Banner Privacy & Cookie Policy
Version control
This policy was last updated on 27th May 2025 (V1.1)
The purpose of this Privacy Policy
Welcome to Banner Limited privacy policy. We respect your privacy and are committed to protecting your personal data. This privacy notice aims to give you information on how we collect and process your personal data.
Banner Limited (we/us) is the owner and processor of all customer data across the group. Banner Limited is the controller and responsible for your personal data (collectively referred to as Banner, we, us or our in this privacy notice). We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this privacy notice.
About us
Banner Limited is one of the UKs largest wholesalers of school uniform. We supply uniforms to thousands of schools through our network of retailers and are committed to delivering high quality garments and excellent service. We take your privacy seriously and are dedicated to protecting your personal data.
When you interact with us via our website, email or phone you may provide us with personal information which we then use. This notice explains what information you provide and how we use it. If you would like further details, please feel free to email us at privacy@banner.co.uk.
Please be mindful that we sometimes have links to other companies or schools on our website that are not part of our business or group. If you follow a link to one of these websites, please remember that they will have their own privacy information for you to review, and we're not responsible for how they use your information.
What personal information do we collect about you?
- Identity data: such as first name, surname, and title.
- Contact data: including your email address, billing and delivery addresses, and telephone number.
- Transactional data: such as order number, currency, delivery address, quantity of items, product number, individual item price and tax information. We also keep records of payments made to and received from you, as well as any correspondence related to your orders.
- Financial data: such as your chosen method of payment. We do not store any bank or card details; these are processed securely by our payment gateway provider.
- Usage data: which includes information about how and when you use our website, your navigation through it, search activity, website performance, traffic levels, location, and weblogs.
- Technical data: relating to the device(s) you use to access our website, such as your IP address, login details, username and password, browser type and version, time zone and location settings, browser plug-in details, operating system, and platform.
- Marketing data: including your marketing preferences and limited information on how you engage with our marketing emails.
- Contact data: captured when you phone or email us regarding any issues, queries, or data-related requests.
We also collect, use, and share Aggregated Data which may be derived from your personal data. This isnt considered personal data as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
How do we collect your data, why do we collect it and how do we use it?
We collect your data when you:
- Create an account with us or make a purchase online or via email/phone.
- Subscribe to our emails.
- Contact us with an enquiry or to report an issue by phone or email.
- Interact with our website.
We only collect and use your personal data to:
- Fulfil your order/s with us or orders made on your behalf.
- Keep you up to date with our latest offers and promotions.
- Improve your shopping experience.
- Make any marketing conducted by us more relevant to you.
- Improve our services and our website.
- Meet our legal responsibilities.
We will only collect and use your data if:
- We have your consent to do so, or
- Your personal data is required to perform a contract with you such as fulfilling an order or processing a payment from you, or
- We have a legitimate interest to do so which is not overridden by your rights, or
- We have a legal obligation to collect or disclose your personal data.
How do we process your data?
We use your personal data to support a range of different activities which are listed in the table below. Also included is the type of data used and the legal basis in which we rely on when processing it. This includes, where appropriate, our legitimate interests. Please be aware that we may process your personal data using more than one lawful basis, depending on the specific activity involved. Please contact us if you need details about the specific legal grounds that we are relying on to process your personal data where more than one ground has been set out in the table below.
