Privacy Policy

Effective from 21 May 2018

This privacy policy sets out how Markus Lupfer collects and processes your personal data through your use of our website and/or signing up for newsletters, entering our competitions, and other marketing activities off or online. Markus Lupfer is committed to ensuring that your privacy is protected. Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this privacy statement. Markus Lupfer may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes.

Information About Us

Marlu Design Ltd is the controller responsible for your personal data (referred to here as “we”, “our”, “us” throughout this privacy policy). We are the primary data controller for the purposes of this website and our registered office is Unit 11 De Beauvoir Block, 92-96 De Beauvoir Road, London N1 4EN, United Kingdom. If you have any questions about this privacy policy, the use of your personal data, you can contact us on

Information You May Provide To Us

We may collect some or all of the following information to us when you purchase goods from our website, register for a customer account, sign up for our newsletter, or participate in marketing activities either in person or online.

- Your identity and contact details: name, email address, postal address, billing address, telephone number.

- Your payment details: payment card details, expiry date and security code. These details are encrypted by our payment processing partner and we do not retain any payment details submitted by you.

- Demographic information: when you create a customer account we may collect information such as your data of birth, your interests, and preferences.

- Additional information: we occasionally keep additional information relevant to competitions, offers and surveys which we use to help us understand our business and for the purpose of direct marketing.

We do not collect any sensitive personal data and this website is not intended for children so we do not knowingly collect data relating to children.

Information We May Collect

When you visit our site we automatically collect usage and technical data about your browsing including the pages you visit and how you interact with these pages. We collect this data by using cookies, server logs, and similar technologies.

Technical data includes:

- Your IP (internet protocol) address, browser type, operating system and platform, and other device information.

- Information about your visit including products you viewed, searched for, length and frequency of visit, page interaction information and other communication data.

- If you access via mobile we also collect mobile network information, mobile operating system and the type of browser you use.

- We may also receive information from third parties we work closely with such as online fashion retail platforms, payment processors, and fraud prevention agencies.

How We Use The Data

We collect and process your personal data for the following purposes:

- When you purchase a product we ask you for the personal data necessary to fulfil our contract with you. This includes taking payment, performing anti-fraud checks, shipping and delivery of the order, and if necessary handling the return.

- Keeping you updated on the progress of your order, we usually communicate with you via email but we, or our delivery service providers, may contact you by phone if there are issues with regards to delivery.

- When visiting the site we collect the data necessary for us to provide you with the services of the website such as placing and holding items in your shopping bag.

- When you register on the site we collect the data necessary to ensure we can recognise you on subsequent visits and provide you with the services that registrations offers such as your order history, wish list, loyalty program, and stored information for expedited checkout.

- Processing the data required for your entry into a competition or promotion.

- We process data to analyse sales to help us improve our business.

- We process data to analyse the performance of our website.

- We analyse purchase history, web browsing history, and account data to tailor our marketing communications, web site presentation, and internet advertising to meet your preferences.

- If you contact Customer Care we will use the data you provide in order to respond to your request for help or information.

What Is Our Legal Basis For Processing Your Personal Data?

Under the law we must have a valid reason for using your personal data and we may not collect, store, or use data about you that is not compatible with that reason. We have four valid reasons for our use of your personal data:

- To fulfil our Contractual Obligation to you. Most of the data we collect from you is necessary to allow us to fulfil the contract we enter into with you when you purchase an item. The data is related to processing your payment, delivering your goods, and communicating your order status to you.

- Consent. In certain circumstances we will ask for your consent for us to use your personal data, for example, if we would like to send you marketing information about items we believe will be of interest to you.

- Legitimate Interests. We may also have a legitimate interest in using your data, for example ensuring the content of our website and marketing is relevant to your interests, and to ensure the effective presentation of our website to you. If this is our reason we must ensure that our interests do no override yours, and you are entitled to object to this use of your personal data.

- Legal Obligation. We may use your personal data in order to meet a legal obligation or to ensure your interests are protected, for example, where we may exchange data with specialist third parties for the purposes of fraud detections and credit risk reduction.

To provide some examples of our use of your personal data and the legal basis:

A. When you purchase a product on we ask for the necessary personal data to allow us to fulfil our contract with you including processing payments, completing fraud checks, delivering the products, and if required handling a return. The legal basis in this instance is Contractual Obligation. Without your data it would not be possible to execute the contract. We also are required to meet Legal Obligations as we are required to process orders in accordance with tax provisions and statutory rules which apply.

B. When you visit we collect the necessary personal information to allow to provide you with the services of the website, for example, placing items in your shopping bag. We also collect data about how you arrived at the website, the time spent on the website, what you viewed and searched for, page interactions, and response times. The legal basis in this instance is Legitimate Interest in order to provide adequate services to you and to ensure that the services are managed correctly.

C. When you visit we also collect data about your use of the site using cookies. For more information on cookies please view our Cookie Policy. The legal basis in this instance is Consent as you would have accepted use of these cookies via the cookie banner on our site. Some cookies are necessary in our legitimate interest to provide you with the services of the website, for example, we would not be able to store items in your shopping bag without the use of cookies.

D. When you register a customer account on we collect the data required to administer your account, recognise you on subsequent visits and provide you with the benefits of the services offered under registration, such as a wish list, loyalty program, and stored shipping data for expedited checkout. The legal basis for this information is Contractual Obligation as without provision of such data we would not be able to execute the obligations we have laid out in offered in the registration service.

E. If you sign up to receive the newsletter. The legal basis for this is Consent as you have given your permission for us to contact you about goods and services which may be of interest to you.

