Privacy Policy

We are committed to safeguarding your privacy rights and ensuring that your personal data is protected.

This Privacy Policy explains the types of personal data we collect and how we process and protect that data in connection with the services we offer. This includes information collected offline in our stores or through our customer services, and online through our websites, applications (including mobile apps) and third party platforms (“Sites”).

This Privacy Policy also applies to our targeted content, including online offers and advertisements for products and services, which you may see on third party websites, platforms and applications (“Third Party Sites”) based on your online activity. These Third Party Sites may have their own privacy policies and terms and conditions. We encourage you to read them before using those Third Party Sites.

1.Who is responsible for what happens with your data?

Superdrug Stores plc ("Kind Patches" or “we”) are responsible for processing your personal data on our Site. 

2.How do I contact the Data Protection Officer?

If you have a question in relation to how we process your personal data you can contact our Data Protection Officer via email

3.What is Personal Data?

Personal Data means information that can directly or indirectly identify you ("Personal Data"). This typically includes information such as your name, address, email address, and telephone number, but can also include other information such as IP address, shopping habits, information about your health and information about your lifestyle or preferences such as your hobbies and interests. Information about health are called “special categories of Personal Data” that require special protection because of their sensitivity.

  1. What happens when you provide us with your Personal Data or when we otherwise receive your personal data?

We collect your Personal Data directly in a number of ways, for example when you provide us with your information to register as a customer for our site, register for prize draws or competitions, subscribe to our newsletter, receive information or mailings, use our applications, buy a product or service from us, complete a survey, complete a beauty or health diagnostic test, make a comment or enquiry or contact our Customer Team.

When you provide us with your Personal Data, we will process it in accordance with this Privacy Policy. If you do not wish us to process your Personal Data in this way, please do not provide us with your personal information.

We may also receive your Personal Data from other sources, including information from commercially available sources, such as public databases and data aggregators, and information from third parties. If you do not want us to receive your Personal Data from other sources, please communicate your preferences directly with the relevant sources.

We process your Personal Data to provide you with our services as further explained below. In certain instances, we only process your Personal Data if you have given us permission to do so, for example in most cases where we process your Personal Data for marketing purposes, use cookies or location data or where we process your sensitive personal information. In other instances we may rely on other legal grounds for processing your personal data, such as performance of the contract with you or legitimate interests, like fraud prevention.

Where we process your Personal Data on the basis of your consent, we will ask for your consent explicitly and only for a particular purpose. We will also ask you to provide additional consent if we need to use your Personal Data for purposes not covered by this Privacy Policy.

Please refer to the table in Section 6.1 for details of the various types of Personal Data we may collect, the relevant purposes and the legal basis for such processing.

  1. What happens if our customer is a child?

Our Sites are intended for adults, but there could be instances where some customers under the age of 13 view or purchase products on our Sites. If we know a customer is under the age of 13, we will not use such customer’s Personal Data for marketing purposes unless parental consent is provided to us.

To provide parental consent to marketing, please ask your parent or guardian to contact our Customer Team, and they will be able to help you

In some cases, we will infer from your actions that you obtained parental consent. We then reserve the right to decide whether you will receive our marketing until you reach the eligible age.

Note however that access to certain parts of our Sites and/or eligibility to receive prizes, samples or other rewards may be limited to users over a certain age. We may use your Personal Data to carry out age verification checks and enforce any such age restrictions.

  1. For which purposes do we process your Personal Data?

6.1 To see which categories of Personal Data we collect for which purposes, click on the headings below: 

Purchasing/Agreeing to purchase a service

Customer Service 

Suggesting Products and Services that may interest you

Online Shopping

Fraud Prevention and Other Administration Services

6.2 Cookies and Similar Technologies

We use cookies and similar technologies (“Cookies”) to improve our products and your experience on our Sites by collecting information on how you use our Sites. Some of the Cookies we use are required to enable core site functionality, for example to provide secure log-in or to remember how far you are through an order, but we also use Cookies that allow us to analyse site usage (so we can measure and improve performance), and advertisement Cookies which are used by advertising companies to serve ads that are relevant to your interests.

We may also tailor our Sites and our products to your interests and needs, by collecting information about your device and linking this to your Personal Data so as to ensure that our Sites present the best web experience for you.

Where we use Google Analytics, we have set up the service to anonymize your IP address as soon as data is received by the Analytics Collection Network  , before any storage or processing takes place. To opt out of being tracked by Google Analytics across all websites please visit

You can view more information on the Cookies we use and adjust your preferences via the Cookie Consent Tool on our Sites. Please note, however, that without cookies you may not be able to use all of the features of our Sites or online services.

