-managed profiles |
| Subscription and billing | Billing address, plan, invoice, payment status, transaction reference and promotion eligibility | Controller |
| Authentication and technical records | Sign-in events, IP address, browser/device type, access errors, session identifiers and security events | Controller for our platform security; processor for customer operational audit records |
| Checks and tasks | Completion status, answers, staff identifier, timestamps, manager review and corrective actions | Processor |
| Training | Assigned modules, acknowledgements, completion dates, results and refresher dates | Processor |
| Store documentation | Licence details, named DPS details, expiry dates and uploaded operational documents | Processor |
| Incidents and refusals | Necessary factual details, staff involved, approximate age where appropriate, action taken and attachments | Processor |
| Correspondence | Enquiries, support messages, complaints and privacy requests | Controller; processor where troubleshooting customer content |
| Preferences | Communication choices, cookie choices and permitted usage measurements | Controller |
We should not be given unnecessary ID documents, payment card information, medical histories or detailed allegations. A refusal record will often need only a brief factual description rather than a customer's full identity. Do not upload full passports or driving licences merely to show an age check took place.
Payments are currently arranged manually (for example by bank transfer or Direct Debit agreed with us). We record the plan, amount, payment status and payment reference; we do not collect or store payment card details. Never send card details to support.
4. Where information comes from
We receive information directly from users through registration, forms, messages and account activity; from organisation administrators who invite staff and assign roles; from use of the website and service; and, where enabled, from customer-authorised integrations and payment providers.
If someone creates an account for you, we normally receive your name, work contact details and store or role assignment from that organisation. For information we control and obtain indirectly, we provide the required privacy information within the applicable legal timeframe, including source and data categories, unless a lawful exception applies. The customer's controller remains responsible for transparency about its own uploaded records.
5. Why we use information and our lawful bases
The following applies to processing for which we are controller. Where more than one basis is listed, we select and document the basis applicable to the particular activity rather than treating them as interchangeable.
| Purpose | Data involved | Lawful basis and explanation |
|---|---|---|
| Supply a subscription to an individual contracting customer | Account, contact, billing and subscription information | Contract, where necessary to perform our contract with that person or requested pre-contract steps |
| Administer a corporate customer relationship and authorised user access | Business contacts, roles, invitations and service messages | Legitimate interests in delivering and administering the organisation's service; contractual necessity only where the individual is the contracting party |
| Answer enquiries and provide support | Contact details, correspondence and relevant technical details | Contract where necessary for an individual customer's contract; otherwise legitimate interests in responding and resolving problems |
| Keep the platform secure and investigate abuse | Technical access logs and security information | Legitimate interests in protecting users, customer organisations and the service; legal obligation where a specific duty requires processing |
| Issue invoices and meet applicable accounting obligations | Billing and financial records | Legal obligation where required by tax/accounting law; contract or legitimate interests for other billing administration |
| Handle privacy rights and regulatory requirements | Identity verification, request and response records | Legal obligation |
| Establish or defend legal claims | Relevant account, communication and dispute records | Legitimate interests in resolving disputes and protecting legal rights; legal obligation where compelled |
| Send permitted business marketing | Contact details, subscriber category, marketing preferences | Consent or legitimate interests, subject to the additional electronic-marketing rules explained below |
| Use optional cookies or similar technologies | Device identifiers and permitted measurement data | Consent where required; any applicable statutory exception must be assessed and documented, with required information and objection controls |
When relying on legitimate interests, we assess necessity, reasonable expectations and the potential effect on individuals. We do not use that basis where your interests or rights override ours. You can ask about the assessment and object where applicable.
Customer-controlled store records are processed under the Data Processing Agreement, not under a new general-purpose lawful basis selected by us. The customer must identify an Article 6 basis and any additional conditions its content requires.
6. Sensitive information and criminal allegations
Health information and other special-category information need both a lawful basis and an applicable additional condition. Information about offences, alleged offences and convictions has separate legal safeguards. An ordinary incident report can fall into these categories depending on its content.
