Privacy policy
We are committed to protecting the privacy of our customers and those who use our website www.justoverthetop.co.uk.
It is important that you read this Privacy Policy so you are aware of how and why we use your personal data. We may update this Privacy Policy at any time.
This Privacy Policy supplements other notices and privacy policies and is not intended to override them. Please read this Privacy Policy alongside our Terms of Use and our Terms & Conditions.
This website is not intended for children and we do not knowingly collect data relating to children.
Who is responsible for processing my personal data?
For the purpose of data protection legislation, JOTT-JUST OVER THE TOP-UK Limited is a “data controller”. A data controller decides how and why your personal data is used.
If you have any questions about this Privacy Policy please contact us:
JOTT-JUST OVER THE TOP-UK Limited
103 Marylebone High Street
London 1U 4RP
United Kingdom
email: vieprivee@jott.fr
Why does JOTT collect my personal data?
JOTT uses your personal data for the following purposes:
- Order management and customer services. We use your personal data for the management of your orders and the after sales service. For example, management of customer accounts, deliveries, invoices and complaints handling.
- Payments. Your payment details are collected by trusted payment service providers (see ‘What personal data is collected about me?’ below for further information). JOTT does not collect your payment data.
- Personalisation of our services and the messages we send you. Your personal data allows us to improve and personalise our services and communications. For example, we may send you personalised emails or recommend products similar to those you have already purchased or viewed. Please see further information under ‘Do you carry out marketing activities?’ below.
- Security. We collect browsing data to allow us to (i) put in place appropriate security measures, (ii) detect any malicious activities, and (iii) detect any violation of our Terms of Use.
- To improve our website and products. We may use data to better understand our customers, or to improve our products and services. We may collect information about how you use our website, for example, the number of pages viewed, the number of visits to the site, your activity on the site and frequency of return.
-
Fraud prevention. We may assess the risk of fraudulent activity on our site, and may use your personal data as part of that assessment. If we suspect fraud, we may take measures such as:
- requesting additional supporting documents from customers or proposing an alternative delivery method;
- suspending or cancelling orders; and/or
- flagging the details provided in the order in our systems, so that we can identify any future orders using the same details, and take appropriate action (such as making additional security checks on those orders).
What personal data is collected about me?
We collect and process:
- contact details, such as your name, first name, address, email address and telephone number;
- transactions data, such as order history and delivery information;
- technical and analytics data, such as IP address, connection data and navigation data, email open rate data, and in some cases, location data (for example, to show you the store closest to you);
- profile information, such as any password provided, and your preferences and interests; and
- communications data, including any data you share with us when you interact with us, and when making any complaints.
JOTT does not collect or store customer payment details. This is done using trusted, PCI-DSS certified third party suppliers, PayPal and Shopify Payments, who collect and safeguard this data. For more information on how your data is handled, refer to their privacy policies.
How do we collect your information?
We use different methods to collect data from and about you, including through:
-
Direct interactions. For example, when you fill in forms or correspond with us. This includes personal data you provide when you:
- place an order on our website or visit our store;
- enter a competition, promotion or survey;
- contact our customer service team; or
- give us feedback or contact us.
- Automated technologies or interactions. As you browse our website, we will automatically collect technical data about your browsing patterns and technical data about the equipment you are using to access the website. We collect this personal data by using cookies and other similar technologies. Please see ‘Do you use cookies?’ below for further information.
- From third parties. When you use our website, we may collect technical data using reputable third-party service providers. For example, analytics providers such as Google Analytics, based outside the UK.
What legal basis do we rely on when using your personal data?
- we need to perform the contract we are about to enter into, or have entered into, with you;
- it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests;
- we have obtained your consent (you can withdraw this consent at any time); or
- we need to comply with a legal obligation.
We will rely on our legitimate interests to conduct activities to:
- administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data);
- understand the effectiveness of the advertising we serve to you;
- use data analytics to improve our website, products/services, marketing, customer relationships and experiences; and
- share data within the JOTT group.
Do you carry out marketing activities?
We may use your personal data to understand your preferences and interests. This is how we decide which products and offers may be relevant to you.
We may send you newsletters and offers. You may opt out of marketing communications at any time.
Our website gives you the option to sign up to product availability alerts. You can register for alerts by clicking on the “Alert” button, and may unsubscribe at any time.
Will you disclose my data to third parties?
We share data we collect within the JOTT group and with selected trusted third parties including:
- our business partners, suppliers and sub-contractors in order to provide our services (for example, where we enter into agreements with third parties to assist with the management, execution, processing, payment of your orders, as well as for marketing operations);
- analytics and search engine providers that assist us in the improvement of our website and the services we provide; and
- the police and law enforcement bodies in relation to the prevention and investigation of fraud and other crime.
