Repark. Legal / Privacy

UK GDPR · Data Protection Act 2018

Privacy Policy

How Repark collects, uses and protects personal data when fulfilling marketplace orders and operating the Repark RMS platform.

Version 1.1 Last updated 2 August 2026 Trading as Repark / G4GADGET

Controller record UK GDPR
Legal entityRepark LTD (“Repark”, “we”, “us”)
Registered addressUnit 2 Brook Street, Thurmaston, Leicester, LE4 8DA, United Kingdom
Incorporated9 January 2014 (England & Wales)
Company number08839062
VAT numberGB 183 8958 47
ICO registration00012897145
Data protection contactMuhammad Hamza · hamza@repark.co.uk · 0116 260 7078

01Who we are

Repark is an online retailer and wholesale distributor that sells and fulfils orders across multiple e‑commerce marketplaces. We operate an internal order and inventory management system (“Repark RMS”) to receive, organise, fulfil and account for those orders.

For the purposes of UK data protection law — the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 — the data controller is the legal entity set out in the controller record above.

02Scope of this policy

This policy explains how we handle personal data within the Repark RMS platform. It applies to:

Where you buy through a marketplace such as Temu, B&Q, Amazon, eBay, Shopify or TikTok Shop, that marketplace is also a controller of your data and operates its own privacy policy. We process your order data to fulfil the purchase you made on that marketplace.

03The personal data we process

3.1 Customer / order data

We do not receive or store full payment card numbers — payment is taken by the marketplace.

3.2 System user (staff) data

3.3 Supplier / business contact data

04Where we get your data from

05Why we process your data and our lawful bases

PurposeData usedLawful basis (UK GDPR)
Receiving, picking, packing and shipping ordersCustomer / order dataPerformance of a contract; and our legitimate interests in fulfilling marketplace orders
Customer service, returns and queriesCustomer / order dataLegitimate interests; performance of a contract
Inventory, supplier and logistics managementSupplier / order dataLegitimate interests
Operating, securing and auditing the RMS (logins, 2FA, access logs)System user dataLegitimate interests in securing our systems; legal obligation (security of processing)
Keeping accounting and transaction recordsOrder / financial dataLegal obligation (UK tax and company law)
Responding to legal requests and protecting our rightsAny relevant dataLegal obligation; legitimate interests

Where we rely on legitimate interests, we have balanced those interests against your rights and only process the minimum data needed to fulfil the order or operate the service.

06Marketplace integrations

Repark RMS connects to marketplaces using authorised, token‑based connections (OAuth where the marketplace requires it). For each connected shop we store only the access credentials needed to retrieve orders, and the order data itself. We use this data solely to fulfil and account for the orders placed on that marketplace, in line with the marketplace’s developer and data‑processing terms. We do not use customer data for independent marketing.

07Who we share your data with

We share personal data only where necessary, with:

We do not sell your personal data. All processors act under written terms requiring them to protect your data and use it only on our instructions.

08International data transfers

Our platform and database are hosted by Amazon Web Services in its Asia Pacific (Singapore) region. Because we are a UK-based business, hosting your data in Singapore is a transfer of personal data outside the UK. This transfer is protected by an appropriate safeguard — the International Data Transfer Agreement (IDTA) / UK Addendum to the EU Standard Contractual Clauses that forms part of our agreement with AWS. Some marketplaces and delivery partners may also process data outside the UK under equivalent safeguards. We also hold encrypted backup copies in AWS Europe (London, eu-west-2), within the United Kingdom, so a copy of the data exists outside the live hosting region. We keep a record of these transfers and their safeguards.

09How long we keep your data

DataRetention period
Buyer personal data — recipient name, delivery and billing address, phone number and marketplace email address. This includes any file rendered from that data, such as shipping labels, invoices and packing documents.Deleted or irreversibly anonymised within 30 days of confirmed delivery. Where a carrier delivery confirmation is not available, the 30 days run from dispatch — which is earlier than delivery, and therefore stricter.
Transaction / accounting records — order identifier, dates, items, quantities, amounts and VAT. These contain no buyer name, address, phone number or email address.Up to 6 years, to meet UK accounting and tax obligations (Companies Act 2006 / HMRC).
System user accountsWhile the account is active; deactivated and deleted when staff leave or access is no longer required.
Security audit and sync logsRetained for 400 days, then deleted or anonymised.

No buyer personal data is retained beyond 30 days. The only order records we keep longer are the transaction and accounting records above, which carry no buyer name, address, phone number or email address. When data is no longer needed for these purposes, we delete it or irreversibly anonymise it.

10How we protect your data

We apply technical and organisational measures appropriate to the risk, including:

11Your rights

Under UK data protection law you have the right to:

Because orders originate on a marketplace, you may also exercise rights directly with that marketplace. To make a request to us, contact us using the details in section 15. We will respond within one month. We may need to verify your identity, and certain data (such as accounting records) may need to be retained where the law requires it.

12Cookies and local storage

The Repark RMS application is an internal operational tool. It uses a secure, httpOnly session cookie to keep authorised users signed in, together with a matching security token that protects against forged requests. It does not use third‑party advertising or tracking cookies.

13Children’s data

Our services are intended for business operations and are not directed at children. We do not knowingly collect personal data relating to children.

14Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top shows when it last changed. Material changes will be made available through our usual channels.

15How to contact us & complain

For any privacy question or to exercise your rights, contact:

If you are not satisfied with our response, you can complain to the UK Information Commissioner’s Office (ICO) — ico.org.uk/make-a-complaint · Helpline 0303 123 1113.