Separately from analytics, we keep a record of activity on the website so that we can investigate a disputed order, a suspected account takeover, fraud, or automated scraping of our catalogue and pricing. This record covers pages visited, actions taken (signing in, failed sign-in attempts, basket and checkout steps, orders, quotes, downloads), your IP address, and your browser, operating system and device type.
It deliberately excludes passwords, card numbers, security codes, and the contents of anything you type. Web addresses are stored without their query strings, because those can contain sign-in and password-reset links.
Activity records are deleted automatically after 180 days. A smaller set of security-significant events is also written to our audit log and kept for longer, because we may need it to defend or resolve a legal claim.
Where you are signed in, we rely on our legitimate interest in keeping accounts and payments secure, preventing fraud, and resolving disputes — not on consent, since a security record that could be switched off would not protect anyone. Where you are not signed in, this is only recorded if you accept analytics cookies, and it is linked to a random browser identifier rather than to your name or contact details.
Access is restricted to named staff granted it explicitly for support, security or fraud investigation, and every search of the record is itself logged. You may object to this processing or request a copy using the contact details below.