Privacy Policy
Privacy Policy
Last updated: 29 September 2026
This Privacy Policy explains how PhoneMart collects, uses, shares and protects your personal data when you visit phonemart.uk (the "Site"), create an account, buy a product, trade in a device, contact customer service or otherwise interact with us. It also explains the rights you have over your data and how to exercise them.
It is supplemented by our Cookie Policy, which covers cookies and similar technologies used on the Site.
- Who controls your personal data
- What personal data we collect
- Why we use your personal data and on what legal basis
- Who we share your personal data with
- International transfers
- How long we keep your personal data
- How we keep your personal data secure
- Your rights
- Children
- Automated decision-making and fraud prevention
- Marketing
- Third-party links and social login
- Changes to this policy
- How to contact us and complain
1. Who controls your personal data
I Repair Dar Limited, trading as PhoneMart, registered in England and Wales under company number 17455371, registered office 40 Northgate, Darlington, DL1 1PP, is the data controller for personal data processed through the Site. This means we decide why and how your personal data is used.
We are registered with the Information Commissioner's Office (ICO).
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).
You can contact our data protection lead at [email protected] or by post at the registered address above.
2. What personal data we collect
We collect personal data in three ways: data you give us, data collected automatically when you use the Site, and data we receive from third parties.
2.1 Data you give us
| Context | Data |
|---|---|
| Creating an account | Name, email address, password (stored hashed), phone number, date of birth (to confirm you are 16 or over) |
| Placing an order | Billing and delivery addresses, phone number, order contents, payment method (we receive a token and the last four digits of a card, never the full card number) |
| Trading in a device | Name, address, contact details, UK bank account details for payment, device model, IMEI or serial number, declared condition, photos you upload |
| Contacting customer service | Name, contact details, order number, the content of your message, WhatsApp chat transcripts and any attachments |
| Leaving a review | Display name, review text, star rating, order reference used to verify the purchase |
| Returning a product or making a warranty claim | Description of the fault, photos or video, return tracking details |
| Marketing preferences | Your opt-in or opt-out choices |
| Identity verification (where fraud checks require it) | Photo ID and a selfie or short video, processed by our verification partner |
2.2 Data collected automatically
When you browse the Site we collect: IP address, device type and identifiers, browser type and version, operating system, referring URL, pages viewed, products viewed and added to basket, search terms, time and duration of visits, approximate location derived from IP address, and crash/error logs. Some of this is collected through cookies and similar technologies, see our Cookie Policy for detail and controls.
2.3 Data from third parties
We may receive data about you from:
- Payment and fraud-prevention providers: payment confirmation, risk scores, chargeback notifications
- Delivery carriers: tracking events, delivery confirmation, proof of delivery
- Device databases: whether a traded-in device is reported lost, stolen or blocked (CheckMEND / GSMA)
- Social login providers (if you sign in with Google or Apple), name, email address and the identifier the provider assigns
- Publicly available sources and analytics providers: aggregated audience data
2.4 Data we do not deliberately collect
We do not ask for special category data (such as health, ethnicity, religion or biometric data used to identify you). If you volunteer such information, for example in a customer service message, we process it only to handle your request and delete it when no longer needed. Identity-verification selfies are processed by our provider for one-off matching and are not retained by us as biometric identifiers.
3. Why we use your personal data and on what legal basis
UK GDPR requires a lawful basis for each use. The tables below set out every purpose for which we process personal data and the basis we rely on.