Customers must minimise such information, restrict access and confirm the relevant lawful conditions before uploading it. RetailShield does not authorise collection simply by providing an incident form. Contact us before using the service for substantial health records, criminal-record screening, biometric identification or systematic sensitive-data monitoring. Such uses are outside the standard service unless separately assessed and agreed.
If we need such data for our own legal claims or statutory duties, we identify the applicable legal basis and additional condition and apply the required safeguards. We do not treat a tick-box acceptance of this policy as sufficient permission.
7. Staff visibility, store permissions and audit records
An organisation's authorised administrators may view account membership, relevant task activity and records within their permitted stores. Managers may review training and sign off checks where the customer has configured that role. Access follows the permissions assigned by the organisation and is enforced on our servers, not only by hiding menus.
Staff should understand that named completion records and timestamps may be visible to their managers. A customer must explain its monitoring arrangements and use records fairly. A completion entry is not, by itself, proof that a physical check was performed properly or that an employee committed misconduct.
Customer audit history may retain an attributable record after a user leaves employment. Where correction is necessary, it may be appropriate to append a correction while preserving a justified audit record. Accuracy, minimisation and deletion rights still apply; describing a record as an audit trail does not make it exempt from data protection law.
RetailShield personnel may access customer records only as authorised under the processing agreement, including necessary support, security or legal work. Our platform administration tools are separated from customers' compliance records.
8. Who receives information
Depending on purpose, recipients may include authorised users within the customer organisation; contracted hosting, database, authentication, email, support and security suppliers; independently controlled payment providers; professional advisers subject to confidentiality; and authorities where disclosure is legally required or otherwise lawfully justified.
We do not give regulators routine access to a retailer's account. Customer-initiated exports or access grants are the customer's decision. If a legal demand requires us to disclose information, we assess its scope and disclose only what is lawfully required or justified. We notify the customer where permitted.
For a proposed business sale or restructuring, relevant information may be shared with advisers or a prospective successor under appropriate safeguards. A successor must respect applicable data protection obligations. This does not permit unrestricted onward use.
We do not sell identifiable customer or staff records, use them for third-party advertising, or train general-purpose AI models on them. Irreversibly anonymised service statistics may be used for improvement; pseudonymised information remains personal information.
9. Suppliers, hosting and international transfers
A UK retail service is not automatically hosted solely in the UK. Storage, support access and onward transfers must all be considered. Where a restricted international transfer occurs, we use a lawful mechanism, such as applicable UK adequacy regulations, an appropriate International Data Transfer Agreement or UK Addendum, supported by the required assessment and supplementary protections. Any reliance on a certification-based arrangement is verified for the particular recipient and data covered.
Contact sagarhussain2020@gmail.com for information about our hosting locations, suppliers and applicable safeguards, and an appropriately redacted copy where available. We do not promise a particular region unless confirmed in your agreement.
10. Security
We implement appropriate technical and organisational measures reflecting the nature and risk of the information, including individual sign-in, organisation and store-level permissions enforced on our servers, and recorded change history for compliance records.
Customers must protect their devices and accounts, remove access for departing workers, use individual staff identities where attribution matters and keep shared devices securely configured.
No online service eliminates all risk. We do not claim ISO certification, penetration testing, a specific encryption standard, tamper-proof records or a recovery guarantee. A customer can request our available security information at sagarhussain2020@gmail.com.
11. Retention and deletion
We keep controller information only for the period justified by its purpose, applicable law and relevant disputes.
| Record | Retention rule |
|---|---|
| Account administration | While the account is open, then for up to 6 years after closure for legal claims |
| Invoices and tax records | 6 years from the end of the financial year they relate to |
| Unconverted enquiries | Up to 2 years from last meaningful contact |
| Support correspondence | Up to 2 years from resolution |
| Platform security logs | Up to 90 days on our hosting platform; longer only for documented incidents or claims |
| Rights requests and privacy complaints | Up to 3 years from closure |
| Marketing preferences | While relevant, with a minimal suppression record for as long as needed to honour objections |
| Customer operational records | Customer instructions and the agreed retention settings; no universal claim that all compliance records must be retained for the same period |
| Closed-workspace exports and active-system deletion | 30-day export window, followed by deletion from active systems within 60 days |
| Backup copies | Expire within a further 90 days after active deletion; deletion is reapplied if a backup is restored |
An account being disabled does not necessarily delete its historical records. If retention is required by law or a genuine legal hold, we limit access and retain only the necessary information. Deleted information may remain temporarily in protected backups until expiry; it is not used in ordinary operations.
