Home
Trade-in

Privacy Policy

Privacy Policy

Last updated: 29 September 2026

This Privacy Policy explains how PhoneMart collects, uses, shares and protects your personal data when you visit phonemart.uk (the "Site"), create an account, buy a product, trade in a device, contact customer service or otherwise interact with us. It also explains the rights you have over your data and how to exercise them.

It is supplemented by our Cookie Policy, which covers cookies and similar technologies used on the Site.

1. Who controls your personal data

I Repair Dar Limited, trading as PhoneMart, registered in England and Wales under company number 17455371, registered office 40 Northgate, Darlington, DL1 1PP, is the data controller for personal data processed through the Site. This means we decide why and how your personal data is used.

We are registered with the Information Commissioner's Office (ICO).

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).

You can contact our data protection lead at [email protected] or by post at the registered address above.

2. What personal data we collect

We collect personal data in three ways: data you give us, data collected automatically when you use the Site, and data we receive from third parties.

2.1 Data you give us

ContextData
Creating an accountName, email address, password (stored hashed), phone number, date of birth (to confirm you are 16 or over)
Placing an orderBilling and delivery addresses, phone number, order contents, payment method (we receive a token and the last four digits of a card, never the full card number)
Trading in a deviceName, address, contact details, UK bank account details for payment, device model, IMEI or serial number, declared condition, photos you upload
Contacting customer serviceName, contact details, order number, the content of your message, WhatsApp chat transcripts and any attachments
Leaving a reviewDisplay name, review text, star rating, order reference used to verify the purchase
Returning a product or making a warranty claimDescription of the fault, photos or video, return tracking details
Marketing preferencesYour opt-in or opt-out choices
Identity verification (where fraud checks require it)Photo ID and a selfie or short video, processed by our verification partner

2.2 Data collected automatically

When you browse the Site we collect: IP address, device type and identifiers, browser type and version, operating system, referring URL, pages viewed, products viewed and added to basket, search terms, time and duration of visits, approximate location derived from IP address, and crash/error logs. Some of this is collected through cookies and similar technologies, see our Cookie Policy for detail and controls.

2.3 Data from third parties

We may receive data about you from:

  • Payment and fraud-prevention providers: payment confirmation, risk scores, chargeback notifications
  • Delivery carriers: tracking events, delivery confirmation, proof of delivery
  • Device databases: whether a traded-in device is reported lost, stolen or blocked (CheckMEND / GSMA)
  • Social login providers (if you sign in with Google or Apple), name, email address and the identifier the provider assigns
  • Publicly available sources and analytics providers: aggregated audience data

2.4 Data we do not deliberately collect

We do not ask for special category data (such as health, ethnicity, religion or biometric data used to identify you). If you volunteer such information, for example in a customer service message, we process it only to handle your request and delete it when no longer needed. Identity-verification selfies are processed by our provider for one-off matching and are not retained by us as biometric identifiers.

UK GDPR requires a lawful basis for each use. The tables below set out every purpose for which we process personal data and the basis we rely on.

3.1 Providing the Site and your account

PurposeLegal basis
Letting you browse the Site and use its featuresPerformance of a contract (our Terms of Use)
Creating, securing and managing your accountPerformance of a contract
Signing in with Google or AppleConsent (you choose to use social login)
Remembering your basket, preferences and recently viewed itemsLegitimate interest (a functioning shopping experience); consent for non-essential cookies

3.2 Orders, payment and delivery

PurposeLegal basis
Processing and fulfilling your orderPerformance of a contract (our Terms of Sale)
Taking payment and issuing refundsPerformance of a contract
Arranging delivery and sharing your address with the carrierPerformance of a contract
Sending order confirmations, dispatch notices and delivery updatesPerformance of a contract
Issuing invoices and keeping accounting recordsLegal obligation

3.3 Trade-in

PurposeLegal basis
Quoting for, receiving and inspecting your devicePerformance of a contract (our Trade-in Terms)
Paying you for your devicePerformance of a contract
Checking a device against lost/stolen databases and verifying ownershipLegal obligation (stolen-goods and proceeds-of-crime rules) and legitimate interest (fraud prevention)
Recording IMEI/serial numbers of devices we buyLegal obligation and legitimate interest (traceability of second-hand goods)
Securely erasing data from received devicesLegitimate interest (protecting your privacy) and legal obligation

3.4 Customer service, returns and warranty

PurposeLegal basis
Answering your questions and complaintsPerformance of a contract; legitimate interest
Handling returns, repairs and warranty claimsPerformance of a contract; legal obligation (consumer law)
Keeping correspondence and WhatsApp chat transcriptsLegitimate interest (quality, training, evidence of what was agreed)
Managing disputes and legal claimsLegitimate interest; legal obligation

