Privacy Policy (Step Right)
Last updated: 14/01/2026
Step Right (“we”, “us”, “our”) operates the website stepright.ie (the “Site”). We are committed to protecting your privacy and handling your personal data in a safe and transparent way in line with the General Data Protection Regulation (GDPR) and Irish data protection law.
This Privacy Policy explains what information we collect, how we use it, and what rights you have.
1. Who we are (Data Controller)
Step Right is the data controller responsible for your personal data collected through this website.
If you have any questions about this Privacy Policy or how we use your data, you can contact us at:
Email: [ENTER YOUR EMAIL]
Website: stepright.ie
2. What personal data we collect
We may collect the following categories of personal data:
A) Information you provide to us
When you place an order, create an account, sign up to emails, or contact us, you may provide:
-
Name
-
Email address
-
Phone number
-
Billing address
-
Shipping/delivery address
-
Order details (products purchased, size, preferences, etc.)
-
Any information you include in messages to us (for example via contact forms or email)
B) Payment information
Payments on our Site are processed securely through Shopify and its payment providers. We do not store full card payment details.
C) Information collected automatically (website usage)
When you browse our Site, we may automatically collect:
-
IP address
-
Browser type and device information
-
Pages visited and time spent on the Site
-
Approximate location (based on IP address)
-
Referral source (e.g. Google, social media)
-
Cookies and tracking identifiers
3. How we use your personal data
We use your personal data to:
-
Process and fulfil your orders (including delivery and order confirmations)
-
Provide customer support and respond to queries
-
Manage returns, exchanges, and warranty issues
-
Send service emails related to your purchases (order updates, delivery notifications, etc.)
-
Improve the performance and user experience of our website
-
Prevent fraud and keep our website secure
-
Send marketing communications (only where permitted by law or where you have opted in)
-
Measure and improve advertising performance (including Meta and Google advertising)
4. Our legal basis for processing (GDPR)
Under GDPR, we must have a valid legal basis to process your personal data. We rely on the following:
-
Contract: where processing is necessary to fulfil your order or provide services you request
-
Legal obligation: where we must keep records for tax/accounting purposes
-
Legitimate interests: where it is necessary for operating our business (e.g. improving our website, preventing fraud, basic analytics) and your rights do not override those interests
-
Consent: where you have given clear permission (e.g. email marketing, non-essential cookies/tracking)
You may withdraw consent at any time (see Section 9).
5. Marketing emails
If you sign up to our mailing list, we may send you emails such as:
-
Promotions and special offers
-
Product updates
-
Foot health tips and advice
-
Store news and announcements
You can unsubscribe at any time by clicking the unsubscribe link in any email, or by contacting us directly.
6. Cookies, tracking, and analytics
We use cookies and similar technologies to help our Site work properly and to understand how visitors use our Site.
These may include:
Essential cookies
These are required for the website to function (for example, cart and checkout features).
Analytics cookies (Google Analytics)
We use Google Analytics to understand website traffic and improve our services. Google may collect information such as your device type, browsing behaviour, and pages visited.
Advertising cookies (Meta Pixel / Facebook Pixel)
We use the Meta Pixel to measure the effectiveness of our advertising and to show relevant ads to people who have visited our Site.
You can manage your cookie preferences through our cookie banner (where available) and through your browser settings.
7. Who we share your personal data with
We may share your personal data with trusted third parties where necessary to operate our business, including:
-
Shopify (our website and e-commerce platform)
-
Payment processors (for secure payment handling)
-
Delivery and courier services (to ship your order)
-
Email marketing platforms (to send emails if you subscribe)
-
Analytics and advertising providers (such as Google and Meta)
We only share the information needed for these services, and we require service providers to protect your data.
8. International data transfers
Some of our service providers may process personal data outside of Ireland or the European Economic Area (EEA), including in the United States.
Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or other lawful transfer mechanisms under GDPR.
9. Your data protection rights (GDPR)
You have the following rights in relation to your personal data:
-
Right of access – request a copy of the personal data we hold about you
-
Right to rectification – request correction of inaccurate or incomplete data
-
Right to erasure – request deletion of your data (in certain cases)
-
Right to restrict processing – request limited use of your data
-
Right to object – object to processing based on legitimate interests
-
Right to data portability – request transfer of your data to another provider
-
Right to withdraw consent – where we rely on consent (e.g. marketing/cookies)
To exercise any of these rights, contact us at: [ENTER YOUR EMAIL]
You also have the right to lodge a complaint with the Irish Data Protection Commission:
Data Protection Commission (Ireland)
Website: dataprotection.ie
10. How long we keep your data
We keep personal data only as long as necessary for the purposes described in this policy, including legal and accounting requirements.
Typical retention periods include:
-
Order records: retained for up to 6–7 years for tax and accounting purposes
-
Customer support messages: typically retained for up to 12 months
-
Marketing subscriptions: retained until you unsubscribe or request deletion
-
Analytics data: retained according to our analytics settings and provider policies
11. Security of your information
We take reasonable technical and organisational steps to protect your personal data, including secure systems and restricted access.
However, no method of online transmission or storage is 100% secure, and we cannot guarantee absolute security.
12. Children’s privacy
Our Site is not intended for children under the age of 16. We do not knowingly collect personal data from children.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our business, website, or legal requirements.
The most recent version will always be posted on this page, with the updated date shown at the top.
If you want, I can also write your Cookie Policy (separate page) + a Terms & Conditions that matches your setup (including the fact you offer free shipping across Ireland but not free returns).