Skip to main content

Privacy Policy

1. WHO WE ARE

We are HHGL Limited trading as Homebase (we/our/us) (Company number 00533033 with registered office address Witan Gate House, 500-600 Witan Gate, Milton Keynes, United Kingdom, MK9 1BA). This policy describes how we use your personal information.

We respect your privacy and value the trust you place in us when you share your personal information with us. This policy sets out how we, as Data Controller, collect, process, use and disclose your personal information, why we use it, with whom we share it, the rights to which you may be entitled and your choices about our use of your personal information.

This policy covers our use of your personal information arising from your interaction with us, including but not limited to your use of our website. If you have any questions or need any further clarity, please get in touch via email to Data.Protection@Homebase.co.uk or via post to Head of Legal, HHGL Limited, Witan Gate house, 500-600 Witan Gate, Milton Keynes, Bucks, MK9 1BA.

By using the Homebase website and mobile website, you are agreeing to our Privacy and Cookie policies.

2. YOUR INFORMATION

Data Collection and Usage

Personal Data includes any data that can identify you as a person or be used in conjunction with other information to identify you. The type of personal data we will collect will depend upon the interaction that we have with you.

We comply with all applicable laws in relation to data protection and privacy, including the Data Protection Act 2018 and the General Data Protection Regulation (GDPR).

What we collect

Lawful basis for processing

How we use it

Information that you actively give us to set up an account:

  • Your full name
  • Address
  • Email address
  • Payment card address
  • Phone number
  • Your payment card details
  • Your order details

Consent. You provide your consent when setting up an account. You can withdraw this consent at any time.

We use this information to:

  • Provide our products and services
  • Manage and administer our services
  • Personalise your experience

Information that you actively give us to make a purchase:

  • Your contact details including: your name, address, email address and phone number
  • Your bank account or credit/debit card details
  • The product or service purchased

Performance of contract. We cannot perform our sales contract without this information.

We use this information to:

  • Provide our products and services
  • Manage and administer our services
  • Process your order
  • Take payment from or give you a refund
  • Help us ensure that our customers are genuine and to prevent fraud

Information that you actively give us to subscribe to our newsletter, receive information or mailings:

  • Your name
  • Email address

Consent. You must provide consent to sign up to our mailing lists. You can withdraw this consent at any time. Please see below section 4 for more information.

Provide our products and services; Help us ensure that our customers are genuine and to prevent fraud; Send news on our offers, great value products and inspiring DIY projects.

Information that you actively give us to sign up for a prize draw or competition. Your contact details including: your name, address, email address and phone number (this may include your social media account if that's the way you communicate with us).

Legitimate Interest. We need this information to administer any prize draw competitions. Each competition will have Terms and Conditions, please consult them with any further questions.

Provide our products and services; Manage and administer prize draws, competitions and our services. Take payment from or give you a refund. Help us ensure that our customers are genuine and to prevent fraud.

Information about the way you use our products and services including:

  • The things that we've provided or you've purchased
  • When and where you've made the purchases
  • What you paid and how
  • Whether you've opened electronic communications from us
  • Whether you've clicked on links in electronic communications from us

Legitimate Interest. We use this information to deliver quality service and tailor your experience.

We use this information to: develop new products and services improve our products and services, personalise our products and services, identify products and marketing that may be of interest to your, and for statistical analysis and research.

Information that we may collect through your use of our website including:

  • Device information such as operating system, unique device identifiers the mobile network system
  • Hardware and browser settings
  • Email address
  • Date and time of requests
  • The requests you make
  • The pages you visit and search engine terms you use
  • IP address
  • Approximation of your location for geolocation, store-based services

Legitimate Interest. We use this information to deliver quality service and tailor your experience.

We use this information to:

  • Provide our products and services
  • Develop new products and services
  • Improve our products and services
  • Personalise our products and services
  • Identify issues with the website and user's experience of it
  • Make improvements to the user experience
  • Manage and administer our systems
  • Monitor the way our website is used
  • Identifying your nearest store
  • Personalise the advertisements we provide to you, so they are more relevant to your interests

Information we collect from you (including via our online shopping website host) when you use our website or send us emails, including:

  • Name
  • Billing/shipping address
  • Telephone, mobile number
  • IP address
  • Device
  • Past order history
  • External references, such as chargeback systems

Legitimate interest. We use this information to detect and prevent fraud.

