Leafletfrog Privacy & Cookie Policy
Last updated: 13 August 2026
This notice explains how Leafletfrog Limited collects, uses, shares and protects personal data when you visit www.leafletfrog.co.uk, create an account, ask for a quote or sample, place an order, supply artwork or mailing data, contact us, or receive marketing from us. It also explains how cookies and similar technologies are used.
Leafletfrog Limited is the data controller for the activities described in this notice, except where we process personal data contained in customer-supplied artwork, mailing lists or other files solely on a customer's documented instructions. In that situation, the customer is normally the controller and Leafletfrog is its processor.
1. Who we are and how to contact us
Leafletfrog Limited (company number 07938754), Units 38–39 Britannia Way, Bolton, BL2 2HH, United Kingdom.
Privacy contact: roddy@leafletfrog.co.uk | Telephone: 01204 328273
We have not appointed a statutory Data Protection Officer. Privacy enquiries and rights requests should be sent to the contact above. ICO Number ZA353098.
2. Personal data we collect
- Identity and contact details: name, organisation, billing and delivery addresses, email address, telephone number and account details.
- Transaction and order details: products, quantities, prices, invoices, delivery instructions, order history, refunds, correspondence and customer-service records.
- Payment-related details: payment status, method and transaction references. Card or PayPal credentials are collected and processed by Paypal, Apple Pay or Google Pay; we do not receive or store full card details.
- Artwork and production data: files, images, text, proofs, job instructions and metadata supplied for printing. These files may contain personal data about you or other people.
- Mailing and fulfilment data: recipient names, postal addresses and other delivery information supplied for direct-mail, personalised print or fulfilment services.
- Technical and usage data: IP address, browser and device information, identifiers, approximate location, referral source, pages and products viewed, interactions, security logs and cookie choices.
- Marketing data: subscription status, preferences, campaign delivery, and—where enabled—opens, clicks and other engagement information.
- Enquiry and feedback data: information in emails, forms, calls, reviews, quote requests, complaints and survey responses.
Please do not send special-category data or criminal-offence data unless it is genuinely required for an agreed print service and suitable safeguards have first been agreed with us.
3. How we obtain personal data
We obtain information directly from you; automatically from your device when you use the website; from a business or person ordering on your behalf; from payment providers, delivery partners and fraud-prevention providers; and from customer-supplied files where we provide print, mailing or fulfilment services. If you provide another person's details, you must have authority to do so and give them any required privacy information.
4. Why we use personal data and our lawful bases
|
Purpose |
Data used |
Lawful basis |
|
Quotes, accounts, orders, proofs, production, payment, delivery, refunds and customer service |
Identity/contact, order, transaction, artwork and delivery data |
Contract; steps at your request before a contract |
|
Accounting, tax, product safety, legal claims and regulatory compliance |
Order, invoice, payment-reference and correspondence data |
Legal obligation; legitimate interests in establishing or defending claims |
|
Website operation, account security, fraud prevention and service resilience |
Technical, account, transaction and security data |
Contract where necessary for requested services; legitimate interests in protecting customers and our business; legal obligation where applicable |
|
Improving the website, products and customer experience |
Usage, device, enquiry and aggregated transaction data |
Consent for non-essential analytics cookies; otherwise legitimate interests where no consent is legally required |
|
Sending requested service messages and transactional emails |
Contact and order data |
Contract; legitimate interests in effective service administration |
|
Email marketing and measuring campaign effectiveness |
Contact, preference and engagement data |
Consent where PECR requires it; otherwise legitimate interests for permitted business marketing or the PECR soft opt-in, with an opt-out in every message |
|
Personalised advertising, visitor identification and conversion measurement |
Online identifiers, device and usage data |
Consent |
|
Handling privacy requests, complaints and disputes |
Identity, correspondence and verification data |
Legal obligation; legitimate interests in protecting legal rights |
Where we rely on legitimate interests, those interests are operating and protecting our printing business, providing good customer service, improving our services, communicating with business contacts, preventing fraud and defending legal rights. We balance those interests against your rights and expectations.
5. When information is required
Some information is needed to provide a quote, enter into or perform a contract, take payment, produce print or arrange delivery. Required fields are identified when collected. If you do not provide necessary information, we may be unable to open an account, process an order, manufacture the goods, deliver them or respond fully to your request.
6. Customer-supplied artwork and mailing data
When a customer supplies files containing personal data for printing, personalisation, direct mail or fulfilment, Leafletfrog normally processes that data only to provide the ordered service and in accordance with the customer's instructions. The customer is responsible for having a lawful basis, providing privacy information to affected people, ensuring the data is accurate and minimised, and giving us lawful instructions. We apply appropriate security and require relevant suppliers to protect the data. Unless a different period is agreed, production and mailing files are deleted or securely rendered inaccessible after the job and a short operational recovery period; the customer should confirm the required deletion timetable before supplying sensitive or high-risk files.
