Main Menu
18+ Years Expertise18+ Years Expertise
Next Day DeliveryNext Day Delivery
FSC CertifiedFSC Certified
UK ManufacturingUK Manufacturing
Award WinningAward Winning
Trustpilot: ExcellentTrustpilot: Excellent
Privacy Policy

[UPDATED 2026]

This privacy policy sets out how Tiny Box Company Limited, uses and protects any information that you give Tiny Box Company Limited. Tiny Box Company Limited is a company registered in England and Wales under company number is 06350135 and with Our registered office at Units 1 & 2, Bluebell Business Estate, Sheffield Park, Uckfield, East Sussex, TN22 3HQ, Tiny Box Company Limited is committed to ensuring that your privacy is protected. Should we ask you to provide certain information by which you can be identified, then you can be assured that it will only be used in accordance with this privacy statement.

 

What information we collect

Depending on how you use our website and services, we may collect:

Information you give us

  • Name, billing address, delivery address
  • Email address and phone number
  • Order details (what you bought, when, how it was delivered)
  • Customer service details (messages you send us, and information you share in support requests or live chat)
  • Marketing preferences (email and SMS choices)

Information collected automatically

When you use our site, we may collect technical and usage information such as:

  • IP address, device type, browser type, time zone and language settings
  • Pages viewed, clicks, scrolls, and how you move through the site
  • Referring links and marketing tags (for example, whether you came from an ad)

Information from other sources

We may receive information from service providers who help us run our site and marketing (for example, delivery updates, fraud checks, and marketing reporting).

 


 

How we use your information

1) To process orders and deliver products

We use your information to:

  • Take payments, confirm orders, deliver items, handle returns and refunds
  • Send important updates about your order (for example, dispatch and delivery updates)
  • Prevent fraud and keep transactions secure

Reason: We need this information to perform our contract with you (to supply what you ordered) and to meet legal obligations.

2) To provide customer support (including live chat)

If you contact us by phone, email, or live chat, we use your information to respond and help resolve issues.

We use Zendesk to manage support tickets and provide website live chat. If you use live chat, Zendesk may use cookies or similar tools so the chat works properly.

Reason: Legitimate interests (we need to support customers) and sometimes contract (helping you with an order).

3) To send marketing (email)

If you opt in to email marketing, we will send you marketing emails. Every marketing email includes a way to unsubscribe.

Reason: Consent (you can withdraw consent at any time).

4) To send marketing (SMS / text messages)

If you opt in to SMS marketing, we will use your mobile number to send you marketing text messages (for example, offers, reminders, product updates).

We keep a record of your SMS opt in, including when and how you opted in, so we can respect your choices and demonstrate consent if needed.

Reason: Consent (you can stop SMS at any time).

SMS cart reminders

If you opt in to SMS and start a checkout or add items to your basket but do not complete your purchase, our site uses cookies and similar tools to help keep track of items you put into your shopping basket, including when you have abandoned your cart. We use this information to determine when to send cart reminder messages via SMS.


5) To improve our website and measure performance

We use analytics and performance tools to understand how people use the site, fix issues, improve pages, and measure marketing performance.

Reason: Legitimate interests (running and improving our business and give you better service). For non essential cookies and tracking, we rely on your cookie choices.


6) To keep our website secure

We use security and performance services to protect the site from attacks, reduce fraud, and improve reliability.

We use Cloudflare as a security and performance provider. This means Cloudflare may process technical data like IP address and traffic data to protect and deliver the website.

Reason: Legitimate interests (security and fraud prevention) and legal obligations where applicable to protect your data and security.

 


Server-side tracking

We use “server-side tracking” for some measurement and reporting. This means that in some cases, data about activity on the site (for example, page views, purchases, or marketing source information) is sent from our servers to our analytics and advertising partners, instead of being sent only from your browser.

This can reduce the number of third party scripts running in your browser. Where tracking relies on cookies or similar tools, we follow your cookie choices.



Who we share your information with

We share personal information with trusted service providers who help us operate our business. This may include:

  • Ecommerce platform and website providers (including Magento and related services, and Hyvä technology used to improve the storefront experience)
  • Payment providers
  • Delivery and fulfilment partners
  • Fraud prevention and security partners
  • Customer support tools (including Zendesk, including live chat)
  • Marketing platforms (including Klaviyo for email and SMS)
  • Analytics and advertising partners (only where allowed by your cookie choices)

We only share what is needed for them to provide their services to us.