7Who do we share your Personal Data with?

7.1 Our Service Providers

We share your Personal Data with the following data processors (i.e. service providers that help us to perform the above tasks):

  • trusted third parties which directly support our promotional activities, and site administration 
  • trusted third parties to help us process and analyse your Personal Data for us, to support us when suggesting products & services which may interest you in line with Section 6.1 above.
  • if you order a product or service from us, trusted third parties to allow payment and delivery of the products and services you have ordered.  Unless you provided consent, any such trusted third parties are not authorised by us to use your Personal Data in any other way and will be required by us to implement adequate technical and organisational measures to protect your Personal Data.

7.2 Other Recipients

We share your Personal Data with the following third parties that process your Personal Data for their own purposes (i.e. these third parties are no processors; they rather use your Personal Data because they have their own interest or because you had consented):

  • interested third parties that will send you marketing, but only if you consented to receive such communications from them.
  • law enforcement or other agencies if we are required to do so by law, or by a warrant, subpoena or court order to disclose your Personal Data.

Please note that we never share your Personal Data with social media platforms. When we engage in audience building or customer matching activities with social media platforms like Facebook or Google, your Personal Data is always anonymized before the transfer. If there are any changes in the future and we have to share your Personal Data with a social media platform, we will ask for your consent.

7.3 Sharing your Site Usage Information

With your consent, we will share Site usage information with trusted third parties (e.g. advertisers, advertising agencies, advertising networks, data exchanges, etc.) in order to offer you tailored content which may be of interest to you based on your prior activity on our Site. These trusted third parties may set and access their own Cookies, web beacons and similar tracking technologies on your device in order to help us deliver customised content and advertising to you when you visit our relevant Sites. Please see Section 6.2 for more information about Cookies and how to opt out.

You can also visit the website to choose which companies can deliver customised advertisements.

Please note that even if you opt out, you may still receive advertisements from us that are not customised based on your Site usage information.

  1. To which countries do we transfer your Personal Data?

All of our trusted third parties are based in countries that provide an adequate level of data protection, such as the UK and the European Economic Area.

When we need to transfer your Personal Data to a trusted third party based in a country where data protection laws are considered not to offer the same level of protection, we ensure adequate data protection safeguards by relying on other legitimate means, such as the Privacy Shield certification and/or Standard Contractual Clauses.

More details on the transfer mechanism can be obtained from our Data Protection Officer (see contact details in Section 2).

9How long do we process your Personal Data?

We will store your Personal Data only until the aforementioned purposes for which we have collected or received your Personal Data are fulfilled and once our statutory obligations to preserve records have expired as further described in Section 6.1.

10What are your rights?

If certain requirements are fulfilled, you have the right to:

  • Obtain from us confirmation as to whether or not we process Personal Data from you and, where that is the case, access to your Personal Data;
  • Rectification of inaccurate Personal Data;
  • Erasure of Personal Data;
  • Objection to the processing of Personal Data;
  • Restriction of processing of Personal Data; and
  • Portability of Personal Data - receive the Personal Data you have provided to us in a structured, commonly used and machine-readable form and transmit it to another data controller.

You can learn more about these rights here: To exercise your rights, please contact the Data Protection Officer (see Section 2 for contact details) or get in touch with our Customer Team on the details set out below.

Note that you do not need to contact our Data Protection Officer to exercise your rights to stop receiving marketing communications from us. You can opt out of receiving such communications by going to the Privacy Preferences section of your 'My Account' if you have an account with us, directly from the communications we send you or by contacting our Customer Team.

11Can you withdraw your consent to the processing of personal data?

Where your consent is the legal basis for the processing of your Personal Data, you can withdraw your consent for:

  • Marketing communications: by logging into your account under Privacy Preferences or using the unsubscribe link in any of our marketing communications.
  • Use of Cookies: via our Cookie Consent Tool at the bottom of our Sites.
  • Other purposes: by sending us an email to or by contacting our Customer Team as detailed in Section 10.

Please note that withdrawing your consent will not affect the lawfulness of the processing before the withdrawal.

  1. Can you complain with the data protection authorities?

If you think that the processing of Personal Data by us violates data protection laws, you can lodge a complaint with the Information Commissioner in the UK ( or the Data Protection Commissioner in the Republic of Ireland (

  1. How do we protect your Personal Data?

We maintain appropriate technical and organisational measures to protect the Personal Data you provide to us against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your Personal Data.

  1. Can we change our Privacy Policy?

We may change this Privacy Policy from time to time by posting the updated version of the Privacy Policy here. We encourage you to visit this area frequently to stay informed.