Privacy
Privacy notice
28 September 2026.
This notice says what this website does with personal information, and the reason for each use. The termscover shop orders, workshop tickets, hire, and payments.
Who we are
LAURENNE HOPKINS FLOWERS LTD, company number 16301498, registered in England. Registered office: 26 Oxcroft Estate, Oxcroft, Worksop, England, S80 4NA. ICO registration ZC016531.
Data protection contact:contact@laurennehopkinsflowers.co.uk. The public phone is+44 7920 715992. The studio is in Bolsover, Derbyshire. The visit address is on thecontact page.
Why we use personal information
Contract.Shop orders, workshop bookings, A La Carte hire, wholesale orders, and pay-page payments.
Legal obligation.Keeping financial and accounting records.
Legitimate interests.Responding to what the person asked for: the contact form, the client list, and Dubsado enquiries.
Explicit consent.Dietary and allergy notes on a workshop booking. The booking form asks for that consent, and the box starts unticked. We do not send marketing emails. We would not send them without a separate consent. We send none now.
Stripe checkout
Card payments are taken on Stripe Checkout, in pounds, with prices that already include VAT at 20%. The card number is entered on Stripe’s page. The records this site writes store a Stripe session id, payment intent id, and customer id. They do not include a card number.
Shop.The basket asks how you want the flowers (collection or local delivery), the date, the time slot, your name, and optional order notes. Some flowers also carry a gift message or a line note. Checkout then asks Stripe for a billing address and a phone number, and for a UK delivery address when you chose delivery. A paid shop order is stored as an order. Cancelling before you pay returns you to this site and nothing is charged.
Workshops.The events basket asks for the lead booker’s name and email, how many tickets, optional emails for other people on the booking, an optional group name, and an optional food, allergy, or dietary note. If that note has text, the consent box must be ticked before checkout starts. Stripe Checkout asks for a billing address. A paid booking is stored as an event booking, with the consent and the time it was given when a note was sent. The lead booker and each participant are emailed a ticket. Cancelling before you pay charges nothing.
A La Carte deposit.The booking step collects the wedding date, colour palette, preferences, name, email, and an optional phone number, then charges either the £100 deposit including VAT or the full menu total including VAT. Stripe Checkout asks for a billing address and a phone number. A paid booking is stored as a wedding booking. Leaving Checkout before you pay returns you to the booking page and does not charge you.
Wholesale.A signed-in florist pays for buckets on a separate checkout. Stripe is given the florist’s email and asks for a billing address and a phone number. Collection only. A paid order is stored with the shop orders, marked as wholesale.
A one-off payment.The pay page takes a name, an amount, and an optional email and note, and sends them to Stripe. That payment is not written into the orders table.
Stripe also emails the customer receipt for a shop or wholesale order. A workshop ticket says a receipt comes from Stripe as well. Stripe keeps its own records under its legal duties. Its privacy policy is atstripe.com/gb/privacy.
Email through Resend
The contact form sends your enquiry by email through Resend. It asks for your name, email, an optional phone number, an optional date, what the enquiry is about, an optional location, and a message. The message goes to the studio inbox (or another address set for enquiries), with your email as the reply-to. This site does not write that form into the database.
The wedding estimate page can also open a message in your own email app, with the estimate included. That path is not sent by Resend. Wedding and funeral enquiry pages embed a Dubsado form instead, described below.
After a paid workshop, Resend sends the lead booker a ticket. That email says workshops are not refunded, and that if you cannot attend a box kit is set aside to make at home — reply to arrange collection. Each participant gets a joining note without the payment line. The same moment emails the studio. Shop, wholesale, and A La Carte payments email the studio through Resend. They do not send the customer a Resend confirmation: the customer receipt for shop and wholesale is Stripe’s, and an A La Carte booking has a staff email only.
A florist can ask for a one-time wholesale sign-in link. Resend sends it to the email address they type. The link expires after 20 minutes. It is only sent when that email is already on the florist list.
While a Resend account is active, Resend says email and log data is kept for 30 days on the Free, Pro, and Scale plans. Enterprise plans can keep it for a different period. Resend stores that data in the United States. Choosing a sending region does not move the stored data. After an account is closed, Resend says remaining customer data is deleted within 90 days, and backups within 7 days. This website does not record which Resend plan is in use. The source isresend.com/security/gdpr.
Records in Supabase, in the EU
Paid checkouts are written to Supabase Postgres hosted in the EU (AWS region eu-west-1). The site connects with a database URL. It does not use a public anonymous key as that connection.
- Orders — shop and wholesale. Email, name, amount, currency, what was bought, and the collection or delivery date, time, and address when Stripe or the basket provided them.
- Event bookings — workshop tickets. Email, name, session, quantity, optional group name, optional dietary note, the dietary consent and the time it was given when a note was stored, and any participant emails.