Mobile Terms of Service

The Tiny Box Company mobile message service (the "Service") is operated by Tiny Box Company (“Tiny Box Company”, “we”, or “us”). Your use of the Service constitutes your agreement to these terms and conditions (“Mobile Terms”). We may modify or cancel the Service or any of its features without notice. To the extent permitted by applicable law, we may also modify these Mobile Terms at any time and your continued use of the Service following the effective date of any such changes shall constitute your acceptance of such changes.

By consenting to Tiny Box Company’s SMS/text messaging service, you agree to receive recurring SMS/text messages from and on behalf of Tiny Box Company through your wireless provider to the mobile number you provided, even if your mobile number is registered on any state or federal Do Not Call list. Text messages may be sent using an automatic telephone dialing system or other technology. Service-related messages may include updates, alerts, and information (e.g., order updates, account alerts, etc.). Promotional messages may include promotions, specials, and other marketing offers (e.g., cart reminders).

You understand that you do not have to sign up for this program in order to make any purchases, and your consent is not a condition of any purchase with Tiny Box Company. Your participation in this program is completely voluntary.

We do not charge for the Service, but you are responsible for all charges and fees associated with text messaging imposed by your wireless provider. Message frequency varies. Message and data rates may apply. Check your mobile plan and contact your wireless provider for details. You are solely responsible for all charges related to SMS/text messages, including charges from your wireless provider.

You may opt-out of the Service at any time. Text the single keyword command STOP to Tiny Box Co or click the unsubscribe link (where available) in any text message to cancel. You'll receive a one-time opt-out confirmation text message. No further messages will be sent to your mobile device, unless initiated by you. If you have subscribed to other Tiny Box Company mobile message programs and wish to cancel, except where applicable law requires otherwise, you will need to opt out separately from those programs by following the instructions provided in their respective mobile terms.

For Service support or assistance, text HELP to Tiny Box Company or email marketing@tinyboxcompany.com.

We may change any short code or telephone number we use to operate the Service at any time and will notify you of these changes. You acknowledge that any messages, including any STOP or HELP requests, you send to a short code or telephone number we have changed may not be received and we will not be responsible for honoring requests made in such messages.

The wireless carriers supported by the Service are not liable for delayed or undelivered messages. You agree to provide us with a valid mobile number. If you get a new mobile number, you will need to sign up for the program with your new number.

To the extent permitted by applicable law, you agree that we will not be liable for failed, delayed, or misdirected delivery of any information sent through the Service, any errors in such information, and/or any action you may or may not take in reliance on the information or Service.

We respect your right to privacy. 

 

Important SMS data sharing note

We will not share your opt in to an SMS campaign with any third party for purposes unrelated to providing you with the services of that SMS campaign. We may share your personal information, including your SMS opt in or consent status, with third parties that help us provide our messaging services, including platform providers, phone networks, and other vendors who assist us in delivering text messages.

How long we keep your information

We keep personal information only as long as needed for the purposes described above:

  • Orders: we normally keep order information for 7 years for legal and accounting purposes (for example VAT).

  • Customer support: we normally keep support records for up to 3 years after your last interaction, unless we need to keep them longer for legal reasons.

  • Marketing: if you unsubscribe or opt out, we will stop marketing and keep a minimal record of your request so we can respect it.

How do you use my data?

When you purchase products from our website

When you purchase goods from our website, we will use your personal information to complete your purchase. The details we collect from you will include your name, address, email address, phone number and payment information.

To complete your purchase, we share your personal information with our subcontractors who are involved in the purchase process, such as payment providers, as well as credit reference agencies who we use to assess fraud, credit and/or security risks.

We need to process your personal information in this way to enter into and perform the contract for the item you have purchased from us.

When you phone us, email us or use our website chat service

When you phone us or message us using our website chat service, we may also handle your personal information (your name, contact details and the other details you provide to us) in order to provide the customer services you have asked us to.

We use Zendesk to manage customer service enquiries, including Zendesk live chat.

We will need your personal information to process an order by telephone. It may also be required if you ask us to confirm whether a particular product is available or explain how our delivery or returns process works.

We rely on your consent to handle your personal information in this way, which you can withdraw at any time. If you do not provide us with the personal information we request from you for customer services purposes, we may not be able to fully answer your queries.

