Privacy Policy
Privacy Policy
Last updated: 16 June 2026

1. Who we are
Undercover Genius Ltd (trading as BioMirco) is the data controller. Company No. 14013075. Registered office: BioMirco c/o Undercover Genius Ltd, 2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE, England. VAT No. 455 0402 22. We are registered with the UK Information Commissioner's Office (ICO), registration reference ZC178301.
2. What data we collect
- Information you provide when ordering (name, address, email, phone, payment information)
- Information you provide via newsletter signup or account creation
- Information about how you use our website (cookies, analytics, only with your consent)
3. How we use your data
- To process and fulfil your orders
- To send you order updates, dispatch notifications, and post-purchase information
- With your consent, to send you marketing emails about new products, offers, and content
- To improve our website and customer experience
- To comply with our legal obligations (tax, accounting, fraud prevention)
4. Lawful basis
We process your personal data under one or more of:
- Contract. To fulfil your order.
- Consent. For marketing communications and non-essential cookies.
- Legitimate interests. To run our business and improve our service.
- Legal obligation. For tax, accounting, and regulatory compliance.
5. Who we share data with
We share data only with providers necessary to operate our business. Payment processors (Shopify Payments, Stripe), shipping providers, email service providers (MailerLite), and analytics tools. We never sell your data.
6. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, and object to processing of your personal data. To exercise any of these rights, email hello@biomirco.com.
7. Cookies
See our Cookie Policy for details on the cookies we use and how to manage them.
8. International transfers
Some of our service providers (e.g. Shopify, MailerLite) are based outside the UK. Where data is transferred internationally, we ensure appropriate safeguards (UK adequacy decisions or Standard Contractual Clauses).
9. How long we keep your data
We keep order data for 7 years (HMRC requirement). Marketing data is retained until you unsubscribe.
10. Complaints
If you are not happy with how we handle your data, you can complain to the UK Information Commissioner's Office at ico.org.uk.