LAST UPDATED
3 August 2026
About this Privacy Policy
This Privacy Policy explains how Phone World Ltd collects and uses personal information when you visit PhoneWorld.co, create an account, buy products, arrange or receive a repair, contact us, subscribe to marketing, visit a store or otherwise deal with Phone World.
Phone World Ltd is the data controller for the personal information described in this Policy unless a different controller is identified at the point of collection. We are responsible for deciding why and how that information is used.
Who we are and how to contact us
Company: Phone World Ltd
Company number: 11823435
Registered office: Phone World, 1B West Street, Dunstable, England, LU6 1SL
Telephone: 01582 671721
Website: https://phoneworld.co
For a privacy question or to exercise a data-protection right, use the Contact Us page, call the number above or write to the registered office. Please mark written correspondence 'Privacy Request'. We may need information to confirm your identity before acting on a request.
The information we collect
Depending on how you use Phone World, we may collect:
1. Identity and contact information, such as your name, title, billing or delivery address, email address and telephone number.
2. Account information, such as your sign-in details, password hash, saved addresses, preferences, basket and wish-list activity.
3. Order and transaction information, such as products, prices, discounts, delivery details, payment status, refunds, receipts and purchase history.
4. Repair information, such as the device type, make, model, IMEI or serial number, reported fault, physical condition, photographs, diagnostic results, technician notes, parts used, repair status and collection details.
5. Device-access information supplied for an agreed repair or test, such as a screen-lock code. We do not need your online-banking password, card PIN or one-time passcode.
6. Communications, including enquiries, customer-service messages, call notes, complaints, reviews, survey responses and records of consent or preferences.
7. Marketing information, including newsletter sign-up, campaign engagement, opt-in source, opt-out and suppression records.
8. Technical and usage information, such as IP address, browser and device type, operating system, pages viewed, referring page, approximate location derived from IP, security events, cookie identifiers and consent choices.
9. Fraud-prevention and verification information supplied by you or returned by payment, address-verification or security providers.
10. CCTV images where a Phone World store uses CCTV and displays a local notice.
Payment information
Full payment-card details entered during checkout are handled through the secure payment process by the relevant payment provider and banking network. Phone World may receive a transaction reference, payment status, fraud or authentication result and limited or masked payment details needed to administer the order, refund or dispute.
Never send full card numbers, security codes, online-banking passwords or one-time passcodes by email, text, WhatsApp, social media or an ordinary website message.
Information on devices presented for repair
A phone, tablet, laptop, console or other device may contain personal information about you and other people. Phone World does not need to browse personal content for an ordinary repair. Where access is reasonably necessary for an agreed diagnostic or functional test, it is limited to what is needed for that purpose and to staff or service providers involved in the job.
Before handing over a device, back up important information, remove SIM and memory cards where practical, sign out of sensitive applications and remove or restrict content that is not needed for testing. If a lock code is required, provide it only through the method agreed for the repair. Device-access details should be removed from the active repair record when they are no longer needed.
We do not intentionally collect special-category information through repair work. However, health, biometric, religious, political or other sensitive information may be incidentally visible on a device. We will not use that information for an unrelated purpose. A separate agreement may apply to data-recovery work because it can require broader access to stored content.
How we obtain information
11. Directly from you when you order, register, book a repair, visit a store, subscribe, contact us or submit content.
12. Automatically from your browser or device through logs, cookies and similar technologies, as described in the Cookie Policy.
13. From payment providers, banks, couriers, repair platforms, communications providers and fraud-prevention services involved in your transaction or request.
14. From social-media or review platforms when you contact Phone World through them or make information publicly available to us.
Why we use information and our lawful bases
UK data-protection law requires a lawful basis for each use of personal information. The basis depends on the purpose and circumstances. Our main purposes are set out below.
|
Purpose |
How information is used |
Main lawful basis |
|
Orders, accounts and delivery |
Create and manage accounts; process orders; take payment; provide updates; deliver or arrange collection; manage returns and refunds. |
Contract; legal obligation |
|
Repairs and diagnostics |
Book, inspect, quote, diagnose, repair, test, track and return devices; administer repair warranties and claims. |
Contract; legal obligation; legitimate interests |
|
Customer service |
Answer questions; keep contact records; resolve complaints; handle warranty, return and rights requests. |
Contract; legal obligation; legitimate interests |
|
Payment and fraud prevention |
Authorise transactions; verify identity or address; prevent misuse, chargebacks and fraud; keep systems and customers secure. |
Contract; legal obligation; legitimate interests |
|
Business and legal records |
Keep invoices, repair records, tax and accounting records; establish, exercise or defend legal claims; cooperate with regulators or law enforcement. |
Legal obligation; legitimate interests |
|
Website and service improvement |
Measure performance, diagnose errors, understand demand and improve website, products, stores and repairs. |
Consent; legitimate interests; a PECR exception where its conditions are met |
|
Marketing |
Send offers, news or reminders; measure campaign engagement; maintain opt-out records. |
Consent or the limited customer soft opt-in; legitimate interests for suppression records |
|
CCTV and premises security |
Protect customers, staff, stock and premises; investigate incidents and support legal claims where CCTV is used. |
Legitimate interests; legal obligation where applicable |
Where we rely on legitimate interests, those interests include operating and improving a secure retail and repair business, preventing fraud, keeping proportionate records and protecting legal rights. We consider necessity, reasonable expectations and the effect on individuals before relying on this basis.
