Sustrans is committed to ensuring that your privacy is protected in compliance with the Data Protection Act, including ensuring that any personal data collected is used fairly and responsibly, kept accurate and up-to-date and held securely.
Sustrans is named as the Data Controller on the public register of data controllers which is available on the Information Commissioner's website (Registration Number Z7399708).
This policy applies to all the pages hosted on this site – http://www.sustransshop.co.uk
It does not apply to other organisations to which we may link and whose privacy policies may differ.
We collect only information which you give to us via email, the various forms on the website, via telephone or postal mail. Some information is gathered when you make a donation, sign up to a campaign, take part in an online survey, or sign up to receive email updates. During these processes, the only information required is your name, address, phone, email (and payment method for joining or donating); although we may request other information, including your principal area(s) of interest in order to be able to provide you with more tailored information.
If you purchase items from the Sustrans Shop website, or make an on-line donation we will record your name, address, e-mail, and phone number to allow us to process your order. The relevant information will then used by us, our agents and sub-contractors to provide you with statements of your account, to inform you of events which may be of interest to you and to communicate with you on any matter relating to the conduct of your account in general.
In addition, we may also contact you via Sustrans’ email newsletters regarding our activities, events or products we think may be of interest to you (which you can unsubscribe from at any time), and we may contact you via post, telephone or email about how you can financially support us.
We may also use aggregate information and statistics for the purposes of monitoring website usage in order to help us develop the website and our services and we may provide such aggregate information to third parties. These statistics will not include information that can be used to identify any individual. Sustrans will not share your details with anyone else without your consent or as required by law. In all cases where personal data is recorded, they will be stored securely.
The Sustrans Shop website uses "cookies" to help personalise your online experience. A cookie is a small piece of information sent by a web server to a web browser, which enables the server to collect information from the browser. Cookies cannot be used to run programs or deliver viruses to your computer. Cookies are uniquely assigned to you, and can only be read by a web server in the domain that issued the cookie to you.
You have the ability to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. If you choose to block all cookies, parts of the Sustrans Shop website may not work properly.
You may configure your browser to accept all cookies, reject all cookies, or notify you when a cookie is set. Each browser is different, so check the "Help" menu of your browser to learn how to change your cookie preferences. Click here for further information on how to prompt or block cookies on various browsers: http://www.allaboutcookies.org/manage-cookies/index.html
List of cookies on the Sustrans Shop website:
_utma - Used by Google Analytics to identify unique visitors v returning visitors
_utmb - Used by Google Analytics for generally visitor tracking. __utmb takes a timestamp of the exact moment in time when a visitor enters a site
_utmc - Used by Google Analytics for generally visitor tracking. __utmb takes a timestamp of the exact moment in time when a visitor leaves a site
_utmz - Used by Google Analytics for tracking source visits (i.e. where the user came from).
Quantum session – essential session cookie used by the site for the purposes of: tracking when a user logs in and out; what is in users shopping basket and wishlist; associating order with user’s account; managing a user’s account address; keeping track of the user being sent to SagePay.
When you are on the Sustrans website and are asked for personal information, your information is for Sustrans’ use only, and will not be shared with third parties unless you specifically authorise us to do so.
The internet is not a secure medium. However we have put in place various security procedures as set out in this policy.
All credit card transactions on our online shop are processed by Sage Pay. Sage Pay is audited annually under the Payment Card Industry Data Security Standards (PCI DSS) and is a fully approved Level 1 payment services provider, which is the highest level of compliance. They are also active members of the PCI Security Standards Council (SSC) that defines card industry global regulation.
No cardholder information is ever passed to the Sustrans servers; rather an authorisation code and payment confirmation is received to complete and process orders.
You can be completely secure in the knowledge that nothing you pass to the Sage Pay servers can be examined, used or modified by any third parties attempting to gain access to sensitive information.
We also keep your information confidential. The internal procedures of Sustrans cover the storage, access and disclosure of your information.
If any of the information that you have provided to Sustrans changes, for example if you change your e-mail address or name, please let us know the correct details by sending an e-mail to email@example.com or by sending a letter to Sustrans Shop, 2 Cathedral Square, College Green, Bristol BS1 5DD.
The Data Protection Act applies to all personal data held within the European Economic Area (EEA). We will only transfer personal data to an organisation outside the EEA if we have a contract with it which ensures that the standards set out in this policy are maintained.
The Sustrans Shop website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that Sustrans does not have any control over other websites. Therefore, Sustrans cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.
Children should always ask a parent or guardian for permission before sending personal information to anyone online. It is our policy not to knowingly send information, or request donations from children. No information should be submitted to or posted to the Sustrans Shop website by children without the prior consent of their parent or legal guardian; if you are under 18, please do not submit any personal information to the Sustrans Shop website.
If children register to receive information from the Sustrans Shop website, and we are not made aware of an individual’s age, their personal information will be securely stored and we may contact them regarding future events. However, if we become aware (or are advised) that an individual under 18 has registered on the Sustrans Shop website, their personal data will be deleted, until parental/legal guardian consent has been received.
The Internet is not a 100% secure medium for communication and, accordingly, we cannot guarantee the security of any information you send to us (or we send to you) via the Internet.
In no event shall we be liable for any direct, indirect, incidental, special, exemplary, or consequential damages (including, but not limited to, procurement of substitute goods or services; loss of use, data, or profits; or business interruption) however caused and on any theory of liability, whether in contract, strict liability, or tort (including negligence or otherwise) arising in any way out of the use of this service, even if advised of the possibility of such damage.
We are not responsible for any damages which you, or others, may suffer as a result of the loss of confidentiality of such information.
We cannot ensure or warrant the security of any information you transmit to us or from our online products or services, and you do so at your own risk. Once we receive your transmission, we make our best effort to ensure its security on our systems.
On receipt of proof of identity and a written request, we will provide you with a copy of any information that we hold about you. Please write to:
2 Cathedral Square
We will reply within forty calendar days.