Privacy policy

Privacy Policy

Chill.com

Last updated: 25 May 2026

1. Introduction

Welcome to Chill.com ("Chill", "we", "us" or "our"). We are committed to protecting your personal data and respecting your privacy rights under UK law.

This Privacy Policy explains how we collect, use, store, share and protect your personal data when you:

  • visit and use our website at chill.com (the "Website");

  • purchase products through our dropshipping service;

  • follow affiliate links to third-party retailers;

  • read our published content (articles, guides, reviews);

  • store preferences about purchases and supplements; or

  • communicate with us by any electronic means.

Please read this policy carefully. By using our Website you acknowledge you have read and understood it.

2. Who We Are (Data Controller)

Chill.com is the data controller for personal data collected through this Website. This means we determine the purposes and means of processing your personal data.

If you have any questions about this policy or wish to exercise your rights, please contact us:

  Email: privacy@chill.com

  Postal address: Eastcastle House, 27-28 East Castle Street, London W1W 8DH

We are registered with the Information Commissioner's Office (ICO). 

3. Legal Bases for Processing (UK GDPR)

We only process your personal data where we have a valid legal basis to do so under UK GDPR Article 6. The bases we rely on are:

  • Contract performance - processing necessary to fulfil your order or provide a service you have requested.

  • Legitimate interests - processing necessary for our legitimate business interests (e.g. preventing fraud, improving our Website), where these are not overridden by your rights.

  • Legal obligation - processing required to comply with a legal duty (e.g. tax and accounting records).

  • Consent - where you have given us clear, specific, freely given and withdrawable consent (e.g. marketing emails, non-essential cookies).

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

4. Personal Data We Collect

4.1 Data You Provide to Us

  • Identity data: name, username or similar identifier.

  • Contact data: email address, postal address, telephone number.

  • Transaction data: details of products you have ordered via our dropshipping service, including delivery address and payment confirmation reference (we do not store full card details).

  • Preference data: supplement preferences, purchase history preferences, dietary information, and similar information you choose to save.

  • Correspondence data: records of emails, enquiries, survey responses or feedback you send us.

  • Account data: login credentials and account settings if you create an account.

4.2 Data Collected Automatically

  • Technical data: IP address, browser type and version, operating system, device identifiers, time zone setting.

  • Usage data: pages visited, links clicked, traffic source, referral URLs, time on page.

  • Cookie and tracking data: see Section 7 (Cookies) below.

4.3 Data Received from Third Parties

  • Analytics providers (e.g. Google Analytics) may share aggregated or pseudonymised usage data with us.

  • Affiliate networks may pass limited transaction reference data when you follow an affiliate link and make a purchase.

  • Advertising partners may provide audience segmentation data for interest-based advertising.

4.4 Special Category Data

We may collect health-related information (e.g. dietary preferences or supplement usage) only where you voluntarily provide it when saving preferences. This is special category data under UK GDPR Article 9. We process it only with your explicit consent, which you may withdraw at any time by deleting your preferences or contacting us.

5. How We Use Your Personal Data

  • Process and fulfil orders placed via our dropshipping service and communicate order updates. (Legal basis: Contract performance.)

  • Pass necessary fulfilment data (name, delivery address, product) to our dropshipping suppliers to dispatch your order. (Legal basis: Contract performance.)

  • Display affiliate links and track affiliate referrals to third-party retailers. We earn a commission on qualifying purchases; the third-party retailer processes your order and is an independent data controller. (Legal basis: Legitimate interests.)

  • Store and apply your purchase and supplement preferences to personalise your experience. (Legal basis: Consent.)

  • Publish and improve our editorial content. (Legal basis: Legitimate interests.)

  • Send transactional communications (order confirmations, account notices). (Legal basis: Contract performance / Legal obligation.)

  • Send marketing communications (newsletters, product recommendations) where you have opted in. (Legal basis: Consent.)

  • Analyse Website usage to improve performance and user experience. (Legal basis: Legitimate interests.)

  • Detect and prevent fraud and abuse. (Legal basis: Legitimate interests / Legal obligation.)

  • Comply with legal and regulatory obligations. (Legal basis: Legal obligation.)

We will not use your personal data in a way that is incompatible with the purpose for which it was collected without informing you and, where required, obtaining fresh consent.

6. Sharing Your Personal Data

We do not sell your personal data. We may share it with:

  • Dropshipping suppliers - solely to fulfil your order (name, delivery address, product details). Suppliers are contractually bound to process data only for that purpose.

  • Affiliate networks and third-party retailers - limited transaction reference data when you follow an affiliate link. Once you are on the third party's website, their own privacy policy applies.

  • Technology and hosting providers - website hosting, email delivery, analytics, and customer support tools, each under appropriate data processing agreements.

