Privacy policy

Last updated: September 18, 2025

DigDrum is a trading name of Petosu Ltd, a company registered in England & Wales with its registered office at:
1 Court Mews, London Road, Charlton Kings, Cheltenham, GL52 6HS, United Kingdom.

Our Services are hosted and powered by Shopify.

This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you visit or make a purchase. By using our Services, you acknowledge you have read this Privacy Policy.

1. Data Controller

For the purposes of UK data protection law, the data controller of your personal data is:
Petosu Ltd (trading as DigDrum)
📍 1 Court Mews, London Road, Charlton Kings, Cheltenham, GL52 6HS
📧 support@digdrum.com

2. Data We Collect

  • Contact details (name, address, email, phone)
  • Payment information (processed securely by providers; we do not store full card details)
  • Account information (username, preferences)
  • Transaction history
  • Customer communications
  • Device & usage data (cookies, IP, browser)

3. How We Use Data & Legal Bases

We use your data to:

  • Provide and deliver our Services (contract)
  • Process payments and fraud prevention (contract/legal obligation)
  • Handle support and returns (legitimate interests)
  • Send marketing (consent/legitimate interests)
  • Improve services (legitimate interests)
  • Comply with legal and tax obligations (legal obligation)

4. Marketing Choices

  • We send marketing with your consent or under the “soft opt-in” rule.
  • You can opt out anytime by clicking “unsubscribe” or emailing us.

5. Cookies

We use cookies for site functionality, analytics, and marketing. Consent is requested where required.

6. Sharing Your Data

We may share data with:

  • Shopify (hosting & payments)
  • Payment processors & logistics providers
  • Marketing partners (with consent/soft opt-in)
  • Legal authorities if required

7. International Transfers

Where data is transferred outside the UK/EEA, we use safeguards such as Standard Contractual Clauses.

8. Data Retention

  • Orders: 6 years (legal requirement)
  • Marketing data: until consent is withdrawn or 24 months inactivity
  • Accounts: until closure or deletion request

9. Your Rights

You can request access, correction, deletion, portability, or object to processing.
Contact: support@digdrum.com

10. Security

We use appropriate technical and organisational measures but cannot guarantee complete security.

11. Complaints

Concerns: support@digdrum.com
ICO: www.ico.org.uk

12. Changes

We may update this policy; updates will be posted here.