We will disclose data we collect to third parties:
- if we undergo a change of control, or if any of our business or assets are sold or transferred (in which case we would disclose your data to the prospective seller or buyer);
- if all or substantially all of our assets are acquired by a third party, in which case data held by us about our website users will be one of the transferred assets; or
- if we are under a duty to disclose or share your data in order to comply with any legal obligation or legal process, or in order to enforce or apply our contractual rights, including the Terms of Use and Terms & Conditions, or any other agreement; in order to protect the rights, property, or safety of JOTT, our website users, or others.
Do you use cookies?
Our website (www.justoverthetop.co.uk) uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and allows us to improve our site.
A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer if you agree. Cookies contain information that is transferred to your computer’s hard drive.
We may use the following cookies:
· Functional cookies. These are cookies that are required for the operation of our website. They include, for example, cookies that enable you to log into secure areas of our website, and to allow our website to remember choices you have made in the past, like what language you prefer.
· Analytical or performance cookies. These allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily.
· Targeting cookies. These cookies record your visit to our website, the pages you have visited and the links you have followed.
You can find more information about the individual cookies we use and the purposes for which we use them in the table below:
|
Cookie name |
Type of Cookie |
Purpose |
Session or Persistent |
|
_cfruid |
Functional |
Cookie associated with sites using CloudFlare, used to identify trusted web traffic. |
Session |
|
_ga |
Analytical |
Cookie associated with Google Analytics 4 to count and store various statistics about audience activities (page views, time spend, path...) |
2 years |
|
_ga_EPWTWY49BV |
Analytical |
Cookie associated with Universal Analytics to count and store various statistics about audience activities (page views, time spend, path...) |
2 years |
|
_gat_UA-24041818-1 |
Analytical |
Cookie associated with Universal Analytics to read and filter requests from bots. |
a minute |
|
_gid |
Analytical |
Cookie associated with Universal Analytics to count and store various statistics about audience activities (page views, time spend, path...) |
a day |
|
_landing_page |
Analytical |
Cookie associated with Shopify, used to track, report, and analyze on landing pages. |
14 days |
|
_orig_referrer |
Functional |
Cookie associated with Shopify, used in connection with a shopping part. |
14 days |
|
_s |
Analytical |
Cookie associated with Shopify's analytics suite |
30 minutes |
|
_secure_session_id |
Functional |
Cookie associated with Shopify, used in connection with navigation through a storefront. |
a day |
|
_shopify_s |
Analytical |
Cookie associated with Shopify's analytics suite |
30 minutes |
|
_shopify_sa_p |
Analytical |
Cookie associated with Shopify's analytics suite concerning marketing and referrals. |
30 minutes |
|
_shopify_sa_t |
Analytical |
Cookie associated with Shopify's analytics suite concerning marketing and referrals, to store and track conversions. |
30 minutes |
|
_shopify_y |
Analytical |
Cookie associated with Shopify's analytics suite |
a year |
|
_y |
Analytical |
Cookie associated with Shopify's analytics suite |
a year |
|
cart |
Functional |
Cookie associated with Shopify, used in connection with the shopping cart. |
14 days |
|
cart_currency |
Functional |
Cookie associated with Shopify, used to recognize the user’s country of origin and populate the correct transaction currency. |
14 days |
|
cart_sig |
Functional |
Cookie associated with Shopify, used in connection with checkout. |
14 days |
|
cart_ts |
Functional |
Cookie associated with Shopify, used in connection with checkout. |
14 days |
|
cart_ver |
Functional |
Cookie associated with Shopify, used in connection with the shopping cart. |
14 days |
|
didomi_token |
Functional |
Cookie associated with Didomi, this cookie contains consent information for custom purposes and vendors along with the Didomi-specific information. |
a year |
|
euconsent-v2 |
Functional |
Cookie associated with Didomi, this cookie contains the IAB TCF consent string and consent information for all the standard IAB vendors and purposes. |
a year |
|
keep_alive |
Functional |
Cookie associated with Shopify, used in connection with buyer localization. |
30 minutes |
|
locale_bar_accepted |
Functional |
Cookie associated with Shopify, used in connection with buyer localization. |
Session |
|
localization |
Functional |
Cookie associated with Flickr, used to track usage of photo galleries embedded from Flickr. |
a year |
|
secure_customer_sig |
Functional |
Cookie associated with Shopify, used in connection with a customer login. |
a year |
Third Party Cookies
Please note that third parties may also use cookies, over which we have no control. These third parties may include, for example, advertising networks and providers of external services like web traffic analysis services. These third-party cookies are likely to be analytical or performance cookies or targeting cookies.
