Florist Touch Website Privacy Policy

This privacy policy explains how Florist Touch Ltd collects and uses your personal data when you use our website or the Florist Touch platform, and how personal data flows between Florist Touch, florists, and independent Resellers.

This website is not intended for children, and we do not knowingly collect data relating to children.


1. Important information and who we are

Florist Touch Ltd (company number 12456022) is the controller responsible for this website, for your account information when you subscribe to our platform, and for billing and administrative data.

Florist accounts and platform use

For account, billing and platform-administration data:

  • Florist Touch Ltd is the controller.

Florist customer data processed through your Florist Touch website

For orders, delivery details, contact preferences, user content and any information relating to your florist customers:

  • You (the florist business) are the controller;
  • Florist Touch acts as your processor when providing the platform.

Independent resellers

Where you choose to work with a Reseller for onboarding, design, content support or technical work:

  • Resellers act as independent controllers for any personal data they collect directly from you; and
  • where they access your florist-customer data to perform work for you, they act as your processors, not Florist Touch’s.

Florist Touch does not supervise, manage or take responsibility for a Reseller’s data processing outside the platform environment.

Contact details for exercising your rights are set out in paragraph 10.


2. The data we collect about you

We may collect and process:

  • Identity Data – name, business name, job title.
  • Contact Data – business address, email, phone number.
  • Account Data – login credentials, subscription information.
  • Billing/Transaction Data – payment records (held by processors), plan details.
  • Technical Data – IP address, device data, browser data, login logs.
  • Usage Data – platform interactions, page views, feature use.
  • Profile Data – preferences, saved settings, support interactions.
  • Marketing Data – communication preferences.

Data about your florist customers

This may include:

  • order information,
  • delivery details,
  • contact preferences,
  • message content submitted through your website.

Florist Touch processes this strictly on your instructions when providing the platform.

We do not use your florist-customer data for our own marketing or analytics.


3. How your data is collected

Direct interactions

You provide data when you:

  • create a Florist Touch account;
  • subscribe to a plan;
  • request support;
  • provide materials for onboarding or site setup.

Automated interactions

We collect Technical and Usage Data using cookies and analytics tools.

Third parties

We may receive:

  • analytics data from third-party tools;
  • payment details from Stripe/WorldPay;
  • business information from public sources such as Companies House.

Resellers

Where a Reseller is engaged:

  • they may collect data directly from you as independent controllers;
  • Florist Touch does not receive this data unless required to deliver the platform.

4. How we use your personal data

We use your personal data to:

  • create and manage your account (contract performance);
  • provide, support and secure the platform (contract; legitimate interests);
  • process billing and payments (contract; legitimate interests);
  • communicate service updates (legitimate interests);
  • send optional marketing (legitimate interests / consent);
  • improve the platform (legitimate interests);
  • comply with legal obligations (legal duty).

Data used by resellers

Resellers use your data:

  • only for onboarding, design or development work you request;
  • under their own privacy notices;
  • as independent controllers or processors acting for you, not for Florist Touch.

Florist Touch is not responsible for reseller data processing outside the platform.


5. Sharing your personal data

We may share your data with:

  • hosting providers and technical infrastructure partners;
  • email and communication system providers;
  • analytics platforms;
  • payment processors;
  • professional advisers;
  • HMRC/regulators where required.

Sharing with resellers

If you choose to work with a Reseller:

  • we may share Identity and Contact Data so they can support you;
  • we do not grant Resellers access to florist-customer data unless you authorise it;
  • Resellers are not sub-processors of Florist Touch;
  • they process data under your instructions and under their own contracts with you.

No joint controllership

Nothing in our relationship with Resellers creates joint controllership under UK GDPR.


6. International transfers

Where services require data to be transferred outside the UK, we use:

  • the International Data Transfer Agreement (IDTA),
  • the UK Addendum to EU SCCs, or
  • UK adequacy regulations.

7. Data security

We use organisational and technical measures including encryption, access controls, logging, backups and incident response procedures.


8. Data retention

We retain:

  • account and billing data for six years after the end of your subscription;
  • usage logs for a shorter period for security and diagnostics;
  • florist-customer data only as long as necessary to provide the platform and as instructed by you.

At the end of the relevant retention period, we delete or anonymise data.


9. Your rights

You have the right to:

  • access your data;
  • correct inaccurate data;
  • request deletion;
  • restrict processing;
  • object to processing;
  • request portability;
  • withdraw consent.

