Privacy Policy
Who we are
This website is operated by Nastine, a sole trader business operating in the United Kingdom (“we”, “us”, “our”).
In this Privacy Policy, references to “you” and “your” refer to the user or customer of this website.
Business contact address:
Suite RA01
195–197 Wood Street
London
E17 3NU
United Kingdom
Email: official@nastine.co.uk
This address is provided for business correspondence only and is not a returns address.
The returns address is different and is provided in accordance with our Returns & Refund Policy.
Items sent to this address will not be accepted or processed.
What data we collect
When you use this website, place an order, create an account, or contact us, we may collect the following personal data:
Full name
Billing and shipping address
Email address
Phone number
Order details
IP address
Browser and device information
If you create an account, we securely store your login information.
Payments are processed securely by Stripe. When processing payments, certain personal data (including name, billing address, IP address and transaction details) may be shared with Stripe for the purpose of completing the transaction and preventing fraud. We do not store full card details on our servers.
Stripe’s Privacy Policy: https://stripe.com/gb/privacy
How we use your data
We process personal data in order to:
Process and deliver your orders
Communicate about your order status
Respond to enquiries
Prevent fraud and ensure website security
Comply with UK legal, accounting, and tax obligations
Send marketing communications (only where you have provided consent)
We do not sell, rent, or trade your personal data.
Legal basis for processing (UK GDPR)
We process personal data under the following lawful bases:
Contract – to fulfil and manage your order
Legal obligation – to comply with tax, accounting, and regulatory requirements
Legitimate interest – for fraud prevention, website security, and business management
Consent – where you have opted in to receive marketing communications
Data sharing
We share personal data only where necessary to operate our business. This may include:
Payment processors (e.g. Stripe)
Delivery companies
Website hosting providers
Email service providers
HMRC or other legal authorities (where legally required)
We ensure that third-party providers process data securely and in compliance with applicable data protection laws.
Data retention
We retain personal data only for as long as necessary to fulfil the purposes outlined in this policy, including legal, accounting, or reporting requirements.
In particular:
Financial records and transaction data are retained for 6 years following the end of the financial year they relate to, in accordance with HMRC regulations.
Inactive accounts may be deleted after 24 months of inactivity.
Certain data may be retained where required for fraud prevention or legal defence.
Your rights
Under the UK General Data Protection Regulation (UK GDPR), you have the right to:
Request access to your personal data
Request correction of inaccurate data
Request erasure of your data (where legally permitted)
Object to or restrict certain processing
Withdraw consent for marketing at any time
Please note: Under Article 17(3)(b) of the UK GDPR, we may be unable to delete certain transactional data (such as invoices and financial records) where we are legally required to retain it for tax or accounting purposes.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
https://ico.org.uk
Cookies
This website uses cookies to ensure proper functionality and improve user experience.
We use:
Strictly necessary cookies (required for cart and checkout functionality)
Security cookies
Analytics cookies (if enabled)
Marketing cookies (only where consent is given)
You can manage your cookie preferences at any time via our cookie banner.
Website Performance & Caching
This website uses caching technology (LiteSpeed Cache) to improve performance and loading speed. Caching may temporarily store copies of web pages and certain technical data (such as IP address and browser information) as part of server performance optimisation. Cached data is stored temporarily and is automatically refreshed or deleted. It is not used for marketing, profiling, or commercial purposes. Please see https://quic.cloud/privacy-policy/ for more details.
Data security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
However, no method of transmission over the Internet is completely secure, and we cannot guarantee absolute security.
International data transfers
Some of our service providers may process data outside the United Kingdom. Where this occurs, appropriate safeguards are implemented to ensure that your data is protected in accordance with UK data protection laws.
Last updated: February 2026
This Privacy Policy may be updated from time to time. The latest version will always be available on this page

