Security and Privacy Policy

How secure is my information?

At Bags Direct, we promise that your personal information is secure. Every transaction is processed online by SagePay and Paypal using the latest industry standards for secure online credit card transactions. Secure servers protect your information using advanced encryption and firewall technology throughout the ordering process.

What do we do with your information?

Data Protection law is changing and we want to keep you up to date with the steps Bagsdirect is taking

On the 25th May 2018 the General Data Protection Regulation, known as GDPR, came into effect. GDPR imposes additional obligations on organisations and gives you extra rights around how your data is used.

We want you to know that Bagsdirect respects the information we hold on you and that we take the security of your information very seriously. Please see below our new policy and other information about how we handle your information.

Data protection policy

Context and overview

Key details

  • Policy prepared by: BagsDirect.
  • Approved by board / management on: 25/05/2018.
  • Policy became operational on: 25/05/2018.
  • Next review date: 25/05/2019.


Bags Direct needs to gather and use certain information about individuals.

These can include customers, suppliers, business contacts, employees and other people the organisation has a relationship with or may need to contact.

This policy describes how this personal data must be collected, handled and stored to meet the company’s data protection standards — and to comply with the law.

Why this policy exists

This data protection policy ensures Bags Direct:

  • Complies with data protection law and follow good practice
  • Protects the rights of staff, customers and partners
  • Is open about how it stores and processes individuals’ data
  • Protects itself from the risks of a data breach

Data protection law

The Data Protection Act 1998 describes how organisations — including Bags Direct- must collect, handle and store personal information.

These rules apply regardless of whether data is stored electronically, on paper or on other materials.

To comply with the law, personal information must be collected and used fairly, stored safely and not disclosed unlawfully.

The Data Protection Act is underpinned by eight important principles. These say that personal data must:

  1. Be processed fairly and lawfully
  2. Be obtained only for specific, lawful purposes
  3. Be adequate, relevant and not excessive
  4. Be accurate and kept up to date
  5. Not be held for any longer than necessary
  6. Processed in accordance with the rights of data subjects
  7. Be protected in appropriate ways
  8. Not be transferred outside the European Economic Area (EEA), unless that country or territory also ensures an adequate level of protection
People, risks and responsibilities

Policy scope

This policy applies to:

  • The head office of Bags Direct
  • All branches of Bags Direct
  • All staff and volunteers of Bags Direct
  • All contractors, suppliers and other people working on behalf of Bags Direct

It applies to all data that the company holds relating to identifiable individuals, even if that information technically falls outside of the Data Protection Act 1998. This can include:

  • Names of individuals
  • Postal addresses
  • Email addresses
  • Telephone numbers
  • any other information relating to individuals

Data protection risks

This policy helps to protect Bags Direct from some very real data security risks, including:

  • Breaches of confidentiality. For instance, information being given out inappropriately.
  • Failing to offer choice. For instance, all individuals should be free to choose how the company uses data relating to them.
  • Reputational damage. For instance, the company could suffer if hackers successfully gained access to sensitive data.

What information we collect when you shop with us and why?

When you buy goods from us, you are entering into a contract with us. You will need to set up a Bagsdirect Account before ordering from us, so we can set this up we will ask you to provide some personal information such as;

  • full name
  • address & Shipping address
  • contact numbers, and
  • email address.

As an existing customer if you have shopped with us using a credit or debit card, or we have taken these details for a payment authorisation, we will securely collect and store this payment card information.

In order to undertake website personalisation, we will also gather information about the devices you use to access our sites (desktop and mobile), and this may include IP address. For further information on our use of cookies and tracking please see our Cookie Notice.

How do we use your information?

Data Protection says that we are allowed to use and share your personal data only where we have a proper reason to do so. The law says we must have one or more of these reasons and these are:

  • Contract - your personal information is processed in order to fulfil a contractual arrangement e.g. in order to send you your order
  • Consent – where you agree to us using your information in this way e.g. for storing your payment card details.
  • Legitimate Interests - this means the interests of Bagsdirect in managing our business to allow us to provide you with the best products and service in the most secure and appropriate way e.g. to transfer your data to certain Third Party’s such as delivery partners.
  • Legal Obligation – where there is statutory or other legal requirement to share the information e.g. when we have to share your information for law enforcement purposes.

Bagsdirect do not send newsletters to cutsomers, the only emails we will send as a company are to confirm your order or provide information regarding your order.

What are cookies?

"Cookies" are small pieces of information that are stored by your web browser on your computers hard drive. Our cookies do not contain any personally identifying information. We may use cookies to store visitors preferences, record session information, record user specific information on what pages users access or visit, alert visitors to new areas that we think might be of interest to them when they return to the site, record past activity on the site in order to provide better service when visitors return to our site, ensure that visitors are not repeatedly sent the same banner ads and customise Web page content based on visitors browser type or other information collected.


This website may contain links to other sites. Bags Direct is not responsible for the privacy practices or the content of such web sites. If you have a question about the privacy policy of those web sites, please contact them directly.

Contacting us

If you have any questions about our Security & Privacy Policy, our site practices, or your personal experience dealing with this web site, you can contact us by email or by telephone: 0845 838 4677 or by post to, 1 Sketty Close, Brackmills Industrial Estate, Northampton, NN4 7PL, UK. Full contact information can be found on our Contact Us page.