These rights apply only to processing for which Florist Touch is the controller.

For data processed by Resellers, you must contact the Reseller directly.


10. Contact details

Florist Touch Ltd
3rd Floor Suite, 207 Regent Street, London, W1B 3HH
Email: Please visit: https://floristtouch.co.uk/contact
Telephone: 07481 355601


11. Complaints

You may complain to the ICO (www.ico.org.uk). We encourage you to contact us first.


12. Changes to this policy

We may update this policy from time to time. The latest version will always be available on our website.


13. Third-party links

Our website may link to external sites. We are not responsible for their privacy practices.


14. Alignment of our privacy policy with our Reseller agreement

  • Resellers act as independent businesses, not subcontractors of Florist Touch.
  • Resellers may access florist-customer data only on your lawful instructions.
  • Resellers are responsible for their own compliance with UK GDPR.
  • Florist Touch is not liable for Reseller processing outside the platform.
  • Data sharing is limited to what is necessary to facilitate onboarding or support.
  • There is no joint controllership between Florist Touch and any Reseller.

15. Social media integrations and message data

Where a florist chooses to connect a supported business social-media account to Florist Touch, the platform may receive and display information made available through the provider’s authorised application programming interfaces (APIs). Supported services may include Facebook Pages and Instagram professional accounts provided by Meta.

Depending on the features enabled by the florist and the permissions granted to Florist Touch, this information may include:

  • the connected business account or Page name and identifier;
  • the social-media username, display name or provider-scoped identifier of a person communicating with the florist;
  • direct-message content and available recent conversation history;
  • message attachments or an indication that an attachment was sent;
  • comments, mentions, replies and related post or media identifiers;
  • message timestamps and technical events such as delivery, read, edit or reaction information; and
  • technical records needed to authenticate, secure, diagnose and prevent duplicate processing of provider events.

When an account is first connected, Florist Touch may import conversation history that the provider makes available so the florist can work from a useful unified inbox. Provider restrictions may mean that only recent messages or recently active conversations are available.

Roles and instructions

For social-media enquiries and messages handled for a florist:

  • the florist business is normally the controller;
  • Florist Touch acts as the florist’s processor and handles the data on the florist’s documented instructions; and
  • the relevant social-media provider processes information under its own terms and privacy notice.

16. How social-media information is used

We process connected social-media information to:

  • place enquiries from supported channels into a unified florist inbox;
  • show conversation history and help authorised florist staff respond consistently;
  • identify messages, comments or mentions that may require attention;
  • maintain conversation status, assignment, private notes and follow-up reminders;
  • protect the service, verify provider notifications, avoid duplicate records and investigate faults; and
  • provide optional assistance such as classification, summarisation or reply drafting where the florist enables those features.

Florist Touch does not use florist-customer social-media messages for its own marketing. Optional automated assistance does not send a customer message, publish content, merge customer records or make another consequential change without an authorised user’s confirmation.

Sharing and service providers

Social-media information may be processed by Meta or another connected provider, and by hosting, security, storage and technical service providers used to operate Florist Touch. We limit access to what is necessary to provide and secure the service and apply appropriate contractual and international-transfer safeguards where required.


17. Social-media retention, disconnection and deletion

We retain imported social-media messages and related enquiry records only for as long as necessary to provide the connected service, meet the florist’s documented instructions and satisfy applicable legal or security requirements.

Disconnecting a Facebook Page or Instagram professional account stops future access once the provider authorisation has been withdrawn or expired. Disconnection does not automatically remove records already imported into the florist’s workspace where they remain required for the florist’s business records.

A florist may request deletion of imported social-media information or connected-account credentials by using the contact details in paragraph 10. A person who has communicated with a florist should normally direct a request about the florist’s copy of a conversation to that florist as controller. We will assist the florist with an appropriate access, correction or deletion request.

Deletion from Florist Touch does not delete the original conversation or content held by Facebook, Instagram or another provider. Requests concerning the provider’s own copy must be made to that provider. Residual copies may remain temporarily in restricted backups until they are overwritten in the normal backup cycle.


18. Managing connected social-media access

A florist controls which eligible business accounts are connected and may withdraw the permissions granted to Florist Touch through the relevant provider’s business settings. Florist Touch requests only the permissions needed for features the florist chooses to use. Access credentials are stored server-side and are not exposed to ordinary website visitors or customer devices.

For questions about a social-media connection, or to request disconnection or deletion assistance, please use the contact details in paragraph 10.