F. If you have made a purchase from we may use your personal data such as your purchase history, to contact you regarding goods and services which may be of interest to you. The legal basis in this instance is Legitimate Interest as the use of your data is necessary to ensure you receive relevant information.

G. If you contact customer care to request information, help, or to make a complaint. The legal basis in this instance is Contractual Obligation, the data is necessary for us to execute the contract.

Opting Out Of Marketing

If you have given your consent for us to use your personal data for marketing you have the right to withdraw your consent at any time. You can opt out of direct marketing, or change your preferences by unsubscribing from our newsletters, or by contacting Customer Care via email on

Who Will Process Your Data

Your data will be processed by the internal staff of Markus Lupfer who have been authorised for this processing. Where your data is transmitted to the third parties that we use to provide our services these parties have been assessed and provide the guarantee of compliance with the legislation of the processing of personal data.

Who We Share Your Data With

We may share your information with select third parties:

- Payment Acquiring Services to process your payment.

- Delivery and Courier companies to supply your order.

- Credit Reference and Fraud Prevention agencies.

- Analytics and search engine providers that assist in analysing and optimising the performance of our website.

- Companies who carry out marketing activities on our behalf.

- Companies specialising in market research and data processing.

Transfer Outside The European Union

Some of the third parties listed above may be located in countries outside of the European Union, whenever we transfer your personal data outside of the European Union we ensure we take the following safeguards:

- We may transfer your data to countries that have privacy laws providing the same level of protection of your personal data as the European Union.

- We may use contract clauses with recipients which mean they must protect your personal data with the same level of protection as the European Union.

- We may transfer personal data to organisations if they are part of the Privacy Shield framework which required them to provide similar protection to personal data shared between the European Union and the US.

Security Measures

We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online. We are committed to regularly testing and evaluating the effectiveness and resilience of our technical and organisation measures.

How Long We Keep Your Data

We keep your data for as long as you are a customer and thereafter we may retain your data in order to respond to questions or complaints and to maintain the necessary records for legal, accounting or reporting purposes. We may also keep your data for research or statistical purposes.

Your Rights

You have the right to request a copy of the data that we hold about you, and we will provide this to you free of charge once we have confirmed your identity.

If we hold this data we will provide you with:

- A description of the data.

- The reasons why we are holding it.

- Inform you who it could be shared with.

- Inform you of how long we will keep this data.

- If the data was not provided by you will we give you any available information we have such as the source of the data.

- Inform you if the data is stored outside of the European Union and if so what safeguards are in place.

- Provide you with a clear and concise copy of the data.

You have the right to:

- Request a correction if the personal data we hold on you is incomplete or inaccurate.

- Request erasure of your personal data. On receiving and reviewing your request if there is no good reason for us to continue processing your personal data we will be responsible for promptly ceasing processing and deleting it. Please note, we may not always be able to comply for specific legal reasons which we will notify you of after receiving your request.

- Object to processing your personal data where we rely on legitimate interests (or those of a third party). You will need to explain the reasons behind your request and allow us to consider your request and respond to you.

- Request restriction of processing your personal data. You can ask us to suspend processing of your personal data if you want us to establish the data’s accuracy, where our use of the data is unlawful but you do not want it erased, where you need us the hold the data even if we longer require it in order to establish, exercise or defend legal claims, or you have objected to our use of your data but we need to review whether we have overriding legitimate grounds to use it.

- Request the transfer of your personal data to you or a third party. We will provide your personal data in a standard format and if you wish, and it is technically possible we can transfer your personal data directly to a third party for you.

- Withdraw consent at any time if we are relying on your consent to process your personal data, such as direct marketing or cookies. If you choose to do this we may not be able to provide certain products or services to you.

To exercise any of these rights please contact or write to us at: Markus Lupfer, Unit 11 De Beauvoir Block, 92-96 De Beauvoir Road, London N1 4EN, United Kingdom.

How we use cookies

A cookie is a small file which asks permission to be placed on your computer's hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.

We use traffic log cookies to identify which pages are being used. This helps us analyse data about web page traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.

Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us. You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.

Links to other websites

Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.

List of cookies we collect

The table below lists the cookies we collect and what information they store.

Cookie NameCookie Description
FORM_KEY Stores randomly generated key used to prevent forged requests.
PHPSESSID Your session ID on the server.
GUEST-VIEW Allows guests to view and edit their orders.
PERSISTENT_SHOPPING_CART A link to information about your cart and viewing history, if you have asked for this.
STF Information on products you have emailed to friends.
STORE The store view or language you have selected.
USER_ALLOWED_SAVE_COOKIE Indicates whether a customer allowed to use cookies.
MAGE-CACHE-SESSID Facilitates caching of content on the browser to make pages load faster.
MAGE-CACHE-STORAGE Facilitates caching of content on the browser to make pages load faster.
MAGE-CACHE-STORAGE-SECTION-INVALIDATION Facilitates caching of content on the browser to make pages load faster.
MAGE-CACHE-TIMEOUT Facilitates caching of content on the browser to make pages load faster.
SECTION-DATA-IDS Facilitates caching of content on the browser to make pages load faster.
PRIVATE_CONTENT_VERSION Facilitates caching of content on the browser to make pages load faster.
X-MAGENTO-VARY Facilitates caching of content on the server to make pages load faster.
MAGE-TRANSLATION-FILE-VERSION Facilitates translation of content to other languages.
MAGE-TRANSLATION-STORAGE Facilitates translation of content to other languages.