Last updated: 12 April 2026
Who we are
B-Glamorous (“we”, “our” or “us”) is a fashion retail business registered in Malta. Our physical shop is located at Commercial D, Capital Heights, George Borg Olivier & Santa Marta Street, Victoria (Rabat), Gozo, Malta. Our website address is https://b-glamorous.com.
For the purposes of the EU General Data Protection Regulation (GDPR) 2016/679 and the Malta Data Protection Act (Cap. 586), B-Glamorous is the data controller responsible for your personal data.
If you have any questions about this Privacy Policy or how we handle your data, you can contact us at shop@b-glamorous.com.
What personal data we collect and why
When you place an order
We collect your name, email address, billing address, shipping address, phone number and payment information. We use this data to fulfil your order, process payment, arrange shipping, send order confirmations, and communicate with you about your purchase. The legal basis for this processing is the performance of a contract (GDPR Article 6(1)(b)).
Payment processing is handled by our third-party payment providers. We do not store your full credit or debit card details on our servers. Payment data is transmitted directly to our payment processor under their own privacy policy and PCI-DSS compliance.
When you create an account
If you register for an account on our website, we store your name, email address, and shipping/billing details in your user profile. You can view, edit or request deletion of this information at any time through your account dashboard or by contacting us.
When you browse our website
We automatically collect technical data including your IP address, browser type and version, time zone, operating system, and information about how you interact with our website (pages visited, products viewed, search queries). This data is collected through cookies and similar technologies. The legal basis is our legitimate interest in ensuring our website functions correctly, improving the user experience, and analysing site traffic (GDPR Article 6(1)(f)).
When you subscribe to our newsletter
If you sign up for our newsletter, we collect your email address. We use it solely to send you updates about new collections, promotions and shop news. The legal basis is your consent (GDPR Article 6(1)(a)). You can unsubscribe at any time by clicking the unsubscribe link in any email or by contacting us.
When you contact us
If you reach out to us via email, social media or our website, we collect your name, email address and the content of your message. We use this to respond to your enquiry. The legal basis is our legitimate interest in providing customer support (GDPR Article 6(1)(f)).
In our physical shop
Our shop in Victoria, Gozo uses CCTV for the prevention and detection of crime, the safety of staff and customers, and operational purposes. CCTV footage is retained for a limited period and is only reviewed or shared when required for security investigations or by law. The legal basis is our legitimate interest in protecting our premises, staff and customers (GDPR Article 6(1)(f)).
Cookies
Our website uses cookies — small text files placed on your device — to make the site work properly and to understand how visitors use it.
Essential cookies (always active)
These are strictly necessary for the website to function. They include session cookies for your shopping cart, login cookies if you have an account, and security cookies. Because these are essential, they do not require your consent under GDPR and the ePrivacy Directive.
Analytics and marketing cookies (consent required)
We use analytics tools (such as Google Analytics) and may use marketing pixels to understand how our website is used and to improve our services. These cookies are only placed on your device after you give your explicit consent via our cookie consent banner. You can change your cookie preferences at any time by clicking the cookie settings link in the footer of our website.
Who we share your data with
We share your personal data only where necessary to provide our services:
- Payment processors — to securely process your online payments.
- Shipping and courier services — your name, address and phone number so your order can be delivered.
- Website hosting and infrastructure providers — who store and serve our website data on servers within the EU.
- Email service providers — if you subscribe to our newsletter, your email address is shared with our mailing platform.
We do not sell, rent or trade your personal data to third parties for their marketing purposes. We may disclose your data if required to do so by law, by a court order, or by a competent regulatory authority.
International data transfers
Your data is primarily processed and stored on servers within the European Economic Area (EEA). Where data is transferred outside the EEA (for example, by a service provider), we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, or that the recipient country has been granted an adequacy decision.
How long we keep your data
We retain your personal data only for as long as necessary for the purposes it was collected:
- Order data — retained for 10 years after your last purchase to comply with Maltese tax and accounting obligations (Income Tax Act Cap. 123, VAT Act Cap. 406).
- Account data — retained for as long as your account is active. You can request deletion at any time.
- Newsletter subscribers — retained until you unsubscribe.
- CCTV footage — retained for a maximum of 30 days unless required for an ongoing investigation.
- Website analytics data — anonymised and aggregated; individual-level data is not retained beyond 14 months.
Your rights
Under the GDPR and the Malta Data Protection Act (Cap. 586), you have the following rights regarding your personal data:
- Right of access (Article 15) — you can request a copy of all personal data we hold about you.
- Right to rectification (Article 16) — you can ask us to correct any inaccurate or incomplete data.
- Right to erasure (Article 17) — you can ask us to delete your personal data, subject to legal retention obligations.
- Right to restrict processing (Article 18) — you can ask us to limit how we use your data.
- Right to data portability (Article 20) — you can request your data in a structured, commonly used, machine-readable format.
- Right to object (Article 21) — you can object to processing based on our legitimate interests, including direct marketing.
- Right to withdraw consent (Article 7(3)) — where processing is based on your consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at shop@b-glamorous.com. We will respond within 30 days as required by law.
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Office of the Information and Data Protection Commissioner (IDPC), the supervisory authority in Malta:
Office of the Information and Data Protection Commissioner
Floor 2, Airways House, High Street, Sliema SLM 1549, Malta
Website: https://idpc.org.mt
Email: idpc.info@idpc.org.mt
Phone: +356 2328 7100
Children’s privacy
Our website and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at shop@b-glamorous.com and we will delete it promptly. The age threshold of 16 applies in accordance with the Malta Data Protection Act (Cap. 586, Article 10).
Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. Our website uses SSL/TLS encryption for all data transmitted between your browser and our servers. Access to personal data is restricted to authorised personnel only.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. The date at the top of this page shows when it was last revised. We encourage you to review this page periodically. Continued use of our website after any changes constitutes your acceptance of the updated policy.