Customers are responsible for their own downloaded copies and for retention instructions they choose. When an account is closed we explain the last date for export before deletion begins.
13. Marketing and service messages
Service messages include security alerts, invoices, training and policy reminders and material subscription notices. These are distinguished from promotional campaigns; unsubscribing from marketing does not stop necessary service communications.
For sole traders and other individual subscribers, electronic marketing requires consent unless a lawful exception such as the properly implemented customer soft opt-in applies. That exception requires its conditions to be met, including an opportunity to opt out at collection and in each message. Corporate business communications remain subject to identification, opt-out and data protection rules.
You can unsubscribe using the message control or contact sagarhussain2020@gmail.com. We keep a minimal suppression entry where needed to prevent renewed marketing. We do not share contacts for another business's marketing.
14. Your rights
Depending on the circumstances, you may request access to your personal information; correction; erasure; restriction; transfer of qualifying information in a portable format; or object to processing. You can withdraw consent where processing relies on it, without affecting the lawfulness of earlier processing. You have an absolute right to object to direct marketing.
Rights have conditions and exceptions. For example, erasure may not apply to necessary legal records, and a staff member's portability right does not automatically include an entire store's business records. We explain any refusal or limitation and the available complaint route.
Contact sagarhussain2020@gmail.com, stating what you want us to consider. We verify identity proportionately and protect other people's information. We normally respond within one month, subject to lawful extensions. Requests are normally free.
If the request concerns your employer's records, contact that organisation first where practical. You may still contact us: we identify the relevant controller, forward the request appropriately and assist it under our agreement. We do not require you to buy a subscription or obtain your manager's approval to raise a privacy request.
15. Automated processing and AI
Routine due-date calculations, reminders and overdue indicators may organise records. They must not be treated as an automatic employment decision, legal ruling or regulatory approval.
The service does not make solely automated decisions producing legal or similarly significant effects about individuals. An optional feature lets organisation owners and admins paste their own training material to generate draft quiz questions using an AI model; drafts must be reviewed by a person before use. Store records such as incidents, refusals and staff details are not sent to the AI model.
16. Children and younger workers
The service is sold to organisations, not directly to children. A retailer may employ workers under 18. If such workers are authorised users or appear in records, the organisation must consider their needs and provide understandable information.
Do not upload identifiable details of child customers unless necessary and lawful. Incident and refusal records should avoid unnecessary names, images and identification-document copies.
17. Privacy complaints and incidents
Contact sagarhussain2020@gmail.com or write to Sag Hussain trading as Retail Shield Group (a sole trader), 52 Woodlands Road, Middlesbrough TS1 3BW. Tell us what happened and the outcome you seek; a concern need not use legal terminology to be recognised.
We acknowledge data protection complaints within 30 days and investigate without undue delay, keep you appropriately informed and explain the outcome.
You may complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint. You do not have to accept our outcome before approaching the regulator.
If you suspect unauthorised account access or exposure, contact us promptly. Do not include passwords or full sensitive records in an ordinary email. For customer-controlled data, we inform the controller without undue delay and assist its assessment.
18. Changes and contact
We date and version this policy. Material changes are communicated through account notices or direct messages. A policy update does not retrospectively authorise incompatible processing. Older versions are available on request.
Questions, rights requests, privacy complaints and general support: sagarhussain2020@gmail.com.
Operated by Sag Hussain trading as Retail Shield Group (a sole trader), 52 Woodlands Road, Middlesbrough TS1 3BW. Related documents: Privacy Policy · Business Terms · Data Processing Agreement · Suppliers · Contact