Last updated June 2023
Choosing to shop with Victoria’s Secret means you've placed a great deal of trust in us. In sharing your personal information we hope you in return benefit from a tailored and convenient shopping experience. With trust comes responsibility and we take this responsibility very seriously.
This privacy policy helps you to understand how we use your personal information and who we share it with. It applies if you shop on a NEXT or Victoria’s Secret website, use the NEXT app, shop in a NEXT or Victoria’s Secret store or if you otherwise share your personal information with us, for example if you contact us with a query or we send you marketing.
We change the terms of this privacy policy from time to time and you should check it regularly. The last updated date is shown at the beginning of the document. If we make any material changes we will take steps to bring it to your attention.
We are NEXT Plc (company number: 4412362), when we say “we”, “our” or “us” in this policy we are referring to the companies that are part of the NEXT Group, which are:
Next Retail Limited, Next Holdings Limited, Next Distribution Limited, Next Manufacturing Limited, Next Sourcing Limited, Next Retail Ireland Limited, Next Germany GmbH, Next Beauty Limited, Lipsy Limited, Victoria’s Secret (VS Brands Holdings UK Limited), GAP (West Apparel UK Holdings Limited), Reiss (Pink Topco Limited), JoJo Maman Bébé (Regent BidCo 1 Limited) and Joules (The Harborough Hare Limited).
We are the data controller, which means we are responsible for deciding how and why your personal information is used. We are also responsible for making sure it is kept safe, secure and handled legally.
We operate to the highest standards when protecting your personal information and respecting your privacy. If you have any questions about your personal information, or how we use it, you can contact our Data Protection Officer via email at dataprotection@next.co.uk or by writing to our registered office at the below address:
Data Protection Officer, NEXT Group, Desford Road, Enderby, Leicester, LE19 4AT.
You have a number of "Data Subject Rights", we have explained below what they are and how you can exercise them. You can read more about these rights on the Information Commissioner's Office website at www.ico.org.uk
Right of access - You have the right to request a copy of the personal information that we hold about you.
Right to rectification - If you think any of your personal information that we hold is inaccurate, you have the right to request it is updated. We may ask you for evidence to show it is inaccurate.
Right to erasure (also known as the Right to be Forgotten) - You have the right to request that we delete your personal information that we hold.
Right to restriction of processing - You have the right to request we restrict or suppress the personal data we hold about you.
Right to data portability - You have the right to ask us to electronically transfer your personal information to another organisation in certain circumstances.
Rights with regards to automated decision making, including profiling - We sometimes use your personal information to make decisions by automated means. This involves us analysing your account activity including applications, orders, payments etc. We do this to confirm your identity, prevent and detect crime, and lend responsibly. This automated decision making is necessary if you would like to continue to shop with us online. You have a right to reject automated decisions, but it may mean that you can only shop with us in our stores.
Right to withdraw Consent - Where we are relying on your consent for processing you can withdraw or change your consent at any time.
The above rights may be limited in some circumstances, for example, if fulfilling your request would reveal personal information about another person, if you ask us to delete information which we are required to have by law, or if we have compelling legitimate interests to keep it. We will let you know if that is the case and will then only use your information for these purposes. You may also be unable to continue using our services if you want us to stop processing your personal information.
If you have any general questions or want to exercise any of your rights, please contact dataprotection@next.co.uk or visit https://www.next.co.uk/help for other ways to contact us. In order to maintain the security of our customers' personal details, we may need to request proof of identity before we disclose personal information to you in response to any request.
We encourage you to get in touch if you have any concerns with how we collect or use your personal information. You have the right to lodge a complaint directly with the Information Commissioner's Office, the data protection regulator in the UK, you can do this by visiting the ICO website: https://ico.org.uk/make-a-complaint/.
We will only ever process your information if we have a lawful basis to do so. The lawful bases we rely on are:
We collect and use the information that you provide to us directly, for example; when you register for an account; we use cookies and other similar technologies to collect information from your devices when you interact with our advertising or use our website (you can find out more information in the “Cookie Policy” section below); we keep records when you speak to our customer service teams; we use CCTV in our stores for security monitoring and market research purposes; we take personal information from a number of third parties to help us manage your account and improve your shopping experience.