  • Payment processors - payment data is processed directly by our PCI-DSS-compliant payment provider; we receive only a payment confirmation reference.

  • Advertising partners - pseudonymised identifiers for interest-based advertising, subject to your consent preferences.

  • Professional advisers - lawyers, accountants, insurers, where necessary.

  • Regulators and law enforcement - where required by law, court order, or to protect the rights, property or safety of Chill.com, our users or others.

  • Business successors - in the event of a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction. You will be notified in advance.

7. Cookies and Tracking Technologies

We use cookies and similar technologies (web beacons, pixels) on our Website. Where UK GDPR and PECR require it, we obtain your consent before setting non-essential cookies.

Essential cookies: Necessary for the Website to function (e.g. session management, security). These do not require consent.

Analytics cookies: Help us understand how visitors use the Website (e.g. Google Analytics). Set only with your consent. You may opt out via our cookie preference centre or the Google Analytics opt-out browser add-on.

Preference cookies: Remember your supplement and purchase preferences. Set only with your consent.

Advertising cookies: Used to show you relevant advertisements and to measure campaign effectiveness. Set only with your consent.

You can manage or withdraw cookie consent at any time via the cookie banner or preference centre on our Website. You may also control cookies through your browser settings; note that disabling some cookies may affect Website functionality.

8. International Data Transfers

Some of our service providers are based outside the UK. Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, such as:

  • UK adequacy regulations (where the destination country has been deemed adequate by the UK Government);

  • UK International Data Transfer Agreements (IDTAs) or UK Addendum to EU Standard Contractual Clauses; or

  • Other lawful transfer mechanisms approved by the ICO.

You may request details of the safeguards in place by contacting us.

9. Data Retention

We retain personal data only for as long as necessary for the purposes set out in this policy, unless a longer period is required by law. Key retention periods:

  • Order and transaction records: 7 years from the date of transaction (legal/tax obligation).

  • Account and preference data: for the duration of your account plus 2 years after closure, or until you delete your preferences.

  • Marketing consent records: until you withdraw consent plus 1 year (to evidence lawful processing).

  • Website analytics data: typically 26 months in pseudonymised form.

  • Correspondence and enquiries: 3 years from last contact.

When personal data is no longer needed, we securely delete or anonymise it.

10. Your Rights Under UK GDPR

You have the following rights in relation to your personal data:

  • Right of access - to request a copy of the personal data we hold about you (Subject Access Request).

  • Right to rectification - to ask us to correct inaccurate or incomplete data.

  • Right to erasure ('right to be forgotten') - to ask us to delete your personal data in certain circumstances.

  • Right to restriction - to ask us to restrict processing while a dispute is resolved.

  • Right to data portability - to receive your data in a structured, machine-readable format and transfer it to another controller, where processing is based on consent or contract.

  • Right to object - to object to processing based on legitimate interests, and to direct marketing at any time.

  • Rights related to automated decision-making - not to be subject to solely automated decisions that significantly affect you.

  • Right to withdraw consent - at any time, without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at privacy@chill.com. We will respond within one calendar month. We may need to verify your identity before processing your request. There is no charge for most requests, though we reserve the right to charge a reasonable fee for manifestly unfounded or excessive requests.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk, or by calling 0303 123 1113.

11. Children

Our Website is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe we hold data about a child, please contact us immediately and we will delete it without undue delay.

12. Data Security

We have implemented appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include:

  • Encryption of data in transit (TLS/HTTPS).

  • Access controls and authentication requirements for staff.

  • Regular security assessments and vulnerability testing.

  • Contractual data security obligations imposed on all processors.

Where you have a password for your account, you are responsible for keeping it confidential. Please notify us immediately if you suspect any unauthorised access to your account. No internet transmission is entirely secure; we cannot guarantee the absolute security of data transmitted to our Website.

13. Third-Party Websites and Affiliate Links

Our Website contains links to third-party websites, including affiliate retailer sites. Clicking an affiliate link will take you to the retailer's website, which has its own privacy policy. We are not responsible for the privacy practices of third-party websites and recommend you review their policies before providing any personal data. Our affiliate relationships are disclosed in accordance with ASA and CMA guidelines.

14. Changes to This Privacy Policy

We may update this policy from time to time. Material changes will be notified to registered users by email and/or a prominent notice on the Website homepage. The 'Last updated' date at the top of this page shows when the policy was most recently revised. We encourage you to review this policy periodically. Continued use of the Website after changes take effect constitutes acceptance of the updated policy.

15. Contact Us

For any questions, requests or complaints relating to this Privacy Policy or our data practices:

  Email: privacy@chill.com

  Post: Data Protection, Chill.com, Eastcastle House, 27-27 Eastcastle Street, London W1W 8DH

  ICO (supervisory authority): ico.org.uk | 0303 123 1113