More information on what we collect and why
| Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
| When you create an account and register as a new customer. | Identity | Consent |
| Contact | ||
| To process and deliver your order online or via email/phone... | Identity | Performance of a contract |
| Contact | ||
| To manage our relationship with you... | Identity | Consent Performance of a contract |
| Contact | ||
| Profile | ||
| Marketing | ||
| To enable you to take part in a competition... | Identity | Performance of a contract |
| Contact | ||
| Profile | ||
| Usage | ||
| Marketing | ||
| To administer, protect and improve our business... | Identity | Consent |
| Contact | ||
| Profile | ||
| Technical | ||
| Transaction | ||
| Marketing | ||
| To deliver relevant website content... | Identity | Consent |
| Contact | ||
| Profile | ||
| Usage | ||
| Marketing | ||
| Technical | ||
| To use data analytics to improve... | Technical | Consent Legitimate interests... |
| Usage | ||
| To recommend products, services, discounts... | Identity | Consent |
| Contact | ||
| Profile | ||
| Technical | ||
| Usage | ||
| Marketing | ||
| To inform or remind you by email... | Identity | Consent |
| Contact | ||
| Usage | ||
| To assist with any issues or queries... | Identity | Performance of a contract Legal obligation |
| Contact | ||
| Profile | ||
| Technical | ||
| Usage | ||
| Marketing |
How do we keep your data secure?
While sending information over the internet is never entirely secure, we do our utmost to safeguard your data. However, we cannot guarantee the security of any data you transmit to our websites, and you do so at your own risk. That said, please be assured that when using our website, all personal data transmitted between your browser and our site is protected using a secure, encrypted connection. Any personal data stored by our website is also encrypted using an encryption key to secure passwords and other sensitive information. We use the industry-standard ChaCha20-Poly1305 algorithm with a 256-bit key to encrypt all data that requires protection. As a precaution, we advise against storing any credit card information.
Once your data is received, we apply strict procedures and security features to help ensure it is kept safe. Any third parties engaged by us to process personal data on our behalf are required to have appropriate security measures in place and to handle such data in compliance with the law.
Access to your personal data is limited to employees, agents, contractors, and other third parties who have a legitimate business need to access it, such as embroiderers. They are only permitted to process your data on our instructions and are bound by a duty of confidentiality.
We also have procedures in place to respond to any suspected personal data breaches. Where legally required, we will notify both you and the appropriate regulatory authority of any such breach.
How long do we keep your data?
We wont keep your personal data for any longer than is necessary for the purpose that it was provided for, and to meet our legal obligations. More information about the periods of time that we retain data for is available on request.
If reasonably necessary or required to meet legal or regulatory requirements, resolve disputes, prevent fraud, and abuse, or enforce our terms and conditions or other legal rights, we will also retain of some of your information, even if it is no longer needed to provide our services to you.
In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes.
How do we use your data for marketing purposes?
We only send marketing emails to individuals that have opted in to receiving them. You have the ability to opt in and out of emails when you open an account with us, or if you sign up to receiving emails from us on our website. You can opt out of receiving emails from us at any point by clicking the unsubscribe link at the bottom of every email that we send.
We sometimes use your purchasing data to make sure that the messages that we send out to customers is as relevant as possible.
Cookies
We use cookies for a variety of things on our website, we mostly use them to make sure that your online experience is as smooth and effective as possible, but we also use cookies to monitor performance of our emails and review how customers use our website to see where we can make improvements to it in the future. We also use cookies to recommend products on our website and in emails.
Most cookies require consent. When you first visit our site, a pop-up banner will inform you about our use of cookies. You can choose to accept all cookies, reject all except essential ones, or accept only certain types. By clicking "Accept all Cookies," you consent to non-essential cookies unless disabled in your browser. The differences between essential and non-essential cookies are explained below. You can continue to use our sites and complete transactions without consenting to cookies, but if you do this some site functionality may be impaired.
Essential
These cookies are used to deliver and maintain online services, provide basic site functionality, remember your basket content, facilitate transactions and payments, prevent fraud, and secure our sites.
Non-Essential
With your consent, we use non-essential cookies to enhance our sites and services, comply with contractual duties, improve service quality, develop new features, and enable special site features like widgets or embedded media. These are not essential for site operation but enhance the user experience and allow us to test new features.
Strictly necessary cookies - Essential
These essential cookies enable website functionality and services you request. They cannot be turned off and do not require consent. You can block them in your browser, but some site features may not work. They do not store personal information.