To process any orders that you place with us and to facilitate any returns (Contract)
To provide you with access to an account (Contract)
To provide customer service to you (Legitimate Interest)
To offer and manage any credit we provide to you (Contract & Legitimate Interest)
To personalise and improve your experience when you shop (Legitimate Interest)
To inform you about products and services that may interest you (Legitimate Interest)
We use technologies such as cookies within digital marketing networks, ad exchanges and social media networks such as Facebook’s Custom Audience to get relevant marketing messages across to you and other customers. We share aggregated and anonymised information about the customer segments we are interested in reaching with advertising partners, so they can focus on showing adverts to those who are most likely to be interested in our products, services and offers, and to prevent them showing you irrelevant or repetitive advertisements.
To keep in touch with you (Legitimate Interest)
When you register for an account and shop with us we will keep you up to date with news of products and services including store events, offers, promotions and sale information - unless you tell us you don’t want us to through the “my account” or using the link in every email that we send to you.
n.b. If at any point you have made amendments to your contact preferences in the “my account” section of our website, selecting to receive communications from us, we are operating under consent instead of legitimate interest.
To ensure the Website and the services we offer you operate properly (Legitimate Interest/Consent)
To prevent and detect crime and other incidents (Legitimate interest/Legal obligation)
When you shop in our stores we use CCTV for security monitoring, and for the protection of our staff, customers and products. This includes for the investigation of accidents, incidents, criminal activities and breaches of our policies.
To fulfil our legal obligations (Legal obligation)
What are cookies?
Cookies are small text files that are stored on your computer, mobile device or other web enabled device when you visit the NEXT website or app. Cookies allow us to “remember” your actions or preferences over a period of time, or they may contain data related to the function or delivery of our websites. We also use the term “cookie” to describe similar technologies such as pixels or tags.
What do we use cookies for?
Some cookies are required by our site to enable you to transact whilst other cookies enable us to give you an enhanced, personalised web experience. We use cookies for the following purposes:
We also offer you the facility to share your experience on our website through social sites such as facebook and twitter. More information about how these providers use cookies can be found on their websites.
What cookies do we use?
NEXT uses the following cookies on our website and apps:
For more detailed information and a full list of cookies used on our website please select “Manually Manage Cookies” at the bottom of the page then click “Cookies Detail”.
Can I turn off or block cookies?
NEXT uses cookies to ensure that we provide the best possible standard of service to our online customers. You can change your cookie preferences at any time by clicking on “Manually Manage Cookies” at the bottom of the page. You can then adjust the available sliders to on or off, then click “Confirm my choices”. If you choose not to consent to the use of cookies your experience of our website may be impaired and many integral aspects of the website, including (but not limited to) adding items to your shopping bag and accessing your account, will not work.
Alternatively, most web browsers allow some control of most cookies through the browser settings. To find out more about how to manage cookies, including how to delete cookies, visit www.allaboutcookies.org
We keep your personal information as long as you are a customer of ours and generally for 7 years afterwards to comply with legal requirements. During that time we take steps to remove any personal data as soon as we no longer need it.
We consider you a customer:
We keep CCTV footage on our systems for up to 30 days, it is then deleted. Where accidents, incidents, criminal activities or breaches of our policies are recorded CCTV footage may be kept for a longer period of time.
We work with a number of trusted third parties to provide you high quality goods and services. Anybody we work with is subject to stringent security and data privacy assessments before we begin to do business with them and on an ongoing basis.
We always make efforts to anonymise data and only pass over personal information that is absolutely necessary for the purposes it is being processed. We always do so securely.
We have contracts in place with all suppliers that help us to ensure security and privacy of your personal information, these are reviewed and updated regularly and always in line with data protection laws.
NEXT Group companies - We will share your personal information, in certain circumstances with the other companies within the NEXT Group. This is so that we can provide personalised services across our Group.
Delivery Partners - Helping us to deliver the goods you order to you including our brand partners that dispatch and deliver goods to you directly.
IT Companies - Supporting us in maintaining our website and other business systems including; providing phone lines, data storage facilities, and providing and supporting Cloud based infrastructure used in providing our products and services.
Helping us to manage our electronic communications to you and to help us show you the advertising you are most likely to be interested in, companies that provide marketing and advertising assistance (including management of email marketing operations, mobile messaging services such as SMS, and services that deploy advertising on the internet or social media platforms, such as Facebook and Google) as well as analysis of the effectiveness of our advertising and communications campaigns.
