Privacy Policy
Last updated: May 2025. This policy explains how we collect, use, and protect your personal data in accordance with UK GDPR and applicable US privacy laws.
Who we are
Silk Mahjong operates this website and is responsible for your personal data.
Data controller contact: hello@silkmahjong.com
What data we collect
When you place an order or create an account, we collect: your name, email address, shipping and billing address, and telephone number.
Payment data is handled directly by Stripe. We receive only a tokenised reference and the last four digits of your card - we never see or store your full card number.
When you browse our site, we automatically collect technical data via cookies and analytics tools: IP address, browser type, pages visited, time on page, referring URL, and device information.
If you contact us by email, we retain a record of that correspondence.
How we use your data
Order fulfilment - to process and ship your order, send order confirmations and tracking information, and handle any returns or queries.
Transactional emails - confirmation, shipping updates, and post-purchase follow-up, sent via Amazon SES.
Analytics - to understand how visitors use our site and improve our products and experience. We use Google Analytics 4 (GA4) and PostHog.
Legal compliance - to meet our obligations under applicable law, including tax and export regulations.
We do not sell your personal data to third parties.
Third parties we share data with
Stripe - payment processing. Stripe is PCI-DSS compliant. Their privacy policy is at stripe.com/privacy.
Shipping carriers - your name and delivery address are passed to the courier responsible for your shipment.
Google Analytics 4 - anonymised browsing data. You can opt out via Google's opt-out browser add-on.
PostHog - product analytics. Data is used in aggregate to improve site performance.
Amazon SES - transactional email delivery. Your email address and order details are processed to send you emails.
All third-party processors are contractually required to handle your data in accordance with applicable data protection law.
Data retention
We retain your order and account data for seven years to comply with our legal and tax obligations.
Analytics data is retained in aggregate form; raw session data is typically deleted after 26 months.
If you request deletion of your account, we will remove your personal data within 30 days, except where we are required by law to retain it.
Your rights
Depending on where you are based, you may have the following rights:
Access - request a copy of the personal data we hold about you.
Rectification - ask us to correct inaccurate data.
Erasure - ask us to delete your data (subject to legal retention obligations).
Restriction - ask us to limit how we use your data.
Portability - receive your data in a structured, machine-readable format.
Objection - object to processing based on our legitimate interests.
To exercise any of these rights, email hello@silkmahjong.com. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).
California residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA).
Right to know - you can request details of the categories and specific pieces of personal information we have collected about you in the past 12 months.
Right to delete - you can request deletion of your personal information, subject to certain exceptions.
Right to opt out - we do not sell personal information. If this changes, we will update this policy and provide a 'Do Not Sell My Personal Information' link.
Right to non-discrimination - we will not discriminate against you for exercising your CCPA rights.
To submit a California privacy request, email hello@silkmahjong.com with the subject line 'California Privacy Request'.
Security
We use industry-standard measures to protect your data, including TLS encryption for data in transit and restricted access controls.
No system is completely secure. If you believe your account has been compromised, please contact us immediately.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email to registered customers or via a notice on our site. Continued use of our site after changes are posted constitutes acceptance of the updated policy.
Contact
For any privacy-related questions or requests, please contact:
hello@silkmahjong.com