We use this information to detect and prevent fraud.

Information when you communicate with us in person, through our website or via email, over the phone, through social media or via any other medium, including:

  • Your contact details including: your name, address, email address and phone number (this may include your social media account if that's the way you communicate with us)
  • The details of your communications with us (including call recordings)
  • The details of our messages to you

Legitimate Interest. We use this information to deliver quality service.

We use this information to:

  • Answer any issues or concerns
  • Monitor customer communications for quality and training purposes
  • Develop new products and services
  • Improve our products and services
  • Personalise our products and services
  • Regulatory compliance

Information that we collect incidentally from other sources or public sources, including:

  • Information available in the media
  • Information presented on our social media timelines
  • Information collected by security systems

Performance of contract. We cannot perform our sales contract without this information.

We use this information to:

  • Maintain market awareness
  • Build and maintain social media branding
  • Provide security to our sites
  • Fraud prevention and confirming your identity

Information that we collect from commercially available sources, such as the electoral roll. We will only collect this data from entities that have obtained the data legally from publicly available or consent-based sources.

Legitimate Interest. We use this information to deliver quality service and tailor your experience.

Personalise the advertisements we provide to you, so they are more relevant to your interests.

Information received from credit reference agencies.

Performance of contract where this may be needed for you to obtain finance for purchases. Legitimate Interest - fraud prevention and confirming your identity.


Fraud prevention and confirming your identity.

Information that you actively give us to sign up for notifications when a product is back in stock: Your email address.

Consent. By requesting an email when the item is back in stock, you are consenting to us processing your data in that way.

Provide our products and services.

Information that you actively give us on social media by responding to our request for use: Photo and/or video, including any sound and accompanying text posted through your account on social media, accompanying metadata such as time and place of creation, your username, and links to your social media profile.

Consent – we will ask for your consent to use this data and store your consent on our database. You can withdraw this consent at any time.

We use this information for: social media accounts, websites, blogs, digital displays, advertising, store displays, TV and streaming advertisement, and generally in the promotion of HHGL Limited’s products or services.

Information that we collect from you in premises via our CCTV systems and employee-worn bodycam: Video footage, which may include sound recording in the case of bodycam footage.

Legitimate Interest. We use this information to ensure the safety and security of our premises including crime detection/prevention, and health and safety matters.

We use this information for ensuring the safety and security of our premises including crime detection/prevention, and health and safety matters.


Homebase does not knowingly collect data from any unsupervised person under the age of 18. If you are under the age of 18, you must not use the Homebase website or submit any Personal Data to us unless you have the consent of, and are supervised by, a parent or guardian.

Legal requirements

Your personal information may also be processed if it is necessary on reasonable request by a law enforcement or regulatory authority, court, or other competent body or agency or in the defence of a legal claim. We will not delete personal information if relevant to an investigation or a dispute. It will continue to be stored until those issues are fully resolved.

How long we keep your information

We will keep your information for as long as it is reasonably necessary or required by legislation. It will depend on factors such as whether you have any outstanding purchases or have interacted with recent offers.

Information we share

There are certain circumstances where we may transfer your Personal Data to contractors, service providers, and to other parties.

  • We may share information about you with other members of our group of companies so we can provide the best service across our group. They are bound to keep your information in accordance with this privacy policy.
  • We may also share your information with certain contractors or service providers who assist us in the provision of products and services we supply to you, are involved in prize draws and competitions we run or provide other services to assist with our day-to-day operations. They may process your Personal Data for us, for example, if we use a marketing agency. Other recipient’s/service providers include professional advisers (such our lawyers or accountants), manufacturers, logistics/delivery providers, advertising agencies, IT specialists, database providers, backup and disaster recovery specialists or email providers. Our suppliers and service providers will be required to meet our standards on processing information and security. The information we provide them, including your information, will only be provided in connection with the performance of their function.
  • We may also share your information with certain third parties. We will do this either when we receive your Consent or because we need them to see your information to provide products or services to you. These include credit reference agencies, anti-fraud databases, screening agencies and other partners we do business with.
  • We may share your information with our online shopping website host for the purpose of detecting and preventing fraud.
  • Lastly, we may share your information with third party service providers to perform data matching, data analysis or online advertising services on our behalf. These third parties include Google / Alphabet, Meta including Facebook and Instagram, TikTok, X / Twitter, Snapchat, Pinterest, Yahoo!, PubMatic, GumGum, ID5 and InfoSum.

