Privacy Policy
This Privacy Policy explains how Otto & Bear’s Letters Ltd (“we”, “us”, “our”) collects, uses, and protects your personal information when you visit www.ottoandbearsletters.com (“the Website”) or purchase our digital or paper story-letter subscriptions.
We are committed to respecting your privacy and keeping your information safe.
This policy should be read alongside our Terms & Conditions.
1. Who We Are
Otto & Bear’s Letters Ltd
Shropshire, United Kingdom
Email: hello@ottoandbearsletters.com
We are the “data controller” for the purposes of the UK GDPR.
2. Information We Collect
We collect the following types of personal information:
Information you provide
Name
Email address
Postal address (for paper letters)
Payment information (processed securely by Stripe / Shopify Payments)
Any messages you send to us
Information collected automatically
IP address
Device information
Browser type
Usage data (pages visited, time spent, interactions)
Cookies (see section 10)
3. How We Use Your Information
We use your information to:
Deliver digital story letters by email
Print and mail paper story letters to your postal address
Create and maintain your subscription account
Process and manage payments
Provide customer service
Send important service updates (e.g., mailing dates)
Send marketing emails (only if you opt in)
Improve our website and services
We only process your data when lawful to do so, including:
Contractual necessity (to deliver your subscription)
Legitimate interests (improving services, preventing fraud)
Consent (marketing communications)
Legal obligations
4. Sharing Your Information
We never sell your information.
We share data only with trusted third parties who help us operate our service:
Stripe / Shopify Payments (payment processing)
Shopify (website + account hosting)
Email delivery providers (Klaviyo or equivalent)
Printing and mailing partners (for paper letters)
Customer support tools
Each partner processes data only as required to deliver the service.
If you purchase paper letters, your name and address may be securely shared with our print and mail partner for fulfilment.
5. International Data Transfers
Some service providers (e.g., Shopify, Klaviyo, Stripe) may process data outside the UK/EU.
Where this occurs, they use approved legal safeguards such as:
Standard Contractual Clauses (SCCs)
Adequacy decisions
Equivalent protections required by UK law
6. How Long We Keep Your Information
We keep:
Account information: while your subscription is active + up to 6 years (for tax/legal reasons)
Email and postal data for fulfilment: until your subscription ends
Marketing email information: until you unsubscribe
Cookies: see section 10
You may request deletion at any time (see Your Rights).
7. Your Rights
Under UK GDPR, you have the right to:
Access your information
Correct inaccurate information
Request deletion
Restrict processing
Object to processing
Withdraw consent (for marketing)
Request data portability
To exercise your rights, email hello@ottoandbearsletters.com.
If you are unhappy with our response, you may contact the ICO (UK data protection authority).
8. Children's Privacy
While our letters are for children, all accounts must be created by a parent or legal guardian.
We do not knowingly collect personal data directly from children.
All contact information must belong to an adult.
9. Security
We protect your data using:
Secure encrypted connections (HTTPS)
Shopify’s secure infrastructure
Restricted internal access
Secure payment processing (we never store card details)
No internet system is 100% secure, but we follow industry-standard protections.
10. Cookies
Our website uses cookies to improve functionality, analyse use, and personalise your experience.
Types include:
Necessary cookies – essential for checkout and account login
Performance cookies – analytics to understand site use
Functional cookies – remember preferences
Marketing cookies – show relevant ads (only with consent)
You can manage or disable cookies through your browser settings at any time.
11. Links to Other Websites
Our site may contain links to external websites.
We are not responsible for their privacy practices.
12. Changes to This Policy
We may update this Privacy Policy from time to time.
Any changes will be posted on this page with an updated “last modified” date.
13. Contact Us
For any questions about this policy or your data, contact: