You hold more customer data than you think, mostly in your phone. What to collect, where to keep it, what to delete, and the privacy note you can copy.
Sailo team14 min read
Count the places a customer's address currently exists in your life. WhatsApp thread. Screenshot in your camera roll. A notes app. A spreadsheet. A courier's website. A scrap of paper by the kettle. If you've been selling for a year at 30 orders a month, that's 360 people whose home addresses are scattered across six systems you've never thought of as systems.
Collect only what the order needs, keep it in as few places as you can name out loud, never add someone to a marketing list because they bought something, and delete what you no longer need. Then write three sentences telling buyers what you do, and put them where they can see them.
This is good practice, not legal advice. If you're in the UK, the regulator is the Information Commissioner's Office and their site has a section written for small organisations. Read that rather than a blog, this one included, before you decide what your obligations are.
Write the list down once. It's uncomfortable and it takes about ninety seconds.
The riskiest thing in most small shops isn't the shop. It's the phone in your pocket, holding a year of addresses in a chat backup, signed into a laptop somebody else in the house also uses.
The simplest privacy improvement available to you is a field test. For every piece of information you ask for, ask: does this change anything I do?
Every field you don't collect is a field you can't lose, can't leak and don't have to look after. For a digital product, you may need nothing but an email address. For a service booking, a name and a way to reach them.
The safest place to keep a piece of customer data is in a form you never asked for it in.
Most small sellers don't have a data problem in their shop. They have one in their handset.
Four things that take an evening and cover most of the real risk:
A screen lock and a device that's encrypted by default. Modern phones do this if you set a passcode. Without a passcode, a lost phone is a lost customer list.
Two-factor authentication on the email address everything resets to. If someone gets your email, they get the shop, the courier account, the payment account and the chat history. This is the single highest-value hour on this list.
Stop keeping order screenshots in the camera roll. They sync to a cloud album that might be shared with a family member, and they get backed up in places you'll never audit. Move the order details somewhere deliberate and delete the picture.
One place for orders, not five. A single sheet, or your shop's order list, with everything in it. Scattered data is what makes deletion impossible later, because you can never be sure you got it all.
If you share a laptop, use separate user accounts. It's free and it takes ten minutes.
I'm not going to give you thresholds, fees, deadlines or article numbers, because getting one of them wrong would be worse than saying nothing.
What's worth knowing is the shape of it:
There are rules about personal data, and running a tiny business doesn't exempt you. In the UK the framework is UK GDPR and the Data Protection Act 2018, overseen by the ICO. Most of the other markets these articles cover now have their own data protection law and their own regulator. Look up yours by name rather than assuming your country's rules match the UK's.
Some organisations that handle personal data have to pay a data protection fee. In the UK that's paid to the ICO, and whether you owe it depends on what you do. Their site has a self-assessment. Do that rather than guessing either way.
Marketing messages are governed separately from data protection, and the marketing rules are usually stricter about unsolicited email and SMS than people expect. "They bought from me, so I can email them" is not a safe assumption anywhere. Check before you build a list.
If you sell to buyers in another country, their rules may apply to you. A UK seller shipping to the EU, or a Nigerian seller with UK customers, is worth ten minutes of reading rather than a shrug.
The general registration question for a small shop, which is different from the data question but usually asked at the same time, is in do you need to register your business, and the UK-specific setup is in selling online in the UK.
Most small sellers need something short and true, not a 2,000-word policy copied from a template site. Here's the short version, for a shop page or a bio link:
Your details. I use your name, address and phone number to make and deliver your order, and to talk to you about it. I don't sell or share your details with anyone except the courier who delivers your parcel. I keep order records for as long as my tax rules require, then delete them. If you want to know what I hold about you, or want it removed, message me and I'll sort it.
Three sentences and an offer. It's honest, it's readable, and it tells a buyer the two things they actually want to know: are you going to sell my number, and can I get out.
If you run a mailing list, add one line:
I only email you if you've asked me to, and every email has an unsubscribe link that works.
If you take card payments, add:
Card payments are handled by Stripe. Your card details go to them, never to me, and I never see your card number.
That last line is worth putting in even though it's boring, because a decent share of first-time buyers hesitate over exactly that.
The tempting move, after a year of orders, is to put 400 phone numbers into a broadcast list and announce a sale. Don't, and not only for legal reasons.
Ask, and ask at a moment when the answer is likely to be yes. The best one is right after delivery:
Glad it arrived. Want me to message you when I do the next batch? Reply YES if so, and nothing at all if not, I won't be offended.
That gets you a smaller list of people who want to hear from you, which outperforms a big list of people who didn't ask, and it means the broadcast doesn't cost you the goodwill you just earned.
Two practical rules once you have a list. Keep a record of who said yes and when, because "they opted in" is only useful if you can show it. And make leaving easy: a reply of STOP, an unsubscribe link, something that works without them having to ask you twice.
