1. Introduction
The Cot Mattress Company is committed to protecting your privacy and personal data. This policy explains how we collect, use, store, and protect your information when you use our website or purchase our products.
2. Information We Collect
2.1 Information You Provide
When you place an order, create an account, or contact us, we may collect:
- Name and contact details (email address, phone number, postal address)
- Payment information (processed securely by Stripe; we do not store card details)
- Order history and preferences
- Communications with our team
- Baby's due date or birth date (optional, for product recommendations)
2.2 Information Collected Automatically
When you visit our website, we may automatically collect:
- IP address and browser type
- Pages visited and time spent on our site
- Referring website
- Device information
3. How We Use Your Information
We use your personal data to:
- Process and fulfil your orders
- Communicate with you about your order and delivery
- Provide customer support
- Send order confirmations and updates
- Improve our website and services
- Comply with legal obligations
3.1 Marketing Communications
With your consent, we may send you:
- Newsletter updates about new products and offers
- Helpful tips for baby sleep and mattress care
- Reminders when your baby might be ready for their next mattress
You can unsubscribe from marketing communications at any time by clicking the unsubscribe link in any email or contacting us directly.
4. Legal Basis for Processing
We process your personal data based on:
- Contract: To fulfil orders and provide our services
- Legitimate interests: To improve our website and prevent fraud
- Consent: For marketing communications
- Legal obligation: To comply with tax and business regulations
5. Data Sharing
We may share your data with:
- Courier services: To deliver your order (name, address, phone number, email for delivery notifications)
- Payment processors: Stripe processes payments securely on our behalf
- Email service providers: To send transactional and marketing emails
We never sell your personal data to third parties.
6. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Secure SSL encryption on our website
- Secure payment processing through Stripe
- Access controls for our systems
- Regular security reviews
7. Data Retention
We retain your data for as long as necessary to:
- Provide our services and fulfil orders
- Comply with legal and tax requirements (typically 6 years)
- Resolve disputes and enforce agreements
8. Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data (subject to legal requirements)
- Portability: Receive your data in a portable format
- Object: Object to processing for marketing purposes
- Withdraw consent: Withdraw consent at any time
To exercise any of these rights, please contact us using the details below.
9. Cookies
Our website uses cookies to improve your experience. These include:
- Essential cookies: Required for the website to function (e.g., shopping cart)
- Analytics cookies: Help us understand how visitors use our site
You can control cookies through your browser settings.
10. Children's Privacy
Our website is not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have collected such data, please contact us immediately.
11. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via email or a notice on our website.
12. Contact Us
If you have questions about this policy or wish to exercise your rights, please contact us:
- Email: info@cotmattresscompany.com
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Last updated: January 2026