- Clients — a row matched on the email address, or else on the Stripe customer id. The name, email, that customer id, and a label for where the checkout came from (shop, wholesale, workshop, or A La Carte wedding). An existing client keeps their other labels.
- Wedding bookings — the A La Carte deposit or full payment. Name, email, optional phone, wedding date, palette, preferences, the menu lines, and whether you paid the deposit or the full amount.
A one-off payment on the pay page is not one of these rows. If saving the client fails, the paid order or booking is still stored, without that client link.
Vercel: hosting, analytics, and speed
The site is built to run on Vercel. Every page loads Vercel Web Analytics and Vercel Speed Insights.
Vercel Web Analytics does not use cookies. Visitors are identified by a hash of the incoming request, and that hash is not used to track someone across different days or different websites. The hash is valid for a single day and then resets. Vercel’s analytics privacy policy says the product works without third-party cookies, and that the visitor session is discarded after 24 hours. Seevercel.com/docs/analyticsandvercel.com/docs/analytics/privacy-policy.
The Speed Insights privacy policy does not say whether that script sets a cookie. It says the measurements are anonymous, are not tied to an individual visitor or IP address, and cannot be used to reconstruct a browsing session or identify a user. The Speed Insights package loaded by this site does not read or write a cookie or localStorage. Seevercel.com/docs/speed-insights/privacy-policy.
Google Maps, other pages, and fonts
The contact page does not embed a map. It links to a Google Maps search for the business name and Bolsover. Opening that link leaves this site. The search is the business name, not the sat-nav postcode. The same page also links to a what3words address for the farm. Following either link is a request to that other site.
Wedding enquiry, the wedding estimate, and the funeral enquiry embed a Dubsado form from hello.dubsado.com. What you type in that frame is sent to Dubsado, not through the contact form on this site. Enquiry answers are kept in Dubsado until we delete them. Enquiries that do not lead to a booking are cleared after 2 years.
Each page asks your browser to load typefaces from fonts.googleapis.com and fonts.gstatic.com. The footer links to the studio’s Instagram and Facebook profiles. Those sites have their own notices.
Cookies and what stays on your device
This website’s own code does not use localStorage. There is no basket stored that way.
The shop basket is kept in sessionStorage, under the name lhf-shop-basket-v2. That holds the flowers, collection or delivery, the date, the time slot, notes, and any gift message. A second sessionStorage flag remembers that you just added something, so the basket can show that once. The browser keeps sessionStorage for the tab. It is not sent to the database until you pay.
An A La Carte estimate and the booking form are kept in sessionStorage underlhf.alc-book: the year, the menu lines, the date, the palette, preferences, your name, email, phone, and whether you chose the deposit or the full amount. The success page clears that draft. Leaving Checkout before you pay leaves it in the tab so the form can be restored.
Wholesale sign-in sets one cookie, lhf_wholesale. It is HttpOnly, sent only on HTTPS, SameSite Lax, and it lasts 14 days. It holds the florist’s id, name, business name, and email. It does not hold the access code. Signing out clears it.
Your rights
Under UK GDPR you can ask for access to the personal information we hold about you, and for rectification, erasure, restriction, objection, and portability. You can also complain to the Information Commissioner’s Office (ICO). The ICO’s site isico.org.uk.
To ask, emailcontact@laurennehopkinsflowers.co.uk. UK GDPR expects a response without undue delay and within one month. This website does not contain its own request form.
How long information is kept
Orders, workshop bookings, A La Carte deposits and payments, wholesale orders, pay-page payments, and the emails about them, are kept for 6 years from the 31 March after the transaction. The financial year ends on 31 March. A pay-page payment is not written into the orders table. Stripe keeps that payment under its own legal duties. Any email we keep about it is kept for 6 years from the 31 March after the payment.
Dietary and allergy notes are deleted within 30 days after the workshop. This website has no scheduled job that deletes them. Until one is added, staff delete the note by hand within those 30 days. The record that consent was given, and the time it was given, stay on the booking after the note text is gone.
Enquiries that do not lead to a booking are cleared after 2 years. That covers the contact form and Dubsado enquiries. Enquiry answers stay in Dubsado until we delete them. The contact form is an email, not a database row. Resend’s own copy follows the 30 days above.
The client list is kept for 6 years from the 31 March after the last purchase or booking.
Apart from deleting a dietary note by hand, this website does not yet run a job that removes rows or emails when a period ends.
The wholesale sign-in cookie lasts 14 days, or until you sign out. The wholesale sign-in link expires after 20 minutes. The shop basket and the A La Carte draft stay in the browser tab, and the draft is removed on the booking success page.
Shop, workshop, and hire terms are on theterms page.