When you have expressed an interest in our products:

If you have opted in via our website or over the telephone to receive marketing communications from us, we will handle your personal information (such as your name, email address and postal address and telephone number) to provide you with marketing communications in line with any preferences you have told us about.

When we send you marketing emails, we rely on your consent to contact you for marketing purposes. Every email we send to you for marketing purposes will also contain instructions on how to unsubscribe from receiving them.

SMS marketing (text messages)

If you have opted in via our website (including at checkout) or over the telephone to receive marketing text messages from us, we will handle your personal information (such as your name and telephone number) to send you marketing text messages in line with any preferences you have told us about.

We use Klaviyo to help manage and send marketing communications, including SMS.

Every text message we send you for marketing purposes will also include how to unsubscribe (for example, by replying STOP).

SMS cart reminders 

If you have opted in to receive SMS marketing, our website may use cookies and similar technologies to help keep track of items you put into your shopping basket, including when you have abandoned your cart. This information is used to determine when to send cart reminder messages via SMS.

SMS opt-in data sharing clarification

We will not share your opt-in to an SMS campaign, or your SMS consent status, with any third party for purposes unrelated to providing you with the services of that SMS campaign. We may share your personal data, including your SMS opt-in or consent status, with third parties that help us provide our messaging services (such as platform providers, phone networks and other vendors who assist in delivering text messages).

We may also use your email address for marketing via social media. We rely on our legitimate interest to promote the success of our business to do this. When we use your email address in this way, we do not add your email address to any third party platforms in a personally identifiable form.

You are not under any obligation to provide us with your personal data for marketing purposes.

You can tell us that you do not want your personal information to be processed in this way at any time by contacting us at marketing@tinyboxcompany.com or, where relevant, by following the unsubscribe link shown in every marketing communication you receive from us.

To make our site better:

We will also use your personal information to provide you with a more effective user experience (such as by displaying products we think you will be interested in, based on your purchase history and browsing habits).

Our use of your information in this way means that your experience of our site will be more tailored to you, and that the products you see on our site may differ from someone accessing the same site with a different purchase history or browsing habits.

We also share your aggregated, anonymous data with third party analytics and search engine providers that assist us in the improvement and optimisation of our site.

We will also use your personal information for the purposes of making our site more secure, and to administer our site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes.

We may also use server-side tracking to help measure and improve the performance of our website and marketing.

We process your data for this reason because we have a legitimate interest to provide you with the best experience we can, and to ensure that our site is kept secure.

You can prevent us from using your personal information in this way by using the 'do not track' functionality in your internet browser. If you do not track functionality, our site may be less tailored to your needs and preferences.

If our business is sold:

We will transfer your personal information to a third party:

  • if we sell or buy any business or assets, we will provide your personal information to the seller or buyer (but only to the extent we need to, and always in accordance with data protection legislation); or
  • if Tiny Box Company Limited or the majority of its assets are acquired by somebody else, in which case the personal information held by Tiny Box Company Limited will be transferred to the buyer.

We process your personal information for this purpose because we have a legitimate interest to ensure our business can be continued by the buyer. If you object to our use of your personal information in this way, the relevant seller or buyer of our business may not be able to provide services to you.

In some circumstances we may also need to share your personal information if we are under a duty to disclose or share it to comply with a legal obligation.

What about technical information and analytics?

Information we collect about you: When you visit our site we will automatically collect the following information:

  • technical information, including the Internet protocol (IP) address used to connect your computer to the internet, your login information, browser type, language and version, time zone setting, browser plug-in types and versions, screen resolution, operating system and platform; and
  • information about your visit, including the full Uniform Resource Locators, clickstream to, through and from our site (including date and time), page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs) and methods used to browse away from the page.
  • Information we receive from other sources: We are also working closely with third party advertising networks, analytics providers, hosting providers and search information providers from whom we may also receive general aggregated anonymous information about you.

We will combine the information you provide to us with information we collect about you.

Your rights

You have rights under UK data protection law, including:

  • The right to access your information

  • The right to correct inaccurate information

  • The right to ask us to delete your information (in certain situations)

  • The right to restrict or object to certain processing

  • The right to data portability (in certain situations)

  • The right to withdraw consent at any time (for example, marketing)

To exercise your rights, email marketing@tinyboxcompany.com

Marketing choices

  • Email: use the unsubscribe link in any marketing email

  • SMS: follow the instructions in the message (for example, reply STOP)

Cookies

Our site uses cookies to distinguish you from other users of our site. This helps us to provide you with a good experience when you browse our site and also allows us to improve our site. By continuing to browse the site, you are agreeing to our use of cookies.