7. Who we share personal data with
We share only what is reasonably necessary with:
- BigCommerce, which hosts and supports our online shop (BigCommerce/Commerce privacy information: https://www.bigcommerce.com/privacy/).
- Brevo, which provides email marketing and transactional-email services (https://www.brevo.com/legal/privacypolicy/). Email messages may contain technologies that record delivery, opens and link clicks where enabled.
- DPD for parcel delivery and tracking (https://www.dpd.co.uk/privacy_policy.jsp).
- FedEx for parcel delivery and tracking (https://www.fedex.com/en-gb/privacy-policy.html).
- Payment processors and banks, including PayPal/Braintree where selected (https://www.paypal.com/uk/legalhub/privacy-full and https://www.braintreepayments.com/gb/legal/braintree-privacy-policy).
- Google for consented website analytics (https://policies.google.com/privacy).
- Cloudflare for security, traffic management and website resilience (https://www.cloudflare.com/privacypolicy/).
- Poptin for consented website pop-ups, conversion measurement or marketing functionality where enabled (https://www.poptin.com/privacy-policy/).
- Trustpilot and other customer-review or website-function providers when you interact with their features.
- Professional advisers, insurers, IT/support providers, printers or fulfilment subcontractors, auditors, regulators, law-enforcement bodies, courts, and a buyer or successor in a business sale or reorganisation.
Delivery partners receive recipient contact and address details so that they can deliver and provide tracking notifications. They may act as independent controllers for parts of their delivery service; their notices explain their own use of the data.
8. International transfers
Some suppliers, including BigCommerce, Google and other technology providers, may process data outside the United Kingdom. Where personal data is transferred to a country that is not covered by UK adequacy regulations, we use an appropriate safeguard, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary measures where required. You may contact us for further information or a copy of the relevant safeguard, subject to necessary redactions.
9. How long we keep personal data
|
Record |
Typical retention |
|
Orders, invoices and core transaction records |
Normally 7 years after the end of the relevant financial year or longer. |
|
Customer account data |
While the account is active, unless earlier deletion is requested. |
|
Quotes and general enquiries that do not become orders |
Normally up to 12 months. |
|
Artwork, proofs and production files |
For production and a limited reprint/recovery period under our operational schedule, we aim to keep artwork for customers for as long as practical; shorter periods may be agreed. Files containing third-party personal data should be deleted as soon as no longer needed. |
|
Mailing and fulfilment recipient files |
For the service and a short reconciliation/recovery period, then securely deleted or rendered inaccessible, unless a different written period is agreed. |
|
Marketing contact records |
Until you unsubscribe, withdraw consent or we decide the data is no longer useful; a minimal suppression record may be kept indefinitely to honour your opt-out. |
|
Customer-service and complaint records |
Normally up to 6 years after closure where needed for claims; routine correspondence may be deleted sooner. |
|
Security and website logs |
Default BigCommerce period which is 365 days. |
|
Cookies |
For the period shown in section 15, or until you delete them or withdraw consent. |
We may retain information for longer where the law, a regulator, litigation hold, fraud investigation or legal claim requires it. We may anonymise data so that it no longer identifies anyone and use that information indefinitely.
10. Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures include access controls, encryption in transit, supplier controls, backups and staff procedures appropriate to the risk. No internet transmission or storage system can be guaranteed completely secure. If a personal-data breach creates a legal duty to notify you or the Information Commissioner's Office, we will do so.
11. Your rights
Depending on the circumstances, you may have rights to access your personal data; correct inaccurate data; request erasure; restrict processing; receive certain data in a portable format; object to processing based on legitimate interests; and withdraw consent at any time. Withdrawing consent does not affect processing that was lawful before withdrawal. Rights can be limited by law, including where records must be retained for tax, contractual or legal-claims purposes.
Your right to object to direct marketing: you can object at any time. We will stop using your personal data for direct marketing. Use the unsubscribe link in an email or contact roddy@leafletfrog.co.uk.
To exercise a right, contact us using section 1. We may ask for proportionate proof of identity. We normally respond within one month, although the law permits an extension for complex or numerous requests. There is usually no fee.
12. Complaints
Please contact us first so we can try to resolve your concern. You also have the right to complain to the Information Commissioner's Office: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; telephone 0303 123 1113; https://ico.org.uk/make-a-complaint/. You may complain without first contacting us.
13. Automated decisions and children
We do not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects. Our website and services are not directed at children, and we do not knowingly collect personal data from children through the website without appropriate authority
14. Cookies and similar technologies
Cookies are small text files stored on your device. We also use comparable technologies such as tags, pixels, local storage and scripts. Strictly necessary cookies support security, checkout, shopping baskets, sessions and consent choices. Non-essential analytics, functional and advertising technologies are used only after the consent required by the Privacy and Electronic Communications Regulations (PECR) has been obtained.
