Privacy Policy

Bella Coco Ltd Privacy Policy

The Crochet Community is a trading name of Bella Coco Ltd. All references to “we”, “our”, or “us” in this privacy policy refer to Bella Coco Ltd, the legal entity behind The Crochet Community.

Bella Coco Ltd is a company registered in England and Wales (Company Registration Number: 9990941). Our registered office is at 6 Clinton Avenue, Nottingham, England, NG5 1AW. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Bella Coco Ltd is the Data Controller.

If you have any questions about how we handle your data, please contact us at help@bellacococrochet.com.

1. Introduction

The Crochet Community is an online platform passionate about fostering a vibrant and inclusive community for crochet enthusiasts. Our mission is to provide a supportive space where members can connect, learn, and share their love for crochet.

This privacy policy explains how we collect, use, store, and share your personal data when you visit and use our website properties (including bellacococrochet.com and thecrochetcommunity.com), and your rights regarding that data.

2. Information We Collect and Our Lawful Basis

Under the GDPR, we must have a valid “lawful basis” for processing your personal data. We collect the following categories of information:

Account & Identity Data

  • What it Includes: Name, email address, username, password.
  • Purpose: To register your membership and provide access to the platform.
  • Lawful Basis: Performance of a Contract

Financial Data

  • What it Includes: Billing address, payment card details, transaction history.
  • Purpose: To process membership payments and prevent fraud.
  • Lawful Basis: Performance of a Contract & Legal Obligation (tax/accounting records)

Profile & Community Data

  • What it Includes: Forum posts, comments, photos, voluntary survey responses.
  • Purpose: To facilitate community interaction and provide our core services.
  • Lawful Basis: Legitimate Interests (fostering our community) & Consent

Technical & Usage Data

  • What it Includes: IP address, browser type, operating system, pages visited.
  • Purpose: To ensure site security, analyse trends, and improve user experience.
  • Lawful Basis: Legitimate Interests (network security) & Consent (for non-essential analytics)

Marketing Data

  • What it Includes: Preferences in receiving marketing from us.
  • Purpose: To send you newsletters, promotions, and updates.
  • Lawful Basis: Consent

3. Age Assurance & Special Category (Biometric) Data

To comply with our legal obligations under the UK Online Safety Act 2023, the Australian Online Safety Amendment Act 2024, and the Texas SCOPE Act, we must stress that our website is not intended for individuals under the age of 18.

3.1. Purpose of Processing: We process biometric data (facial geometry) for the sole purpose of age assurance to protect children from accessing age-restricted services (Social Media).

3.2. Lawful Basis: Under the UK GDPR, biometric data used for identification is classified as “Special Category Data.” We process this based on Substantial Public Interest (safeguarding children) and your Explicit Consent, which you provide prior to initiating the scan.

3.3. Data Minimisation & Retention: We utilise a strict “Short-Term-Retention” model.

  • Our Role: The Crochet Community receives only a “Pass/Fail” token. We do not receive, view, or store your biometric image on our servers.
  • Partner Role: Our third-party age assurance provider, didit.me (ISO 27001 & iBeta Level 1 certified), captures the scan via an encrypted tunnel. The biometric template is used only for the duration of the calculation (typically under 2 seconds) and is retained for a maximum period of one month before being permanently deleted.

3.4. ID Check Fallbacks: If the age estimation system cannot confirm age with high confidence, we offer a “Document Fallback.” didit.me will verify a scan of your government-issued ID. This document is used strictly for age verification and is NEVER shared with any other parties.

4. How We Share Your Information (Third-Party Processors)

We do not sell your personal data. We share your data only with trusted third-party service providers (Data Processors) who assist us in operating our platform. We have appropriate Data Processing Agreements (DPAs) in place with:

  • WordPress & BuddyBoss: To host our website and facilitate the community forum structure.
  • PMPro & High Level: To manage your membership subscription lifecycle.
  • Stripe: To securely process your financial transactions. (We do not store your full credit card details on our servers).
  • Flodesk: To manage our email marketing communications.
  • Didit.me: To provide secure age assurance and verification as detailed in Section 3.

We may also disclose your data if required by law, regulation, or a valid governmental request, or in the event of a merger, acquisition, or sale of business assets.

5. International Data Transfers

We are based in the United Kingdom. However, some of our third-party processors (such as Stripe and Flodesk) may store or process data outside of the UK or the European Economic Area (EEA), predominantly in the United States.

Whenever we transfer your personal data outside of the UK/EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • The country has been deemed to provide an Adequate Level of Protection by the UK Government / European Commission.
  • We use specific contracts approved for use in the UK (the International Data Transfer Agreement / Standard Contractual Clauses) which give personal data the same protection it has in the UK.
  • The provider is certified under the UK Extension to the EU-US Data Privacy Framework.

6. Data Security & Retention

We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way.

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements:

  • Account Data: Kept for the duration of your active membership. If you cancel your membership, we will erase your profile data after 365 days of the cancellation. You can request this to be erased sooner and we will action such requests as soon as practicable.
  • Financial Data: Kept for 7 years to comply with UK HMRC tax and accounting laws.
  • Biometric Data: Processed instantly and permanently deleted by our provider within 1 month.

7. Your Legal Rights

Under the UK GDPR, you have the following rights regarding your personal data:

  1. The Right to Access: Request a copy of the personal data we hold about you.
  2. The Right to Rectification: Request correction of incomplete or inaccurate data.
  3. The Right to Erasure (Right to be Forgotten): Request deletion of your personal data where there is no good reason for us continuing to process it.
  4. The Right to Restriction: Ask us to suspend the processing of your data in certain scenarios.
  5. The Right to Data Portability: Request the transfer of your data to you or a third party in a structured, machine-readable format.
  6. The Right to Object: Object to our processing of your data where we are relying on a legitimate interest. You have an absolute right to object to direct marketing.
  7. The Right to Withdraw Consent: Where we are relying on consent to process your data (e.g., marketing emails or age verification), you can withdraw it at any time.

To exercise any of these rights, please email help@bellacococrochet.com. We aim to respond to all legitimate requests within one month.

8. Cookies and Tracking Technologies

We use cookies to distinguish you from other users, manage your session, and improve our website. For detailed information on the non-essential cookies we use, the purposes for which we use them, and how you can manage your preferences, please see our Cookie Banner.

9. Complaints

If you have any concerns about our use of your personal information, you can make a complaint to us at help@bellacococrochet.com.

You also have the right to lodge a complaint at any time with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). If you are based in the EU, you may complain to your local supervisory authority. We would, however, appreciate the chance to deal with your concerns before you approach the ICO.

10. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on our website or sending an email to registered members.

This Privacy Policy was last updated on 05.08.2026.

f.t.