We use technologies such as cookies, pixels, and device IDs within digital marketing networks, ad exchanges and social media networks such as Facebook’s Custom Audience to get relevant marketing messages across to you.
Consumer profiling organisations - These organisations provide demographic or other data to help better understand customers' demographics, lifestyles or shopping.
Payment processors - Payment card processors to process credit and debit card payments and store payment information.
Credit Reference Agencies (CRAs) - We share your personal information with CRAs on an ongoing basis, including details of settled accounts and any debts not fully repaid on time. CRAs will share your information with other organisations.
The identities of the CRAs, and the ways in which they use and share personal information, are explained in more detail at:
- Experian Credit Reference Agency Information Notice
- TransUnion Credit Reference Agency Information Notice
- Equifax Credit Reference Agency Information Notice
We also take information from CRAs to allow us to make decisions about your credit account and credit facility.
Fraud prevention services - Before we provide goods and services to you, we may use third parties to undertake fraud and money laundering checks and verify your identity. These organisations will report to us on industry fraud indicators and if they have reason to believe an identity is fraudulent. If we have reason to suspect fraud or other criminal offences we will pass your personal information to fraud prevention agencies or law enforcement agencies for the detection, investigation and prevention of crime. If we think there is a risk of fraud, we may suspend activity on your account or refuse access to your account and/or cancel an order. If we do this we will inform you by email or SMS and ask you to contact us.
Debt collection agencies (DCAs) - If you default on repayments to your credit account we may share your data with DCAs to allow them to collect the outstanding debts from you.
Debt purchase companies – Where appropriate will share certain information on defaulted accounts with prospective debt purchasers as part of the negotiations for sale of the debt.
Debt management companies – where we have received appropriate instruction we will share information about your credit account with debt management companies to allow them to assist you with managing your debts.
Research and analytics companies - We may share personal details to allow research companies and feedback providers to contact you directly on our behalf in order to capture your opinions on our products, services, websites and apps. We may ask these research companies to analyse the results so that we can better understand your online experience, which will help us to improve our services. We only provide them with the information they need to perform their function. This may take the form of a survey, where you may be asked to review a product or service you’ve bought or provide general feedback on our products and services. You will always have the choice about whether to take part in our market research or surveys. We may share information with specialist companies to analyse customer information to help us better understand how you use our services and to tailor products, services and offers that may be relevant for you. We utilise companies that help us track and record the way you navigate our website, so that we can understand your online experience and use it to improve our services and offer a more personalised experience.
Product technicians - We use professional third party companies to assist us in independently reviewing issues and complaints with our products. We will share information with these technicians to allow them to review the product and return it to you or to review the product in your home.
General service companies - Such as insurance companies, printers and mailing houses that assist us in providing our products and services.
Regulators and law enforcement - We will share data with regulators and other official bodies (including law enforcement such as the Police) if they make formal requests or pursuant to legal proceedings.
Our main operations are based in the UK and your personal information is generally processed, stored and used within the UK and other countries in the European Economic Area (EEA). In some instances your personal information may be processed outside the European Economic Area. For example, NEXT operates a call centre in Pune, India. Operatives in this location will have access to your account information in order to assist you with your query. We also work with suppliers and partners who may make use of Cloud and /or hosted technologies across multiple geographies.
If and when this is the case we take steps to ensure there is an appropriate level of security so your personal information is protected in the same way as if it was being used within the UK.
Where we need to transfer your data outside of the UK or EEA we will use one of the following safeguards:
We always ensure that personal data is secure by continuously developing our security systems and training for our employees. We have implemented appropriate technical and organisational security measures designed to protect your personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful or unauthorised forms of processing, in accordance with applicable law.
If you use any third party apps, websites or services to access our services, your usage is subject to the relevant third party's terms and conditions, cookies policy, and privacy policy. For example, if you interact with us on social media, your use is subject to the terms and conditions and privacy policies of the relevant social media platform (Facebook, Twitter etc.). The same applies if you use third party services, like Amazon's Alexa. In certain cases we may be required to share your personal information, in relation to transactions and usage of the services, with the relevant third party.
Should you need to contact us please write to:
Data Protection Officer
NEXT Plc
Desford Road
Enderby
Leicester
LE19 4AT
or you can email: dataprotection@next.co.uk