Privacy policy
Last updated: 29/09/2026
Makoto Collective Ltd is the data controller for the personal data collected through this website. This policy explains what we hold, why we hold it, how long we keep it and what you can ask us to do about it. It is written to the General Data Protection Regulation (EU) 2016/679 and the Data Protection Act 2018.
We are a small company. Your data is handled by us and by a short list of named suppliers, and by nobody else. We do not sell it, and we do not share it for anyone else's advertising.
Who we are
| Data controller | Makoto Collective Ltd |
| Registered office | 65 Willow, Trimbleston, Goatstown, Dublin, D14 FX36, Ireland |
| Companies Registration Office number | 818005 |
| VAT number | IE4747479NH |
| hello@makotocollective.com | |
| Phone | +353 87 143 8621 |
We are not required to appoint a Data Protection Officer and we have not appointed one. Data protection questions come to hello@makotocollective.com and are answered by a director.
What this policy covers
It covers people who visit this website, place an order, create an account, subscribe to our emails, or write to us. It does not cover our suppliers, our trade customers or people who apply to work with us; if that is you, write to us and we will tell you how your data is handled.
What we collect
| What | Examples | Where it comes from |
|---|---|---|
| Identity and contact details | Name, email address, phone number, delivery address, billing address | You, when you order, create an account, write to us or ask to be told a product is back |
| Order details | What you bought, when, for how much, the order number, delivery and returns history | Created when you order |
| Payment details | The type of card, the last four digits, the authorisation result, the billing address | Shopify Payments. We never see or hold your full card number. |
| Account details | Your email address and login state, if you choose to create an account | You. Accounts are optional on this store. |
| Correspondence | The emails you send us and our replies, including anything you tell us about a reaction to a product | You |
| Marketing preferences | Whether you have opted in, when, and whether you have since opted out | You |
| Technical and usage data | IP address, browser and device type, pages viewed, referring site, and the cookies described below | Collected automatically |
We do not ask for special category data. If you tell us about a skin condition, an allergy, a food intolerance or a reaction to a product, we use that only to answer you and to decide what to keep on the shelf, and we delete it when it has served that purpose. Where a food allergy is the reason for a question, we may keep the answer against the order while that order is live, and no longer.
Why we use it, and on what legal basis
| Purpose | Legal basis | How long we keep it |
|---|---|---|
| Taking, packing and delivering your order, and dealing with returns and refunds | Performance of a contract with you | 6 years from the end of the accounting period, because the order is also a tax record |
| Taking payment and screening for fraud | Performance of a contract, and our legitimate interest in not being defrauded | 6 years |
| Keeping accounting and VAT records | Legal obligation under Irish tax law | 6 years |
| Answering your questions and handling complaints | Performance of a contract, and our legitimate interest in running the shop well | 2 years from the last message |
| Telling you a product is back in stock, when you ask us to. You are not added to our newsletter | Your consent, given when you submit the form | Until we have written to you once, then deleted |
| Running an optional customer account | Performance of a contract | Until you close it, or 3 years after your last order |
| Sending marketing emails | Your consent, or the soft opt-in described below | Until you opt out, plus 2 years to prove the opt-out was honoured |
| Product safety, including recalls and reporting serious undesirable effects | Legal obligation under Regulation (EC) 1223/2009 for cosmetics and Regulation (EU) 2023/988 for everything else | 10 years, as those regulations require |
| Food traceability, so that a batch of tea or other food can be traced and withdrawn if it ever needs to be | Legal obligation under Regulation (EC) 178/2002 | 5 years |
| Non-essential cookies and site analytics | Your consent, given through the cookie banner | See the cookie section |
| Defending a legal claim | Our legitimate interest in defending ourselves | Until the claim is out of time |
Where we rely on legitimate interests, we have weighed our interest against your rights, and you can ask us for that assessment.