3.5 Reviews

PurposeLegal basis
Inviting you to review a product after purchaseLegitimate interest (helping other customers; we only invite verified buyers)
Publishing your review under your chosen display nameConsent (you choose to submit it)
Moderating reviews to remove unlawful or abusive contentLegitimate interest; legal obligation

3.6 Fraud prevention and security

PurposeLegal basis
Screening orders and trade-ins for fraud, including risk scoring by our payment and fraud partnersLegitimate interest (protecting us, our customers and card issuers from fraud); legal obligation
Requesting identity verification where a transaction is flagged as high riskLegitimate interest; legal obligation
Detecting and blocking bots, scraping and attacks on the SiteLegitimate interest (security)
Keeping records of fraudulent or abusive accountsLegitimate interest

3.7 Marketing and personalisation

PurposeLegal basis
Sending you email or SMS marketing about our products and offersConsent, or the "soft opt-in" for existing customers (PECR), you can opt out at any time
Showing you personalised content and recommendations on the SiteConsent (non-essential cookies)
Running advertising on third-party platforms and measuring its effectivenessConsent (advertising cookies and pixels)
Sending you abandoned-basket remindersConsent / soft opt-in
Sending surveys about your experienceLegitimate interest (improving our service); you may decline

3.8 Analytics and improvement

PurposeLegal basis
Understanding how the Site is used and where it failsConsent (analytics cookies) for identifiable data; legitimate interest for aggregated data
Producing anonymised statisticsNot personal data once anonymised

3.9 Legal, tax and regulatory obligations

PurposeLegal basis
Keeping tax and accounting recordsLegal obligation
Responding to lawful requests from police, regulators or courtsLegal obligation
Complying with consumer and product-safety regulationsLegal obligation
Establishing, exercising or defending legal claimsLegitimate interest

Where we rely on legitimate interest, we have balanced that interest against your rights and expectations. You can ask us for details of any balancing assessment and you have the right to object (section 8).

4. Who we share your personal data with

We never sell your personal data. We share it only with the categories of recipient below, and only what each needs.

Service providers acting on our instructions (processors)

  • Website hosting and infrastructure
  • Payment processing (Stripe)
  • Fraud-detection and identity-verification services
  • Delivery and returns carriers and label providers
  • Email, SMS and push notification providers
  • Customer service and helpdesk software
  • WhatsApp Business (Meta), which we use for customer chat: Meta processes message metadata under its own terms and the WhatsApp Business messaging is end-to-end encrypted; see the independent controllers below
  • Review collection and display platforms
  • Analytics tools
  • Data erasure and device-diagnostic software used on trade-in devices
  • Accounting, invoicing and tax software

Each processor is bound by a contract requiring it to protect your data, use it only for our purposes and delete it when the service ends. A current list of our principal processors is available on request from [email protected].

Independent controllers

  • Card networks and your bank for payment authorisation and chargebacks
  • Klarna when you choose to pay with Klarna, we share your name, email address, phone number, billing and delivery addresses and order details so Klarna can verify your identity, assess your application (which may include a credit check) and manage your payments, under Klarna's privacy notice
  • Lost/stolen device databases when we check or register a traded-in device
  • Advertising platforms (e.g. Google, Meta) when you consent to advertising cookies, they act as controllers for the data collected by their tags
  • Social login providers when you sign in with Google or Apple
  • Meta (WhatsApp) when you contact us by WhatsApp chat, Meta is an independent controller for account and metadata processing under WhatsApp's own privacy policy; message content is end-to-end encrypted and stored by us in our helpdesk records

Professional advisers and authorities

  • Our lawyers, accountants, auditors and insurers where necessary
  • Police, HMRC, Trading Standards, the ICO, courts and other authorities where the law requires or permits disclosure
  • Debt-recovery agencies where a payment remains unpaid

Business transfers

If PhoneMart is sold, merges or transfers its assets, personal data may be transferred to the buyer or successor, who will be bound by this policy.

5. International transfers

We aim to store personal data in the United Kingdom. Some of our providers process data in the European Economic Area or the United States. Where personal data leaves the UK we ensure one of the following safeguards is in place:

  • the destination country is covered by UK adequacy regulations (this includes the EEA);
  • the transfer is covered by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses;
  • the transfer is to a US organisation certified under the UK Extension to the EU-US Data Privacy Framework.

You can request a copy of the relevant safeguard from [email protected].

