Last updated: 26 April 2026
RemCurl ("we", "us", "our") takes your privacy seriously. This Privacy Policy explains exactly what personal data we collect when you visit remcurl.com, place a pre-order, create an account, or interact with our services — and how we protect, use, and give you control over that data. It applies to residents of the United Kingdom, the European Economic Area, and all other jurisdictions we serve.
RemCurl is a product innovation company that designs, manufactures, and sells the RemCurl automated curl-definition device for textured hair. We are the data controller for personal data collected through this website. You can reach our privacy team at privacy@remcurl.com.
We only collect data that is necessary for the purposes described in this policy.
Account & Identity Data
Order & Payment Data
Returns & Support Data
Communications Data
Technical & Usage Data
Referral & Marketing Data
For users in the UK and EEA, we process your personal data under one or more of the following lawful bases:
Processing necessary to fulfil your order, manage your account, process a return, or perform any other contractual obligation you have entered into with us. Without this data we cannot deliver the product or service.
Processing where our legitimate business interests outweigh your privacy rights, after balancing both. You have the right to object.
Processing based on your freely given, specific, informed, and unambiguous consent. You may withdraw consent at any time.
Processing required to comply with a legal obligation, including statutory financial and tax record-keeping requirements.
We do not sell your personal data. We share data only with the following specific third parties, and only to the extent necessary:
Stripe
Privacy PolicyPurpose
Payment processing
Data Shared
Billing address, payment card details, order amount
Location
United States (EU/UK Standard Contractual Clauses in place)
PayPal
Privacy PolicyPurpose
Alternative payment processing
Data Shared
Name, email, PayPal account reference, order amount
Location
United States (EU/UK Standard Contractual Clauses in place)
Supabase
Privacy PolicyPurpose
Database, authentication, and file storage infrastructure
Data Shared
All personal data stored on our platform (encrypted at rest)
Location
European Union (AWS eu-west-1)
Mailgun
Privacy PolicyPurpose
Transactional and marketing email delivery
Data Shared
Email address, name, and email engagement events (opens, clicks, bounces)
Location
European Union (EU data region enabled)
Shipping Carriers
Purpose
Order fulfilment and delivery
Data Shared
Name, shipping address, and order reference
Location
Varies by carrier and destination country
All third-party processors are bound by data processing agreements and may only use your data for the purposes we specify.
We retain your data only for as long as necessary for the purpose it was collected or as required by law.
| Data Category | Retention Period | Reason |
|---|---|---|
| Order and payment records | 7 years from order date | HMRC / statutory tax obligations |
| Active account data | Duration of account + 30 days after deletion request | Service delivery |
| Inactive account data (no login for 3 years) | Deleted after 90-day inactivity notice | Data minimisation |
| Return claims and supporting images | 90 days after final resolution | Fraud prevention and dispute resolution |
| Customer support messages | 3 years from last interaction | Continuity of support |
| Marketing preferences and consent records | Until opt-out + 1 year | Proof of consent |
| Email engagement logs | 1 year | Delivery optimisation |
| IP addresses (return fraud logs) | 12 months | Fraud prevention |
| Audit logs (admin actions) | 2 years | Security and accountability |
Under UK GDPR and EU GDPR you have the following rights. We will respond to all requests within 30 days. To exercise any right, email us at privacy@remcurl.com with the subject line "Data Subject Request".
Right of Access (Art. 15)
Request a copy of all personal data we hold about you, including what it is, why we hold it, who we share it with, and for how long.
Right to Rectification (Art. 16)
Ask us to correct inaccurate or incomplete personal data. You can also update most data directly in your account settings.
Right to Erasure / Right to Be Forgotten (Art. 17)
Request deletion of your personal data where there is no compelling reason for its continued processing. Note: we may be unable to delete data we are legally required to retain (e.g. financial records).
Right to Restriction of Processing (Art. 18)
Ask us to restrict processing of your data while a dispute about accuracy or lawfulness is resolved.
Right to Data Portability (Art. 20)
Receive a copy of data you have provided to us in a structured, machine-readable format (e.g. JSON or CSV), and transfer it to another controller.
Right to Object (Art. 21)
Object to processing based on legitimate interests or for direct marketing. Where you object to direct marketing, we will stop immediately.
Right to Withdraw Consent (Art. 7)
Where processing is based on consent, you can withdraw it at any time via your account notification settings or by emailing us. Withdrawal does not affect the lawfulness of prior processing.
Right to Lodge a Complaint
If you are in the UK, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk or call 0303 123 1113. EEA residents may contact their local supervisory authority.
We implement appropriate technical and organisational measures to protect your data:
No internet transmission is completely secure. If you suspect a data breach, contact us immediately at privacy@remcurl.com.
Some of our third-party processors (Stripe, PayPal) are based in the United States. Transfers to these processors are made under EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA), ensuring an equivalent level of data protection to that provided under UK GDPR and EU GDPR. Our primary data storage through Supabase is located in the EU (AWS eu-west-1).
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the "Last updated" date at the top of this page. Your continued use of our services after notification constitutes acceptance of the revised policy. The current version is always available at remcurl.com/privacy.
For any privacy-related queries, data subject requests, or concerns, please contact our privacy team:
RemCurl Privacy Team
Email: privacy@remcurl.com
Alternatively, use our contact form.
We aim to respond to all privacy requests within 30 calendar days.