Your personal information may be transferred to other third-party organisations in certain scenarios:

  • If we're discussing selling or transferring part or all of our business – the information may be transferred to prospective purchasers under suitable terms as to confidentiality.
  • If we are reorganised or sold, information may be transferred to a buyer who can continue to provide services to you.
  • If we're required to by law, or under any regulatory code or practice we follow, or if we are asked by any public or regulatory authority – for example the courts or the Police.
  • If we are defending a legal claim your information may be transferred as required in connection with defending such claim.

Your Personal Data may be shared if it is made anonymous and aggregated, as in such circumstances the information will cease to be personal data.

Where your information will be held

Our offices are based in England and your data will be held on systems accessible by this office.

We will only transfer data to jurisdictions outside the scope of the General Data Protection Regulation (GDPR) where the appropriate safeguards set out in the GDPR are in place.

We are happy to provide you with copies of the regulator-approved standard contractual clauses, which you can request from us using the contact details below.

3. YOUR RIGHTS

Data Subject Rights

We've listed the rights you have over your information and how you can use them below.

These rights will only apply in certain circumstances. Some of these rights will not be available if there are outstanding contracts between us if we are required by law to keep the information or if the information is relevant to a legal dispute.

We will normally respond to or action (as applicable) requests within one month from receipt of your request and relevant proof of identification. This period may be extended by 2 further months if necessary, taking into account the complexity or number of requests. If this is the case, we will let you know within one month of your original request.

In general, the information or action requested will be provided free of charge. However, if requests are manifestly unfounded or excessive (or repetitive in nature) we may charge a fee (or alternatively refuse to deal with the request).

It is important that we establish that the individual right is being exercised by the correct person. Therefore, we may need to ask you for information in order to verify your identity prior to processing your request. This may include asking you to confirm certain details we hold about you (such as postcode or first line of your address) or to provide proof of identification.

You have the right to make the following types of requests regarding the Personal Data Homebase holds about you:

  • Right of access (subject access requests) – the right to request a copy of the Personal Data (if any) that we have concerning you and supporting information explaining how your Personal Data is used.
  • Right of rectification – the right to request that we rectify inaccurate or incomplete Personal Data concerning you.
  • Right of erasure (right to be forgotten) – the right, in some situations, to delete your Personal Data.
  • To exercise any of those points please contact our team on this page.
  • Right to restrict processing – the right, in some situations, to request that we do not use the Personal Data you have provided (e.g. if you believe it to be inaccurate). This is intended as a temporary right until the reason for such restriction has been resolved or rectified.
  • Right to data portability – the right, in some situations, to request that we transmit your data to you or another entity.
  • Right to object - the right to object to certain processing of your Personal Data (unless we have overriding compelling grounds to continue the processing) and the right to object to direct marketing/profiling in certain circumstances, we will be exempted from responding to certain requests. We will use these exemptions to the extent appropriate.

The supervisory body for Data Protection in the UK is the Information Commissioner’s Office. They have information about your rights and how to enforce them, as well as processes for complaints.

4. CONTACT US

How to contact us 

If you have any questions about this policy, please contact our Legal team at Data.Protection@homebase.co.uk, or by writing to Head of Legal, HHGL, Witan Gate House, 500-600 Witan Gate, Central Milton Keynes, MK9 1BA.

Want to be removed from the Homebase direct marketing list?

If you want to be removed from our email mailing list, please email Data.Protection@Homebase.co.uk. In addition, each email we send you will contain details of how you can unsubscribe.