To deactivate the use of third-party cookies, you can select or deselect these using the cookies banner on our website.
Managing my cookies
You can choose which analytical and targeting cookies we can set by adjusting the toggle options in the cookies banner on our website. In the alternative, you can contact us at vieprivee@jott.fr to manage the use of cookies.
However, if you use your browser settings to block all cookies (including functional cookies) you may not be able to access all or parts of our website or it may affect the functionality of the website.
What about links to other websites?
Third party links
Our site may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our site, we encourage you to read the privacy policy of every website you visit.
Social plug ins and modules
We use social modules and plug-ins. For example, our site presents buttons which allow you to “like” and “share” information with your social media contacts, such as on Facebook, Twitter and Google+.
When you visit a page of our website containing social plug-ins or modules, a connection is established with the social network servers (Facebook, Twitter, etc.). These sites are told that you have accessed the corresponding page of our website, even if you do not have a Facebook or Twitter user account, and even if you are not logged in to your Facebook or Twitter account.
If you use plug-ins (such as a “like” or “share”), your actions can be recorded and published on your accounts in social networks depending on the settings of your social networks account. If you do not want social media to post your plug-in actions in your social media accounts, you should log out of your social media before visiting our site.
Is my data transferred outside the UK?
We share your personal data within the JOTT group. This will involve transferring your data to entities outside the UK.
We also share your personal data with third parties (e.g. our suppliers) located in countries outside of the UK which may have a lower level of data protection than in the UK. Whenever we transfer your personal data to entities outside of the UK, we will put in place adequate safeguards. These safeguards are intended to ensure a similar degree of protection is afforded to your data wherever it may be transferred and include:
- only transferring your personal data to countries which have been deemed to provide an adequate level of protection for personal data by the Information Commissioner’s Office; or
- where your data will be transferred outside of the UK and the EEA, by putting in place adequate safeguards to protect your personal data (for example, by entering into specific contractual terms which have been approved by the Information Commissioner’s Office and which are intended give personal data the same protection as within the UK).
Please contact us if you want further information on the mechanism used by us when transferring your personal data outside of the UK and the details of where your personal data is transferred.
How do we store and retain your information?
We have put in place appropriate security measures to reduce the risk of your personal data being accidentally lost, used or accessed in an unauthorised way. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a legitimate business reason to access it. They are instructed to only process your personal data on our instructions, and they are subject to a duty of confidentiality.
We will only retain your personal information for as long as is necessary to fulfil the purposes we collect it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. In order to comply with legal requirements that apply to us, and to ensure we have the necessary information required to resolve future issues that might arise, we generally retain all personal data for a minimum period of 5 years from collection from your last activity (for example a purchase of our products). After the 5 year period, your data is archived with restricted access for an additional period for limited reasons authorised by law. After this period, the data is deleted.
Please see the table below examples of our data retention periods.
|
Purpose of processing |
Legal basis |
Retention period in operational database |
Archiving |
|
Order management for products or services |
Contract |
5 years from the last activity |
5 to 10 years |
|
Using the justoverthetop.co.uk account |
Contract |
5 years from the last activity |
5 to 10 years |
|
Personalisation of our services |
Contract |
200 last views for onsite recommendation. 3 years from last activity for emails |
|
|
Sending messages via email or text message |
Consent or legitimate interests |
3 years from the last activity |
N/A |
|
Fraud prevention |
Legitimate interests |
3 years from subscription to a notification list |
2 years |
What are my rights?
If we process your data on the basis of your consent (for example, marketing communications), you may withdraw your consent at any time by contacting us.
Under data protection law, you have the following rights:
- Your right of access. You have the right to ask us for copies of your personal information.
- Your right to rectification. You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
- Your right to erasure. You have the right to ask us to erase your personal information in certain circumstances.
- Your right to restriction of processing. You have the right to ask us to restrict the processing of your information in certain circumstances.
- Your right to object to processing. You have the right to object to the processing of your personal data in certain circumstances.
- Your right to data portability. You have the right to ask that we transfer the information you gave us to another organisation, or to you, in certain circumstances.
If you wish to exercise any of these rights, please contact us by email at vieprivee@jott.fr or by post to JOTT, 103 Marylebone High Street, London W1U 4RP. Please indicate your name, first name, e-mail and address and describe your request and / or the right you wish to exercise.
If you make a request, we have one month to respond to you. You are not usually required to pay any charge for exercising your rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.
How to complain?
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), details of which are set out below. However, we would appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.
https://ico.org.uk/global/contact-us/
Helpline number: 0303 123 1113
Last update: 12 January 2023