We also use third party widgets on our website, including Elfsight widgets (for example, offers). These widgets may use cookies or similar technologies for their functionality and to measure interactions.

 

Category: Necessary (1)

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

Cookie name

Provider

Type

Expiry

Purpose description

frontend

tinyboxcompany.co.uk

HTTP

Session

Stores a random ID which ensures that a user can be uniquely identified as a guest or logged-in user. Functions such as “Items last viewed” or retention of the logged-in state are connected with this cookie.

 

Category: Statistics (5)

Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

Cookie name

Provider

Type

Expiry

Purpose description

_ga

tinyboxcompany.co.uk

HTTP

2 years

Registers a unique ID that is used to generate statistical data on how the visitor uses the website.

_gat

tinyboxcompany.co.uk

HTTP

Session

Used by Google Analytics to throttle request rate.

_gid

tinyboxcompany.co.uk

HTTP

Session

Registers a unique ID that is used to generate statistical data on how the visitor uses the website.

collect

google-analytics.com

Pixel

Session

Used to send data to Google Analytics about the visitor’s device and behaviour. Tracks the visitor across devices and marketing channels.

p.gif

typekit.net

Pixel

Session

Unclassified.

 

Category: Functionality (8)

Functionality table B

Cookie

Duration

Description

Cookie type

PHPSESSID

4 days 4 hours

This cookie is native to PHP applications. The cookie stores and identifies a user's unique session ID to manage user sessions on the website. The cookie is a session cookie and will be deleted when all the browser windows are closed.

Necessary

wp_ga4_customerGroup

1 year

No description

Other

__cf_bm

1 Hour

This cookie, set by Cloudflare, is used to support Cloudflare Bot Management.

Necessary

_gcl_au

3 months

Google Tag Manager sets the cookie to experiment advertisement efficiency of websites using their services.

Analytics

ga*

1 year 1 month 4 days

Google Analytics sets this cookie to store and count page views.

Analytics

_gid

1 Day

Google Analytics sets this cookie to store information on how visitors use a website while also creating an analytics report of the website's performance. Some of the collected data includes the number of visitors, their source, and the pages they visit anonymously.

Analytics

_dc_gtm_UA-*

1 Minute

Google Analytics sets this cookie to load the Google Analytics script tag.

Functional

_uetsid

1 Day

Bing Ads sets this cookie to engage with a user that has previously visited the website.

Performance

_uetvid

1 Year 24 Days

Bing Ads sets this cookie to engage with a user that has previously visited the website.

Performance

MUID

1 Year 24 Days

Bing sets this cookie to recognise unique web browsers visiting Microsoft sites. This cookie is used for advertising, site analytics, and other operations.

Advertisement

__cfruid

Session

Cloudflare sets this cookie to identify trusted web traffic.

Necessary

_fbp

3 months

Facebook sets this cookie to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising after visiting the website.

Analytics

form_key

1 Day

Magento sets this cookie as a security measure that appends a random string to all form submissions to protect the data from Cross-Site Request Forgery (CSRF).

Functional

mage-cache-storage

4 Days 4 Hours

Magento sets this cookie for local storage of visitor-specific content that enables e-commerce functions.

Functional

mage-cache-storage-section-invalidation

4 Days 4 Hours

Magento sets this cookie for local storage of specific content sections that should be invalidated.

Functional

mage-cache-sessid

4 Days 4 Hours

Magento sets this cookie as a value, and this cookie triggers the cleanup of local cache storage. When the cookie is removed by the backend application, the administrator cleans up local storage and sets the cookie value to true.

Functional

mage-messages

4 Days 4 Hours

Magneto sets this cookie to manage the web messages for the user.

Necessary

form_key

4 Days 4 Hours

Magento sets this cookie as a security measure that appends a random string to all form submissions to protect the data from Cross-Site Request Forgery (CSRF).

Functional

amcookie_policy_restriction

10 Days

Amasty GDPR sets this cookie to check whether the user has accepted the cookie consent box or not.

Necessary

product_data_storage

4 Days 4 Hours

Magneto sets this cookie to store the product information.

Necessary

wp_ga4_user_id

Past

tinyboxcompany.co.uk

Other

mage-cache-storage

Never

Magento sets this cookie for local storage of visitor-specific content that enables e-commerce functions.