3.1 Providing the Site and your account
| Purpose | Legal basis |
|---|---|
| Letting you browse the Site and use its features | Performance of a contract (our Terms of Use) |
| Creating, securing and managing your account | Performance of a contract |
| Signing in with Google or Apple | Consent (you choose to use social login) |
| Remembering your basket, preferences and recently viewed items | Legitimate interest (a functioning shopping experience); consent for non-essential cookies |
3.2 Orders, payment and delivery
| Purpose | Legal basis |
|---|---|
| Processing and fulfilling your order | Performance of a contract (our Terms of Sale) |
| Taking payment and issuing refunds | Performance of a contract |
| Arranging delivery and sharing your address with the carrier | Performance of a contract |
| Sending order confirmations, dispatch notices and delivery updates | Performance of a contract |
| Issuing invoices and keeping accounting records | Legal obligation |
3.3 Trade-in
| Purpose | Legal basis |
|---|---|
| Quoting for, receiving and inspecting your device | Performance of a contract (our Trade-in Terms) |
| Paying you for your device | Performance of a contract |
| Checking a device against lost/stolen databases and verifying ownership | Legal obligation (stolen-goods and proceeds-of-crime rules) and legitimate interest (fraud prevention) |
| Recording IMEI/serial numbers of devices we buy | Legal obligation and legitimate interest (traceability of second-hand goods) |
| Securely erasing data from received devices | Legitimate interest (protecting your privacy) and legal obligation |
3.4 Customer service, returns and warranty
| Purpose | Legal basis |
|---|---|
| Answering your questions and complaints | Performance of a contract; legitimate interest |
| Handling returns, repairs and warranty claims | Performance of a contract; legal obligation (consumer law) |
| Keeping correspondence and WhatsApp chat transcripts | Legitimate interest (quality, training, evidence of what was agreed) |
| Managing disputes and legal claims | Legitimate interest; legal obligation |
3.5 Reviews
| Purpose | Legal basis |
|---|---|
| Inviting you to review a product after purchase | Legitimate interest (helping other customers; we only invite verified buyers) |
| Publishing your review under your chosen display name | Consent (you choose to submit it) |
| Moderating reviews to remove unlawful or abusive content | Legitimate interest; legal obligation |
3.6 Fraud prevention and security
| Purpose | Legal basis |
|---|---|
| Screening orders and trade-ins for fraud, including risk scoring by our payment and fraud partners | Legitimate interest (protecting us, our customers and card issuers from fraud); legal obligation |
| Requesting identity verification where a transaction is flagged as high risk | Legitimate interest; legal obligation |
| Detecting and blocking bots, scraping and attacks on the Site | Legitimate interest (security) |
| Keeping records of fraudulent or abusive accounts | Legitimate interest |
3.7 Marketing and personalisation
| Purpose | Legal basis |
|---|---|
| Sending you email or SMS marketing about our products and offers | Consent, or the "soft opt-in" for existing customers (PECR), you can opt out at any time |
| Showing you personalised content and recommendations on the Site | Consent (non-essential cookies) |
| Running advertising on third-party platforms and measuring its effectiveness | Consent (advertising cookies and pixels) |
| Sending you abandoned-basket reminders | Consent / soft opt-in |
| Sending surveys about your experience | Legitimate interest (improving our service); you may decline |
3.8 Analytics and improvement
| Purpose | Legal basis |
|---|---|
| Understanding how the Site is used and where it fails | Consent (analytics cookies) for identifiable data; legitimate interest for aggregated data |
| Producing anonymised statistics | Not personal data once anonymised |
3.9 Legal, tax and regulatory obligations
| Purpose | Legal basis |
|---|---|
| Keeping tax and accounting records | Legal obligation |
| Responding to lawful requests from police, regulators or courts | Legal obligation |
| Complying with consumer and product-safety regulations | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interest |
Where we rely on legitimate interest, we have balanced that interest against your rights and expectations. You can ask us for details of any balancing assessment and you have the right to object (section 8).
4. Who we share your personal data with
We never sell your personal data. We share it only with the categories of recipient below, and only what each needs.
Service providers acting on our instructions (processors)
- Website hosting and infrastructure
- Payment processing (Stripe)
- Fraud-detection and identity-verification services
- Delivery and returns carriers and label providers
- Email, SMS and push notification providers
- Customer service and helpdesk software
- WhatsApp Business (Meta), which we use for customer chat: Meta processes message metadata under its own terms and the WhatsApp Business messaging is end-to-end encrypted; see the independent controllers below
- Review collection and display platforms
- Analytics tools
- Data erasure and device-diagnostic software used on trade-in devices
- Accounting, invoicing and tax software
Each processor is bound by a contract requiring it to protect your data, use it only for our purposes and delete it when the service ends. A current list of our principal processors is available on request from [email protected].
Independent controllers
- Card networks and your bank for payment authorisation and chargebacks
- Klarna when you choose to pay with Klarna, we share your name, email address, phone number, billing and delivery addresses and order details so Klarna can verify your identity, assess your application (which may include a credit check) and manage your payments, under Klarna's privacy notice
- Lost/stolen device databases when we check or register a traded-in device
- Advertising platforms (e.g. Google, Meta) when you consent to advertising cookies, they act as controllers for the data collected by their tags
- Social login providers when you sign in with Google or Apple
- Meta (WhatsApp) when you contact us by WhatsApp chat, Meta is an independent controller for account and metadata processing under WhatsApp's own privacy policy; message content is end-to-end encrypted and stored by us in our helpdesk records
Professional advisers and authorities
- Our lawyers, accountants, auditors and insurers where necessary
- Police, HMRC, Trading Standards, the ICO, courts and other authorities where the law requires or permits disclosure
- Debt-recovery agencies where a payment remains unpaid
Business transfers
If PhoneMart is sold, merges or transfers its assets, personal data may be transferred to the buyer or successor, who will be bound by this policy.
5. International transfers
We aim to store personal data in the United Kingdom. Some of our providers process data in the European Economic Area or the United States. Where personal data leaves the UK we ensure one of the following safeguards is in place:
- the destination country is covered by UK adequacy regulations (this includes the EEA);
- the transfer is covered by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses;
- the transfer is to a US organisation certified under the UK Extension to the EU-US Data Privacy Framework.
