Privacy Policy
Last updated: 29 July 2026
This Privacy Policy explains how Night Imp Claymancy collects and uses personal information under the UK General Data Protection Regulation, the Data Protection Act 2018 and, where applicable, the EU General Data Protection Regulation.
1. Who controls your information
The data controller is:
Simon Braik trading as Night Imp Claymancy (NI Claymancy)
48 Craig Crescent
Lisburn
BT28 1HB
Northern Ireland
United Kingdom
Email: hello@niclaymancy.com
2. Information we collect
Depending on how you use the website, we may collect:
Account and identity information
- Name.
- Username.
- Email address.
- Telephone number where supplied.
- Account identifiers.
- Password in securely hashed form.
Order information
- Billing and delivery addresses.
- Products ordered.
- Prices, discounts and shipping charges.
- Payment status.
- Order notes.
- Tracking information.
- Refund and dispute information.
Custom-order information
- Cutter, Stamp, Bulk and Repeat Item specifications.
- Measurements and sizes.
- Clay thickness and style selections.
- Customer notes.
- Reference Images.
- Proof files.
- Proof approvals and change requests.
- Design Nook messages.
- Administrator design files and internal production records.
Design Review information
- Contact email.
- Requested product type.
- Approximate size.
- Notes.
- Private Reference Images.
- Review status and dates.
Technical and security information
- IP address.
- Browser and device information.
- Login and security events.
- Cookie and session identifiers.
- Fraud and payment-risk signals.
- Server and error logs.
Communications
- Emails sent to or from us.
- Contact-form submissions.
- Live-chat messages when live chat is enabled.
- Newsletter preferences when newsletter services are enabled.
3. Why we use personal information
We process information for the following purposes and lawful bases.
To perform a contract or take steps before a contract
This includes:
- Providing Design Reviews.
- Processing orders and payments.
- Creating and managing Projects.
- Preparing designs and Proofs.
- Manufacturing products.
- Delivering orders.
- Handling messages, changes, returns and refunds.
To comply with legal obligations
This includes:
- Maintaining accounting and transaction records.
- Responding to lawful requests.
- Managing consumer-rights obligations.
- Preventing unlawful transactions.
- Meeting customs and shipping requirements.
For legitimate interests
This includes:
- Protecting the website and private customer files.
- Preventing fraud, spam and abuse.
- Troubleshooting technical problems.
- Keeping appropriate records of customer service.
- Improving business operations.
- Defending or establishing legal claims.
We consider whether these interests are necessary and balanced against your rights.
With consent
We rely on consent for:
- Email marketing where consent is required.
- Non-essential analytics cookies.
- Advertising and remarketing technologies.
- Certain live-chat or embedded-content technologies.
- Other optional tracking features.
You can withdraw consent at any time.
4. Private customer files
Reference Images, Proofs and other private customer files handled through the Night Imp Workshop system are stored outside the publicly accessible website directory.
They are not listed in the normal WordPress Media Library and are delivered only after an access check.
Although reasonable technical and organisational measures are used, no internet service can guarantee absolute security.
5. Payments
Payments may be processed through WooPayments and Stripe.
These providers receive the information required to:
- Process and authenticate payments.
- Prevent fraud.
- Manage refunds and disputes.
- Meet financial and regulatory obligations.
Night Imp Claymancy does not receive or store your complete card number.
If Revolut Checkout is enabled later, Revolut will process payment and fraud-prevention information under its own terms and privacy notice.
WooPayments is built in partnership with Stripe and uses a Stripe Express account for payment activity.
6. Who receives information
We share information only where reasonably necessary with categories including:
- Website and database hosting providers.
- WooCommerce and Automattic services.
- WooPayments and Stripe.
- Revolut when enabled.
- Royal Mail, delivery partners and customs authorities.
- Email-delivery providers used through WP Mail SMTP.
- Website security providers, including Wordfence.
- Backup and recovery providers used through UpdraftPlus.
- Professional advisers where required.
- Government, regulatory, law-enforcement or judicial authorities where legally required.
- Newsletter, live-chat, analytics and advertising providers when those services are enabled.
We do not sell personal information.
7. Security monitoring
Wordfence may process IP addresses, request information and security-event data to detect malicious activity and protect the website.
WooPayments may use fraud-prevention systems supplied through Stripe, including risk-analysis technology.
8. International transfers
Some service providers may process information outside the United Kingdom.
Where required, transfers are protected using an applicable adequacy decision, the UK International Data Transfer Agreement, an approved addendum to standard contractual clauses, or another lawful safeguard.
9. Retention
We retain information only for as long as reasonably necessary for the purpose for which it was collected.
Normal periods include:
- Unsubmitted custom-order and Design Review drafts: normally seven days.
- Closed Design Review requests and their private files: normally 90 days.
- Converted custom-order submission records: normally 30 days after conversion where no longer required separately.
- Notification-delivery records: normally 90 days.
- Completed and shipped custom Projects: personal Project content is normally minimised after six years, while limited transaction information may be retained where legally required.
- Order and accounting records: normally up to six years, or longer where a tax enquiry, dispute, chargeback or legal requirement applies.
- Security logs: for the period reasonably required to investigate and prevent abuse.
- Marketing information: until consent is withdrawn, an unsubscribe request is received or the information is no longer reasonably required.
- Backups: until the relevant backup expires under the backup rotation schedule.