Functional cookies - Non-Essential
These cookies provide enhanced functionality and personalisation. They may be set by us or third-party services we use. If turned off, some services may not work properly.
Performance cookies - Non-Essential
These cookies help us count visits and traffic sources to measure and improve website performance. All information collected is aggregated and anonymous. Turning them off prevents us from knowing when you visit and hinders performance monitoring.
Who do we share your data with?
We will never sell any of your information to any third party. We do, however, share your information with some select trusted partners who are third parties to enable us to provide our products and services to you, to send marketing information and to improve our business. These fall into the following categories:
- Companies within the Banner Group for analysis and business purposes and to improve our products and services.
- Companies that enable us to get your purchases to you, such as payment service providers, warehouses, order packers, and delivery companies.
- Brand partners that send purchases directly to you. We'll make it clear if this applies when you place your order. We may also share your personal information with brand partners if you raise a serious complaint about a product of theirs that youve purchased through us or if you tell us that you havent received your order.
- Professional service providers such as marketing agencies, IT development partners, advertising partners and website hosts/providers/developers, who help us run our business.
- Third party payment processers such as CyberSource, PayPal, Klarna, Apple Pay & Google Pay to process your payment to us. Banner does not store your payment information. Your payment details are provided to the payment processing service that you select, who are required to comply with applicable regulations and data protection laws. Please refer to the privacy policy of the relevant provider for details of how they process your personal data.
- Credit reference agencies, law enforcement and fraud prevention agencies so we can help tackle financial crime, including, but not limited to, fraud and sanctions. If you would like to know more about the third parties, we may share personal data with, or how to find out more on how they will use your data, please contact us at the details below.
We have partnered with trusted third parties to offer you additional products and services. These may include tools to enhance your shopping experience, such as product recommendations, video content, or analytics. If you would like a list of our current partners, please get in touch with us.
Where do we store your data?
We share your personal data within our own group of companies and to external service providers where necessary. This may involve transferring your data outside the European Economic Area (EEA). We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe.
What are your rights?
You have the right to:
- Withdraw your consent where the legal basis of our processing is consent.
- Ask for access to the personal data that we hold (subject access request)
- Prevent our use of your personal data for direct marketing purposes.
- Object to our processing of personal data in limited circumstances.
- Ask us to erase personal data (right to be forgotten):
- If it is no longer necessary in relation to the purposes for which it was collected or otherwise processed.
- If the only legal basis of processing is consent and that consent has been withdrawn and there is no other legal basis on which we can process that personal data.
- If you object to our processing where the legal basis is the pursuit of a legitimate interest, or the public interest and we can show no overriding legitimate grounds or interest.
- If the data subject has objected to our processing for direct marketing purposes.
- If the processing is unlawful.
- Request that inaccurate data is rectified (or to complete incomplete data).
- Restrict processing in specific circumstances e.g. where there is a complaint about accuracy.
- Request a copy of the safeguards under which any personal data is transferred outside of the EU.
- The right not to be subject to decisions based solely on automated processing, including profiling, except where necessary for entering into, or performing a contract. It is based on the data subjects explicit consent and is subject to safeguards; or is authorised by law and is also subject to safeguards.
- Prevent processing that is likely to cause damage or distress to the data subject or anyone else.
- To be notified of a personal data breach which is likely to result in high risk to their rights and freedoms.
You can reach out to us using the contact information provided below if you wish to exercise any of these rights. There may be instances where we are unable to fulfil your request; in such cases, we will inform you and explain why.
You also have the right to make a complaint to the ICO. You can do this by following this link - https://ico.org.uk/make-a-complaint/
How can you contact us?
If you have any questions about your data or this policy, wed be happy to help. Please send your queries, requests or comments to privacy@banner.co.uk, or write to us at:
Banner Limited, Kennet Way, Trowbridge, Wiltshire, BA14 8BL.
Our nominated data protection representative will respond to you.