Simple, secure and family-first | Last updated: 17 August 2026
Our promise: We use your child's photo and details only to create the personalised product you ordered. We never sell children's data, and we never use children's photos for advertising, public sharing or AI model training without separate, clear permission. Production copies are securely deleted within 30 days after confirmed delivery.
TinyTalesCompany creates personalised children's books and gifts and is the data controller for the information covered by this policy. We process personal information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, for electronic marketing and cookies, the Privacy and Electronic Communications Regulations (PECR). Contact: sales@tinytalescompany.com.
We collect the customer's name, contact, billing and delivery details; order and payment status; and the child's name, age or age range, interests, selected story details and uploaded photographs. Under the UK GDPR, we process this information where necessary to perform our contract with you, take steps you request before an order, meet legal obligations, pursue legitimate interests such as security and customer service, or where you have given consent. Payments are handled by an authorised payment provider; TinyTales does not store full card details.
Orders and photo uploads must be submitted by an adult aged 18 or over who is the child's parent or legal guardian, or has their permission. We may use carefully selected AI-assisted tools to turn an uploaded photograph into story artwork, only for fulfilling the order. We do not permit customer images to train general-purpose AI models. Access is limited to authorised staff and approved providers who need the information to produce or deliver the order.
We do not sell personal information. We share only what is necessary with trusted providers such as website hosting, secure storage, payment, printing, delivery and customer-support services, or where the law requires it. Providers must protect the information and use it only for the agreed service. We use access controls, secure transfer and storage, staff confidentiality and deletion procedures to safeguard your information.
Children's uploaded photos and working production files are securely deleted within 30 days after confirmed delivery. If you report a problem, we may keep only the files needed until the replacement or complaint is completed. Order and accounting records may be retained for up to six years where required by tax, legal or accounting rules. Other information is kept only for as long as reasonably necessary.
Under the UK GDPR, you may ask to access, correct or erase your information; restrict or object to processing; receive certain information in a portable format; withdraw consent; and object to direct marketing. These rights may be subject to legal limits. Email sales@tinytalescompany.com. We normally reply within 3–5 business days and complete formal UK GDPR requests within the timeframe required by law.
We send marketing only where permitted, and you can unsubscribe at any time. Tagging TinyTales or sending a review does not automatically give us permission to reuse a child's image or book pages in advertising; we will ask separately. We may update this policy when our services or legal duties change and will publish the revised date.