Veo and Wearth are now Ziracle. Same mission, better platform. See what's new

Legal

We believe in being as transparent about how we operate as we are about the products we sell. Everything you need to know is below.

Ziracle

Privacy Policy

Last updated: 1st April 2026

ZIRACLE LTD (SC844466) • 7 Gladstone Terrace, Edinburgh, Scotland, EH9 1LU

hello@ziracle.com • ziracle.com

1. Introduction

Welcome to Ziracle’s Privacy Policy. Ziracle is operated by ZIRACLE LTD, a company registered in Scotland (Company No. SC844466), whose registered office is at 7 Gladstone Terrace, Edinburgh, Scotland, EH9 1LU (“Ziracle”, “we”, “us”, “our”).

We are committed to protecting your personal data and respecting your privacy in compliance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 (“DPA 2018”), and the Privacy and Electronic Communications Regulations 2003 (“PECR”).

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and what your rights are. It applies to all personal data processed by us in connection with your use of ziracle.com and any purchase made through our platform.

Please read this policy carefully. If you have any questions, contact our Data Protection Contact using the details in Section 2.

2. Who We Are and How to Contact Us

Ziracle is the Data Controller for personal data collected through this Website. This means we determine the purposes and means of processing your personal data.

Data Protection Contact: Hamish Lawson

Email: hello@ziracle.com

Post: 7 Gladstone Terrace, Edinburgh, Scotland, EH9 1LU

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (ico.org.uk). We would appreciate the chance to address your concerns before you approach the ICO, so please contact us in the first instance.

3. Personal Data We Collect

We may collect and process the following categories of personal data about you:

Identity & Profile Data: first name, last name, gender, date of birth, username or similar identifier.

Contact Data: email address, delivery address, billing address, telephone number.

Transactional Data: details of purchases you have made through our platform, including order history, products ordered, and order values.

Financial & Billing Data: payment card details (processed securely by our payment provider — we do not store full card numbers), billing address.

Technical Data: IP address, browser type and version, device identifiers, time zone setting and location, operating system and platform, and other technology on the devices you use to access our Website.

Usage Data: information about how you use our Website, including pages visited, products viewed, search terms, time spent on site, clickstream data, and referral source.

Marketing & Communications Data: your preferences for receiving marketing communications from us, and records of your communication history with us.

Customer Support Data: records of any correspondence, complaints, feedback or survey responses.

We also collect, use and share aggregated and anonymised data (for example, overall traffic patterns or category-level purchase trends). This data does not identify you personally and is not subject to this Privacy Policy.

We do not knowingly collect any Special Category personal data (such as data relating to race, ethnicity, religion, health, sexual orientation or biometric data), nor data relating to criminal convictions or offences.

4. How We Collect Your Personal Data

We collect personal data through the following means:

  • Directly from you — when you create an account, place an order, subscribe to our mailing list, complete a form, contact us, or participate in a promotion or survey.

  • Automatically — as you interact with our Website, we automatically collect Technical Data and Usage Data via cookies and similar tracking technologies. Please see our Cookie Policy at ziracle.com/cookie-policy for full details.

  • From third parties — including our e-commerce platform (Shopify), our payment processor (Stripe), our email and SMS marketing platform (Klaviyo), advertising platforms (Google, Meta, TikTok), and our affiliate network (Awin) where you have clicked through a tracked affiliate link.

5. How We Use Your Personal Data

We will only use your personal data where we have a lawful basis to do so. The table below sets out our main processing activities, the type of data involved, the lawful basis we rely on, and our standard retention period.

PurposeData TypeLawful BasisRetention
Process and fulfil your orderIdentity, Contact, Transactional, FinancialContract — necessary to perform our contract with you7 years (tax / legal obligations)
Manage your accountIdentity, Contact, ProfileContractDuration of account + 2 years after closure
Process payments and prevent fraudFinancial, Technical, TransactionalContract; Legitimate Interests (fraud prevention)7 years
Send order and account notificationsIdentity, ContactContractDuration of account
Send marketing emails and SMS (opted-in only)Identity, Contact, MarketingConsent — can be withdrawn at any timeUntil unsubscribe or 3 years of inactivity
Personalise your experience and product recommendationsUsage, Profile, TransactionalLegitimate Interests2 years
Website analytics and improvement (Google Analytics)Technical, UsageLegitimate Interests26 months
Targeted advertising (Google, Meta, TikTok)Technical, UsageConsent (via cookie consent banner)Duration of ad campaign
Manage returns, refunds and complaintsIdentity, Contact, TransactionalContract; Legal Obligation7 years
Comply with legal and regulatory obligationsIdentity, Contact, Financial, TransactionalLegal ObligationAs required by law (typically 7 years)
Manage our affiliate programme (Awin)Identity, Contact, TechnicalLegitimate Interests; ContractDuration of relationship + 2 years

Where we rely on Legitimate Interests as our lawful basis, we have determined that our interests are not overridden by your rights and freedoms. You have the right to object to processing on this basis — see Section 9.

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another compatible reason. If we need to use your data for an unrelated purpose, we will notify you and explain the legal basis.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our Website. Cookies are small files placed on your device that allow us and our third-party partners to recognise your browser and collect certain information.

We use the following categories of cookies:

  • Strictly necessary cookies — essential for the Website to function (e.g. shopping cart, user session). These do not require your consent.

  • Analytics cookies — used to understand how visitors interact with our Website, including Google Analytics. These require your consent.

  • Marketing and advertising cookies — used to deliver relevant ads and measure campaign performance across Google, Meta and TikTok. These require your consent.

  • Functional cookies — used to remember your preferences and enhance your experience. These require your consent.

When you first visit our Website, you will be asked to set your cookie preferences via our cookie consent banner. You can update your preferences at any time using the cookie settings link in the footer of our Website.

