CURRENT BASKET VALUE
£0.00

PRIVACY & COOKIE POLICY

Privacy & Security Policy

The JS Group

The JS Group is made up of the following companies:

John Smith's Bookshops

John Smith's Student Stores

John Smith's International

Hammicks Legal Information Services

Aztec Aspire

Security and Privacy

Security:

John Smith's online uses industry standard Secure Socket Layer (SSL) encryption to ensure the highest security for credit card and personal details submitted to us over the Internet. Our security certificate is issued by Comodo CA and we use High Grade Encryption 256bit - US industry standard security software. Information passed between your computer and our website cannot be read in the unlikely event that it is intercepted by someone else.

Privacy:

Topics:

1. What information do we collect about you?

2. How will we use the information about you?

3. Marketing

4. Access to your information and correction

5. The Data Controller and contact details

6. Cookies

7. Other websites

8. Changes to our privacy policy

9. How to contact us

1. What information do we collect about you?

We collect information about you when you register with us or place an order for products or services. We also collect information when you voluntarily complete customer surveys, provide feedback and participate in competitions. Website usage information is collected using cookies.

Universities also share information with us for the purposes of our bursary management schemes. During the registration/enrolment process students will have signed-up to allow this sharing of data in order for us to receive details of the funds available to spend.

Email address, name, contact telephone number and chosen passwords (encrypted) are saved on a central database when a visitor registers, in order that we may update them on the status of an order placed. The University of study and student number are also stored for payment purposes where University-issued funds are used. Delivery and Billing addresses used for orders are also stored. Finally, IP addresses used are stored in case of security / fraud issues. No other personal information is stored on our website.

The visitor is able to update and edit this information at any time by accessing 'View My Account' on the top toolbar. The visitor may also opt-out of being contacted for marketing purposes - please contact us via email at: marketing@johnsmith.co.uk

No personal credit or debit card information is stored by John Smith's. We use SagePay to process all credit card orders. SagePay are an industry leading card payment gateway and financial information is held on a PCI-compliant secure database with very restricted access. These security measures prevent unauthorised release of or access to personal information.

A secure server is used and all payment information is input directly onto SagePay servers. We ensure that any personal information (such as address, telephone numbers or email given when placing an order) is stored securely on our servers.

All of our users' information, not just the sensitive information mentioned above, is restricted in our offices. Only employees who need the information to perform a specific job (for example, our finance department or a customer service representative, either in one of our stores, our distribution centre or head office) are granted access to personally identifiable information.

Data is retained for the purposes of bursary management, order tracking and future warranty claims etc. We will not keep data for any longer than is necessary to manage customer accounts and transactions.

2. How will we use the information about you?

We collect information about you to process your order, manage your account and, if you agree, to email you about other products and services we think may be of interest to you. We use your information collected from the website to personalise your repeat visits to our website. When processing your order, we may send your details to our third party suppliers and couriers (e.g. delivery address and contact telephone number), as necessary to enable them to process your order. We may subsequently share relevant information as required by legal or fraud prevention agencies.

We will e-mail you to keep you up to date with your orders.

JS Group does not sell, rent, share or intentionally make personal information available to any third parties except for those reasons mentioned above. Information may be used by other companies within the John Smith Group, as detailed at the start of this privacy policy. Rest assured that any information you give to John Smith's will not be distributed to any other company outside of the John Smith Group or its affiliated partners. We share relevant financial and transactional information with universities who fund bursary schemes.

We have the right to contact users who have supplied their contact information in relation to orders placed and technical website related issues. John Smith's recognises the concern of our customers regarding privacy of information. The personal information which we hold will be held securely in accordance with our internal security policy and the law.

If we intend to transfer your information outside the EEA (European Economic Area) we will always obtain your consent first.

We are committed to protecting your privacy. We will only use the information that we collect about you lawfully (in accordance with the Data Protection Act 1998 & the UK's implementation of the GDPR). We collect information about you for 2 reasons: firstly, to process your order and second, to provide you with the best possible service.

3. Marketing

We would like to send you information about products and services which may be of interest to you. We may also use contents of abandoned baskets within a limited period of time (45 days) to re-market to you. If you have consented to receive marketing, you may opt out at a later date. You have a right at any time to stop us from contacting you for marketing purposes or giving your information to other members of the JS Group. If you no longer wish to be contacted for marketing purposes, please email us at: ku/oc/htimsnhoj//gnitekram

4. Access to your information and correction

You have the right to request a copy of the information that we hold about you. If you would like a copy of some or all of your personal information, please email ku/oc/htimsnhoj//RPDG or write to us at the following address: JS Group, Ash House, Headlands Business Park, Ringwood, HAMPSHIRE, BH24 3PB. We will respond within one month of receipt of your request. We want to make sure that your personal information is accurate and up to date. You may ask us to correct or remove information you think is inaccurate. Again, we will correct and respond within one month.

You also have the right for your information to be erased - due to your 'right to be forgotten'. This will mean that we will remove all details of you from our systems and servers. Your order details etc. will still be accessible but in an encrypted form. Email us at ku/oc/htimsnhoj//RPDG to request this. Please note that any remaining balances of bursary funds will then not be available to be spent.

You also have the right to lodge a complaint with the supervisory authority (ICO) if you feel we are handling your data in an inappropriate way and you have contacted us in the first instance. Details are to be found here https://ico.org.uk/concerns/

5. Data Controller and Contact Details

For all information that we collect from you JS Group is the Data Controller and can be contacted at the address at the end of this policy. The university is the Data Controller for any information they supply to us for bursary management purposes.

6. Cookies

Cookies are small pieces of information sent by a web server to a web browser, which allows the server to uniquely identify the browser on each page. John Smith's uses 'session cookies' which are automatically deleted from your computer when you close your browser. You are always free to decline our cookies if your browser permits, although in that case you may not be able to place an order on our website. Our cookies contain numerical identifiers only, no personal information or passwords are saved in the cookie.

If you want to delete any cookies that are already on your computer, please refer to the instructions for your file management software to locate the file or directory that stores cookies. Our cookies will have the file names starting with johnsmith.co.uk or hammickslegal.com. Information on deleting or controlling cookies is available at www.aboutcookies.org or www.allaboutcookies.org. The visitor has the right to delete internet cookies placed on their hard drive. Please note that by deleting our cookies or disabling future cookies, it will erase the numerical identifier and our site will not recognise the visitor.

John Smith's relies on the use of cookies to process orders. Whilst you do not need to allow your browser to accept cookies in order to browse much of our website, you must have cookies enabled if you wish to shop or register at John Smith's. You can set your browser not to accept cookies and the above websites tell you how to remove cookies from your browser. However as stated some of our website features may not function as a result.

7. Other websites

JS Group websites contain links to other websites and we are not responsible for the content or privacy practices of these external internet sites. Users should be aware and read the privacy policies of these external sites. This privacy statement is only applicable to information collected by JS Group.

8. Changes to our privacy policy

By entering this website you accept all the terms and conditions outlined in this privacy policy. This policy is effective as of 21stFebruary 2018 and we reserve the right to change this policy at any time by notifying visitors of the existence and location of the new/ revised privacy policy.

9. How to contact us

Please contact us if you have any questions about our privacy policy or information we hold about you:

JS Group can be contacted:

By post: GDPR Department, JS Group, Ash House, Headlands Business Park, Ringwood, HAMPSHIRE, BH24 3PB

By telephone: +44 (0)1425 485910

By email: ku/oc/htimsnhoj//RPDG

If you have any questions or comments about privacy, you can also contact us via our Enquiry Form