YOUR INFORMATION
Your information, clearly explained.
This policy explains what personal information WE BUY BACK LTD handles, why we need it and the choices available to you when you browse our website, place an order or send us a product.
Last reviewed 1 September 2026
1. About this policy
This policy applies to the We Buy Back website, customer and business enquiries, product buyback or recycling orders, parcel journeys, inspections and payments. It should be read alongside our Terms and Conditions.
1.1 Who controls your information
WE BUY BACK LTD is the controller responsible for the personal information described in this policy. We are registered in England and Wales under company number 16713774. Our registered office is 11 The Crofts, Rotherham, England, S60 2DJ. The current director is Zohab Khan.
Companies House registration alone is not a postage instruction. Follow only the postage route and address attached to your order. The registered office is not presented as a public walk-in or general drop-off point.
1.2 How to contact us about privacy
Use the dedicated privacy request form at the end of this page. It lets you choose the right request type and gives our team the information needed to locate the relevant records without asking you to disclose sensitive details in an ordinary message.
2. Information you provide
The information we collect depends on what you ask us to do. We do not need every category of information for every visitor.
2.1 Checkout and customer details
When you place an order, we may collect your name, email address, telephone number, postal address, order selections, postage choice, payment choice and the confirmations you make about ownership, device preparation and account locks. Checkout can also submit the seller type, company name, company number and VAT number when those fields are supplied. A company number or VAT number can remain in a submitted checkout after the seller choice is changed from business to consumer; the different storage and handover treatment is explained below.
2.2 Payment instructions
For Bank Transfer, this can include the account holder name, account number and sort code. For PayPal, it includes the PayPal email address. For Cheque, the payment instruction includes the payee name; the cheque is sent to the customer postal address stored in the ordinary order and customer record. We use the information for the payment route you selected and for associated reconciliation and support.
2.3 Enquiries and business information
If you contact us, we collect the details you submit, the subject of your enquiry and our response history. Business or corporate enquiries may also include an organisation name, role, inventory information and collection requirements.
3. Order and inspection records
3.1 The order record
We keep the order number, products, selected conditions, preliminary quotes, postage and payment methods, order status, timestamps and communications needed to manage the transaction. The readable order also keeps the seller type. It keeps the company name, company number and VAT number only when the seller is recorded as a business. The website sends the completed checkout to Aevum, which owns the resulting customer and order record.
3.2 Product identity and history checks
An inspection process may record identifiers such as an IMEI or serial number and may submit the identifier to a device-history service such as CheckMEND, operated by Recipero. Live use of CheckMEND was not verified at this review date. If used, a result can contain information relevant to ownership, loss, theft, insurance, network or finance status.
3.3 Inspection evidence
Inspection notes, diagnostic results and photographs may be created to document the product received, explain the outcome, investigate suspected fraud, answer a dispute and demonstrate how an order was handled.
4. Data on received devices
Your phone, tablet, laptop or smart watch may contain personal content that is separate from the customer and order information described above.
4.1 Prepare the product before sending it
Back up anything you want to keep, sign out of accounts, remove activation locks, remove SIM and memory cards, and erase the product where possible. Our How to Prepare Your Device page gives step-by-step guidance.
4.2 If information remains on the product
Product handling should be limited to identifying the product, checking its security state, inspecting it and erasing it where this can be done safely. Operational staff handling has not been independently verified for this policy, so customers should erase the product before sending it wherever possible.
4.3 When erasure is not possible
A passcode, activation lock, technical fault or safety issue can prevent normal access or erasure. We do not defeat security controls merely to reach personal content. The product may need to be returned, held while we contact you, or handled through an appropriate secure reuse or recycling route.
4.4 Free recycling orders
The same preparation guidance applies to a £0.00 recycling order. Erase the product before sending it wherever possible; a zero-value order does not make remaining personal content safe to leave on the device.
Do not send identity documents, payment cards, handwritten passwords or account recovery codes inside the parcel.
5. Website and communications
5.1 Technical information
When you use the website, technical records may include your IP address, browser or device type, pages requested, approximate time, referrer and security events. These records help deliver the site, diagnose faults and protect it from misuse.
5.2 Cookies and similar technologies
Essential technologies can remember basket and checkout state, maintain security and deliver functions you request. Optional analytics or marketing technologies should operate only where the required choice has been given. Our Cookie Policy explains the live storage inventory and preference controls in detail.