5. CHANGE TO THE POLICY

This policy may be changed from time to time and will be posted here. We encourage you to visit this area frequently to stay updated.

6. OTHER POLICIES

Cookies

Our website uses cookies which are text files which contain small amounts of information that a website can send to, and store on, your computer or device through your browser. Cookies may be used by us to provide you with, for example, customised information from our website to make our website more user-friendly. This may include, for example, remembering your postcode for you so you don’t have to re-enter it every time you check the stock levels for an item you are interested in.

In addition, cookies allow us to understand who has seen which pages and advertisements, to determine how frequently particular pages are visited and to determine the most popular areas of our website.

We are required to provide you with clear and comprehensive information about the cookies which we use on the site and to obtain your Consent to the use of cookies. In order to comply with these requirements, we have prepared a cookie policy setting out information about cookies, detailing the cookies we use and providing information on how to manage cookies on your computer.

By using the Homebase website and mobile website, you are agreeing to our cookie policy and Consent to the use of cookies and similar technologies by us and our carefully selected third party partners as described in our cookie policy. If you do not agree to such use, please see the 'Managing your cookies' section for details on how to adjust your settings. For more information about cookies, the types of cookies we use and how we use them please see our Cookie Policy.

Security

We are committed to keeping your personal information safe. We've got appropriate physical, technical, and administrative measures in place to protect your information against accidental or unauthorised destruction, loss, access or alteration.

7. PRODUCT REVIEWS

Through the Review Service, you may submit star ratings, reviews, comments, photos, videos, questions, and other user-generated content (collectively, “UGC”). Any UGC you submit may be used for advertising purposes and posted to publicly-facing websites, including other websites across the Internet and on the PowerReviews network, in addition to the website that you originally submitted the UGC. Accordingly, please do not post anything that you do not want to share with the general public (for example, financial information, social security number, etc.).

In addition, the UGC that you submit may be used for other advertising, analytic and statistical purposes including, for example, product improvement, benchmarking (e.g. where various products/services or categories of products/services are compared against each other or against the market as a whole), sentiment analysis (e.g. using the data from multiple reviews it is possible to determine how consumers as a whole feel about a product/service), and online behavioural advertising. In order to submit UGC, you may have to create an account with the PowerReviews’ client whose products, services or goods you are reviewing or rating. During the course of creating an account, you may be asked to submit information, such as but not limited to, your name, email address, phone number, and other data (collectively, “Consumer Account Info”). The Consumer Account Info may be collected by both PowerReviews and the applicable PowerReviews’ client. To further understand how the PowerReviews’ client to whom you have submitted UGC and Consumer Account Info will use such data, please consult the terms and conditions of that client’s website (e.g. privacy policy). We may also col lect other types of information in connection with your activities on the Services, such as demographic information (including, without limitation, your age, weight, size, hair colour, sex, occupation, interests, location, and income) and information about or contained in postings you make in forums or any other interactive areas of the Services, your answers to surveys, your participation in sweepstakes, contests, games and promotional offers; and in any email request you send us for any reason (such as to provide us with comments or feedback).

8. GLOSSARY

Data Controller:

The person or organisation that determines when, why and how to process Personal Data. It is responsible for establishing practices and policies in line with the GDPR. We are the Controller of all Personal Data relating to our Company Personnel and Personal Data used in our business for our own commercial purposes.

Personal Data:

Any information identifying a Data Subject or information relating to a Data Subject that we can identify (directly or indirectly) from that data alone or in combination with other identifiers we possess or can reasonably access. Personal Data includes Special Categories of Personal Data and Pseudonymised Personal Data but excludes anonymous data or data that has had the identity of an individual permanently removed. Personal data can be factual (for example, a name, email address, location or date of birth) or an opinion about that person's actions or behaviour.

Consent:

Agreement which must be freely given, specific, informed and be an unambiguous indication of the Data Subject's wishes by which they, by a statement or by a clear positive action, signify agreement to the Processing of Personal Data relating to them.

Legitimate Interest:

Means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your Personal Data for our Legitimate Interests.

Performance of Contract:

Means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.

This privacy policy was last reviewed and updated on 10 January 2024.

homebase