Functional

mage-cache-storage-section-invalidation

Never

Magento sets this cookie for local storage of specific content sections that should be invalidated.

Functional

recently_compared_product_previous

Never

Magneto sets this cookie to store the data on recently compared products.

Necessary

recently_compared_product

Never

Magento 2 set this cookie to store information on recently compared products.

Necessary

product_data_storage

Never

Magneto sets this cookie to store the product information.

Necessary

recently_viewed_product

Never

Magento 2 set this cookie to store product IDs of recently viewed products for easy navigation.

Necessary

recently_viewed_product_previous

Never

Magento 2 set this cookie to stores product IDs of recently viewed products for easy navigation.

Necessary

__kla_id

2 years

Klaviyo sets this cookie to help identify a visitor (for example, when you interact with sign-up forms or marketing features) and to support marketing measurement.

Analytics



Tool / provider

What it does / why it’s used

Disqus

Disqus uses “authentication” cookies (for example, sessionid, disqusauth, disqusauths) to keep you logged in from your web browser and personalise your Disqus experience. Disqus uses “unique” cookies (for example, disqus_unique and _jid) to associate web-based activities with a page load and with a web browser, including activities that violate our Terms of Service, and understand your interests and product usage. When Disqus loads ads, it uses ad serving technologies from Google that may set cookies for personalised marketing, associating ads with later activities, and limiting how often you are shown specific ads.

Amazon S3

Storage for website files and assets (for example, images and files used by the site).

Cloudflare

Cloudflare is a content delivery network (CDN) and cloud security platform that provides website optimisation, security, and performance services. It acts as a mediator between a website’s server and its visitors, improving the speed and reliability of the website while also protecting it from online threats.

Font Awesome

Provides icons used across the website.

Direct Registration

Used for registration-related functions (where applicable on the site).

Magento / Adobe Commerce

Our website is currently hosted on Magento (Adobe Commerce) and we may use Hyvä technology as part of our storefront experience.

Google Analytics 4

Analytics cookies or performance cookies are used to track website visitors and their user behaviour. This data is then used to improve the way the website works and in turn, used to improve user experience. Google Analytics (GA) cookies are one of the most common analytics cookies set by websites.

Google Fonts

Google Fonts makes it easy to bring personality and performance to your websites and products. Our robust catalog of open-source fonts and icons makes it easy to integrate expressive type and icons seamlessly — no matter where you are in the world.

Google Tag Manager

Google Tag Manager sets the cookie to experiment advertisement efficiency of websites using their services.

hCaptcha

hCaptcha helps your favourite online services keep out bots, spam, and abuse by asking simple questions that are easy for humans and difficult for machines. A service you use has chosen to improve your experience on their site by installing hCaptcha to reduce malicious traffic.

Meta ads conversion tracking

Used to measure the performance of Meta ads (for example, Facebook and Instagram).

Meta Events Manager

Used to manage and measure events related to Meta advertising and tracking.

Microsoft Advertising

Used to measure the performance of Microsoft/Bing ads and advertising audiences.

OneSignal

OneSignal is a service that enables push notifications, abstracting details such as the platform the device is running on.

PayPal

PayPal uses performance cookies to understand how you interact with our site. For example, performance cookies help us learn which parts of PayPal are the most popular and which parts we could improve for you. PayPal also uses functional cookies to customise your experience.

Pingdom

Pingdom is a global performance and availability monitoring solution for websites, applications and servers. With its monitoring platform, it helps deliver the best possible web experience by monitoring performance and uptime.

Stripe

Payment processing provider used to take payments securely.

Zendesk Widget

Customer support tools, including support tickets and website live chat (where enabled).

Klaviyo

We use Klaviyo to help manage and send marketing communications, including email and SMS. Klaviyo may use cookies or similar technologies when you interact with sign-up forms or on-site marketing features.

Elfsight

We use Elfsight widgets (for example, offers). Elfsight widgets may use cookies or similar technologies for functionality and measurement.

 

Links to other websites

Our website may include links to third party websites. If you follow a link, those websites have their own policies and we are not responsible for them.

 


 

Changes to this policy

We may update this policy from time to time. We will post changes on this page and, where appropriate, notify you.

 


 

Contact

Questions, comments, and requests about this privacy policy should be emailed to marketing@tinyboxcompany.com