Deletion from the live website may not immediately remove information from an encrypted backup. It will disappear when that backup is overwritten or expires.
UK GDPR requires retention periods to be justified and personal information not to be held indefinitely. HMRC requires self-employed business records to be retained for at least five years after the relevant Self Assessment deadline.
10. Your rights
Depending on the circumstances, you may have the right to:
- Request access to your personal information.
- Request correction of inaccurate information.
- Request deletion.
- Request restriction of processing.
- Object to processing based on legitimate interests.
- Object to direct marketing at any time.
- Request portability of information supplied under contract or consent.
- Withdraw consent.
- Complain to a data-protection authority.
Some rights are limited where information must be retained for legal obligations, fraud prevention, disputes or legal claims.
To make a request, email:
We may need to confirm your identity before acting on a request.
You may also complain to the Information Commissioner’s Office. We would appreciate the opportunity to address your concern first.
The ICO requires privacy notices to identify purposes, lawful bases, recipients, retention and applicable individual rights.
11. Marketing
We will send marketing emails only where we have an appropriate legal basis.
Every marketing email will provide an unsubscribe method.
Unsubscribing from marketing does not prevent us from sending transactional messages about an order, account, security issue, Design Review or active Project.
12. Analytics, advertising, social media and live chat
The site may later use:
- Google analytics or advertising services.
- Pinterest tags.
- Instagram or other social-media embeds.
- A newsletter platform.
- A live-chat provider.
Non-essential tracking associated with these services will not be intentionally activated until the required consent controls are in place.
The Privacy Policy and Cookie Policy will be updated where necessary when a specific provider is selected or enabled.
13. Children
The website is not directed specifically at children.
A person under 18 should place an order only with the involvement and permission of a parent or guardian.
14. Changes to this policy
We may update this Privacy Policy when our services, providers, technology or legal obligations change.
The current version and update date will remain available on this page.
15. Cookie Policy
This policy explains how niclaymancy.com uses cookies and similar storage technologies.
What cookies are
Cookies are small files or identifiers stored by a website, browser or connected service.
They can be used to:
- Keep a shopping cart working.
- Maintain a logged-in session.
- Remember preferences.
- Protect accounts and checkout.
- Process payments.
- Measure website use.
- Support advertising or social-media features.
Essential cookies
Essential cookies are required for the website, cart, checkout, account, security and private customer areas to function.
They may be set without optional cookie consent where they are strictly necessary.
WooCommerce cookies may include:
| Cookie | Normal purpose |
|---|---|
woocommerce_cart_hash | Detects changes to the shopping cart |
woocommerce_items_in_cart | Records whether the cart contains items |
wp_woocommerce_session_ | Connects the browser to stored cart/session information |
| WordPress login cookies | Keeps an authenticated user logged in |
| Security cookies | Helps detect malicious or unauthorised activity |
WooCommerce documents the cart cookies above as session cookies, with the WooCommerce session identifier normally lasting two days.
Payment and fraud-prevention technologies
WooPayments and Stripe may use cookies, device identifiers, IP addresses and similar technologies to:
- Process payments.
- Authenticate customers.
- Prevent fraud.
- Meet legal and regulatory obligations.
If Revolut Checkout is enabled, Revolut may use equivalent technologies for payment and fraud prevention.
Some of these technologies are essential to complete the payment selected by the customer.
Functional cookies
Functional cookies may remember choices or support optional features, such as:
- Saved account preferences.
- Live chat.
- Embedded media.
- Accessibility preferences.
Where a functional technology is not strictly necessary, it will be controlled through the cookie-consent system.
Analytics cookies
Google Analytics or another analytics provider may be enabled later to understand:
- Which pages are visited.
- How visitors reach the website.
- Whether pages produce errors.
- How the shop and checkout are used.
Analytics cookies will not be intentionally enabled before the required consent is obtained.
Advertising and social-media technologies
The site may later use:
- Pinterest tags.
- Google advertising tags.
- Instagram, Pinterest or other embedded social content.
- Newsletter conversion tracking.
- Similar marketing technologies.
These services may recognise a browser across websites or combine information with data held by the provider.
They will be treated as non-essential and require consent where the law requires it.
Newsletter and live chat
A newsletter sign-up form may store:
- Email address.
- Consent status.
- Sign-up date and source.
- Unsubscribe status.
A live-chat service may store:
- Messages.
- Name and email where supplied.
- IP address and device information.
- Chat identifiers.
The chosen provider will be identified in the Privacy Policy or cookie settings before the feature is enabled.
Managing consent
You can use the website’s cookie control to:
- Accept optional cookies.
- Reject optional cookies.
- Select individual categories.
- Change your choice later.
Rejecting optional cookies will not prevent normal shopping, checkout or account access, although some optional content or features may not work.
Browser settings can also delete or block cookies, but blocking essential cookies may prevent the cart, login or checkout from functioning.
Current and future services
At the date of this policy, WordPress, WooCommerce, WooPayments and security-related technologies are used for core website operation.
Google analytics or advertising, Pinterest tracking, newsletter tracking, live chat, social-media embeds and Revolut Checkout should be treated as enabled only when they are visible in the cookie-preference control or otherwise active on the website.
ICO guidance requires consent before using non-essential storage or tracking technologies; the rules can also apply where the information is not directly identifying.
