Privacy policy

Privacy Policy

Held Anew
Last updated: [7 May 2026]

This Privacy Policy explains how Held Anew collects, uses, and protects your personal information when you visit our website, place an order, or otherwise interact with us. We are committed to handling your data lawfully, transparently, and with care.

This policy applies to information we collect through heldanew.com and through our order intake process.

1. Who we are

Held Anew is a trading name of John Jenkins, operating as a sole trader in the United Kingdom.

The Data Controller responsible for your personal information is:

John Jenkins, trading as Held Anew
c/o Crowfoot & Co Accountants Ltd
Lonsdale House
High Street
Lutterworth
Leicestershire LE17 4AD
United Kingdom

Email: hello@heldanew.com

For all data protection enquiries, including requests to access, correct, or delete your information, please contact us at the email address above.

2. What information we collect

We collect the following categories of personal information:

Information you provide directly to us:
- Your name and email address (when you place an order or join the waitlist)
- Your delivery address (if you order printed products in future)
- Information about your dog, including name, age, breed, and a written description provided by you in our order intake form
- Photographs of your dog that you upload as reference material for your portrait
- Any messages or correspondence you send us

Information collected automatically when you visit our website:
- Technical information including your IP address, browser type, device type, and operating system
- Information about how you interact with our website, including pages visited, time spent, and referring sources
- Cookies and similar technologies (see Section 9 below)

Information from third parties:
- Payment information processed by our payment providers (we do not see or store your full card details)

3. How we use your information

We use your personal information for the following purposes:

To provide our portrait service. We use the photograph and information you supply about your dog to produce your portrait. This is the core purpose of our relationship with you and is necessary for the performance of our contract with you.

To process payments. We use your billing information to charge the £15 commission fee at the point of order and the £64 balance when you approve your final proof. Payment processing is performed by our payment providers (see Section 5).

To communicate with you about your order. We send transactional emails about your order status, your watermarked proof, revision requests, and final delivery. These are necessary for the performance of our contract.

To improve our service. We may analyse aggregated, anonymised information about how customers use our site to improve our offering. This is done on the basis of our legitimate interest in operating and improving our business.

To comply with our legal obligations, including UK consumer protection law, tax law, and accounting record-keeping requirements.

4. Legal basis for processing

Under UK GDPR, we rely on the following legal bases for processing your personal information:

- Performance of a contract — to fulfil your portrait order
- Legitimate interests — to operate, secure, and improve our business, where this does not override your rights
- Consent — for non-essential cookies and any optional marketing communications (you can withdraw consent at any time)
- Legal obligation — to comply with applicable UK law

5. Who we share your information with

We share your personal information only with the following categories of recipients, and only to the extent necessary:

Our website and store platform: Shopify Inc. (Canada) hosts our website, processes your orders, and provides customer account services. Shopify processes personal data on our behalf as a data processor under a data processing agreement.

Payment processors: Shopify Payments and PayPal handle the processing of your payments. Your full card or bank details are never visible to us — payment information passes directly between you and the payment processor.

Image generation service provider: fal – Features & Labels, Inc. (a US-based company, registered at 2261 Market St. Suite 10467, San Francisco, CA 94114) provides the technical infrastructure we use to produce your portrait from your reference photograph. The reference photograph and the generated portrait pass briefly through fal.ai's systems during processing.

We have implemented technical measures to minimise this exposure: we instruct fal.ai's systems to delete uploaded reference photographs and generated portraits within the shortest possible timeframe permitted by their platform (typically minutes after processing completes), and we use fal.ai's available controls to prevent persistent storage of generated images.

International transfers to fal.ai (United States) are made under contractual safeguards as referenced in fal.ai's privacy policy. We acknowledge that, under their standard terms, fal.ai reserves certain rights with respect to data derived from inputs to their platform; however, by using their short-retention controls and avoiding persistent storage where possible, we limit the practical scope of any such use. For more information about fal.ai's data practices, please see their privacy policy at https://fal.ai/privacy.

