Effective date: 01 January 2025
Last updated: 02 March 2026
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use the MenTools website, create an account, place orders, access digital products, or contact us.
This website is operated by Loico Ltd trading as MenTools (“MenTools”, “we”, “us”, “our”). Loico Ltd is the data controller responsible for your personal data.
Company: Loico Ltd (England & Wales) – Company number 11994296
Registered office: Dale House, 64 Fink Hill, Horsforth, Leeds, England, LS18 4DH
Privacy contact email: support@mentools.co
If you have concerns, please contact us first and we’ll try to resolve them. You also have the right to complain to the Information Commissioner’s Office (ICO) (UK).
We may collect and process the following categories of personal data:
A. Account and identity data
Name (if provided)
Email address
Account credentials (password is stored in encrypted/hashed form)
Account settings/preferences
B. Order and transaction data
Products purchased (digital and/or physical)
Order IDs, invoices/receipts
Payment status, refunds, disputes/chargebacks
Pricing, currency, VAT/tax info where applicable
Important: We do not store full payment card details. Card payments are processed by our payment provider (Stripe). (See Section 6.)
C. Delivery data (physical products)
Shipping name and address
Delivery updates and correspondence related to shipping
D. Digital access and usage data
Records of digital product access/download availability through your account
Website interactions (pages viewed, clicks, approximate location derived from IP, device/browser info)
E. Support and communications
Messages you send to us (email, forms, support tickets)
Our responses and related logs
F. Marketing preferences
Whether you opted in/out of marketing
Email engagement (e.g., delivery, opens/clicks where tracking is enabled)
G. Cookies and similar technologies
Cookie identifiers and preferences (see Section 8)
We do not intentionally collect “special category” data (e.g., health data). If you choose to include sensitive information in messages to us, we will process it only to respond to your request.
We collect data:
Directly from you when you place an order, create/login to an account, complete a form, subscribe to emails, or contact support.
Automatically via cookies and similar technologies when you browse the site (see Section 8).
From service providers involved in processing payments, sending emails, analytics, security, and fraud prevention (see Section 6).
We only use personal data where the law allows us. Common lawful bases include: contract, legal obligation, legitimate interests, and consent.
A. To create and manage your account
Purpose: account creation (including automatic creation at checkout), authentication, account security
Lawful basis: contract; legitimate interests (security)
B. To process and fulfil orders (digital + physical)
Purpose: confirmations, making digital products available in your account, dispatching physical products, customer service
Lawful basis: contract
C. To take payments, prevent fraud, and manage disputes/chargebacks
Purpose: payment processing, risk screening, responding to disputes
Lawful basis: contract; legitimate interests (fraud prevention); legal obligation where applicable
D. To meet legal/accounting/tax requirements
Purpose: invoices, VAT/tax records, compliance
Lawful basis: legal obligation
E. To provide support and handle requests
Purpose: respond to messages, resolve complaints, process returns/refunds
Lawful basis: contract; legitimate interests (customer service)
F. To improve our website and products
Purpose: analytics, performance monitoring, troubleshooting, security
Lawful basis: legitimate interests (running and improving our business)
G. Marketing (where permitted)
Purpose: send newsletters and offers
Lawful basis: consent (where required) and/or legitimate interests for similar-product communications where permitted by law. You can opt out at any time.
We may share personal data with trusted third parties where necessary, including:
Payment processing: Stripe (to process payments and manage disputes/fraud)
Email delivery / marketing tools: providers that send order emails and marketing emails
Website hosting and technical providers: hosting, storage, content delivery, security
Analytics providers: website usage analytics (where enabled and permitted)
Shipping / fulfilment partners: carriers and fulfilment services (for physical deliveries)
Professional advisers: legal/accounting/insurance where necessary
Authorities/regulators: where required by law or to protect rights and safety
We require service providers to protect personal data and process it only on our instructions.
We do not sell your personal data.
Payments on the MenTools website are processed by Stripe. Stripe acts as an independent controller for certain processing and/or a processor depending on context, and handles payment card data securely. We receive transaction references and payment status information needed to fulfil your order and provide customer support.
Some service providers may process data outside the UK/EEA. Where we transfer personal data internationally, we use appropriate safeguards such as adequacy decisions and/or standard contractual clauses and take steps to ensure data remains protected.
We use cookies and similar technologies for:
Essential site functions (e.g., login/session, security)
Preferences (remember settings)
Analytics (understanding site usage)
Marketing (where enabled)
Where required by law (UK/EU), we will ask for your consent before setting non-essential cookies. You can change cookie preferences at any time using our cookie banner/settings (where available) or your browser controls.
We keep personal data only as long as necessary for the purposes described above, including legal/accounting requirements. Typical retention periods:
Order and accounting records: typically 6 years (UK standard limitation/accounting practice)
Account data: for as long as your account remains active; then deleted or anonymised within a reasonable period unless we must keep certain records
Support communications: typically up to 24 months after closure
Analytics data: typically 12–26 months depending on configuration
We may retain anonymised/aggregated data longer where it no longer identifies you.
You have rights under UK/EU data protection law, including:
access to your data
correction
erasure (in certain circumstances)
restriction
objection (including to direct marketing)
data portability
withdrawal of consent (where processing is based on consent)
To exercise your rights, email support@mentools.co. We may need to verify your identity to protect your information. We aim to respond within one month (or longer where legally permitted for complex requests).
We take appropriate technical and organisational measures to protect personal data, including access controls and encryption in transit where appropriate. No method of transmission or storage is completely secure, but we work to maintain safeguards and respond to incidents as required by law.
The website is not intended for children under 16, and we do not knowingly collect personal data from children.
The Site may link to third-party websites. We are not responsible for their privacy practices. Please review third-party privacy policies before providing information.
We may update this policy from time to time. We will post the updated version on this page and update the “Last updated” date.
Questions, requests, and complaints about this notice or our handling of personal data should be sent to support@mentools.co. You can also lodge a complaint with the UK Information Commissioner’s Office (ICO).
If you are located in the EU/EEA and have questions or concerns regarding your personal data, you may contact our appointed GDPR representative:
EU Representative:
Euverify Ltd (Ireland)
Unit 3D North Point House
North Point Business Park
New Mallow Road
Cork
T23 AT2P
Ireland
Email: gdpr@euverify.com
To submit a Data Subject Access Request (DSAR), data deletion request, or any other GDPR-related inquiry, please use our secure portal:
https://gdpr.euverify.com/verify/c623bb29-585e-4cfd-a1c5-987360ce4b22
This portal allows you to verify our appointed representative and submit GDPR requests directly. Requests submitted through this portal are logged and tracked to support timely responses and compliance.
(Note: The EU/EEA representative acts as a contact point for data subjects and supervisory authorities; responsibility for GDPR compliance remains with MenTools.)
We may receive visitors from the United States. This Privacy Policy describes our general practices for the Site. If specific US state privacy laws apply to our processing (for example, based on our activities and applicable thresholds), we will provide any additional notices and rights required by law. For any privacy requests, contact support@mentools.co.
