Privacy policy
Last updated: 17 August 2026
Who we are
This site is published by Martin Global Limited (company number 07730531), registered office 5 Brooklands Place, Brooklands Road, Sale, Cheshire, United Kingdom, M33 3SD ("we", "us"). We are the data controller for the personal data described below.
This site is not aimed at children
Bear and Friends To The Rescue is a book for children, but this website is aimed at the adults who buy it — parents, teachers, librarians and booksellers. We don't knowingly collect personal data from children, and there's nothing on this site built for a child to use unsupervised.
What we collect, and why, and how long we keep it
Contact form: if you use the contact form, we collect your name, email address, chosen subject and message, so we can reply to you. Our lawful basis is legitimate interest — responding to enquiries you've sent us. We keep this for up to 24 months after our last exchange with you, then delete it. [REVIEW: confirm retention period.]
Direct orders (when available): if you order a signed copy or other product directly from us, payment is handled entirely by Stripe — we never see or store your card details. We receive your name, delivery address, order details and (if you choose personalisation) a dedication name, so we can fulfil and post your order. Our lawful basis is performance of a contract with you. We keep order records for 6 years after the order, in line with UK tax and accounting record-keeping requirements.
We do not use cookies or trackers for advertising. If we ever add website analytics, we'll only use a privacy-friendly, cookieless tool, and we'll update this policy first.
Who we share it with, and international transfers
Email sending: Amazon Web Services (AWS SES), to deliver contact form and order emails. Our AWS infrastructure is hosted in the UK (London).
Payments (when direct orders launch): Stripe, to process card payments. Stripe's own privacy policy applies to the payment details you give them directly. Stripe may transfer data outside the UK and European Economic Area as part of its global payments infrastructure; where it does, it relies on legal safeguards such as Standard Contractual Clauses. [REVIEW: confirm once Stripe is actually wired up.]
We do not sell personal data, and we don't share it with anyone else except where the law requires it.
Keeping your data secure
We use reasonable technical and organisational measures to protect the personal data we hold — for example, encrypted connections (HTTPS) throughout the site, and access to our systems limited to people who need it. No method of transmission or storage is ever completely secure, but we work to protect your information appropriately.
Your rights
Under UK GDPR you have the right to: be informed how your data is used; access the personal data we hold about you; have inaccurate data corrected; have data deleted in certain circumstances; restrict or object to how we use it; and receive your data in a portable format. To exercise any of these, contact us via our Contact page.
If you're unhappy with how we've handled your data, you also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, at ico.org.uk or 0303 123 1113. We'd appreciate the chance to put things right first, but you don't have to come to us before contacting the ICO.
Changes to this policy
We may update this policy as the site grows — for example, when direct sales or a newsletter launch. The date at the top shows when it was last changed.
