Privacy Policy
Last updated: 29 August 2026 · DrMobilePhone
Contents
1. Data Controller
DrMobilePhone is the data controller responsible for your personal data collected through this website, as defined under Article 4(7) of the GDPR. As data controller, we determine the purposes and means of processing your personal data.
Data Controller Contact Details
Organisation: DrMobilePhone
2. Data We Collect
We collect personal data in the following categories, depending on how you interact with our website:
Account & Identity Data
- ◆Full name and display name
- ◆Email address
- ◆Password (stored as a one-way cryptographic hash — we cannot see it)
- ◆Phone number (if provided)
- ◆Profile photograph (if uploaded)
Order & Transaction Data
- ◆Shipping address(es)
- ◆Order history, items purchased, and quantities
- ◆Order value, payment status, and refund history
- ◆Selected shipping method
- ◆Discount codes used
Payment Data
- ◆Payment is processed exclusively by Stripe, Inc. via their secure payment infrastructure
- ◆We receive only a payment confirmation and a Stripe session/payment ID — we never see, store, or process your card number, CVV, or full banking details
Repair Ticket & Service Data
- ◆Customer name and contact details provided when submitting a device for repair
- ◆Device details (make, model, IMEI, serial number, reported fault)
- ◆Device access credentials (PIN/password) — stored securely and used solely to perform the repair, never shared
- ◆Repair history and service notes
- ◆Repair status and completion records
Communications Data
- ◆Messages submitted via our contact form
- ◆Customer service correspondence by email
- ◆Product reviews and ratings you submit
Cookie & Browsing Preferences
- ◆Cookie consent preferences (stored in localStorage under
dmp-cookie-consent) - ◆Recently viewed products (stored locally on your device, not transmitted to our servers unless you are logged in)
- ◆Site preferences and settings stored in your browser
Technical & Usage Data
- ◆IP address and general geographic location
- ◆Browser type and version
- ◆Device type and operating system
- ◆Pages visited and time spent on the website
- ◆HTTP request logs (retained at server/infrastructure level)
We collect data directly from you when you register, place an order, or contact us. Technical data is collected automatically as part of normal website operation. We do not purchase or obtain personal data from third-party data brokers.
3. Legal Basis for Processing
We process your personal data on the following legal grounds as set out in Article 6 of the GDPR:
- ◆Contract (Article 6(1)(b)): To process your orders, manage your account, handle returns and refunds, provide repair services, and provide customer service. This processing is necessary to perform our contract with you.
- ◆Legal Obligation (Article 6(1)(c)): To comply with our obligations under Irish tax law (Revenue Commissioners requirements), consumer protection legislation, and anti-money laundering obligations.
- ◆Legitimate Interests (Article 6(1)(f)): To maintain website security and prevent fraud, to improve our website and services based on usage patterns, and to send you service-related notifications. We have assessed that these interests do not override your rights and freedoms.
- ◆Consent (Article 6(1)(a)): For optional marketing communications (where you have explicitly opted in), and for functional and analytics cookies (where you have consented via our cookie banner). You may withdraw consent at any time by unsubscribing, updating your cookie preferences, or contacting us.
4. How We Use Your Data
We use your personal data for the following purposes:
- ◆Processing and fulfilling your orders, including dispatching products and issuing invoices
- ◆Sending order confirmation, dispatch notification, and delivery updates via email
- ◆Creating and maintaining your customer account and purchase history
- ◆Processing returns, exchanges, and refunds
- ◆Providing repair services — logging repair tickets, diagnosing faults, communicating repair status, and returning devices
- ◆Securely storing device access credentials (PIN/password) during the repair process, used solely to perform the repair and deleted upon completion
- ◆Responding to your customer service enquiries and contact form messages
- ◆Publishing product reviews you have submitted (display name and review content only)
- ◆Detecting, investigating, and preventing fraudulent transactions and abuse of our platform
- ◆Complying with our legal obligations including tax record-keeping
- ◆Improving the functionality and user experience of our website
- ◆Sending marketing emails where you have opted in (you can opt out at any time)
6. International Data Transfers
Some of our third-party processors are located outside the European Economic Area (EEA), specifically in the United States. We ensure all international transfers of personal data are protected by one or more of the following safeguards:
- ◆EU Standard Contractual Clauses (SCCs): Contractual obligations binding the recipient to GDPR-equivalent data protection standards, as approved by the European Commission under Article 46(2)(c) GDPR.
