Free standard shipping over $105 - patio furniture orders are dispatched on a stated schedule
Porchline

Privacy Policy

This page sets out privacy plainly, so you can see at a glance what is collected, what it is used for, how long it is kept and what you can ask us to do.

Information we collect

Two kinds of information are involved. The first is technical and is generated simply by visiting the site: the device and browser in use, an approximate location derived from the IP address, and the pages viewed. None of it identifies you by name.

The second is supplied by you: your name, email address, delivery and billing addresses, a contact number where the carrier requires one, the items purchased and the result of the payment returned by the processor.

Correspondence you send is filed against the relevant order, so that a later question can be answered without you repeating the history.

Nothing marked optional at checkout has to be filled in, and the fields that are required are labelled before the form is submitted rather than after a failed attempt.

Nothing is collected for the sake of it. If a detail is not needed to fulfil an order, to support you afterwards or to meet an accounting duty, it is not requested.

  • Technical data — device, browser, approximate location, pages viewed.
  • Order data — name, contact details, addresses, items, payment result.
  • Full card number — never received.
  • Special category data such as health or biometric data — never requested.

How we use it

Order details are used to take payment, dispatch the parcel, send delivery updates, handle returns and meet accounting obligations. Technical information is used to run the site, to detect unusual activity and to understand in aggregate which pages are useful.

Correspondence is used to answer your question and, where it concerns an order, to keep a record of what was agreed. We keep a written note of why each category is held, so a specific answer can be given if you ask why a particular detail is needed.

Information is not used to build advertising profiles and is not sold.

Consent, where it is the basis for a particular use, may be withdrawn at any point, and the withdrawal stops future processing without undoing anything already done lawfully.

Order history is not used to decide what advertising you see elsewhere, and no profile of you is built from what you have bought.

  • Taking payment and dispatching orders — yes.
  • Delivery updates and returns — yes.
  • Fraud detection and aggregate analytics — yes.
  • Advertising profiles or sale of data — no.

Cookies

A small number of cookies and browser storage entries are set, in two categories. The essential ones hold your basket and keep the checkout session alive; without them the basket empties whenever you change page.

The analytics cookie records page views in aggregate using a random identifier, and cannot be joined to your order record. No third-party advertising cookies are present.

Where you return to the site, the analytics identifier may recognise your browser as a previous visitor, but that recognition is statistical rather than personal and does not alter prices or content.

Because the essential entries carry the basket, disabling them means the checkout cannot be completed, which is the only reason they cannot be switched off from the site itself.

No advertising identifier is set, and the analytics entry cannot be used to follow you to another website.

  • Essential storage — basket and checkout session.
  • Analytics storage — aggregate page views only.
  • Advertising or retargeting cookies — none.
  • Blocking cookies — possible, but the basket will not survive a page change.

Sharing

Information reaches only the companies needed to complete an order: the payment processor, the delivery carrier, the hosting provider and the service that sends confirmation emails. Each receives the minimum required for its role.

Before appointing any supplier that receives order data we establish what it does with the data and how long it keeps it, and record the answer. Suppliers are bound by contract to process information only on our instruction.

The carrier sees the delivery address and a contact number; the processor sees the payment information. Neither receives the other's data, and neither may reuse what it receives for its own purposes.

Information is released to a public authority only where the law compels it, and you are told unless that disclosure is prohibited.

  • Payment processor — receives payment data, not order history beyond the amount.
  • Delivery carrier — receives the delivery address and a contact number.
  • Hosting and email services — receive only what their role requires.
  • Sold to anyone, or passed to unrelated mailing lists — never.

Retention

Order records, including the delivery address and the items purchased, are kept for seven years because tax and accounting rules require it. Support correspondence is kept for two years.

Aggregate analytics never travel back to a named individual, and a basket that is filled but never ordered is wiped on a short automatic timer.

When a retention period ends the record is deleted rather than hidden, and no copy is left behind in a secondary system that nobody revisits.

If you close your account we remove everything we are not legally obliged to keep, and confirm in writing what was removed and what had to stay.

The periods above are revisited from time to time to confirm they remain correct and that nothing is kept beyond its purpose.

Deletion requests are actioned within the same 30 days as any other request, and a short confirmation is sent once the work is finished.

  • Order records — seven years, as required by tax rules.
  • Support correspondence — two years.
  • Aggregate analytics — no individual link.
  • Account closed at your request — everything not legally required is removed.

Security

Traffic to the site is encrypted in transit, and card details are entered on the processor's hosted page rather than on ours. Access to order data is limited to the small team that packs and supports orders.

Each member of that team uses an individual account rather than a shared credential, and access is removed on the day someone stops working with us.

We monitor for patterns that look unusual, such as a run of failed payments from one address, because those usually indicate card testing rather than genuine shopping.

No system is perfect and we will not claim otherwise. If a breach ever affected your information, you would be told what happened and what has been done about it.

Access rights are reassessed whenever somebody joins or leaves the small team that handles orders.

  • Encryption in transit — applied to all traffic.
  • Card data on our systems — none.
  • Access — role-based, individual accounts.
  • Breach affecting your data — you would be told directly.

Your rights

You may ask for a copy of the information held about you, ask for corrections, ask for deletion, object to a particular use, or ask for the information in a portable format. All of these are free to exercise.

Every marketing message carries an unsubscribe link that works immediately, while order confirmations and dispatch notices keep being sent because they are part of the purchase.

A request is answered within 30 days, and if it is complex we explain why it is taking longer rather than letting the deadline pass in silence.

Where a request cannot be granted in full, we name the rule that prevents it and set out the options that remain, rather than issuing a flat refusal.

The same small team deals with order questions and with data requests, so the person who replies can look at the relevant order straight away.

  • Access — a copy of what we hold.
  • Rectification — corrections to anything inaccurate.
  • Erasure — deletion of what we are not required to keep.
  • Objection and portability — an available option in each case.

Children

The site is intended for adults. Information is not knowingly collected from a child under 13, and no advertising is directed at children.

Where an item is bought for a child, the order is placed by an adult and the contact details held are that adult's rather than the child's.

A parent or guardian can make any of the requests described above on behalf of a child, and the same timescales apply regardless of who writes in.

Photographs sent in for a sizing or fit question are used only to answer that question and are never published or passed on.

Where a product page mentions an age range, the figure describes when the item is safe to use and has nothing to do with who is allowed to place the order.

Tell us if you think a child has provided personal information and the record will be deleted once the position has been checked.

  • Under-13 information — not knowingly collected.
  • Advertising aimed at children — none.
  • Parent or guardian requests — handled like any other.
  • Photographs sent for a sizing question — used only to answer it.

Contact

Write to [email protected] with the word privacy in the subject line and say what you would like us to do. No particular form of words is required.

We answer within one working day, and formal requests are answered within 30 days. Identity may be verified before information is released or deleted.

A question about how a clause applies to your own situation is welcome, and the answer will be written in ordinary language rather than quoted from the policy.

Should the way we handle personal information change in substance, the revised text appears on this page with the revision date at the top.

If we cannot do what you have asked, we will name the rule preventing it and set out the options that remain.

You do not need a legal form of wording, and there is no charge for asking.

  • Contact — [email protected], marked privacy.
  • Reply time — one working day; formal requests within 30 days.
  • No wording requirement — a short email is enough.
  • Unhappy with the answer — ask for a review, and you will be told who decided.