Analytics and website performance providers:
- Google Analytics (Google LLC, United States) — measures website traffic and usage patterns
- Microsoft Clarity (Microsoft Corporation, United States) — provides anonymised heatmap and session recording data to help us improve the site
- Meta Pixel (Meta Platforms Inc., United States) — measures advertising performance if we run paid social campaigns
- Shopify built-in analytics (Shopify Inc., Canada) — provides standard e-commerce reporting

These providers may process information about your visit, including your IP address (which they typically anonymise) and your browsing behaviour. International transfers to these providers (United States) are made under contractual safeguards including Standard Contractual Clauses where applicable.

Professional advisors: We may share your information with our accountants, solicitors, or other professional advisors where reasonably necessary.

Legal authorities: We may disclose your information where required by law, by a court order, or to protect our legal rights.

We do not sell, rent, or trade your personal information.

6. International transfers

Some of the third parties listed above are based outside the United Kingdom — primarily in the United States and Canada. When we transfer your information to these providers, we rely on appropriate safeguards under UK GDPR, including:

- The UK government's adequacy decisions for certain countries (including the EU and EEA)
- Standard Contractual Clauses with the UK International Data Transfer Addendum, where adequacy decisions do not apply
- The contractual privacy safeguards published by each respective service provider

If you would like to know more about the specific safeguards in place for any particular transfer, please contact us at privacy@heldanew.com.

7. How long we keep your information

We retain different categories of information for different periods:

- Reference photographs of your dog: deleted from our systems within 90 days of portrait delivery. The processing copies on fal.ai's infrastructure are deleted within minutes of processing, as described in Section 5.
- Generated portraits and final delivered files: retained for 90 days after delivery to enable any reasonable customer support or revision request, then deleted from our active systems.
- Email address and order history: retained indefinitely while your account or relationship with Held Anew is active. You may request deletion at any time (subject to our legal obligation to retain certain transaction records — see below).
- Order, payment, and tax records: retained for six years from the end of the relevant tax year, as required by HMRC and UK accounting law.
- Website analytics data: retained according to each analytics provider's default retention period (typically 14 to 26 months).

8. Your rights

Under UK GDPR, you have the following rights in relation to your personal information:

- Right of access — to obtain a copy of the personal information we hold about you
- Right to rectification — to have inaccurate information corrected
- Right to erasure — to have your personal information deleted (subject to our legal obligations)
- Right to restriction of processing — to limit how we use your information in certain circumstances
- Right to data portability — to receive your information in a structured, commonly-used format
- Right to object — to object to processing based on legitimate interests
- Right to withdraw consent — where we rely on consent (e.g., non-essential cookies)
- Right to lodge a complaint — with the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your information properly

To exercise any of these rights, please email hello@heldanew.com. We will respond within one month of receiving your request.

9. Cookies and similar technologies

Our website uses cookies and similar technologies to function correctly, to remember your preferences, and to analyse how the site is used. Some cookies are essential for the site to work; others are optional and are only used with your consent.

You can manage your cookie preferences through the consent banner displayed when you first visit our site, or by adjusting your browser settings.

For full details of the cookies we use, please see our Cookie Policy.

10. Security

We take reasonable technical and organisational measures to protect your personal information from unauthorised access, alteration, disclosure, or destruction. These include encryption in transit (HTTPS), restricted access to systems containing customer data, and reliance on reputable third-party providers who maintain their own industry-standard security measures.

No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

11. Children

Our service is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at hello@heldanew.com so we can delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our service providers, or applicable law. The "Last updated" date at the top of this policy will indicate when the most recent change was made. For material changes, we will take reasonable steps to notify you, including by email or by a prominent notice on our website.

13. Contact us

For any questions about this Privacy Policy, or to exercise any of your rights, please contact:

hello@heldanew.com

Or by post:

John Jenkins, trading as Held Anew
c/o Crowfoot & Co Accountants Ltd
Lonsdale House
High Street
Lutterworth
Leicestershire LE17 4AD
United Kingdom