Skip to main content
Free 24-hour delivery over £75 · Same-day dispatch

Privacy policy.

Last updated: 5 August 2026

Kovalabs is the trading name of Floww Group Limited, a company registered in England and Wales (company number 15986643) with its registered office at 66 Paul Street, London, EC2A 4NE. Floww Group Limited is the data controller for personal data collected on this site. We only collect what we need to fulfil orders and improve the service. You can contact us about your data at privacy@kovalabs.co.uk, or by post at the address above.

What we collect

  • Name, email, billing and shipping address, and a phone number if you choose to give one at checkout
  • Order history
  • Usage data about how you use the site. Unless you object, our server immediately reduces a document request to anonymous daily service statistics with no visitor or device identifier. If you accept person-level analytics, it also includes a cookie that recognises your browser between visits and session replays with typed text masked.

We do not store payment card details - those are handled by our PCI-compliant payment provider.

You do not have to give us any personal data. But if you place an order, we need your name, email and delivery address to enter into and fulfil the contract. Without them we cannot accept the order. Everything else, such as marketing sign-up and optional cookies, is entirely your choice.

How we use it

  • To process and ship your orders
  • To send transactional emails (order confirmations, tracking)
  • To send marketing emails - only if you opt in
  • To apply your referral discount and credit the referral partner who introduced you, where you arrive via a partner link or use a partner code. If your first qualifying order creates a recurring partner association, later qualifying orders may also be credited to that partner without you re-entering the code

Marketing emails are sent through Customer.io (email marketing platform, EU data centre), which processes your email address and order history on our behalf only when you have opted in.

We do not use automated decision-making, including profiling, that produces legal or similarly significant effects about you.

Our lawful bases

UK GDPR requires a lawful basis for each way we use your data. Ours are:

  • Contract - processing and shipping your order, taking payment, and sending transactional emails such as order confirmations and tracking updates.
  • Consent - marketing emails (opt-in only), the optional analytics and marketing cookies described in our Cookie Policy, and session replay. You can withdraw consent at any time.
  • Legitimate interests - preventing fraud and abuse, producing anonymous service-improvement statistics under the PECR statistical-purposes exception unless you object, keeping our customer records accurate by linking records that belong to the same customer (see "Keeping customer records accurate" below), crediting referral partners for orders they introduce, maintaining any recurring partner association created by the first qualifying order, and showing that partner your name next to an order they are credited with (see "Who we share it with" below).
  • Legal obligation - keeping order and transaction records we are required to retain for tax and accounting purposes.

Who we share it with

We never sell your data. We share it only with the providers we need to run the store. Most process it on our instructions as our processors. Fena and Royal Mail are regulated businesses that also act as data controllers in their own right for the payment and postal services they provide to you, under their own privacy notices. Google, Meta and TikTok likewise act as controllers in their own right for the advertising measurement data we send them, under their own privacy notices.

  • Fena - initiates your pay-by-bank payment. We never see or store your bank credentials.
  • Royal Mail and Sendcloud - receive your name, delivery address and email address, and your phone number where you gave us one, to create shipping labels, deliver your order and provide tracking. Your contact details let them reach you about the delivery itself, for example if a parcel cannot be delivered or is being returned to us.
  • Resend - sends our transactional emails (order confirmations, dispatch and delivery updates).
  • Customer.io - sends marketing emails (EU data center), only if you have opted in.
  • PostHog - analytics, hosted on EU servers.
  • Anthropic - provides the AI model we use to check whether two customer records belong to the same person (see "Keeping customer records accurate" below). It processes only the limited details involved in that check - email addresses, checkout names, delivery town and postcode, and the timing and contents of orders and baskets - on our instructions, and does not use them to train its models.
  • Google, Meta and TikTok - measure whether an advert led to a visit or a purchase, and reach people with advertising. Measuring advertising and personalising advertising are separate choices in our cookie banner, and we send data for each of those purposes only where you have given that particular choice. What we share is your order and browsing activity on this site, together with contact details you have given us, which we convert into a one-way hash before they leave us wherever the platform accepts one. A one-way hash cannot be turned back into the original value: the platform can only compare it with a hash of data it already holds. Some address details are shared with Google in plain form because Google accepts them only that way. No platform receives your street address, your payment details, or the security records described below. What each platform can accept differs, so the exact fields vary between them and may change as their services change. Without the relevant advertising consent, none of this is sent.
  • Your referral partner - if you buy using a partner's link or discount code, that partner can see your name alongside the order value, the order date, an order reference and the number of items on their commission dashboard, so they can recognise the orders their referrals generated. They are never shown your email address, contact details, delivery address, or - under any circumstances - which products you bought, and they are contractually barred from contacting you or using your name for marketing. If you would rather the partner did not see your name, email privacy@kovalabs.co.uk and we will replace it with a pseudonymous label.
  • Our hosting and infrastructure providers, which store order and account data in UK or EU regions.

