← Back to site

Privacy Policy

Last updated 16 June 2026

This Privacy Policy explains how RIPE ("we", "us", "our") collects, uses, and protects your personal information when you visit our website or use our ecommerce audit services. RIPE is operated by a sole trader based in the United Kingdom.

If you have any questions about this policy or how we handle your data, contact us at info@ripeaudits.com.

Who we are

RIPE provides ecommerce store audits for direct-to-consumer brands. For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), RIPE is the "data controller" for the personal data described in this policy, except where we act as a "data processor" on behalf of our clients (see "Data we access on your store" below).

Information we collect

Information you give us directly

When you submit an inquiry through our website, we collect:

Information collected automatically

When you visit our website, we use Netlify's built-in analytics to understand how the site is used. This is measured from server data and is privacy-friendly: it is cookieless, does not track you across websites, and does not identify you as an individual. It provides us with aggregated information such as:

We do not use cookie-based analytics tools, and we do not build individual profiles of visitors. See our Cookie Policy for details.

How we use your information

We use your personal data to:

Legal basis for processing

Under UK GDPR, we rely on the following legal bases:

Data we access on your store

To carry out an audit, you may grant us read-only access to your Shopify store and connected tools (such as analytics platforms). These may contain personal data belonging to your customers.

When we access this data, we act as a data processor on your behalf — you remain the data controller for your customers' information. We only access this data to perform the audit, we do not use it for any other purpose, and we delete or lose access to it once the engagement is complete. We do not export, retain, or share your customers' personal data.

Sharing your information

We do not sell your personal data. We share it only with:

Some of these providers may be located outside the UK. Where data is transferred internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or equivalent mechanisms.

How long we keep your data

We keep inquiry and client data only as long as necessary to provide our services and meet legal obligations (for example, tax records are kept for the period required by HMRC). Analytics data is retained according to the settings of our analytics tools. After these periods, data is deleted or anonymised.

Your rights

Under UK GDPR you have the right to:

To exercise any of these rights, email info@ripeaudits.com. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

Security

We take reasonable technical and organisational measures to protect your personal data against loss, misuse, and unauthorised access. No method of transmission over the internet is completely secure, so we cannot guarantee absolute security.

Changes to this policy

We may update this policy from time to time. The "last updated" date at the top shows when it was last revised.

Contact

For any privacy-related questions or requests, contact us at info@ripeaudits.com.