What data we collect, why we collect it, who we share it with, and how to get it deleted.
Last updated: 11 July 2026 · Data controller: Replica Sabers, 4 Mill Grange, Caistor, Lincolnshire, LN7 6JG
The short version. We collect what we need to sell you a saber and get it to your door. We do not sell your data. You can ask us to show you what we hold, correct it, or delete it — and we will.
Replica Sabers is the data controller for the personal data described here. Contact us at jedimaster@replicasabers.co.uk for any privacy matter.
| Data | Why | Lawful basis |
|---|---|---|
| Name, email, delivery address, phone | To process and deliver your order, and to contact you about it | Contract |
| Payment details | Handled entirely by our payment provider — we never see or store your full card number | Contract |
| Order history | Warranty claims, returns, and support | Contract / legal obligation |
| Email address (marketing) | To send you updates, if you opted in | Consent |
| Website usage & cookies | To keep the site working and understand what people find useful | Consent / legitimate interests |
| Age confirmation | Legal requirement for bladed items | Legal obligation |
We share only what is necessary, only with parties who need it:
We do not sell your personal data. We do not share it with advertisers or data brokers.
In the event of a chargeback or evidence of fraud, we may share relevant transaction details with payment processors and fraud prevention services, as permitted by data protection law.
Under UK GDPR you have the right to:
Email jedimaster@replicasabers.co.uk and we will respond within one month. There is no charge.
We use cookies to keep the site working (your basket, your login) and to understand how the site is used. You can control cookies through your browser settings or our cookie banner. Blocking essential cookies will break the checkout.
We only send marketing email if you opted in. Every email has an unsubscribe link, and it works immediately. You can also just email us and ask to be removed.
The site runs over HTTPS. Card data is handled by our payment provider and never touches our servers. Access to customer data is limited to those who need it to do their job.
No system is perfectly secure. If a breach occurs that is likely to risk your rights and freedoms, we will notify the ICO within 72 hours and tell you without undue delay.
Some of our providers operate outside the UK. Where data is transferred, it is protected by adequacy regulations or standard contractual clauses.
Our site is not directed at children under 13, and we do not knowingly collect their data. If you believe we have, contact us and we will delete it.
If you are unhappy with how we have handled your data, please tell us first — we would like the chance to fix it.
You also have the right to complain to the Information Commissioner's Office: ico.org.uk, or 0303 123 1113.
We may update this policy. The “last updated” date at the top will always tell you when. Material changes will be flagged on the site.