Privacy Policy
How we collect, use, and protect your personal information.
Last updated: 28 March 2026
Introduction
EatProtein ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you visit eatprotein.co.uk or make a purchase from us.
We are a trading name of ShakeThatWeight Ltd, registered in England and Wales. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using our website, you agree to the practices described in this policy. If you have any questions, please contact us at [email protected].
What Personal Data We Collect
We collect personal data in the following ways:
Information You Provide Directly
- Account details — name, email address, and password when you create an account
- Order information — billing and delivery address, phone number, and payment details when you place an order
- Communications — any information you share when you contact us via email, phone, WhatsApp, or social media
- Reviews and feedback — product reviews or survey responses you submit
- Newsletter sign-up — your email address when you subscribe to our mailing list
Information Collected Automatically
- Device and browser data — IP address, browser type, operating system, and screen resolution
- Usage data — pages visited, time spent on pages, referring URLs, and click patterns
- Cookies and similar technologies — see our Cookies section below for full details
How We Use Your Data
We use your personal data for the following purposes:
To Fulfil Orders (Contractual Necessity)
- Processing and delivering your orders
- Sending order confirmations, dispatch notifications, and delivery updates
- Processing refunds and returns
- Managing your account
With Your Consent
- Sending marketing emails, including promotions, new products, and wellness tips
- Personalising your experience on our website
Legitimate Interest
- Improving our website, products, and services
- Analysing website traffic and usage patterns
- Preventing fraud and ensuring security
- Responding to customer enquiries and support requests
Legal Obligation
- Complying with tax, accounting, and regulatory requirements
- Responding to lawful requests from authorities
Who We Share Your Data With
We never sell your personal data. We only share it with trusted third parties who help us operate our business:
- Payment processors — Stripe and PayPal process your payments securely. We never store your full card details on our servers.
- Delivery partners — Royal Mail, DPD, or other couriers receive your name and delivery address to fulfil your order.
- Email marketing — we use a third-party email service to send newsletters and marketing communications (only if you've opted in).
- Analytics — Google Analytics and similar tools help us understand how visitors use our site. This data is anonymised where possible.
- Hosting and infrastructure — our website is hosted on secure UK/EU-based servers.
- Customer support tools — we may use third-party tools to manage support enquiries.
All third parties are required to handle your data in accordance with applicable data protection laws and our instructions.
Cookies
Cookies are small text files stored on your device when you visit our website. We use them to:
- Essential cookies — keep your shopping basket working, remember your login session, and process checkout. These are necessary for the site to function.
- Analytics cookies — help us understand how visitors use our website so we can improve it (e.g. Google Analytics).
- Marketing cookies — allow us to show you relevant adverts on other platforms (e.g. Meta Pixel, Google Ads). These are only set with your consent.
You can manage your cookie preferences at any time through your browser settings. Disabling essential cookies may affect the functionality of our website.
For a full list of cookies we use and how to manage them, please see our Cookie Policy.
How Long We Keep Your Data
We retain your personal data only for as long as necessary:
- Order data — 6 years after your last order, as required by UK tax and accounting regulations
- Account data — for as long as your account remains active, plus 12 months after deletion request
- Marketing data — until you unsubscribe or withdraw consent
- Analytics data — anonymised and retained for up to 26 months
Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
Right of Access
Request a copy of the personal data we hold about you.
Right to Rectification
Ask us to correct any inaccurate or incomplete data.
Right to Erasure
Request deletion of your personal data where there is no compelling reason for us to keep it.
Right to Restrict Processing
Ask us to limit how we use your data in certain circumstances.
Right to Data Portability
Receive your data in a structured, commonly used format.
Right to Object
Object to processing based on legitimate interest or for direct marketing.
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Data Security
We take the security of your data seriously and implement appropriate technical and organisational measures, including:
- SSL/TLS encryption across our entire website
- PCI DSS-compliant payment processing through Stripe and PayPal
- Regular security updates and monitoring
- Access controls to limit who can view personal data
While we strive to protect your data, no method of transmission over the internet is 100% secure. We encourage you to use strong passwords and keep your account details confidential.
International Data Transfers
Some of our third-party service providers may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions, to protect your data in accordance with UK GDPR.
Children's Privacy
Our website and products are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Any changes will be posted on this page with an updated "last updated" date. We encourage you to review this policy periodically.
Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please get in touch:
- Email: [email protected]
- Phone: 01782 479331
- Post: EatProtein (ShakeThatWeight Ltd), Unit B1, Dewsbury Road, Fenton Trade Park, Stoke-on-Trent, ST4 2TE