Who your data goes to
We use a small number of suppliers who process data on our instructions and cannot use it for their own purposes.
| Recipient | What they do | Where they are | How the transfer is protected |
|---|---|---|---|
| Shopify International Limited | Hosts the store, processes orders and, through Shopify Payments, takes payment | Ireland, with group companies in Canada and the United States | Shopify's data processing addendum. Canada holds a European Commission adequacy decision; transfers to the United States rely on the EU–US Data Privacy Framework or Standard Contractual Clauses |
| DPD Ireland and the DPD network | Carries your parcel and contacts you about the delivery | Ireland and the European Union | Within the EEA, no transfer safeguard needed |
| Xero | Our accounting system, which holds your order as an invoice record | European Union, with group companies in New Zealand | New Zealand holds a European Commission adequacy decision |
| Google Ireland Limited | Our email, through which we correspond with you | Ireland, with group companies outside the EEA | Google's data processing terms and Standard Contractual Clauses |
| Google Ireland Limited (Google Analytics) | Measures visits to the site, if you accept analytics cookies | Ireland, with group companies in the United States | Google's data processing terms; EU–US Data Privacy Framework or Standard Contractual Clauses |
| Meta Platforms Ireland Limited | Measures the effect of our advertising on Facebook and Instagram, if you accept marketing cookies | Ireland, with group companies in the United States | Meta's data processing terms; EU–US Data Privacy Framework or Standard Contractual Clauses |
| Our cookie consent provider | Records and stores your cookie choices | See the cookie section | See the cookie section |
We also disclose data where the law requires it, to Revenue, to a regulator, or to a court. If our business is ever sold, customer records pass to the buyer, and we will tell you before that happens.
We do not sell your personal data, and we do not share it with third parties for their own marketing.
Transfers outside the European Economic Area
Some of our suppliers are part of international groups, and your data may be processed outside the EEA as set out in the table above. Where that happens we rely on an adequacy decision by the European Commission, or on Standard Contractual Clauses, so that your data carries the same protection with it. You can ask us for a copy of the safeguards that apply.
Cookies
A cookie banner appears the first time you visit. Strictly necessary cookies — the ones that keep your basket, log you in and keep the checkout secure — are set without asking, because the site cannot work without them. Everything else is set only if you agree, and you can change your mind at any time through the banner.
| Kind | What it does | Set without asking? |
|---|---|---|
| Strictly necessary | Basket, checkout, login, security, load balancing | Yes |
| Functional | Remembers your language and preferences | No, consent |
| Analytics | Tells us which pages are read and where visitors arrive from | No, consent |
| Marketing | Lets Meta measure whether our Facebook and Instagram adverts led to a visit or an order | No, consent |
Refusing or withdrawing consent does not stop you shopping. It does not affect anything we did before you withdrew it.
Marketing emails
We send marketing email only to people who asked for it, or who bought from us and were offered a clear way to decline at the time. That second route is the soft opt-in permitted by Irish law for our own similar products, it lasts twelve months from your last purchase, and every message carries an unsubscribe link.
Opting out is immediate and costs you nothing. We will still email you about an order you have placed, because that is not marketing.
Your rights
Under the GDPR you can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything that is wrong or incomplete;
- delete your data, where we do not need it for a legal reason such as a tax record;
- restrict what we do with it while a question about it is being settled;
- send it on, to you or to another provider, in a machine-readable form;
- stop processing it where we rely on legitimate interests, and stop marketing to you, which we will always do; and
- withdraw consent you have given, at any time, without affecting what we did before.
Write to hello@makotocollective.com. We answer within one month. If a request is complicated we may take up to two months more, and we will tell you within the first month if that happens. There is no charge unless a request is clearly excessive, and we may ask you to confirm who you are before we release anything.
Automated decisions
We do not make decisions about you by automated means alone, and we do not profile you. Shopify Payments runs automated fraud checks on card payments, and if one of those flags your order a person looks at it before anything is refused.
Children
This store is not intended for children, and we do not knowingly collect data about anyone under 18. If you believe a child has given us their details, write to us and we will delete them.
Security
The site runs over an encrypted connection. Payment card data goes directly to Shopify Payments and never reaches us. Access to customer records is limited to the two directors and protected by two-factor authentication. No system is perfect, and if a breach ever puts your rights at risk we will tell you and the Data Protection Commission as the law requires.
Complaints
If you are unhappy with how we have handled your data, tell us first at hello@makotocollective.com. You also have the right to complain to the supervisory authority at any time:
Data Protection Commission
6 Pembroke Row, Dublin 2, D02 X963
dataprotection.ie
Changes
We may update this policy. The date at the top tells you when this version took effect, and we will tell you directly if a change materially affects you.
Contact
Makoto Collective Ltd, 65 Willow, Trimbleston, Goatstown, Dublin, D14 FX36, Ireland
hello@makotocollective.com · +353 87 143 8621