6. How long we keep your personal data

We keep personal data only as long as needed for the purposes above, then delete or anonymise it. Our main retention periods:

DataRetention
Account dataFor the life of the account, then 3 years after the last activity, unless you ask for earlier deletion
Order, invoice and payment records6 years from the end of the financial year of the order (tax and accounting law; also the limitation period for contract claims)
Trade-in records including IMEI/serial6 years (second-hand goods traceability and tax)
Warranty claim recordsDuration of the warranty plus 6 years
Customer service correspondence and WhatsApp chat transcripts3 years from closure of the query
ReviewsWhile the product is listed and for as long as you leave the review published; you can delete it at any time
Marketing consent and opt-out recordsFor as long as you are opted in, and a record of your opt-out indefinitely so we can honour it
Fraud records5 years from the incident
Identity-verification documentsDeleted within 30 days of the check completing; the outcome is kept with the order record
Website analytics (identifiable)13 months maximum
Server and security logs12 months
Data on traded-in devicesErased on receipt during inspection; not retained

When a retention period ends we delete the data or archive it in restricted form solely to meet legal, accounting or tax obligations and to defend claims, for the remaining limitation period.

7. How we keep your personal data secure

We apply technical and organisational measures appropriate to the risk, including:

  • TLS encryption for all traffic to and from the Site
  • Encryption of personal data at rest in our databases and backups
  • Passwords stored using salted one-way hashing; we never see your password
  • Card payments handled by Stripe, a PCI DSS Level 1 certified provider; card numbers never touch our servers
  • Role-based access control, multi-factor authentication and audit logging for staff access to customer data
  • Network firewalls, intrusion detection and regular vulnerability scanning
  • Certified data-erasure software with erasure certificates for every trade-in device
  • Staff training and confidentiality obligations
  • Vetting of all processors and contractual security requirements

No system is completely secure. If a breach occurs that is likely to put your rights at risk, we will notify you and the ICO as required by law.

8. Your rights

Under UK GDPR you have the following rights. Most are free and we respond within one month (extendable by two months for complex requests, with notice).

  • Access: obtain confirmation that we process your data and a copy of it.
  • Rectification: have inaccurate data corrected and incomplete data completed. You can edit most account details yourself.
  • Erasure: ask us to delete your data where it is no longer needed, where you withdraw consent, or where you object and we have no overriding grounds. We may need to keep some data to meet legal obligations (for example invoices).
  • Restriction: ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
  • Portability: receive the data you provided to us in a structured, machine-readable format, or have it sent to another provider.
  • Objection: object to processing based on legitimate interest; we will stop unless we can show compelling grounds. You can object to direct marketing at any time and we will always stop.
  • Withdraw consent: where processing is based on consent, withdraw it at any time without affecting processing that has already taken place.
  • Automated decisions: not to be subject to a decision based solely on automated processing that significantly affects you, and to ask for human review (see section 10).

To exercise a right, email [email protected], use the privacy request form on the Site, or write to our registered office. We may ask you to confirm your identity before acting. If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse it, and we will explain why.

9. Children

The Site is intended for people aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

10. Automated decision-making and fraud prevention

We use automated fraud screening on orders and trade-ins. Our payment and fraud partners assign a risk score based on factors such as device fingerprint, address matching, order value and velocity. A high score may cause a transaction to be held for manual review or, in a small number of cases, declined automatically.

Where an automated decision would significantly affect you (for example an order being cancelled), you can contact us to request human review, express your point of view and challenge the decision. We do not currently offer instalment finance.

11. Marketing

We send marketing by email and, if you opt in, by SMS and push notification. If you are an existing customer we may email you about similar products under the PECR soft opt-in, having given you the chance to opt out at the point of purchase.

You can stop marketing at any time by:

  • clicking "unsubscribe" in any marketing email
  • replying STOP to any marketing SMS
  • changing your preferences in your account
  • emailing [email protected]

Opting out of marketing does not stop service messages about your orders, trade-ins, warranty or account, which we must send to perform our contract with you.

The Site may link to other websites (for example manufacturer support pages or carriers). We are not responsible for their privacy practices. If you choose to sign in with Google or Apple, that provider will share basic profile data with us and may record that you have used the login; check the provider's privacy policy for details.

13. Changes to this policy

We review this policy regularly and update it when our practices or the law change. The date at the top shows the current version. For material changes we will notify account holders by email or by a notice on the Site before the change takes effect. Previous versions are available on request.

14. How to contact us and complain

Questions, requests and complaints about this policy or our use of your data:

  • Email: [email protected]
  • WhatsApp chat: +44 7913 170620, 9am to 9pm UK time
  • Post: Data Protection, I Repair Dar Limited, 40 Northgate, Darlington, DL1 1PP

If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk, 0303 123 1113.

We would appreciate the chance to resolve your concern first, but you may contact the ICO at any time.