One email on pricing, photographs, delivery and getting paid. No pitch, no filler.
You want to post the lovely message someone sent you. Fine. Before you do:
The rule that keeps this simple: no customer appears in your marketing by accident. Only on purpose, and only after they've said yes.
Nobody should be sending you a card number in a chat, and if someone does, don't act on it and don't keep it. Ask them to pay through the payment link instead, and delete the message.
Bank details are different, because on a transfer rail you'll inevitably have some. Two habits: only ever refund to the account the money came from, and don't keep a spreadsheet column of customer account numbers you don't need. You needed it once, on the day of the refund, and after that it's a liability sitting in a file.
Deletion is the part people skip, mostly because there's a genuine conflict: your tax authority wants records kept for a set number of years, and privacy practice wants old data gone.
The way to hold both: split the record. What the tax authority needs is usually the transaction, the amount and the date. What it doesn't need is the WhatsApp thread where someone told you their gate code and mentioned their divorce.
So a sensible annual habit looks like this:
The record-keeping side is covered properly in keeping records when you hate paperwork, and the retention question specifically is part of what to do about tax on online sales.
It'll happen once or twice a year, usually from someone who's annoyed about something else. Don't get defensive.
Of course. What I've got is your name, your address, your phone number and a record of the two orders you placed, in March and in July. I'll delete the chat and your contact details today. I have to keep the sales records themselves for tax, but they'll only show the order and the amount.
Say it plainly, do it that week, and tell them when it's done. This is one of those situations where the honest, unhurried answer converts an irritated person into someone who quietly thinks better of you.
You email 40 customers and put every address in the To field instead of BCC. Your phone is stolen. A shared spreadsheet gets a public link.
First hour: stop the leak. Recall or delete what you can, change the passwords on the affected account, revoke the link, wipe the device remotely if you can.
Then write down what happened, when you noticed, whose data was involved and what you did. That note is what you'll need if you have to report it, and it's much harder to write three weeks later.
Then look up the reporting rules for your regulator, because there are deadlines and I'm not going to guess them for you. Telling the affected people plainly and early is almost always the right instinct.
Hannah makes cold-process soap in Sheffield, £6.50 a bar or £17 for three, roughly 90 orders a month, mostly through Instagram and a shop link. Payment is about half bank transfer, half card.
She did the ninety-second list and found buyer data in nine places: Instagram DMs, WhatsApp, two spreadsheets, her camera roll, her email, the courier's site, a physical notebook, and a Google Form she'd used for one market stall in 2024 and forgotten about.
The form was the one that mattered. 212 names, addresses and phone numbers, in a sheet with a sharing link she'd sent to a friend who helped on the stall. It had been open for over a year.
What she did in one evening: deleted the old form and its responses, turned on two-factor on her email, moved everything to one order sheet, deleted 400-odd order screenshots from her camera roll, and wrote the three-sentence privacy note onto her shop page.
Then the habit: on the first Sunday of every month she clears chat threads older than a year and empties the screenshots. It takes about five minutes.
The bit that surprised her was the marketing list. She'd been broadcasting to 260 WhatsApp contacts collected from orders. She replaced it with an opt-in message sent after delivery and ended up with 78 people. Her sale announcement to 78 people sold more than the last one to 260, and she got zero of the "how did you get my number" replies she used to get every single time.
Two useful things. On card, the card details go to Stripe, not to you: the charge lands in your own Stripe account and you never see or store a card number, which removes the most dangerous category of data from your business entirely. And having the catalogue, options and order in one place means the buyer's details arrive in one record instead of being reconstructed from a chat.
The limits are real. A WhatsApp order still arrives in WhatsApp, so that thread, with the address and everything else the buyer typed, lives on your phone under your control, not the shop's. Your bank statement is yours. Your camera roll is yours. No shop tool can tidy those, and they're where most of the exposure actually is.
Worth knowing when you pick a plan: how far back your analytics go depends on it, 7 days on free, a year on Pro, three years on Business. That's a data retention decision you're making whether you think of it that way or not, and less history is not automatically worse. And the privacy note that describes your business has to be written by you, because most of what it needs to describe happens outside the shop.
The wider job, being someone a stranger is comfortable handing an address to in the first place, is in building trust before money moves.
Write down every place a customer's name or address currently exists. Phone, laptop, cloud, paper, third-party sites, old forms.
You'll find at least one you'd forgotten, and it'll probably be a form or a spreadsheet shared with someone who stopped helping you months ago. Close that one first.
Then paste the three-sentence privacy note onto your shop page and put a five-minute clear-out in your calendar for the first Sunday of next month.
Written by
Sailo team
One link, your whole shop.
One email on pricing, photographs, delivery and getting paid. No pitch, no filler.
Sailo just gives it a front door — so people can browse, compare and see prices before they message you.
Get your linkFree while in beta · No card required