For the full list of cookies we use, please see our Cookie Policy at ziracle.com/cookie-policy.

7. Who We Share Your Data With

We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients where necessary:

Service Providers (Data Processors)

These companies process personal data on our behalf and are contractually bound to use it only on our instructions:

  • Shopify Inc. — our e-commerce platform, which hosts our storefront and processes order data.

  • Stripe Inc. — our payment processor. Stripe processes your payment card data securely under PCI-DSS compliance. We do not store your full card details.

  • Klaviyo Inc. — our email and SMS marketing platform, used to send order confirmations, account notifications and marketing communications where you have opted in.

  • Google LLC — Google Analytics (website analytics) and Google Ads (advertising).

  • Meta Platforms Inc. — Meta Pixel and Meta Ads, used for advertising and campaign measurement.

  • TikTok Technology Ltd — TikTok Pixel, used for advertising and campaign measurement.

  • Awin Ltd — our affiliate marketing network, used to track and reward referrals from affiliate partners.

  • Delivery carriers — we share your name and delivery address with logistics and courier partners to fulfil your order.

Vendors and Brand Partners

Where you purchase a product from an independent brand sold through our platform, we share the relevant order details (name, delivery address, items ordered) with that Vendor solely for the purpose of fulfilling your order. Vendors are required to handle your data in accordance with applicable data protection law.

Legal and Regulatory Disclosure

We may disclose your personal data to law enforcement agencies, regulators, courts or other authorities if required by law, or where we reasonably believe disclosure is necessary to protect our legal rights or the safety of others.

Business Transfers

In the event that Ziracle is sold, merged or its assets transferred, your personal data may be transferred to the acquiring entity. You will be notified of any such transfer and the acquiring entity’s privacy policy will govern subsequent use of your data.

8. International Transfers of Personal Data

Some of our third-party service providers are based outside the UK. Processing your personal data through these providers involves transferring your data outside the UK. This applies primarily to US-based providers including Shopify, Stripe, Klaviyo, Google, Meta and TikTok.

Whenever we transfer personal data outside the UK, we ensure an appropriate safeguard is in place, which will typically be one or more of the following:

  • The destination country benefits from UK adequacy regulations, meaning the ICO has determined it provides an adequate level of data protection;

  • The transfer is subject to a UK International Data Transfer Agreement (IDTA) or the ICO’s approved addendum to EU Standard Contractual Clauses; or

  • The recipient participates in a recognised data protection framework such as the UK-US Data Bridge where applicable.

You may request further information about the specific safeguards in place for any given international transfer by contacting us at hello@ziracle.com.

9. Your Rights

Under UK GDPR and the DPA 2018, you have the following rights in relation to your personal data:

  • Right of access — you may request a copy of the personal data we hold about you (a Subject Access Request).

  • Right to rectification — you may ask us to correct inaccurate or incomplete personal data.

  • Right to erasure (‘right to be forgotten’) — you may ask us to delete your personal data where there is no legitimate reason for us to continue holding it.

  • Right to restrict processing — you may ask us to suspend the processing of your personal data in certain circumstances.

  • Right to data portability — you may request your personal data in a structured, commonly used, machine-readable format for transfer to another service.

  • Right to object — you may object at any time to processing based on our Legitimate Interests, including profiling, or to processing for direct marketing purposes.

  • Rights related to automated decision-making — you have the right not to be subject to a decision based solely on automated processing where that decision produces significant legal or similarly significant effects on you.

  • Right to withdraw consent — where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, please contact us at hello@ziracle.com. We will respond within one calendar month. We will not charge a fee unless your request is manifestly unfounded or excessive. We may need to verify your identity before actioning your request.

10. Marketing Communications

We will only send you marketing emails or SMS messages where you have opted in to receive them. You can unsubscribe at any time by:

  • Clicking the ‘unsubscribe’ link in any marketing email;

  • Replying STOP to any marketing SMS; or

  • Contacting us at hello@ziracle.com.

Opting out of marketing will not affect transactional communications (such as order confirmations and dispatch notifications), which we send on the basis of contract.

11. Data Security

We have put in place appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, alteration or disclosure. These include:

  • Encryption of data in transit using SSL/TLS;

  • Access controls limiting personal data access to those with a legitimate business need;

  • Use of reputable, certified third-party platforms including Shopify and Stripe (PCI-DSS compliant for payment data);

  • Regular review of our data protection policies and practices.

No method of transmission over the internet is completely secure. Whilst we take all reasonable steps to protect your personal data, we cannot guarantee its absolute security. If you believe your interaction with us is no longer secure, please contact us immediately at hello@ziracle.com.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware and, where required, notify you directly without undue delay.

12. Children’s Privacy

Our Website is not directed at children under the age of 18 and we do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided personal data to us without your consent, please contact us at hello@ziracle.com and we will delete that data promptly.

13. Third Party Websites

Our Website may contain links to third-party websites. This Privacy Policy applies only to ziracle.com. We are not responsible for the privacy practices of any third-party sites and encourage you to read the privacy policy of every website you visit.

14. Changes to This Privacy Policy

We keep this Privacy Policy under regular review. Any updates will be posted on this page with a revised “last updated” date. Where changes are material, we will notify you by email or by a prominent notice on our Website before the changes take effect. Your continued use of our Website after any changes constitutes your acceptance of the updated policy.

15. Governing Law

This Privacy Policy is governed by the laws of Scotland. Any disputes arising in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the Scottish courts.

ZIRACLE LTD • SC844466 • 7 Gladstone Terrace, Edinburgh, Scotland, EH9 1LU • hello@ziracle.com • ziracle.com

This Privacy Policy was last updated on 1st April 2026.