Privacy Policy
Last updated: February 2026
Introduction
This Privacy Policy explains how Shepherd Marine Limited (“we”, “us”, “our”) collects, uses, stores and shares personal data when you interact with us, including through our website www.smlpaints.co.uk, when you place orders, create an account, contact us, or receive marketing communications.
We are committed to protecting your personal data and handling it responsibly, in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
This policy applies to both consumer and trade customers, as well as business contacts acting on behalf of organisations.
Who we are
We are the data controller for the personal data described in this policy. If you have any questions about this policy or how we use your data, you can contact us at:
Shepherd Marine Limited
The Downs
Ashton Road
South Cerney
Cirencester
GL7 6DD
info@smlpaints.co.uk
01285 862132
Registered in England and Wales (05278878)
The personal information we collect
We collect personal information and data in the following ways:
Information you provide to us
This may include:
- Name and contact details (email address, telephone number)
- Billing and delivery addresses
- Account login details
- Trade account details
- Payment and transaction information
- Communications with us including emails, phone calls and contact forms
- Marketing preferences
Information collected automatically when you use our website
When you visit our website, we automatically collect certain information using cookies and similar technologies, including:
- IP address
- Browser type and device information
- Pages visited and actions taken
- Referring websites or marketing campaigns
- Session behaviour and interaction data
Cookies and similar technologies
We use cookies and similar technologies to distinguish you from other users of our website and to improve your experience.
For full details, please see our Cookie Policy.
How we use your personal data
We use personal data for the following purposes:
Orders, payments and fulfilment
- To process and fulfil orders
- To take and manage payments
- To arrange delivery via our courier partners
- To manage returns, refunds and customer service queries
- To maintain order history and saved addresses
Payments are processed securely via our payment provider and we do not store full card details.
Lawful basis: Contractual necessity; Legal obligation
Customer accounts and trade accounts
- To create and manage customer and trade accounts
- To provide account functionality, including saved details and order history
- To manage trade pricing, terms and account administration
- To maintain records of transactions and communications
Lawful basis: Contractual necessity; Legitimate interests
Credit accounts and financial administration
Where we offer credit accounts or payment terms:
- To assess and manage credit risk
- To administer invoicing and payment terms
- To maintain accounting and financial records
This processing may include limited checks and fraud-prevention measures via our payment and accounting providers.
Lawful basis: Contractual necessity; Legitimate interests; Legal obligation
Website operation and improvement
- To operate and secure our website
- To understand how visitors use our website
- To improve site performance, usability and content
This includes the use of analytics and session-monitoring tools.
Lawful basis: Legitimate interests
Marketing communications
If you opt in (or where permitted by law), we may use personal data to:
- Send promotional emails and newsletters to inform you about products, offers and services
- Send abandoned basket reminders
- Measure the effectiveness of marketing campaigns
You can unsubscribe from marketing communications at any time.
Lawful basis: Consent; Legitimate interests (where applicable)
Customer analysis and profiling
We use customer data to:
- Understand purchasing behaviour
- Segment customers (for example, trade vs retail)
- Improve our product range and marketing relevance
This may include using hashed email addresses to create or match audiences on advertising platforms (such as Google) for remarketing or lookalike audiences.
This profiling:
- Is limited in scope
- Does not involve automated decision-making with legal or similarly significant effects
Lawful basis: Legitimate interests; Consent (for marketing activities)
Who we share personal data with
We may share personal data with trusted third parties where necessary, including:
- Payment providers (e.g. Opayo)
- Delivery and logistics providers (e.g. Parcelforce)
- Website analytics and optimisation providers (e.g. Hotjar)
- Marketing and email platforms (e.g. Mailchimp)
- Advertising platforms (e.g. Google Ads)
- Accounting and finance providers (e.g. Sage)
- IT and hosting providers
All third parties are required to handle personal data securely and in accordance with data protection law.
We may also disclose personal data where required by law or to protect our legal rights.
International data transfers
Some of the third-party services we use are based outside the UK. This means that personal data may be processed outside the UK.
Where this occurs, we ensure appropriate safeguards are in place, such as:
- UK adequacy regulations
- Standard contractual clauses and the UK Addendum
These measures are designed to ensure your data remains protected.
How long we keep your data
We retain personal data only for as long as necessary, including:
- For the duration of customer or trade accounts
- To fulfil contracts and provide services
- To comply with legal, tax and accounting obligations
- To resolve disputes or enforce our rights
Retention periods vary depending on the type of data and purpose of processing.
Your rights
You have rights under UK GDPR, including the right to:
- Access your personal data
- Correct inaccurate or incomplete data
- Request deletion of your data (where applicable)
- Restrict or object to processing
- Withdraw consent at any time
- Lodge a complaint with the Information Commissioner’s Office (ICO)
To exercise your rights, please contact us using the details above.
Data security
We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access or disclosure
Changes to this policy
We may update this Privacy Policy from time to time. The “last updated” date at the top of this policy indicates when changes were made.