24 July 2026
1. This Privacy Policy describes how Roots Art Ltd ("Roots Art", "Roots", "we", "us", or "our"), collects, uses, and shares personal data. Roots Art Ltd is registered with the Information Commissioner's Office (ICO) under ZC196595.
1.1. Last updated on the 24 July 2026
2.1. If you visit rootsart.co.uk: IP address, browser, device, and pages viewed, collected by cookies (see Cookies and advertising below). Searches you make, including postcodes, place names, and your location if you use the "Use my Location" feature.
2.2. If you buy from us: name, email, and phone number; delivery and billing addresses; order history and customer service messages; account login details and preferences, if you create one. Payment details go directly to our payment providers — we never see or store your full card details.
2.3. If you are an artist: your public profile (display name, portrait, bio, displayed location, and postcode), legal name and contact details. Your Artist Agreement acceptance record (the version you accepted, the date and time, and the details you submitted). Your artwork (files, titles, descriptions, and preferences). Your bank details — account holder name, sort code, and account number.
3.1. Most comes from you: placing an order, creating an account, contacting us, joining the mailing list, or onboarding as an artist. The rest arrives automatically from your device via cookies; from the providers who run parts of our business (Shopify, payment processors); from Meta and Google, who report on how our advertising performs; and from Shopify's fraud analysis, which gives us risk signals about transactions.
4.1. To fulfil your orders including payment, printing, delivery, returns, confirmations, and dispatch updates.
4.2. To run your account and answer your questions.
4.3. To onboard artists, display their profiles, and pay their commission.
4.4. To send marketing emails if you've opted in.
4.5. To spot potentially fraudulent orders.
4.6. To measure and improve rootsart.co.uk and our advertising.
4.7. To keep the records the law says we must.
5.1. UK data protection law requires a lawful basis for each use:
a. Contract — fulfilling your orders, and onboarding, displaying, and paying artists under the Artist Agreement.
b. Consent — marketing emails and non-essential cookies. Withdraw it whenever you like.
c. Legitimate interests — running, securing, and improving the business, and preventing fraud. You can object at any time (see Your rights).
d. Legal obligation — tax, accounting, and consumer law records.
6.1. Essential cookies (basket, security) are always on. Everything else runs only with your consent, given or withdrawn through the cookie banner.
6.2. With your consent we use: Meta Pixel and Conversions API — the pixel collects data in your browser, and the Conversions API sends events (e.g. purchases) and hashed identifiers to Meta from our systems, so we can measure and target our advertising. Google Analytics 4, to understand how rootsart.co.uk is used, and Google Ads, to measure our advertising. Shopify, which sets cookies to run the store.
6.3. You can change your mind any time via the cookie settings link, opt out of personalised ads in your Meta and Google account settings, and opt out of Google Analytics at tools.google.com/dlpage/gaoptout. We do not currently respond to "Do Not Track" browser signals, which are not standardised.
7.1. We never sell your personal information. We share it only with those who help run Roots, and only what they need:
a. Shopify hosts rootsart.co.uk and processes orders and accounts.
b. Payment providers take your payment directly at checkout.
c. Prodigi prints and delivers your order, so receives your name, delivery address, and the artwork file.
d. Google hosts emails and we use Google Workspace and Drive.
e. Meta receives hashed email, IP address, and event data for advertising, with your consent, as above.
f. An email marketing provider where we use one, to send messages on our behalf.
g. Professional advisers, our bank, accountants, lawyers, insurers.
h. Authorities where the law requires.
i. A buyer or investor if we ever sell, merge, or finance all or part of the business.
8.1. We are UK-based, but some providers process data outside the UK, including in the US. Those transfers are protected by UK adequacy decisions (including the UK Extension to the EU-US Data Privacy Framework) or the UK International Data Transfer Agreement or Addendum.
a. Order and payment records: 6 years from the end of the financial year (tax law).
b. Artist Agreements and acceptance records: 6 years after the agreement ends.
c. Artist bank details: until your final payment is made and reconciled.
d. Artist public profiles: while your work is listed; removed promptly after your agreement ends.
e. Marketing lists: until you unsubscribe or ask us to delete them.
f. Analytics and advertising data: per each tool's settings, set to the shortest available.
9.2. After that, we delete or anonymise it.
10.1. You can ask us to show you the data we hold about you, correct it, delete it (unless the law requires us to keep it), give it to you in a portable format, or restrict or stop processing it — including any processing based on legitimate interests, and direct marketing. You can withdraw consent at any time.
10.2. Email privacy@rootsart.co.uk with "Privacy request" in the subject line. We will verify your identity and reply within one month. Someone can make a request on your behalf if you authorise them.
10.3. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113, or to your local data protection authority in the EEA.
11.1. Encryption in transit, restricted access, and the security programmes of our providers. Shopify handles all card processing and is PCI-DSS compliant. Artist bank details are stored separately, with restricted access. No system is perfectly secure, though, and we cannot guarantee the absolute security of information sent to or from the site.
12.1. We make no automated decisions with legal or similarly significant effects. Where a system flags something — such as a potentially fraudulent order — a person reviews it before any action is taken.
13.1. We may update this policy. The current version is always on this page, and we will flag significant changes.