- ◆UK/EU Adequacy Decisions: Where the destination country has been determined by the European Commission to provide an adequate level of data protection.
You can obtain copies of the transfer safeguards applicable to specific processors by contacting us at the contact address in Section 1.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by law:
| Category | Retention Period | Reason |
|---|---|---|
| Account data | Duration of account + 6 years after deletion | Tax / legal obligations (Irish Revenue) |
| Order records | 6 years from transaction date | Irish tax law (TCA 1997, s.886) |
| Payment records | 6 years | Irish tax / VAT compliance |
| Repair ticket data | 2 years after repair completion | Legitimate interest / service guarantee |
| Device credentials (PIN/password) | Deleted on repair completion | Data minimisation (GDPR Article 5) |
| Contact messages | 1 year from receipt | Legitimate interest |
| Product reviews | Until deleted by user or admin | Legitimate interest |
| Cookie consent preferences | 6 months | GDPR consent records (Article 7) |
| Marketing consent | Until consent is withdrawn | GDPR Article 7 |
| Server / access logs | 90 days | Security / fraud detection |
When data is no longer needed, it is securely deleted or anonymised. You may request early deletion of your data by exercising your right to erasure (see Section 8 below), subject to our legal retention obligations.
8. Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights with respect to your personal data. These rights are not absolute and may be subject to certain exceptions under applicable law:
Right of Access (Article 15)
You have the right to obtain a copy of the personal data we hold about you, along with information on how it is processed. We will respond to verified requests within one calendar month.
How to exercise: Download from your account settings or submit a written request to us.
Right to Rectification (Article 16)
You have the right to have inaccurate personal data corrected, and incomplete data completed.
How to exercise: Update your name and contact details directly in your account settings, or contact us for other corrections.
Right to Erasure / Right to be Forgotten (Article 17)
You have the right to request deletion of your personal data where it is no longer necessary for the purpose it was collected, or where you withdraw consent. Note: we may be required to retain certain data to comply with legal obligations (e.g. 7-year financial records).
How to exercise: Submit a deletion request to us in writing.
Right to Restrict Processing (Article 18)
You have the right to request that we restrict the processing of your data in certain circumstances, for example while you contest its accuracy.
How to exercise: Contact us in writing with your request.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller where processing is based on consent or contract and carried out by automated means.
How to exercise: Contact us to request a data export.
Right to Object (Article 21)
You have the right to object to processing based on our legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
How to exercise: Unsubscribe from marketing emails at any time, or contact us to object to other processing.
Rights Related to Automated Decision-Making (Article 22)
We do not currently use automated decision-making or profiling that produces legal or similarly significant effects on you.
How to exercise: Not applicable at this time.
To exercise any of these rights, contact us at the contact address in Section 1. We will respond within one calendar month of receiving your request. We may need to verify your identity before fulfilling the request.
10. Data Security
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include:
- ◆All data transmission encrypted via TLS/HTTPS
- ◆Passwords hashed using bcrypt — never stored in readable form
- ◆Row-Level Security (RLS) on our database — each user can only access their own data
- ◆Service-role API keys never exposed to client-side code
- ◆Regular security reviews and dependency updates
- ◆Access to production systems restricted to authorised personnel only
Despite these measures, no transmission of data over the internet can be guaranteed completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours and you as soon as reasonably practicable, as required by Article 33 and 34 of the GDPR.
11. Children's Privacy
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16 years of age. If you believe a child has provided us with their personal data, please contact us immediately and we will delete such information as soon as practicable.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or the services we use. The "Last updated" date at the top of this page indicates when the policy was last revised.
For significant changes affecting your rights, we will notify you by email (if you have an account) or by posting a prominent notice on our website. Your continued use of our website after notification of changes constitutes acceptance of the revised policy.
13. Complaints & Contact
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact our data controller:
DrMobilePhone — Data Controller
Contact form: Contact us online
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Website: www.dataprotection.ie
Phone: +353 (0)57 868 4800