Where a provider processes personal data outside the UK, we rely on the UK adequacy regulations or the UK International Data Transfer Addendum to the EU standard contractual clauses to protect it. You can ask for a copy of these safeguards by emailing privacy@kovalabs.co.uk.

We protect your data with encryption in transit, access controls, and UK or EU hosting.

How long we keep it

  • Order and transaction records: 6 years from the end of the relevant financial year, as required for UK tax and accounting.
  • Account details: for as long as you hold an account, then deleted on request.
  • Marketing data: until you unsubscribe or ask us to remove you.
  • Cookies and similar storage: see the durations listed in our Cookie Policy.

Cookies and analytics

Our cookie controls group the optional purposes by capability: Analytics (aggregate service analytics, and person-level analytics and replay), Advertising (advertising storage, advertising measurement and advertising personalisation) and Preferences (functional preferences). Each group switches as one, and every individual purpose stays separately controllable under the group's individual choices. Unless you object, a first-party request is reduced immediately to an anonymous daily service count under the PECR statistical-purposes exception. It has no visitor or device identifier and is not available for advertising. Switching Analytics off (or just its Aggregate service analytics individual choice) is the simple objection path and stops future counts. Every other optional purpose stays off unless you enable it. Essential (necessary and security) processing remains on so the shop can work safely. Each purpose describes a capability rather than a particular tool: the tools serving a purpose can change without changing what you consented to, and a genuinely new purpose would be asked for separately.

If you allow person-level analytics and replay, we remember your browser between visits and measure masked interactions such as clicks, scrolling and pages viewed so we can understand journeys and fix usability problems. Text entered into forms is masked before it leaves your browser. You can change each purpose at any time using the Cookie settings link in the footer. For the complete cookie list and retention periods, see our Cookie Policy.

If you are signed in to an account, we may link the activity we are allowed to collect across the different devices you use - for example your phone and your laptop - so we can recognise it is the same person and understand your journey as a whole. We only combine activity from a device where you have accepted analytics cookies on that device; a device where you declined is not tracked in this way, even when you are signed in, because cookie consent is given per device.

We keep an immutable receipt for each purpose choice, including the decision time, policy version, device identifier, shortened IP address and reduced browser description. We also record the consent screen and recheck reason, site origin and release, bounded display dimensions, and read, write and readback outcomes for the necessary consent storage keys. Those outcomes do not contain the values stored in the keys. If your email later becomes known, the receipt can carry a one-way email hash. A withdrawal creates a new linked receipt rather than rewriting the earlier record. We use this history to honour and demonstrate your choices; it is described in our Cookie Policy.

At checkout we also save the shipping address you submit to your browser's local storage on this device, so your next checkout can pre-fill the form. It never leaves your device. You can clear it any time from the link in the checkout form, and the full retention period is documented in our Cookie Policy.

Product verification & QR scans

Our products carry a QR code / batch verification link. When you scan it or open the link, we record the scan - including the batch code, the date and time, and limited technical information about the request - to confirm product authenticity, monitor for counterfeit activity, and understand how our certificates of analysis are accessed. Where you are already identified to us (for example, you are signed in, or you have an existing first-party analytics identifier from our site), we may associate the scan with you. We process this on the basis of our legitimate interests in protecting product integrity and improving our service. You can object to analytics processing at any time via our cookie settings; verification itself does not require you to be identified.

Security and fraud prevention

To protect your account and our store from fraud and abuse, we automatically record technical information about certain security-relevant requests: when you sign in (including failed attempts), create an account, enter your delivery address or place an order at checkout, change your account details, subscribe to updates or the certificate-of-analysis waiting list, when you make a choice about cookies, and when our systems throttle repeated requests.