5.3 Service messages
The website can create records used to deliver order confirmations and support messages. Other services may send postage instructions, inspection outcomes, revised offers or payment updates when those services are active. These are service communications rather than marketing.
5.4 Optional marketing
The footer lets you request occasional email updates. The request is emailed to our support team for action in the marketing system and is not stored in a local website database. You can use the marketing opt-out page to object to direct marketing. Newsletter signup and opt-out requests submitted through this website are emailed to the support team rather than kept in a local marketing or suppression database. The team applies each request in the responsible marketing system. We must stop using the address for direct marketing once an objection is received, while retaining only what is necessary in that system to respect the choice. Stopping marketing does not prevent essential order or security messages.
6. Why we use information
UK data protection law requires a lawful basis for each use. The basis depends on the purpose and the information involved.
- Orders and payments
- To take steps at your request and perform the agreement, including creating the order, arranging postage, inspecting the product and paying the accepted amount.
- Accounting and legal records
- To meet tax, accounting, company, consumer protection and other legal obligations.
- Inspection and disputes
- To pursue legitimate interests in checking products accurately, documenting outcomes, answering complaints and defending legal claims, balanced against your rights.
- Fraud and security
- To meet legal duties and pursue legitimate interests in protecting customers, the business and product owners. A specific recognised legitimate interest is used only where all statutory conditions are met.
- Support and improvement
- To answer requests, diagnose problems and improve services where this is necessary for the agreement or our legitimate interests.
- Optional activity
- To use consent where the law requires a choice, including certain cookies or electronic marketing. Consent can be withdrawn at any time.
7. Who receives information
No sale, rental or trade of customer personal information was identified in the systems checked for this policy. Information can still leave the website through the specific operational, delivery, payment or legal routes described below when those routes are used.
7.1 Order platform and operational support
Product, price and availability information is requested from Aevum by the website server. The visitor's browser talks to the website rather than receiving credentials for the Aevum service.
Aevum also owns the basket. The website keeps its basket token in an HTTP-only cookie and uses it to read and update the basket on the visitor's behalf. Product identifiers, quantities, selected options and current prices are handled in that service before checkout.
At checkout the website sends Aevum the basket reference, customer and address details, seller type, applicable business details, postage method and the payment destination selected for the order. Aevum creates and retains the operational order; the website does not create a second local customer or order database.
7.2 Product history services
If CheckMEND is used, an identifier may be sent to CheckMEND, operated by Recipero, for product-history and risk information. Live use was not verified at this review date.
7.3 Postage and delivery providers
Aevum records the selected Royal Mail Free Post or Free Collection route. The website does not book a collection with Royal Mail directly. For the current Free Collection journey, the customer follows the Royal Mail link and provides or confirms the collection details directly to Royal Mail under its own service and privacy terms. Any separate operational label or provider connection outside the website systems reviewed, including any related transfer by We Buy Back, was not verified. If you choose Self Post, the carrier you appoint handles information under its own service and privacy terms.
7.4 Payment and professional services
When the relevant route is used, banks, Bacs participants, PayPal and postal providers receive the details needed for that payment or delivery. Hosting, security, communications, accounting, legal or professional providers may also receive information needed for the service they actually provide.
7.5 Authorities and legal disclosures
Information may be disclosed where the law requires it or where necessary to establish ownership, investigate crime or fraud, protect rights and safety, or respond to a lawful request from a court, regulator, law-enforcement body, insurer, finance provider or network.
8. International transfers
Some service providers may store or access information outside the United Kingdom. We have not independently verified every provider's current storage location or contractual safeguards. Where UK law requires protection for an international transfer, available mechanisms can include an adequacy regulation, the UK International Data Transfer Agreement or the UK Addendum to approved contractual clauses.
You may use the privacy request form below to ask which provider and transfer mechanism applies to your information. A particular safeguard is not treated as active in this policy unless it has been verified for that provider.
9. How long we keep information
Information is held across Aevum, support and communications systems and any providers used to complete an order. The website does not run a separate local customer, order, marketing or suppression database. Retention and deletion must be applied in each system that holds a copy. See Companies House for our first accounting period and GOV.UK for the six-year record rule.