You can request a copy of the relevant safeguard from [email protected].
6. How long we keep your personal data
We keep personal data only as long as needed for the purposes above, then delete or anonymise it. Our main retention periods:
| Data | Retention |
|---|---|
| Account data | For the life of the account, then 3 years after the last activity, unless you ask for earlier deletion |
| Order, invoice and payment records | 6 years from the end of the financial year of the order (tax and accounting law; also the limitation period for contract claims) |
| Trade-in records including IMEI/serial | 6 years (second-hand goods traceability and tax) |
| Warranty claim records | Duration of the warranty plus 6 years |
| Customer service correspondence and WhatsApp chat transcripts | 3 years from closure of the query |
| Reviews | While the product is listed and for as long as you leave the review published; you can delete it at any time |
| Marketing consent and opt-out records | For as long as you are opted in, and a record of your opt-out indefinitely so we can honour it |
| Fraud records | 5 years from the incident |
| Identity-verification documents | Deleted within 30 days of the check completing; the outcome is kept with the order record |
| Website analytics (identifiable) | 13 months maximum |
| Server and security logs | 12 months |
| Data on traded-in devices | Erased on receipt during inspection; not retained |
When a retention period ends we delete the data or archive it in restricted form solely to meet legal, accounting or tax obligations and to defend claims, for the remaining limitation period.
7. How we keep your personal data secure
We apply technical and organisational measures appropriate to the risk, including:
- TLS encryption for all traffic to and from the Site
- Encryption of personal data at rest in our databases and backups
- Passwords stored using salted one-way hashing; we never see your password
- Card payments handled by Stripe, a PCI DSS Level 1 certified provider; card numbers never touch our servers
- Role-based access control, multi-factor authentication and audit logging for staff access to customer data
- Network firewalls, intrusion detection and regular vulnerability scanning
- Certified data-erasure software with erasure certificates for every trade-in device
- Staff training and confidentiality obligations
- Vetting of all processors and contractual security requirements
No system is completely secure. If a breach occurs that is likely to put your rights at risk, we will notify you and the ICO as required by law.
8. Your rights
Under UK GDPR you have the following rights. Most are free and we respond within one month (extendable by two months for complex requests, with notice).
- Access: obtain confirmation that we process your data and a copy of it.
- Rectification: have inaccurate data corrected and incomplete data completed. You can edit most account details yourself.
- Erasure: ask us to delete your data where it is no longer needed, where you withdraw consent, or where you object and we have no overriding grounds. We may need to keep some data to meet legal obligations (for example invoices).
- Restriction: ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Portability: receive the data you provided to us in a structured, machine-readable format, or have it sent to another provider.
- Objection: object to processing based on legitimate interest; we will stop unless we can show compelling grounds. You can object to direct marketing at any time and we will always stop.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting processing that has already taken place.
- Automated decisions: not to be subject to a decision based solely on automated processing that significantly affects you, and to ask for human review (see section 10).
To exercise a right, email [email protected], use the privacy request form on the Site, or write to our registered office. We may ask you to confirm your identity before acting. If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse it, and we will explain why.
9. Children
The Site is intended for people aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.
10. Automated decision-making and fraud prevention
We use automated fraud screening on orders and trade-ins. Our payment and fraud partners assign a risk score based on factors such as device fingerprint, address matching, order value and velocity. A high score may cause a transaction to be held for manual review or, in a small number of cases, declined automatically.
Where an automated decision would significantly affect you (for example an order being cancelled), you can contact us to request human review, express your point of view and challenge the decision. We do not currently offer instalment finance.
11. Marketing
We send marketing by email and, if you opt in, by SMS and push notification. If you are an existing customer we may email you about similar products under the PECR soft opt-in, having given you the chance to opt out at the point of purchase.
You can stop marketing at any time by:
- clicking "unsubscribe" in any marketing email
- replying STOP to any marketing SMS
- changing your preferences in your account
- emailing [email protected]
Opting out of marketing does not stop service messages about your orders, trade-ins, warranty or account, which we must send to perform our contract with you.
12. Third-party links and social login
The Site may link to other websites (for example manufacturer support pages or carriers). We are not responsible for their privacy practices. If you choose to sign in with Google or Apple, that provider will share basic profile data with us and may record that you have used the login; check the provider's privacy policy for details.
13. Changes to this policy
We review this policy regularly and update it when our practices or the law change. The date at the top shows the current version. For material changes we will notify account holders by email or by a notice on the Site before the change takes effect. Previous versions are available on request.
14. How to contact us and complain
Questions, requests and complaints about this policy or our use of your data:
- Email: [email protected]
- WhatsApp chat: +44 7913 170620, 9am to 9pm UK time
- Post: Data Protection, I Repair Dar Limited, 40 Northgate, Darlington, DL1 1PP
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk, 0303 123 1113.
We would appreciate the chance to resolve your concern first, but you may contact the ICO at any time.