For each of those moments we record:

  • your IP address, including the address we observe at our network edge, and details about the network it belongs to (the network operator, and whether it looks like a home connection, a data centre, a VPN or similar)
  • the approximate location derived from that IP address by our hosting provider - country, region, city, postal district, timezone and approximate city-level coordinates. This is an estimate from the network, not your device's precise location. For the cookie-choice moment we record no location at all
  • your browser and device details - the browser identification string, your preferred languages, and the technical hints your browser sends by default, which can include the device model
  • this site's own device and session identifiers, read from cookies that are already on your device. In this security system they are used for security only, as strictly necessary to protect the service
  • where you provide it, your email address, one-way scrambled versions of it, and an automatic check that its mail domain really exists
  • references to your account, basket or order where the request relates to one
  • simple derived indicators, such as whether the email domain is a known throwaway provider or whether the browser details look internally inconsistent

We use this information to detect and prevent fraud, account takeover, automated abuse, and duplicate or fake accounts. We never use it for advertising, we never sell it, and we do not use it to build marketing profiles. Security records may be used to notice that two accounts appear to belong to the same customer - see Keeping customer records accurate below. They are visible only to our own staff, and within our own team only to the people who handle security and fraud.

Our lawful basis is our legitimate interest in keeping our store and your account secure and, for the prevention and detection of crime such as payment fraud, the recognised legitimate interest basis. We keep most of this security information for no longer than 90 days and then delete it permanently. Records that relate to an order are kept for no longer than 180 days, because a payment dispute such as a chargeback can be raised months after a purchase and those records are the evidence we would need to answer one. There is one further exception: where the information is evidence in a dispute or investigation that is already open, such as a chargeback, a fraud investigation, or an investigation into misuse of an account, we keep just the records relating to it until it is resolved, as the law allows for legal claims, and delete them afterwards.

You can object to this processing or ask us to delete your security records at any time by emailing us at the address in the Contact us section below; where we rely on it to prevent fraud we may continue processing if we have compelling grounds, but we will always consider your request.

Keeping customer records accurate

If you have shopped with us under two different email addresses, we may notice this and link the two records, so that our records are accurate and your history is in one place. We decide that two records belong to the same person using only details you typed into your own shopping with us: the email addresses themselves (for example, where one is an obvious one-character typo of the other), the name and delivery town and postcode you gave at checkout, and the timing and contents of your own orders and baskets. We do not use your IP address or your device identifiers to make that decision.

An AI assistant, provided by Anthropic (listed above), compares those details for us. Where the evidence is at its strongest - an obvious typo variant of the same email address together with matching checkout details - the link may be made automatically. In every other case a member of our team reviews the suggestion and decides. Every link is recorded together with the evidence and reasoning behind it, and links can be undone. If we ever introduce a further method of deciding that two records belong to the same person, we will update this notice before we start using it, and only where a further assessment supports it.

Our lawful basis is our legitimate interest in keeping accurate customer records. Linked records mean our customer service and, where you have opted in, our marketing see one accurate history instead of two partial ones. You can object to this linking at any time by emailing privacy@kovalabs.co.uk, and we will unlink your records on request.

Your rights

Under UK GDPR you have the right to:

  • ask for a copy of the personal data we hold about you (access)
  • ask us to correct data that is wrong or incomplete (rectification)
  • ask us to delete your data, where this applies (erasure)
  • ask us to limit how we use your data while a question is resolved (restriction)
  • receive the data you gave us in a machine-readable format (portability)

Your right to object

You can object at any time to us using your personal data for direct marketing. This right is absolute. If you object, we will stop straight away. Use the unsubscribe link in any marketing email, or email privacy@kovalabs.co.uk.

You can also object to processing we carry out under legitimate interests, such as fraud prevention or partner crediting. Email privacy@kovalabs.co.uk. We will stop unless we have compelling legitimate grounds to continue.

Withdrawing consent

Where we rely on your consent, you can withdraw it at any time. Use the unsubscribe link in any marketing email, or the Cookie settings link in the footer for optional cookies. Withdrawing consent does not affect processing that happened before you withdrew.

To exercise any of these rights, email privacy@kovalabs.co.uk. We will respond within one calendar month.

Complaints

If you are unhappy with how we have handled your data, please contact us first and we will try to put it right. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk, helpline 0303 123 1113, or Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.