Marketing choices
We may send electronic marketing where you have consented or where the limited existing-customer 'soft opt-in' applies. Every marketing email or text will include a simple way to opt out. You can also contact us at any time. Opting out of marketing does not stop service messages about an order, repair, security issue or legal right.
We may keep the minimum information needed on a suppression list so that we respect an opt-out. You have an absolute right to object to the use of your personal information for direct marketing.
Who we share information with
We may share the minimum necessary information with:
15. Website, hosting, cloud, account, communications and customer-support providers.
16. Payment processors, banks, identity, authentication, fraud-prevention and chargeback services.
17. Couriers, collection points, fulfilment providers and delivery partners.
18. Repair-management platforms, specialist repairers, parts suppliers, manufacturers or authorised service networks where they are involved in the job and this has been explained.
19. Analytics, marketing or advertising providers where the required consent or other lawful permission exists.
20. Professional advisers, insurers, auditors and debt-recovery providers where reasonably necessary.
21. Police, courts, regulators, tax authorities or other public bodies where disclosure is required or permitted by law.
22. A purchaser, investor or successor if the business or relevant assets are reorganised or transferred, subject to appropriate confidentiality and data-protection controls.
We do not sell personal information. Service providers acting for Phone World must use information only for the agreed service and protect it under appropriate contractual and security requirements.
International transfers
Some technology or service providers may process information outside the United Kingdom. Before making a restricted transfer, we use a lawful transfer mechanism, such as UK adequacy regulations or appropriate safeguards including the UK International Data Transfer Agreement or an approved UK Addendum, and carry out any required risk assessment. You may contact us for information about the safeguards relevant to your information.
How long we keep information
We keep personal information only for as long as it is reasonably needed for the purpose, legal obligations, warranty administration, security and the establishment or defence of claims. We then delete, anonymise or securely dispose of it. Typical working periods are below and may be shortened or extended where a specific legal, dispute, fraud or safeguarding reason applies.
|
Record |
Typical retention approach |
|
Orders, invoices and payments |
Normally up to 6 years after the relevant transaction or end of the customer relationship, subject to tax, accounting and legal requirements. |
|
Repair and warranty records |
For the warranty period and normally up to 6 years after completion where needed for consumer-rights records, safety, complaints or legal claims. |
|
Device lock codes or test credentials |
Only while reasonably needed for the agreed repair and testing, then removed from active repair records or securely destroyed. |
|
Customer-service and complaint records |
Normally up to 6 years after the matter closes where needed to evidence the outcome or defend rights. |
|
Inactive website accounts |
Reviewed periodically and deleted or anonymised when no longer needed, while transaction records may be retained separately. |
|
Marketing records |
Until consent is withdrawn, you opt out or the information is no longer reliable; a minimal suppression record may be kept to respect the opt-out. |
|
Technical and security logs |
Normally for a limited period appropriate to security and troubleshooting, and longer only where needed to investigate an incident. |
|
CCTV where used |
For the period stated in the relevant CCTV process, normally short and extended only for a specific incident, investigation or claim. |
Security
We use proportionate technical and organisational measures designed to protect personal information against accidental loss, unauthorised access, alteration or disclosure. Measures may include access controls, role restrictions, secure payment processing, encryption in transit, backups, system monitoring, staff procedures and supplier checks. No website, transmission or storage system can be guaranteed completely secure.
If you believe an account, payment, repair record or communication has been compromised, stop sharing information and contact Phone World promptly through the official Contact Us page or on 01582 671721.
Your data-protection rights
Depending on the circumstances, you may have the right to:
23. Ask for access to your personal information and a copy of it.
24. Ask us to correct incomplete or inaccurate information.
25. Ask us to delete information where there is no lawful reason to keep it.
26. Ask us to restrict how information is used in certain circumstances.
27. Object to processing based on legitimate interests and object at any time to direct marketing.
28. Receive certain information you provided in a structured, commonly used, machine-readable format and ask for it to be transferred where the right to portability applies.
29. Withdraw consent at any time where consent is the basis, without affecting earlier lawful use.
30. Ask for human review where a qualifying solely automated decision has legal or similarly significant effects.
These rights are not absolute. We may need to verify identity, clarify the request or retain information where the law permits or requires it. We normally respond within the time required by data-protection law and will explain any lawful refusal or extension.
Automated checks
Payment and fraud-prevention providers may use automated rules to assess a transaction. Phone World does not intend to make a solely automated decision with legal or similarly significant effects unless the process, consequences and available rights have been explained. A payment provider or bank may make its own decision under its privacy information.
Children
PhoneWorld.co is not directed at young children. A person under 18 should place an order or authorise a repair only with the involvement of a parent or guardian who can lawfully enter into the contract. Tell us if you believe a child has provided personal information inappropriately.
Complaints and the ICO
Please contact Phone World first so we can try to resolve a privacy concern. You also have the right to complain to the Information Commissioner's Office, the UK data-protection regulator. Current complaint information is available at https://ico.org.uk/make-a-complaint/.
Changes to this Policy
We may update this Policy to reflect changes in law, technology, suppliers or the way Phone World operates. The latest version will be published on this page with a revised date. Where a change materially affects how existing personal information is used, we will take reasonable steps to bring it to your attention before the new use begins.