This website does not keep a separate local customer or order database. Customer, order and payment information submitted during checkout is sent to Aevum, while form enquiries are delivered to the support mailbox. Removal from Aevum, communications providers, backups and operational records must be carried out in the system that holds each copy.
- Orders and accounting
- Our first accounting period ends on 30 September 2026. Core transaction and accounting records for that period are retained for six years after its end, through 30 September 2032, and become due for deletion from 1 October 2032 unless a legal hold requires longer.
- Inspection evidence
- Order and inspection records are held in Aevum and connected operational services rather than in a local website database. A later final order closure, complaint or legal hold can affect the applicable retention period. Retention and deletion for inspection photographs, video, diagnostics, CheckMEND results and notes must be applied in the system that holds each record.
- Payment destinations
- Payment instructions submitted at checkout are handled by Aevum as part of the order and are not retained in a separate local website database. The applicable operational, accounting and payment-provider retention rules continue to apply to copies held by those systems.
- Enquiries
- Ordinary enquiries are retained for 24 months. Enquiries connected to an order, complaint, privacy request or legal issue are retained for six years. An unresolved matter or legal hold can require a longer period.
- Security records
- Hosting, security and anti-abuse providers may keep technical records needed to protect the service. Their applicable retention and deletion rules are managed in the system that holds those records.
- Marketing preferences
- Newsletter signup and opt-out requests submitted through this website are emailed to the support team rather than kept in a local marketing or suppression database. The team applies each request in the responsible marketing system. We must stop using the address for direct marketing once an objection is received, while retaining only what is necessary in that system to respect the choice.
10. Security and decisions
10.1 Protecting information
Checkout details are sent from the website server to Aevum to create the order. The website does not retain a separate local copy of customer, order or payment-destination records.
Access to personal information should be limited to people and providers who need it for the stated purpose. No organisation can promise that every system is completely secure. The law can require investigation and notification when a personal data breach occurs.
10.2 Quotes and human review
The website can calculate a preliminary quote from the product, option and condition selections you make. The final order outcome follows receipt and inspection. Our process is designed so that a person can review inspection evidence, revised offers, complaints and exceptional decisions rather than relying only on a computer-generated result.
11. Your data rights
Depending on the circumstances, you may have the right to:
- ask for access to your personal information and information about how it is used;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information where there is no lawful reason to keep it;
- ask us to restrict how information is used in certain circumstances;
- receive eligible information in a portable format;
- object to processing based on legitimate interests;
- stop direct marketing at any time; and
- withdraw consent without affecting earlier lawful processing.
A marketing opt-out submitted through this website is sent to the support team for action in the responsible marketing system. Other objections are sent for staff to assess against the purpose and legal basis for the processing.
11.1 Making a request
Use the form below and choose the request that best fits. It emails the request to the support team and creates a reference; submitting the form does not itself erase retained order records or complete the later staff work. UK data protection law normally sets a one-month response period and permits limited extensions or clarification in defined circumstances.
Do not send passwords, full bank details, activation credentials, identity documents or a full IMEI through the form. This form cannot accept identity documents. Any separate secure verification route must be confirmed before it is offered.
11.2 Data protection complaints
You can choose “Make a data protection complaint” in the form. It emails the complaint to the support team and creates a reference. For a complaint received on or after 19 June 2026, section 164A of the Data Protection Act 2018 requires the controller to acknowledge receipt within 30 days of receiving it; without undue delay, take appropriate steps to respond, make appropriate enquiries and keep the complainant informed; and tell the complainant the outcome without undue delay. See the ICO's complaint-handling guidance, section 103 of the Data (Use and Access) Act 2025 and the commencement regulations.
The form does not itself acknowledge, investigate, send progress updates or issue an outcome. Those later steps require staff action, and the statutory duties above still apply.
You may also complain to the Information Commissioner's Office, the UK supervisory authority, through ico.org.uk.
12. Changes and contact
This policy should be reviewed when services, providers or legal obligations change. The current review date is shown at the beginning. Any direct notice required for a material change depends on the relationship and the law; this policy does not claim an unverified notification workflow.
12.1 Related privacy information
The Cookie Policy explains website storage and access technologies. Our GDPR and Data Rights page provides a practical guide to exercising data rights. The dedicated form below is one available route for a request about this policy or your information.