Legal

Privacy Policy

Last updated: 11 July 2026 · Draft for solicitor review before full public launch

This policy explains what personal information Eyewear Ltd collects when you use itseyewear.com, why we collect it, who we share it with, how long we keep it, and the rights you have under the UK GDPR and Data Protection Act 2018.

1. Who we are

Eyewear Ltd is the data controller for personal information collected through this site. Company no. 14918400 (England and Wales). Registered office and lab: 455 Wick Lane, One Dye House, Unit 3b, London, E3 2TB. ICO registration: ZB712836. Contact: start@itseyewear.com.

2. What we collect, why, and our lawful basis

Accounts and profile — name, email, password hash, and any details you add. Used to run your account. Lawful basis: contract; and our legitimate interest in operating a secure site.

Orders (marketplace and lenses) — name, delivery address, contact details, order and payment metadata (we do not store card numbers; Stripe processes payments on our behalf). Lawful basis: contract; and legal obligation for tax and accounting records.

Prescriptions and pupillary distance (SPECIAL CATEGORY / HEALTH DATA) — prescription values you type or upload as an image, and PD measurements. Processed strictly to manufacture, verify and dispense your lens order. Lawful basis: your explicit consent under Article 9(2)(a) UK GDPR, given when you submit an order with lenses; you can withdraw consent at any time by contacting us, though we may need to cancel an in-progress order.

Course bookings — booking details, dietary/access needs if you tell us. Lawful basis: contract.

Enquiries and contact messages — anything you send us. Lawful basis: our legitimate interest in responding to you, or steps before a contract.

Newsletter — email address and topic preferences. Lawful basis: your consent. Every marketing email contains a one-click unsubscribe link, and you can change your topic preferences at any time.

Chat conversations (customer-service chat and dispensing assistant) — the messages you send and the assistant's replies. Conversations are logged and reviewed by our team to answer follow-ups, improve the service and train our knowledge base. Do not share sensitive personal information you would not want us to see; do not use chat for a medical emergency. Lawful basis: legitimate interest in providing and improving a helpful assistant; consent where you supply health data.

Maker applications — the business, product and identity information you submit when applying to sell. Lawful basis: steps before a contract; and our legitimate interest in operating a curated marketplace.

Site usage — cookies, IP address, request logs. Lawful basis: legitimate interest in a working, secure site (essential cookies) and, where applicable, consent (see the Cookie Policy).

3. Prescription data — extra safeguards

Prescription and PD data is health data and we treat it with extra care.

Access is restricted to you (the customer), to admin users at Eyewear Ltd, and to our lab staff who need it to make and check your lenses. Independent makers on our marketplace never see your prescription — only the frame details they need to fulfil the order.

Prescription images may be processed by an AI extraction step (via the Lovable AI gateway) to pre-fill the numbers on the order form. The extracted values are always shown for you to confirm before the order is placed, and the lab verifies them again before glazing.

The camera-based PD tool processes images on your own device by default; nothing is uploaded unless you explicitly opt in. If you do upload, only the calculated measurement — and, if you consent, the reference image — is stored against your order.

We keep prescription records for as long as they are needed for the order, your warranty, remakes, and any legal or health-record obligation. On request, and where lawful, we will delete records that are no longer needed.

4. Who we share your data with

We share personal data only with the processors we rely on to run the business:

Stripe (Stripe Payments Europe Ltd, Ireland) — payment processing for all orders, and Stripe Connect for paying makers.

Resend (Resend Inc., USA) — transactional email (order confirmations, dispatch notifications, password resets) and, where you have consented, our newsletter.

Lovable / Supabase — hosting, database and storage for the site and its files. Data is held on their EU infrastructure.

Lovable AI gateway — the AI features described above (prescription scanner, dispensing assistant, customer chat). Prompts and replies pass through the gateway to run the models; content is not used to train third-party foundation models.

Independent makers on our marketplace — for a marketplace order, the maker receives the information they need to fulfil it (typically your name, shipping address, chosen frame and any customer notes). They never receive prescription data.

Where a processor is located outside the UK/EEA, we rely on appropriate safeguards (typically UK/EU Standard Contractual Clauses).

We do not sell your personal data and we do not share it with third-party advertising networks.

5. How long we keep your data

Order, invoice and tax records: retained for the period required by UK tax law (currently six years plus the current financial year).

Prescription records: retained while needed for the order, warranty and remakes, and thereafter as required by health-record best practice, then deleted on request where lawful.

Account data: retained while your account is active; deleted or anonymised on request, subject to the retention periods above for related orders.

Enquiries and chat logs: retained for up to 24 months for service and training purposes, then deleted or anonymised.

Newsletter subscriptions: retained until you unsubscribe.

6. Your rights

Under the UK GDPR you have the right to: access your data; ask us to correct inaccurate data; ask us to delete data (subject to legal exceptions); restrict or object to certain processing; withdraw consent (for example for the newsletter or for prescription processing on a pending order); and portability of data you have provided under contract or consent.

To exercise any of these rights, email start@itseyewear.com. We aim to respond within one month.

You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk if you are unhappy with how we have handled your data.

7. Security

We use technical and organisational measures appropriate to the risk: encrypted connections (HTTPS) across the site, encryption at rest for stored data, role-based access controls, and audit logging on sensitive actions. Access to prescription and order data is limited to admin and lab roles.

8. Changes

We will update this policy as the site grows and before full public launch. The 'Last updated' date at the top of the page shows when it last changed.