You can accept, reject or select categories in the website's cookie settings and can change your choice later using the ‘Settings’ or ‘Manage Website Data Collection Preferences’ control. Rejecting non-essential cookies must be as easy as accepting them. Browser controls can also block or delete cookies, but blocking necessary cookies may prevent checkout, account or basket functions from working.
15. Cookie categories and cookies detected on the site
This table records technologies identified from a technical review of the public website on 13 August 2026. Cookie names and lifetimes can change when suppliers update their services, and some cookies appear only after a particular action or consent choice. The live consent tool should be treated as the current preference control.
Strictly Necessary Cookies
These are required for security, network delivery, account/session handling, basket or checkout functions and remembering cookie choices. Consent is not required where a PECR exemption applies, but we still explain them.
|
Cookie / technology |
Provider |
Purpose |
Typical duration |
|
SF-CSRF-TOKEN |
Leafletfrog / BigCommerce |
Protects forms and requests against cross-site request forgery. |
Session |
|
SHOP_SESSION_TOKEN |
Leafletfrog / BigCommerce |
Maintains the storefront shopping session and checkout-related state. |
Session |
|
Shopper-Pref |
Leafletfrog / BigCommerce |
Stores storefront preferences, including consent-related preferences. |
Session or as configured |
|
fornax_anonymousId |
Leafletfrog / BigCommerce |
Provides a pseudonymous storefront identifier used for platform operation and continuity. |
Up to 2 years |
|
athena_short_visit_id |
Leafletfrog / BigCommerce |
Short-lived visit identifier used by the commerce platform for operational/session purposes. |
About 30 minutes |
|
__cf_bm |
Cloudflare |
Distinguishes legitimate traffic from automated or abusive traffic. |
About 30 minutes |
|
Cookie-consent preference cookies (name may vary) |
BigCommerce |
Records the categories you accepted or rejected so the site can apply your choice. |
Up to 1 year or as configured |
Analytics & Performance Cookies
These help us understand visits, traffic sources, pages viewed, interactions, conversions and site performance. They require consent.
|
Cookie / technology |
Provider |
Purpose |
Typical duration |
|
_ga |
Google Analytics |
Distinguishes visitors for aggregated website measurement. |
Up to 2 years |
|
_ga_<container-id> |
Google Analytics |
Maintains session state and measurement for the GA4 property. |
Up to 2 years |
|
_gid / other Google Analytics cookies, if set |
Google Analytics |
Short-term visitor and session measurement; exact cookies depend on configuration. |
Usually 24 hours or as configured |
|
BigCommerce analytics identifiers, where enabled |
BigCommerce |
Storefront usage, performance and commerce-event analytics. |
Session to 2 years, depending on identifier |
Functional Cookies
These support optional features and enhanced presentation. They require consent unless a feature is strictly necessary for a service you specifically request.
|
Cookie / technology |
Provider |
Purpose |
Typical duration |
|
Trustpilot widget storage/cookies (names may vary) |
Trustpilot |
Displays reviews and supports interaction with embedded review widgets. |
As set by Trustpilot |
|
POWR widget storage/cookies, if activated |
POWR |
Supports embedded website widget functionality. |
As set by POWR |
|
Preference or recently-viewed storage, if enabled |
BigCommerce |
Remembers optional display choices or products previously viewed. |
Session to persistent, as configured |
Targeting & Advertising Cookies
These support pop-ups, campaign attribution, visitor recognition, conversion measurement and personalised marketing. They require consent.
|
Cookie / technology |
Provider |
Purpose |
Typical duration |
|
Poptin pixel and related identifiers (names may vary) |
Poptin |
Controls marketing pop-ups, frequency, visitor recognition and conversion measurement. |
As set by Poptin/configuration |
|
Google advertising identifiers, if advertising features are enabled |
|
Measures advertising and may support audience or personalised-ad features. |
As set by Google/configuration |
|
visitor_id, only if the Brevo Tracker is enabled |
Brevo |
Recognises a browser and can associate website activity with a contact after identification. |
As configured by Brevo |
The public page review detected Brevo as an email provider requirement supplied by Leafletfrog, but did not confirm that the Brevo website Tracker currently loads on the reviewed page. The conditional Brevo entry should remain only if the Tracker is enabled. Email open pixels and tracked links are not browser cookies, but may still process engagement data as described in sections 2, 4 and 7.
16. Third-party links
Our website may link to third-party websites. Their operators control their own processing, and their privacy notices apply when you visit them. A link does not make Leafletfrog responsible for the third party's privacy practices.
17. Changes to this notice
We may update this notice when our services, suppliers or legal obligations change. We will publish the updated version on this page and change the ‘last updated’ date. Where a change materially affects how we use personal data, we will take reasonable steps to bring it to your attention and obtain fresh consent where required.